]> git.ipfire.org Git - thirdparty/git.git/commitdiff
bisect: handle NULL commit in `bisect_successful()`
authorJohannes Schindelin <johannes.schindelin@gmx.de>
Fri, 10 Jul 2026 11:39:30 +0000 (11:39 +0000)
committerJunio C Hamano <gitster@pobox.com>
Fri, 10 Jul 2026 15:13:54 +0000 (08:13 -0700)
When `lookup_commit_reference_by_name()` is called to find the first bad
commit, the result is passed to `repo_format_commit_message()`
immediately, which dereferences commit without checking for NULL.

However, the commit could be NULL, even though in practice this is
unlikely because `bisect_successful()` is only called after a successful
bisect run has identified the bad commit, but the ref could still become
dangling due to a concurrent gc or repository corruption.

Pointed out by Coverity.

Assisted-by: Claude Opus 4.6
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Signed-off-by: Junio C Hamano <gitster@pobox.com>
builtin/bisect.c

index 798e28f5012d31bf76cd85be3737b450439fd092..2672cbe5d11cd9a3ec287893c624036249463b19 100644 (file)
@@ -663,6 +663,11 @@ static int bisect_successful(struct bisect_terms *terms)
 
        refs_read_ref(get_main_ref_store(the_repository), bad_ref, &oid);
        commit = lookup_commit_reference_by_name(bad_ref);
+       if (!commit) {
+               error(_("could not find commit for '%s'"), bad_ref);
+               free(bad_ref);
+               return BISECT_FAILED;
+       }
        repo_format_commit_message(the_repository, commit, "%s", &commit_name,
                                   &pp);