get_terms() in builtin/bisect.c and read_bisect_terms() in
bisect.c both read the BISECT_TERMS file but do not check the
strbuf_getline_lf() return values. If the file is truncated
(e.g., a partial write from a crash or disk-full condition),
strbuf_getline_lf returns EOF and the strbuf remains empty.
strbuf_detach then returns an empty string, and the term names
silently become "" instead of the expected "bad"/"good" or
custom terms.
In get_terms(), check for EOF and return -1 on truncation,
matching the existing -1 return for a missing file.
In read_bisect_terms(), die with a descriptive message when a
line cannot be read, consistent with the die_errno for a
non-ENOENT open failure in the same function. Unlike get_terms(),
read_bisect_terms() returns void and uses die() for all error
paths, so the die is the appropriate error handling here.
Pointed out by Coverity.
Assisted-by: Claude Opus 4.6
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Signed-off-by: Junio C Hamano <gitster@pobox.com>
die_errno(_("could not read file '%s'"), filename);
}
} else {
- strbuf_getline_lf(&str, fp);
+ if (strbuf_getline_lf(&str, fp) == EOF)
+ die(_("could not read bad term from file '%s'"), filename);
free(*read_bad);
*read_bad = strbuf_detach(&str, NULL);
- strbuf_getline_lf(&str, fp);
+ if (strbuf_getline_lf(&str, fp) == EOF)
+ die(_("could not read good term from file '%s'"), filename);
free(*read_good);
*read_good = strbuf_detach(&str, NULL);
}
}
free_terms(terms);
- strbuf_getline_lf(&str, fp);
+ if (strbuf_getline_lf(&str, fp) == EOF) {
+ res = -1;
+ goto finish;
+ }
terms->term_bad = strbuf_detach(&str, NULL);
- strbuf_getline_lf(&str, fp);
+ if (strbuf_getline_lf(&str, fp) == EOF) {
+ res = -1;
+ goto finish;
+ }
terms->term_good = strbuf_detach(&str, NULL);
finish: