From: Johannes Schindelin Date: Fri, 10 Jul 2026 11:39:25 +0000 (+0000) Subject: diffcore-break: guard against NULLed queue entries in merge loop X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=a6b8f0143101f35bd5cc59ec5d51c9c4d428620c;p=thirdparty%2Fgit.git diffcore-break: guard against NULLed queue entries in merge loop The outer loop in `diffcore_merge_broken()` sets `q->queue[j]` to NULL when it merges a broken pair back together, and has a NULL check to skip such entries on subsequent iterations. The inner loop, however, lacks this guard: when it scans forward looking for a matching peer, it can encounter a slot that was NULLed by a previous outer-loop iteration and dereference it unconditionally. In practice this requires at least two broken pairs whose peers both survive rename/copy detection and appear later in the queue, which is rare but not impossible. Add the same `if (!pp) continue` guard to the inner loop. Pointed out by Coverity. Assisted-by: Claude Opus 4.6 Signed-off-by: Johannes Schindelin Signed-off-by: Junio C Hamano --- diff --git a/diffcore-break.c b/diffcore-break.c index 17b5ad1fed..b5bcc956cc 100644 --- a/diffcore-break.c +++ b/diffcore-break.c @@ -289,6 +289,8 @@ void diffcore_merge_broken(void) */ for (j = i + 1; j < q->nr; j++) { struct diff_filepair *pp = q->queue[j]; + if (!pp) + continue; if (pp->broken_pair && !strcmp(pp->one->path, pp->two->path) && !strcmp(p->one->path, pp->two->path)) {