From: Johannes Schindelin <redacted>
When push_refs_with_export() finalizes a successful push, it writes
the fast-export marks file to a .tmp sibling and rename()s it into
place. The return value of rename() is currently ignored. If the
rename fails (permission denied, full disk, or an antivirus product
locking the destination on Windows), the .tmp file is left behind
and the existing export_marks file remains stale; the next
fast-export operation that resumes from it then silently operates on
inconsistent bookkeeping.
The push itself succeeded by that point, so promoting this to a
fatal error would be inappropriate. Emit warning_errno() naming both
paths so the user can recover manually, and keep returning 0.
Flagged by Coverity as CID 1427723 ("Unchecked return value").
Assisted-by: Opus 4.7
Signed-off-by: Johannes Schindelin <redacted>
---
transport-helper.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/transport-helper.c b/transport-helper.c
index 31883b244e..ed0543f1ad 100644
--- a/transport-helper.c
+++ b/transport-helper.c
@@ -1184,7 +1184,9 @@ static int push_refs_with_export(struct transport *transport,
if (data->export_marks) {
strbuf_addf(&buf, "%s.tmp", data->export_marks);
- rename(buf.buf, data->export_marks);
+ if (rename(buf.buf, data->export_marks))
+ warning_errno(_("could not rename '%s' to '%s'"),
+ buf.buf, data->export_marks);
strbuf_release(&buf);
}
--
gitgitgadget