http-push: free curl header lists

To pass headers to curl, we have to allocate a curl_slist linked list and then feed it to curl_easy_setopt(). But the header list is not copied by curl, and must remain valid until we are finished with the request. A few spots in http-push get this right, freeing the list after finishing the request, but many do not. In most cases the fix is simple: we set up the curl slot, start it, and then use run_active_slot() to take it to completion. After that, we don't need the headers anymore and can call curl_slist_free_all(). But one case is trickier: when we do a MOVE request, we start the request but don't immediately finish it. It's possible we could change this to be more like the other requests, but I didn't want to get into risky refactoring of this code. So we need to stick the header list into the request struct and remember to free it later. Curiously, the struct already has a headers field for this purpose! It goes all the way back to 58e60dd203 (Add support for pushing to a remote repository using HTTP/DAV, 2005-11-02), but it doesn't look like it was ever used. We can make use of it just by assigning our headers to it, and there is already code in finish_request() to clean it up. This fixes several leaks triggered by t5540. Signed-off-by: Jeff King <peff@peff.net> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Jeff King committed Sep 24, 2024 at 18:05 UTC 747a71019c49d41f46f70562102869e947d944ad
1 file changed +5
http-push.c
+5
@@ -437,9 +437,11 @@ static void start_move(struct transfer_request *request)
437 if (start_active_slot(slot)) {
438 request->slot = slot;
439 request->state = RUN_MOVE;
440 + request->headers = dav_headers;
441 } else {
442 request->state = ABORTED;
443 FREE_AND_NULL(request->url);
444 + curl_slist_free_all(dav_headers);
445 }
446 }
447
@@ -1398,6 +1400,7 @@ static int update_remote(const struct object_id *oid, struct remote_lock *lock)
1400 if (start_active_slot(slot)) {
1401 run_active_slot(slot);
1402 strbuf_release(&out_buffer.buf);
1403 + curl_slist_free_all(dav_headers);
1404 if (results.curl_result != CURLE_OK) {
1405 fprintf(stderr,
1406 "PUT error: curl result=%d, HTTP code=%ld\n",
@@ -1407,6 +1410,7 @@ static int update_remote(const struct object_id *oid, struct remote_lock *lock)
1410 }
1411 } else {
1412 strbuf_release(&out_buffer.buf);
1413 + curl_slist_free_all(dav_headers);
1414 fprintf(stderr, "Unable to start PUT request\n");
1415 return 0;
1416 }
@@ -1516,6 +1520,7 @@ static void update_remote_info_refs(struct remote_lock *lock)
1520 results.curl_result, results.http_code);
1521 }
1522 }
1523 + curl_slist_free_all(dav_headers);
1524 }
1525 strbuf_release(&buffer.buf);
1526 }