From: Jeff King Date: Thu, 2 Jul 2026 08:04:11 +0000 (-0400) Subject: patch-id: discard hash when done X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=64b69225620a4119e1ee6e02620c56a58dc442fb;p=thirdparty%2Fgit.git patch-id: discard hash when done When computing a patch-id, we have a flush_one_hunk() helper that calls git_hash_final() on our running hunk git_hash_ctx, and then reinitializes that context for the next hunk. When we run out of hunks to look at, we return, discarding the git_hash_ctx. This can cause a leak if the hash implementation we are using allocates any memory during its initialization. This includes OpenSSL >= 3.0, for both SHA-1 and SHA-256. Normally we would not use SHA-1 here at all, as we only recommend using non-DC implementations for the "unsafe" variant (and patch-id, though they probably _could_ use the unsafe variant, were never taught to do so). But it is certainly a problem for SHA-256, which you can see with: make SANITIZE=leak \ OPENSSL_SHA256=1 \ GIT_TEST_DEFAULT_HASH=sha256 \ test That results in leak failures of 60 scripts, 57 of which are fixed by this patch (basically anything which runs rebase will hit this case). Signed-off-by: Jeff King Signed-off-by: Junio C Hamano --- diff --git a/builtin/patch-id.c b/builtin/patch-id.c index 2781598ede..57d9bd4a65 100644 --- a/builtin/patch-id.c +++ b/builtin/patch-id.c @@ -173,6 +173,7 @@ static size_t get_one_patchid(struct object_id *next_oid, struct object_id *resu oidclr(next_oid, the_repository->hash_algo); flush_one_hunk(result, &ctx); + git_hash_discard(&ctx); return patchlen; } diff --git a/diff.c b/diff.c index 397e38b41c..f631bf1e2a 100644 --- a/diff.c +++ b/diff.c @@ -6958,6 +6958,7 @@ static int diff_get_patch_id(struct diff_options *options, struct object_id *oid flush_one_hunk(oid, &ctx); } + git_hash_discard(&ctx); return 0; }