]> git.ipfire.org Git - thirdparty/git.git/commitdiff
csum-file: always finalize or discard hash
authorJeff King <peff@peff.net>
Thu, 2 Jul 2026 08:01:30 +0000 (04:01 -0400)
committerJunio C Hamano <gitster@pobox.com>
Thu, 2 Jul 2026 16:50:47 +0000 (09:50 -0700)
When a hashfile struct is created, we always initialize the git_hash_ctx
inside it. We usually end up in hashfile_finalize(), which passes that
ctx to git_hash_final(), cleaning it up.

But a few code paths don't do so:

  1. If we bail on the hashfile and call free_hashfile() directly rather
     than finalizing.

  2. If the skip_hash flag is set, the hashfile_finalize() call will
     never call git_hash_final(). (You might think that we should just
     avoid git_hash_init() entirely in this case, but the skip_hash flag
     is set by the caller after the hashfile is initialized).

For most hash implementations this is OK, but for ones that allocate on
initialization it causes a memory leak. You can see many failures by
running:

  make SANITIZE=leak OPENSSL_SHA1_UNSAFE=1 test

since OpenSSL >= 3.0 is such an allocating hash implementation (and
csum-file uses the "unsafe" algorithm variant).

We can solve this by calling git_hash_discard() as appropriate.

Note that free_hashfile() is used both directly by callers to abort
without finalizing, and by hashfile_finalize() to free memory. In the
latter case we _don't_ want to call git_hash_discard(), because we'll
already have either finalized or discarded it. So we'll push that to an
internal "free_memory" function, and keep free_hashfile() as the public
interface to abort a hashfile without finalizing.

This fix makes several scripts leak-free with the command above: t1600,
t1601, t2107, t7008, t9210, t9211.

Signed-off-by: Jeff King <peff@peff.net>
Signed-off-by: Junio C Hamano <gitster@pobox.com>
csum-file.c

index 2bbedfa36e41fb782405ad179e5a3b9fcfc980a8..69e3b9925490dc3f356c9fcfdd72080ea62b65c8 100644 (file)
@@ -55,13 +55,19 @@ void hashflush(struct hashfile *f)
        }
 }
 
-void free_hashfile(struct hashfile *f)
+static void free_hashfile_memory(struct hashfile *f)
 {
        free(f->buffer);
        free(f->check_buffer);
        free(f);
 }
 
+void free_hashfile(struct hashfile *f)
+{
+       git_hash_discard(&f->ctx);
+       free_hashfile_memory(f);
+}
+
 int finalize_hashfile(struct hashfile *f, unsigned char *result,
                      enum fsync_component component, unsigned int flags)
 {
@@ -69,10 +75,12 @@ int finalize_hashfile(struct hashfile *f, unsigned char *result,
 
        hashflush(f);
 
-       if (f->skip_hash)
+       if (f->skip_hash) {
+               git_hash_discard(&f->ctx);
                hashclr(f->buffer, f->algop);
-       else
+       } else {
                git_hash_final(f->buffer, &f->ctx);
+       }
 
        if (result)
                hashcpy(result, f->buffer, f->algop);
@@ -97,7 +105,7 @@ int finalize_hashfile(struct hashfile *f, unsigned char *result,
                if (close(f->check_fd))
                        die_errno("%s: sha1 file error on close", f->name);
        }
-       free_hashfile(f);
+       free_hashfile_memory(f);
        return fd;
 }