Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Attempt 2 - Fix Missing Git Executable Causing ClusterFuzz Crash #1909

Commits on Apr 26, 2024

  1. Attempt 2 - Fix Missing Git Executable Causing ClusterFuzz Crash

    This is a second attempt at gitpython-developers#1906 and should resolve:
    - gitpython-developers#1905
    - google/oss-fuzz#10600
    
    PR gitpython-developers#1906 had the right idea but wrong implementation, and the differences between
    the ClusterFuzz image that it was supposed to fix and the OSS-Fuzz image where
    the fix was tested led to the issue not being fully resolved.
    
    The root cause of the issue is the same: A Git executable is not globally
    available in the ClusterFuzz container environment where OSS-Fuzz executes
    fuzz tests.
    
     gitpython-developers#1906 attempted to fix the issue by bundling the Git binary and using
    GitPython's `git.refresh(<full-path-to-git-executable>)` method to set it
    inside the `TestOneInput` function of the test harness.
    
    However, GitPython attempts to set the binary at import time via its `__init__`
    hook, and crashes the test if no executable is found during the import.
    
    This issue is fixed here by setting the environment variable that GitPython
    looks in before importing it, so it's available for the import. This was tested
    by setting the `$PATH` to an empty string inside the test files, which
    reproduced the crash, then adding the changes introduced here with `$PATH` still
    empty, which avoided the crash indicating that the bundled Git executable is
    working as expected.
    DaveLak committed Apr 26, 2024
    Configuration menu
    Copy the full SHA
    dac3535 View commit details
    Browse the repository at this point in the history