Skip to content
Open
Changes from 1 commit
Commits
Show all changes
27 commits
Select commit Hold shift + click to select a range
be2b0a8
compat/posix: introduce utimensat(2) wrapper
vonosmas Aug 21, 2026
2c8ab1a
treewide: use utimensat(2) instead of legacy utime(3p)
vonosmas Aug 21, 2026
ae977d6
compat/posix: drop legacy <utime.h> header and shims
vonosmas Aug 21, 2026
dc78849
Merge branch 'kh/doc-datamodel' into ta/command-list-guides-sync-lint
gitster Sep 10, 2026
31ab709
command-list.txt: add gitformat-loose(5) and gitpacking(7)
taahol Sep 10, 2026
4ce144a
lint-docs: check the guide list in command-list.txt
taahol Sep 10, 2026
25f7f09
merge-ll: use strbuf to read back external merge result
peff Sep 11, 2026
5c86262
merge-ll: catch close() errors when writing external tempfiles
peff Sep 11, 2026
2aaf186
merge-ll: use tempfile API for external driver files
peff Sep 11, 2026
1847b18
Merge branch 'ps/odb-alternates-at-creation' into jch
gitster Sep 17, 2026
ba8defa
Merge branch 'hn/history-squash' into jch
gitster Sep 17, 2026
e0cd7bd
Merge branch 'kn/receive-report-hook' into jch
gitster Sep 17, 2026
10957a1
Merge branch 'jc/cocci-free-updates' into jch
gitster Sep 17, 2026
608bf29
Merge branch 'ak/refs-files-root-ref-lock' into jch
gitster Sep 17, 2026
fdb8395
Merge branch 'ps/ref-storage-format' into jch
gitster Sep 17, 2026
9aba6cb
Merge branch 'dk/use-nsec-runtime' into jch
gitster Sep 17, 2026
89dee53
### match next
gitster Sep 17, 2026
31bbc25
Merge branch 'ij/subtree-reject-v2-config' into jch
gitster Sep 17, 2026
aa65892
Merge branch 'ap/http-preserve-wwwauth-redirect' into jch
gitster Sep 17, 2026
a840457
Merge branch 'as/utimensat-utimes' into jch
gitster Sep 17, 2026
d5b21c5
Merge branch 'vv/branch-recurse-no-start-ref' into jch
gitster Sep 17, 2026
5335aa4
Merge branch 'dw/config-read-both-global' into jch
gitster Sep 17, 2026
61d2fe4
Merge branch 'ta/command-list-guides-sync-lint' into jch
gitster Sep 17, 2026
cf22773
Merge branch 'jk/merge-ll-tempfile-cleanup' into jch
gitster Sep 17, 2026
50e9875
Merge branch 'pp/midx-write-skip-empty' into jch
gitster Sep 17, 2026
9f5e444
Merge branch 'hn/range-diff-matched-only' into jch
gitster Sep 17, 2026
aa7921d
Update main.yml
kaykecrystian261-max Sep 17, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
merge-ll: use tempfile API for external driver files
When there's a long(er) running merge driver helper, the user may just
decide to terminate it with Ctrl+C. That sends a signal to the driver
prog and to the whole process group as well, including the git merge
command proper. Hence the cleanup code would not run and .merge_file_*
files are left behind.

We can fix this by using the tempfile API, which auto-cleans files on
signal or other error. That covers the Ctrl+C case above, as well as any
other incidental death (e.g., allocation error due to a gigantic
output).

Note that there is one gotcha here. The current code uses short,
relative filenames for the tempfiles (like ".merge_file_abc123"). But
the tempfile API stores and returns absolute paths. Because we run the
merge driver as a shell command, this can result in problems if the
leading directories contain shell metacharacters (like our tests, which
put a space in the trash directory name for exactly this purpose).

If we were starting from scratch, I'd say the correct solution here is
to shell-quote the filenames we put in the command. But doing so isn't
strictly backwards compatible, because users might have their own shell
characters. For example, if I configure a driver like this:

  [merge "foo"]
  driver = "my-driver '%O' '%A' '%B'"

then adding extra quoting will screw things up! Strictly speaking, this
kind of quoting is wrong (it would fail if %A expanded to something with
a single-quote in it), but it is entirely harmless with the current
vanilla relative paths. It doesn't seem worth breaking it.

So let's take the most conservative route, and just continue reporting
the relative paths.

