> On Mar 17, 2016, at 18:07, Junio C Hamano <gitster@xxxxxxxxx> wrote: > > The latest maintenance release Git v2.7.4 is now available at the > usual places. The same set of bugfix patches from the current > 'master' have been backported to older maintenance tracks and are > available as v2.4.11, v2.5.5 and v2.6.6. These are to fix a heap > corruption / buffer overflow bug and users are strongly encouraged > to upgrade. The fix has already been in the release candidate > v2.8.0-rc3 as well. > > The tarballs are found at: > > https://www.kernel.org/pub/software/scm/git/ > > The following public repositories all have a copy of the 'v2.7.4' > tag and the 'maint' branch that the tag points at: > > url = https://kernel.googlesource.com/pub/scm/git/git > url = git://repo.or.cz/alt-git.git > url = git://git.sourceforge.jp/gitroot/git-core/git.git > url = git://git-core.git.sourceforge.net/gitroot/git-core/git-core > url = https://github.com/gitster/git > > ---------------------------------------------------------------- > > Git v2.7.4 Release Notes > ======================== > > Fixes since v2.7.3 > ------------------ > > * Bugfix patches were backported from the 'master' front to plug heap > corruption holes, to catch integer overflow in the computation of > pathname lengths, and to get rid of the name_path API. Both of > these would have resulted in writing over an under-allocated buffer > when formulating pathnames while tree traversal. > > ---------------------------------------------------------------- > > Changes since v2.7.3 are as follows: > > Jeff King (7): > add helpers for detecting size_t overflow > tree-diff: catch integer overflow in combine_diff_path allocation > http-push: stop using name_path > show_object_with_name: simplify by using path_name() > list-objects: convert name_path to a strbuf > list-objects: drop name_path entirely > list-objects: pass full pathname to callbacks > > Junio C Hamano (4): > Git 2.4.11 > Git 2.5.5 > Git 2.6.6 > Git 2.7.4 FYI, 2.7.4 fails to build on FreeBSD 9.x, that uses by default gcc 4.2.1. I’ve fixed it adding an extra dependency to make force it to require gcc 4.8+. Here is the output: cc -o combine-diff.o -c -MF ./.depend/combine-diff.o.d -MQ combine-diff.o -MMD -MP -isystem/usr/local/include -O2 -pipe -fstack-protector -fno-strict-aliasing -I. -I/usr/local/include -I/usr/local/include -DUSE_CURL_FOR_IMAP_SEND -I/usr/include -DUSE_ST_TIMESPEC -pthread -DHAVE_PATHS_H -DHAVE_STRINGS_H -DGMTIME_UNRELIABLE_ERRORS -DHAVE_CLOCK_GETTIME -DHAVE_CLOCK_MONOTONIC -DHAVE_BSD_SYSCTL -DHAVE_GETDELIM -DSHA1_HEADER='<openssl/sha.h>' -DDIR_HAS_BSD_GROUP_SEMANTICS -DSHELL_PATH='"/bin/sh"' combine-diff.c combine-diff.c: In function 'diff_tree_combined': combine-diff.c:1391: internal compiler error: Segmentation fault: 11 Please submit a full bug report, with preprocessed source if appropriate. See <URL:http://gcc.gnu.org/bugs.html> for instructions. Makefile:1924: recipe for target 'combine-diff.o' failed gmake: *** [combine-diff.o] Error 1 *** [do-build] Error code 1 -- Renato Botelho -- To unsubscribe from this list: send the line "unsubscribe git" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html