fsck: do not reuse child_process structs

The run-command API makes no promises about what is left in a struct child_process after a command finishes, and it's not safe to simply reuse it again for a similar command. In particular: - if you use child->args or child->env_array, they are cleared after finish_command() - likewise, start_command() may point child->argv at child->args->argv; reusing that would lead to accessing freed memory - the in/out/err may hold pipe descriptors from the previous run These two calls are _probably_ OK because they do not use any of those features. But it's only by chance, and may break in the future; let's reinitialize our struct for each program we run. Signed-off-by: Jeff King <peff@peff.net> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Jeff King committed Nov 12, 2018 at 09:46 UTC 4d0984bebc5fc5662d2891ee41f7d49c32488744
1 file changed +6
builtin/fsck.c
+6
@@ -841,6 +841,9 @@ int cmd_fsck(int argc, const char **argv, const char *prefix)
841
842 prepare_alt_odb(the_repository);
843 for (alt = the_repository->objects->alt_odb_list; alt; alt = alt->next) {
844 + child_process_init(&commit_graph_verify);
845 + commit_graph_verify.argv = verify_argv;
846 + commit_graph_verify.git_cmd = 1;
847 verify_argv[2] = "--object-dir";
848 verify_argv[3] = alt->path;
849 if (run_command(&commit_graph_verify))
@@ -859,6 +862,9 @@ int cmd_fsck(int argc, const char **argv, const char *prefix)
862
863 prepare_alt_odb(the_repository);
864 for (alt = the_repository->objects->alt_odb_list; alt; alt = alt->next) {
865 + child_process_init(&midx_verify);
866 + midx_verify.argv = midx_argv;
867 + midx_verify.git_cmd = 1;
868 midx_argv[2] = "--object-dir";
869 midx_argv[3] = alt->path;
870 if (run_command(&midx_verify))