builtin/tag: fix leaking key ID on failure to sign

We do not free the key ID when signing a tag fails. Do so by using the common exit path. Signed-off-by: Patrick Steinhardt <ps@pks.im> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Patrick Steinhardt committed Nov 5, 2024 at 07:17 UTC d06e3ec858d4863baa5f918db414e890b08891d7
2 files changed +2 -1
builtin/tag.c
+1 -1
@@ -164,7 +164,7 @@ static int do_sign(struct strbuf *buffer, struct object_id **compat_oid,
164 int ret = -1;
165
166 if (sign_buffer(buffer, &sig, keyid))
167 - return -1;
167 + goto out;
168
169 if (compat) {
170 const struct git_hash_algo *algo = the_repository->hash_algo;
t/t7004-tag.sh
+1
@@ -10,6 +10,7 @@ Tests for operations with tags.'
10 GIT_TEST_DEFAULT_INITIAL_BRANCH_NAME=main
11 export GIT_TEST_DEFAULT_INITIAL_BRANCH_NAME
12
13 +TEST_PASSES_SANITIZE_LEAK=true
14 . ./test-lib.sh
15 . "$TEST_DIRECTORY"/lib-gpg.sh
16 . "$TEST_DIRECTORY"/lib-terminal.sh