diffcore-break: guard against NULLed queue entries in merge loop
The outer loop in `diffcore_merge_broken()` sets `q->queue[j]` to NULL when it merges a broken pair back together, and has a NULL check to skip such entries on subsequent iterations. The inner loop, however, lacks this guard: when it scans forward looking for a matching peer, it can encounter a slot that was NULLed by a previous outer-loop iteration and dereference it unconditionally. In practice this requires at least two broken pairs whose peers both survive rename/copy detection and appear later in the queue, which is rare but not impossible. Add the same `if (!pp) continue` guard to the inner loop. Pointed out by Coverity. Assisted-by: Claude Opus 4.6 Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de> Signed-off-by: Junio C Hamano <gitster@pobox.com>main
parent
f85a7e6620
commit
a6b8f01431
|
|
@ -289,6 +289,8 @@ void diffcore_merge_broken(void)
|
||||||
*/
|
*/
|
||||||
for (j = i + 1; j < q->nr; j++) {
|
for (j = i + 1; j < q->nr; j++) {
|
||||||
struct diff_filepair *pp = q->queue[j];
|
struct diff_filepair *pp = q->queue[j];
|
||||||
|
if (!pp)
|
||||||
|
continue;
|
||||||
if (pp->broken_pair &&
|
if (pp->broken_pair &&
|
||||||
!strcmp(pp->one->path, pp->two->path) &&
|
!strcmp(pp->one->path, pp->two->path) &&
|
||||||
!strcmp(p->one->path, pp->two->path)) {
|
!strcmp(p->one->path, pp->two->path)) {
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue