receive-pack: crash when checking with non-exist HEAD

If HEAD of a repository points to a conflict reference, such as: * There exist a reference named 'refs/heads/jx/feature1', but HEAD points to 'refs/heads/jx', or * There exist a reference named 'refs/heads/feature', but HEAD points to 'refs/heads/feature/bad'. When we push to delete a reference for this repo, such as: git push /path/to/bad-head-repo.git :some/good/reference The git-receive-pack process will crash. This is because if HEAD points to a conflict reference, the function `resolve_refdup("HEAD", ...)` does not return a valid reference name, but a null buffer. Later matching the delete reference against the null buffer will cause git-receive-pack crash. Signed-off-by: Jiang Xin <worldhello.net@gmail.com> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Jiang Xin committed Jul 22, 2015 at 09:49 UTC b112b14d7869bf3c000abb84cd22e57dd811d031
1 file changed +1 -1
builtin/receive-pack.c
+1 -1
@@ -514,7 +514,7 @@ static const char *update(struct command *cmd, struct shallow_info *si)
514 return "deletion prohibited";
515 }
516
517 - if (!strcmp(namespaced_name, head_name)) {
517 + if (head_name && !strcmp(namespaced_name, head_name)) {
518 switch (deny_delete_current) {
519 case DENY_IGNORE:
520 break;