read-cache: avoid using git_path() in freshen_shared_index()

When performing an interactive rebase in split-index mode, the commit message that one should rework when squashing commits can contain some garbage instead of the usual concatenation of both of the commit messages. The code uses git_path() to compute the shared index filename, and passes it to check_and_freshen_file() as its argument; there is no guarantee that the rotating pathname buffer passed as argument will stay valid during the life of this call. Make our own copy before calling the function and pass the copy as its argument to avoid this risky pattern. Signed-off-by: Christian Couder <chriscool@tuxfamily.org> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Christian Couder committed Mar 30, 2017 at 23:03 UTC ccef2bb5fa752fac9351cabc61c1362c85d620ee
1 file changed +2 -1
read-cache.c
+2 -1
@@ -1690,9 +1690,10 @@ unmap:
1690 */
1691 static void freshen_shared_index(char *base_sha1_hex, int warn)
1692 {
1693 - const char *shared_index = git_path("sharedindex.%s", base_sha1_hex);
1693 + char *shared_index = git_pathdup("sharedindex.%s", base_sha1_hex);
1694 if (!check_and_freshen_file(shared_index, 1) && warn)
1695 warning("could not freshen shared index '%s'", shared_index);
1696 + free(shared_index);
1697 }
1698
1699 int read_index_from(struct index_state *istate, const char *path)