Commit-message-stolen-from: Michal Koutný <mkoutny@suse.com>
Reported-by: Jean Delvare <jdelvare@suse.de>
Signed-off-by: Jeff King <peff@peff.net>
Signed-off-by: Junio C Hamano <gitster@pobox.com>
  • Loading branch information
peff authored and gitster committed Sep 11, 2026
commit 2aaf1866f47da7cc0d577186ea9ad2350156d614
50 changes: 32 additions & 18 deletions merge-ll.c
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,7 @@
#include "quote.h"
#include "strbuf.h"
#include "gettext.h"
#include "tempfile.h"

struct ll_merge_driver;

Expand Down Expand Up @@ -174,15 +175,27 @@ static struct ll_merge_driver ll_merge_drv[] = {
{ "union", "built-in union merge", ll_union_merge },
};

static void create_temp(mmfile_t *src, char *path, size_t len)
static struct tempfile *create_temp(mmfile_t *src)
{
int fd;

xsnprintf(path, len, ".merge_file_XXXXXX");
fd = xmkstemp(path);
if (write_in_full(fd, src->ptr, src->size) < 0 ||
close(fd) < 0)
struct tempfile *t = xmks_tempfile(".merge_file_XXXXXX");
if (write_in_full(t->fd, src->ptr, src->size) < 0 ||
close_tempfile_gently(t) < 0)
die_errno("unable to write temp-file");
return t;
}

static const char *temp_path_basename(struct tempfile *t)
{
/*
* basename() takes a non-const pointer because it can
* modify the input string to remove trailing directory
* separators. We know that we don't have any because
* this is a clean path generated from our vanilla
* tempfile template.
*
* So casting away the const here is safe, albeit gross.
*/
return basename((char *)get_tempfile_path(t));
}

/*
Expand All @@ -197,11 +210,11 @@ static enum ll_merge_result ll_ext_merge(const struct ll_merge_driver *fn,
const struct ll_merge_options *opts,
int marker_size)
{
char temp[3][50];
struct tempfile *tmp_o, *tmp_a, *tmp_b;
struct strbuf cmd = STRBUF_INIT;
const char *format = fn->cmdline;
struct child_process child = CHILD_PROCESS_INIT;
int status, i;
int status;
struct strbuf result_buf = STRBUF_INIT;
enum ll_merge_result ret;
assert(opts);
Expand All @@ -211,19 +224,19 @@ static enum ll_merge_result ll_ext_merge(const struct ll_merge_driver *fn,

result->ptr = NULL;
result->size = 0;
create_temp(orig, temp[0], sizeof(temp[0]));
create_temp(src1, temp[1], sizeof(temp[1]));
create_temp(src2, temp[2], sizeof(temp[2]));
tmp_o = create_temp(orig);
tmp_a = create_temp(src1);
tmp_b = create_temp(src2);

while (strbuf_expand_step(&cmd, &format)) {
if (skip_prefix(format, "%", &format))
strbuf_addch(&cmd, '%');
else if (skip_prefix(format, "O", &format))
strbuf_addstr(&cmd, temp[0]);
strbuf_addstr(&cmd, temp_path_basename(tmp_o));
else if (skip_prefix(format, "A", &format))
strbuf_addstr(&cmd, temp[1]);
strbuf_addstr(&cmd, temp_path_basename(tmp_a));
else if (skip_prefix(format, "B", &format))
strbuf_addstr(&cmd, temp[2]);
strbuf_addstr(&cmd, temp_path_basename(tmp_b));
else if (skip_prefix(format, "L", &format))
strbuf_addf(&cmd, "%d", marker_size);
else if (skip_prefix(format, "P", &format))
Expand All @@ -242,13 +255,14 @@ static enum ll_merge_result ll_ext_merge(const struct ll_merge_driver *fn,
strvec_push(&child.args, cmd.buf);
status = run_command(&child);

if (strbuf_read_file(&result_buf, temp[1], 0) >= 0) {
if (strbuf_read_file(&result_buf, get_tempfile_path(tmp_a), 0) >= 0) {
result->size = result_buf.len;
result->ptr = strbuf_detach(&result_buf, NULL);
}

for (i = 0; i < 3; i++)
unlink_or_warn(temp[i]);
delete_tempfile(&tmp_o);
delete_tempfile(&tmp_a);
delete_tempfile(&tmp_b);
strbuf_release(&cmd);
if (!status)
ret = LL_MERGE_OK;
Expand Down