From: Johannes Schindelin Date: Tue, 14 Jul 2026 22:48:40 +0000 (+0000) Subject: transport-helper: check dup() return in get_exporter X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=5628a09e6eec1882a6f1e588c76d1d9be9d9a4b1;p=thirdparty%2Fgit.git transport-helper: check dup() return in get_exporter get_exporter() duplicates helper->in via dup() and stores the result in fastexport->out. If dup() fails (fd exhaustion), it returns -1. The child_process machinery interprets out = -1 as "create a pipe for stdout", which would silently change the fast-export process's output wiring: instead of sending data back through the helper's input fd, it would write to a new pipe that nobody reads from. Check the return value and report the error before proceeding. Pointed out by Coverity. Assisted-by: Claude Opus 4.6 Signed-off-by: Johannes Schindelin Signed-off-by: Junio C Hamano --- diff --git a/transport-helper.c b/transport-helper.c index 80f90eb7ba..31883b244e 100644 --- a/transport-helper.c +++ b/transport-helper.c @@ -487,6 +487,8 @@ static int get_exporter(struct transport *transport, /* we need to duplicate helper->in because we want to use it after * fastexport is done with it. */ fastexport->out = dup(helper->in); + if (fastexport->out < 0) + return error_errno(_("could not dup helper output fd")); strvec_push(&fastexport->args, "fast-export"); strvec_push(&fastexport->args, "--use-done-feature"); strvec_push(&fastexport->args, data->signed_tags ?