mingw: make `exit_process()` own the process handle on all paths

After "mingw: kill child processes in a gentler way", the ownership of the HANDLE passed to `exit_process()` and `terminate_process_tree()` is inconsistent. `terminate_process_tree()` always closes the handle; `exit_process()` closes it on success and on the terminate-tree fallback, but leaks it on the early return where GetExitCodeProcess() fails or reports the process is no longer STILL_ACTIVE. `mingw_kill()` compensated by closing the handle on its own error path, which is a double-close on every error path that does not hit that one leaky branch -- the callee has already closed the handle by then. Coverity flagged the resulting use-after-free as CID 1437238. Pin down the invariant that `exit_process()` and `terminate_process_tree()` own the handle from the call onward and close it on every return path; with that, the bogus close in `mingw_kill()` goes away. Assisted-by: Opus 4.7 Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Johannes Schindelin committed Jul 5, 2026 at 08:24 UTC 9184231173dea25e922a0ee6ced938c57bca37e5
2 files changed +2 -3
compat/mingw.c
+1 -3
@@ -2269,10 +2269,8 @@ int mingw_kill(pid_t pid, int sig)
2269 }
2270 ret = terminate_process_tree(h, 128 + sig);
2271 }
2272 - if (ret) {
2272 + if (ret)
2273 errno = err_win_to_posix(GetLastError());
2274 - CloseHandle(h);
2275 - }
2274 return ret;
2275 } else if (pid > 0 && sig == 0) {
2276 HANDLE h = OpenProcess(PROCESS_QUERY_INFORMATION, FALSE, pid);
compat/win32/exit-process.h
+1
@@ -159,6 +159,7 @@ static int exit_process(HANDLE process, int exit_code)
159 return terminate_process_tree(process, exit_code);
160 }
161
162 + CloseHandle(process);
163 return 0;
164 }
165