builtin/pull: fix leaking "ff" option

The `opt_ff` field gets populated either via `OPT_PASSTHRU` via `config_get_ff()` or when `--rebase` is passed. So we sometimes end up overriding the value in `opt_ff` with another value, but we do not free the old value, causing a memory leak. Adapt the type of the variable to be `char *` and consistently assign allocated strings to it such that we can easily free it when it is being overridden. Signed-off-by: Patrick Steinhardt <ps@pks.im> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Patrick Steinhardt committed Sep 26, 2024 at 13:46 UTC 49af1b772222673759756048344b142544d39849
2 files changed +8 -4
builtin/pull.c
+7 -4
@@ -84,7 +84,7 @@ static const char *opt_squash;
84 static const char *opt_commit;
85 static const char *opt_edit;
86 static const char *cleanup_arg;
87 -static const char *opt_ff;
87 +static char *opt_ff;
88 static const char *opt_verify_signatures;
89 static const char *opt_verify;
90 static int opt_autostash = -1;
@@ -1024,8 +1024,10 @@ int cmd_pull(int argc, const char **argv, const char *prefix)
1024 * "--rebase" can override a config setting of
1025 * pull.ff=only.
1026 */
1027 - if (opt_rebase >= 0 && opt_ff && !strcmp(opt_ff, "--ff-only"))
1028 - opt_ff = "--ff";
1027 + if (opt_rebase >= 0 && opt_ff && !strcmp(opt_ff, "--ff-only")) {
1028 + free(opt_ff);
1029 + opt_ff = xstrdup("--ff");
1030 + }
1031 }
1032
1033 if (opt_rebase < 0)
@@ -1135,7 +1137,8 @@ int cmd_pull(int argc, const char **argv, const char *prefix)
1137
1138 if (can_ff) {
1139 /* we can fast-forward this without invoking rebase */
1138 - opt_ff = "--ff-only";
1140 + free(opt_ff);
1141 + opt_ff = xstrdup("--ff-only");
1142 ret = run_merge();
1143 } else {
1144 ret = run_rebase(&newbase, &upstream);
t/t7601-merge-pull-config.sh
+1
@@ -4,6 +4,7 @@ test_description='git merge
4
5 Testing pull.* configuration parsing and other things.'
6
7 +TEST_PASSES_SANITIZE_LEAK=true
8 . ./test-lib.sh
9
10 test_expect_success 'setup' '