checkout: check return value of resolve_refdup before using hash
If resolve_refdup() fails it returns NULL and possibly leaves its hash output parameter untouched. Make sure to use it only if the function succeeded, in order to avoid accessing uninitialized memory. Found with t/t2011-checkout-invalid-head.sh --valgrind. Signed-off-by: Rene Scharfe <l.s.r@web.de> Signed-off-by: Junio C Hamano <gitster@pobox.com>
René Scharfe committed
May 6, 2017 at 19:13 UTC
79e913c24aa37d0ede9ed9e8962a19634ae5129a
1 file changed
+2
-1
builtin/checkout.c
+2
-1
@@ -814,7 +814,8 @@ static int switch_branches(const struct checkout_opts *opts,
814
int flag, writeout_error = 0;
815
memset(&old, 0, sizeof(old));
816
old.path = path_to_free = resolve_refdup("HEAD", 0, rev.hash, &flag);
817
- old.commit = lookup_commit_reference_gently(rev.hash, 1);
817
+ if (old.path)
818
+ old.commit = lookup_commit_reference_gently(rev.hash, 1);
819
if (!(flag & REF_ISSYMREF))
820
old.path = NULL;
821