builtin/fetch: fix leaking transaction with `--atomic`

With the `--atomic` flag, we use a single ref transaction to commit all ref updates in git-fetch(1). The lifetime of transactions is somewhat weird: while `ref_transaction_abort()` will free the transaction, a call to `ref_transaction_commit()` won't. We thus have to manually free the transaction in the successful case. Adapt the code to free the transaction in the exit path to plug the resulting memory leak. As `ref_transaction_abort()` already freed the transaction for us, we have to unset the transaction when we hit that code path to not cause a double free. Signed-off-by: Patrick Steinhardt <ps@pks.im> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Patrick Steinhardt committed Aug 22, 2024 at 11:18 UTC c92abe71dfa154d62dc36f1bc7b6c00184c5dbda
2 files changed +5 -4
builtin/fetch.c
+4 -4
@@ -1731,11 +1731,8 @@ static int do_fetch(struct transport *transport,
1731 goto cleanup;
1732
1733 retcode = ref_transaction_commit(transaction, &err);
1734 - if (retcode) {
1735 - ref_transaction_free(transaction);
1736 - transaction = NULL;
1734 + if (retcode)
1735 goto cleanup;
1738 - }
1736 }
1737
1738 commit_fetch_head(&fetch_head);
@@ -1803,8 +1800,11 @@ cleanup:
1800 if (transaction && ref_transaction_abort(transaction, &err) &&
1801 err.len)
1802 error("%s", err.buf);
1803 + transaction = NULL;
1804 }
1805
1806 + if (transaction)
1807 + ref_transaction_free(transaction);
1808 display_state_release(&display_state);
1809 close_fetch_head(&fetch_head);
1810 strbuf_release(&err);
t/t5574-fetch-output.sh
+1
@@ -5,6 +5,7 @@ test_description='git fetch output format'
5 GIT_TEST_DEFAULT_INITIAL_BRANCH_NAME=main
6 export GIT_TEST_DEFAULT_INITIAL_BRANCH_NAME
7
8 +TEST_PASSES_SANITIZE_LEAK=true
9 . ./test-lib.sh
10
11 test_expect_success 'fetch with invalid output format configuration' '