From: Jeff King Date: Thu, 2 Jul 2026 08:01:30 +0000 (-0400) Subject: csum-file: always finalize or discard hash X-Git-Url: http://git.ipfire.org/gitweb/index.cgi?a=commitdiff_plain;h=64337aecded9e91a766b585b86bcf5f0342e0b87;p=thirdparty%2Fgit.git csum-file: always finalize or discard hash When a hashfile struct is created, we always initialize the git_hash_ctx inside it. We usually end up in hashfile_finalize(), which passes that ctx to git_hash_final(), cleaning it up. But a few code paths don't do so: 1. If we bail on the hashfile and call free_hashfile() directly rather than finalizing. 2. If the skip_hash flag is set, the hashfile_finalize() call will never call git_hash_final(). (You might think that we should just avoid git_hash_init() entirely in this case, but the skip_hash flag is set by the caller after the hashfile is initialized). For most hash implementations this is OK, but for ones that allocate on initialization it causes a memory leak. You can see many failures by running: make SANITIZE=leak OPENSSL_SHA1_UNSAFE=1 test since OpenSSL >= 3.0 is such an allocating hash implementation (and csum-file uses the "unsafe" algorithm variant). We can solve this by calling git_hash_discard() as appropriate. Note that free_hashfile() is used both directly by callers to abort without finalizing, and by hashfile_finalize() to free memory. In the latter case we _don't_ want to call git_hash_discard(), because we'll already have either finalized or discarded it. So we'll push that to an internal "free_memory" function, and keep free_hashfile() as the public interface to abort a hashfile without finalizing. This fix makes several scripts leak-free with the command above: t1600, t1601, t2107, t7008, t9210, t9211. Signed-off-by: Jeff King Signed-off-by: Junio C Hamano --- diff --git a/csum-file.c b/csum-file.c index 2bbedfa36e..69e3b99254 100644 --- a/csum-file.c +++ b/csum-file.c @@ -55,13 +55,19 @@ void hashflush(struct hashfile *f) } } -void free_hashfile(struct hashfile *f) +static void free_hashfile_memory(struct hashfile *f) { free(f->buffer); free(f->check_buffer); free(f); } +void free_hashfile(struct hashfile *f) +{ + git_hash_discard(&f->ctx); + free_hashfile_memory(f); +} + int finalize_hashfile(struct hashfile *f, unsigned char *result, enum fsync_component component, unsigned int flags) { @@ -69,10 +75,12 @@ int finalize_hashfile(struct hashfile *f, unsigned char *result, hashflush(f); - if (f->skip_hash) + if (f->skip_hash) { + git_hash_discard(&f->ctx); hashclr(f->buffer, f->algop); - else + } else { git_hash_final(f->buffer, &f->ctx); + } if (result) hashcpy(result, f->buffer, f->algop); @@ -97,7 +105,7 @@ int finalize_hashfile(struct hashfile *f, unsigned char *result, if (close(f->check_fd)) die_errno("%s: sha1 file error on close", f->name); } - free_hashfile(f); + free_hashfile_memory(f); return fd; }