blame: fix segfault on untracked files

Since 3b75ee9 ("blame: allow to blame paths freshly added to the index", 2016-07-16) git blame also looks at the index to determine if there is a file that was freshly added to the index. cache_name_pos returns -pos - 1 in case there is no match is found, or if the name matches, but the entry has a stage other than 0. As git blame should work for unmerged files, it uses strcmp to determine whether the name of the returned position matches, in which case the file exists, but is merely unmerged, or if the file actually doesn't exist in the index. If the repository is empty, or if the file would lexicographically be sorted as the last file in the repository, -cache_name_pos - 1 is outside of the length of the active_cache array, causing git blame to segfault. Guard against that, and die() normally to restore the old behaviour. Reported-by: Simon Ruderich <simon@ruderich.org> Signed-off-by: Thomas Gummerer <t.gummerer@gmail.com> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Thomas Gummerer committed Aug 27, 2016 at 21:01 UTC bc6b13a7d2300e982dd3a3aeef2f3ad4d39cf149
2 files changed +7 -1
builtin/blame.c
+2 -1
@@ -2245,7 +2245,8 @@ static void verify_working_tree_path(struct commit *work_tree, const char *path)
2245 pos = cache_name_pos(path, strlen(path));
2246 if (pos >= 0)
2247 ; /* path is in the index */
2248 - else if (!strcmp(active_cache[-1 - pos]->name, path))
2248 + else if (-1 - pos < active_nr &&
2249 + !strcmp(active_cache[-1 - pos]->name, path))
2250 ; /* path is in the index, unmerged */
2251 else
2252 die("no such path '%s' in HEAD", path);
t/t8002-blame.sh
+5
@@ -6,6 +6,11 @@ test_description='git blame'
6 PROG='git blame -c'
7 . "$TEST_DIRECTORY"/annotate-tests.sh
8
9 +test_expect_success 'blame untracked file in empty repo' '
10 + >untracked &&
11 + test_must_fail git blame untracked
12 +'
13 +
14 PROG='git blame -c -e'
15 test_expect_success 'blame --show-email' '
16 check_count \