From: "Johannes Schindelin via GitGitGadget" <gitgitgadget@gmail.com>
To: git@vger.kernel.org
Cc: Johannes Schindelin <johannes.schindelin@gmx.de>,
Johannes Schindelin <johannes.schindelin@gmx.de>
Subject: [PATCH 4/7] rerere: do not record failed conflict resolution data
Date: Thu, 17 Sep 2026 17:52:33 +0000 [thread overview]
Message-ID: <bd9e06e46c6debb5a8fc8f1d3821250ca110d5ef.1789667556.git.gitgitgadget@gmail.com> (raw)
In-Reply-To: <pull.2231.git.1789667556.gitgitgadget@gmail.com>
From: Johannes Schindelin <johannes.schindelin@gmx.de>
`rerere` can mark a conflict variant as resolved even when writing its
preimage or postimage fails. A later invocation may then replay
incomplete data from the cache, turning a local filesystem failure into
an incorrect working-tree change.
629716d256a7 (rerere: do use multiple variants, 2015-07-30) introduced
the code paths without checks for those I/O results. Treat such failures
as failures, report them, and leave the rerere status unchanged unless
the corresponding data was recorded successfully.
The defect has been latent since 2015. Git for Windows' Coverity run
only reported it after merging v2.56.0-rc0, for reasons that could not
be figured out in a reasonable amount of time.
Assisted-by: GPT-5.6 Luna
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
---
rerere.c | 30 ++++++++++++++++++++++++++----
1 file changed, 26 insertions(+), 4 deletions(-)
diff --git a/rerere.c b/rerere.c
index 1c3745d9e3..45bbe6ab2c 100644
--- a/rerere.c
+++ b/rerere.c
@@ -476,8 +476,11 @@ static int handle_file(struct index_state *istate,
unlink_or_warn(output);
return error(_("could not parse conflict hunks in '%s'"), path);
}
- if (io.io.wrerror)
+ if (io.io.wrerror) {
+ if (output)
+ unlink_or_warn(output);
return -1;
+ }
return has_conflicts;
}
@@ -729,8 +732,25 @@ static void do_rerere_one_path(struct index_state *istate,
/* Has the user resolved it already? */
if (variant >= 0) {
- if (!handle_file(istate, path, NULL, NULL)) {
- copy_file(the_repository, rerere_path(&buf, id, "postimage"), path, 0666);
+ int ret = handle_file(istate, path, NULL, NULL);
+
+ if (ret < 0)
+ goto out;
+ if (!ret) {
+ const int had_postimage =
+ id->collection->status[variant] & RR_HAS_POSTIMAGE;
+ const char *postimage =
+ rerere_path(&buf, id, "postimage");
+
+ if (copy_file(the_repository,
+ postimage,
+ path, 0666)) {
+ if (!had_postimage)
+ unlink_or_warn(postimage);
+ error_errno(_("could not copy resolution for '%s'"),
+ path);
+ goto out;
+ }
id->collection->status[variant] |= RR_HAS_POSTIMAGE;
fprintf_ln(stderr, _("Recorded resolution for '%s'."), path);
free_rerere_id(rr_item);
@@ -778,7 +798,9 @@ static void do_rerere_one_path(struct index_state *istate,
assign_variant(id);
variant = id->variant;
- handle_file(istate, path, NULL, rerere_path(&buf, id, "preimage"));
+ if (handle_file(istate, path, NULL,
+ rerere_path(&buf, id, "preimage")) < 0)
+ goto out;
if (id->collection->status[variant] & RR_HAS_POSTIMAGE) {
const char *path = rerere_path(&buf, id, "postimage");
if (unlink(path))
--
gitgitgadget
next prev parent reply other threads:[~2026-09-17 17:52 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-17 17:52 [PATCH 0/7] Fix issues pointed out in Git for Windows by Coverity after merging v2.56.0-rc0 Johannes Schindelin via GitGitGadget
2026-09-17 17:52 ` [PATCH 1/7] wrapper: guard writev_in_full() against signed overflow Johannes Schindelin via GitGitGadget
2026-09-17 17:52 ` [PATCH 2/7] gpg-interface: make signature-prefix matching length-aware Johannes Schindelin via GitGitGadget
2026-09-17 19:32 ` Junio C Hamano
2026-09-18 7:12 ` Johannes Schindelin
2026-09-18 8:59 ` Junio C Hamano
2026-09-17 17:52 ` [PATCH 3/7] midx: validate incremental MIDX pack IDs Johannes Schindelin via GitGitGadget
2026-09-17 17:52 ` Johannes Schindelin via GitGitGadget [this message]
2026-09-17 19:34 ` [PATCH 4/7] rerere: do not record failed conflict resolution data Junio C Hamano
2026-09-17 17:52 ` [PATCH 5/7] t/unit-tests: check reftable iterator initialization Johannes Schindelin via GitGitGadget
2026-09-17 17:52 ` [PATCH 6/7] oss-fuzz: handle reftable iterator initialization failures Johannes Schindelin via GitGitGadget
2026-09-17 17:52 ` [PATCH 7/7] test-read-midx: check midx_fill_entry() result Johannes Schindelin via GitGitGadget
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=bd9e06e46c6debb5a8fc8f1d3821250ca110d5ef.1789667556.git.gitgitgadget@gmail.com \
--to=gitgitgadget@gmail.com \
--cc=git@vger.kernel.org \
--cc=johannes.schindelin@gmx.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox