From bd58327406c6868b92fb1b61d85b7430839042d4 Mon Sep 17 00:00:00 2001 From: Johannes Schindelin Date: Sun, 5 Jul 2026 08:24:19 +0000 Subject: [PATCH] loose: avoid closing invalid fd on error path `write_one_object()` opens a file at line 186 and jumps to the errout label on failure. The errout cleanup unconditionally calls `close(fd)`, but when `open()` itself failed, fd is -1. Calling `close(-1)` is harmless on most platforms (returns EBADF) but is undefined behavior per POSIX and can confuse fd tracking in sanitizer builds. Guard the close with fd >= 0. Pointed out by Coverity. Assisted-by: Claude Opus 4.6 Signed-off-by: Johannes Schindelin Signed-off-by: Junio C Hamano --- loose.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/loose.c b/loose.c index 940a9e0dfe..bf01d3e42d 100644 --- a/loose.c +++ b/loose.c @@ -201,7 +201,8 @@ static int write_one_object(struct odb_source_loose *loose, return 0; errout: error_errno(_("failed to write loose object index %s"), path.buf); - close(fd); + if (fd >= 0) + close(fd); rollback_lock_file(&lock); strbuf_release(&buf); strbuf_release(&path);