notes: avoid potential use-after-free during insertion

The note_tree_insert() function may free the leaf_node struct we pass in (e.g., if it's a duplicate, or if it needs to be combined with an existing note). Most callers are happy with this, as they assume that ownership of the struct is handed off. But in load_subtree(), if we see an error we'll use the handed-off struct's key_oid to generate the die() message, potentially accessing freed memory. We can easily fix this by instead using the original oid that we copied into the leaf_node struct. Signed-off-by: Jeff King <peff@peff.net> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Jeff King committed Aug 25, 2019 at 03:19 UTC 60fe477a0be2a3801e5ce3913e0be8e8e2e58e4f
1 file changed +1 -1
notes.c
+1 -1
@@ -460,7 +460,7 @@ static void load_subtree(struct notes_tree *t, struct leaf_node *subtree,
460 die("Failed to load %s %s into notes tree "
461 "from %s",
462 type == PTR_TYPE_NOTE ? "note" : "subtree",
463 - oid_to_hex(&l->key_oid), t->ref);
463 + oid_to_hex(&object_oid), t->ref);
464
465 continue;
466