builtin/blame: destroy initialized commit_info only
Since ea02ffa3 (mailmap: simplify map_user() interface, 2013-01-05), find_alignment() has been invoking commit_info_destroy() on an uninitialized auto 'struct commit_info' (when METAINFO_SHOWN is not set). commit_info_destroy() calls strbuf_release() for each 'commit_info' strbuf member, which randomly invokes free() on whatever random stack value happens to reside in strbuf.buf, thus leading to periodic crashes. Reported-by: Dilyan Palauzov <dilyan.palauzov@aegee.org> Signed-off-by: Eric Sunshine <sunshine@sunshineco.com> Signed-off-by: Junio C Hamano <gitster@pobox.com>
Eric Sunshine committed
Feb 9, 2015 at 16:28 UTC
e60059276b26db5760e36aa85cf1091f662430fb
1 file changed
+2
-3
builtin/blame.c
+2
-3
@@ -1843,7 +1843,6 @@ static void find_alignment(struct scoreboard *sb, int *option)
1843
1844
for (e = sb->ent; e; e = e->next) {
1845
struct origin *suspect = e->suspect;
1846
- struct commit_info ci;
1846
int num;
1847
1848
if (compute_auto_abbrev)
@@ -1854,6 +1853,7 @@ static void find_alignment(struct scoreboard *sb, int *option)
1853
if (longest_file < num)
1854
longest_file = num;
1855
if (!(suspect->commit->object.flags & METAINFO_SHOWN)) {
1856
+ struct commit_info ci;
1857
suspect->commit->object.flags |= METAINFO_SHOWN;
1858
get_commit_info(suspect->commit, &ci, 1);
1859
if (*option & OUTPUT_SHOW_EMAIL)
@@ -1862,6 +1862,7 @@ static void find_alignment(struct scoreboard *sb, int *option)
1862
num = utf8_strwidth(ci.author.buf);
1863
if (longest_author < num)
1864
longest_author = num;
1865
+ commit_info_destroy(&ci);
1866
}
1867
num = e->s_lno + e->num_lines;
1868
if (longest_src_lines < num)
@@ -1871,8 +1872,6 @@ static void find_alignment(struct scoreboard *sb, int *option)
1872
longest_dst_lines = num;
1873
if (largest_score < ent_score(sb, e))
1874
largest_score = ent_score(sb, e);
1874
-
1875
- commit_info_destroy(&ci);
1875
}
1876
max_orig_digits = decimal_width(longest_src_lines);
1877
max_digits = decimal_width(longest_dst_lines);