{"thread":{"id":"12678","subject":"Segmentation fault git read-tree","startedAt":"2008-03-14T03:59:06Z","lastAt":"2008-03-14T18:24:27Z","messageCount":9,"participants":["Len Brown","Linus Torvalds","Junio C Hamano"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"72021","messageId":"200803132359.06745.lenb@kernel.org","threadId":"12678","inReplyTo":null,"subject":"Segmentation fault git read-tree","fromName":"Len Brown","fromEmail":"lenb@kernel.org","sentAt":"2008-03-14T03:59:06Z","receivedAt":"2008-03-14T03:59:06Z","isPatch":false,"sender":{"key":"lenb@kernel.org","avatar":null},"body":"i pushed the branches necessary to reproduce this right\nbefore it happened, so you should be able to pull them\nand try it yourself.\n\nthanks,\n-Len\n\n[lenb@t61 acpi (test)]$ git push lenb\nlenb@master.kernel.org's password:\nCounting objects: 723, done.\nCompressing objects: 100% (237/237), done.\nWriting objects: 100% (492/492), 82.22 KiB, done.\nTotal 492 (delta 389), reused 337 (delta 249)\nTo master.kernel.org:/pub/scm/linux/kernel/git/lenb/linux-acpi-2.6.git\n   93d7446..dba92d3  linus -> linus\n   93d7446..dba92d3  release -> release\n   93d7446..c68a500  suspend -> suspend\n   93d7446..5dceb6d  test -> test\n[lenb@t61 acpi (test)]$ git merge test suspend\nAlready up-to-date with 5dceb6d3377c3cbd06f7b3282fec0e201273c302\nTrying simple merge with c68a5009ab9938af22af668e0e2d646d2482c866\n/home/lenb/bin/git-merge-octopus: line 52: 24287 Segmentation fault      git read-tree -u -m --aggressive $common $MRT $SHA1\nMerge with strategy octopus failed.\n[lenb@t61 acpi (test)]$ git merge test suspend\nfatal: unable to create '.git/index.lock': File exists\nAlready up-to-date with 5dceb6d3377c3cbd06f7b3282fec0e201273c302\nTrying simple merge with c68a5009ab9938af22af668e0e2d646d2482c866\nfatal: unable to create '.git/index.lock': File exists\nMerge with strategy octopus failed.\n[lenb@t61 acpi (test)]$ git --version\ngit version 1.5.4.4.537.gb75aa\n[lenb@t61 acpi (test)]$\n"},{"id":"72022","messageId":"alpine.LFD.1.00.0803132125280.3557@woody.linux-foundation.org","threadId":"12678","inReplyTo":"200803132359.06745.lenb@kernel.org","subject":"Re: Segmentation fault git read-tree","fromName":"Linus Torvalds","fromEmail":"torvalds@linux-foundation.org","sentAt":"2008-03-14T04:26:15Z","receivedAt":"2008-03-14T04:26:15Z","isPatch":false,"sender":{"key":"torvalds@linux-foundation.org","avatar":"https://avatars.githubusercontent.com/u/1024025?v=4"},"body":"\n\nOn Thu, 13 Mar 2008, Len Brown wrote:\n>\n> i pushed the branches necessary to reproduce this right\n> before it happened, so you should be able to pull them\n> and try it yourself.\n\nOk, I can reproduce this, I'm on it like a maggot on a two-week-dead baby \ndonkey.\n\n\t\tLinus\n"},{"id":"72023","messageId":"alpine.LFD.1.00.0803132127281.3557@woody.linux-foundation.org","threadId":"12678","inReplyTo":"alpine.LFD.1.00.0803132125280.3557@woody.linux-foundation.org","subject":"Re: Segmentation fault git read-tree","fromName":"Linus Torvalds","fromEmail":"torvalds@linux-foundation.org","sentAt":"2008-03-14T04:30:35Z","receivedAt":"2008-03-14T04:30:35Z","isPatch":false,"sender":{"key":"torvalds@linux-foundation.org","avatar":"https://avatars.githubusercontent.com/u/1024025?v=4"},"body":"\n\nOn Thu, 13 Mar 2008, Linus Torvalds wrote:\n>\n> Ok, I can reproduce this, I'm on it like a maggot on a two-week-dead baby \n> donkey.\n\nOoh, interesting. Compiling with debugging makes the SIGSEGV go away, and \nreplaces it with an endless loop.\n\nThe SIGSEGV when non-debugging seems to be due to a corrupt \"info->prev\" \npointer chain, but this was less obvious than I hoped it would be.\n\nStill looking.\n\n\t\tLinus\n"},{"id":"72025","messageId":"alpine.LFD.1.00.0803132136080.3557@woody.linux-foundation.org","threadId":"12678","inReplyTo":"alpine.LFD.1.00.0803132125280.3557@woody.linux-foundation.org","subject":"Re: Segmentation fault in git read-tree","fromName":"Linus Torvalds","fromEmail":"torvalds@linux-foundation.org","sentAt":"2008-03-14T04:37:40Z","receivedAt":"2008-03-14T04:37:40Z","isPatch":false,"sender":{"key":"torvalds@linux-foundation.org","avatar":"https://avatars.githubusercontent.com/u/1024025?v=4"},"body":"\n\nOn Thu, 13 Mar 2008, Linus Torvalds wrote:\n> \n> Ok, I can reproduce this, I'm on it like a maggot on a two-week-dead baby \n> donkey.\n\nOk, that was embarrassing.\n\nThis should fix it. Spot the stupid stack corruption..\n\n\t\tLinus\n\n---\n unpack-trees.c |    6 ++++--\n 1 files changed, 4 insertions(+), 2 deletions(-)\n\ndiff --git a/unpack-trees.c b/unpack-trees.c\nindex be89d52..b62b054 100644\n--- a/unpack-trees.c\n+++ b/unpack-trees.c\n@@ -8,6 +8,8 @@\n #include \"progress.h\"\n #include \"refs.h\"\n \n+#define MAX_UNPACK_TREES 4\n+\n static void add_entry(struct unpack_trees_options *o, struct cache_entry *ce,\n \tunsigned int set, unsigned int clear)\n {\n@@ -123,7 +125,7 @@ static int unpack_index_entry(struct cache_entry *ce, struct unpack_trees_option\n int traverse_trees_recursive(int n, unsigned long dirmask, unsigned long df_conflicts, struct name_entry *names, struct traverse_info *info)\n {\n \tint i;\n-\tstruct tree_desc t[3];\n+\tstruct tree_desc t[MAX_UNPACK_TREES];\n \tstruct traverse_info newinfo;\n \tstruct name_entry *p;\n \n@@ -327,7 +329,7 @@ int unpack_trees(unsigned len, struct tree_desc *t, struct unpack_trees_options\n {\n \tstatic struct cache_entry *dfc;\n \n-\tif (len > 4)\n+\tif (len > MAX_UNPACK_TREES)\n \t\tdie(\"unpack_trees takes at most four trees\");\n \tmemset(&state, 0, sizeof(state));\n \tstate.base_dir = \"\";\n"},{"id":"72028","messageId":"7viqzpvrr9.fsf@gitster.siamese.dyndns.org","threadId":"12678","inReplyTo":"alpine.LFD.1.00.0803132136080.3557@woody.linux-foundation.org","subject":"Re: Segmentation fault in git read-tree","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2008-03-14T04:44:42Z","receivedAt":"2008-03-14T04:44:42Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Again?\n"},{"id":"72029","messageId":"7vejadvrk7.fsf@gitster.siamese.dyndns.org","threadId":"12678","inReplyTo":"alpine.LFD.1.00.0803132136080.3557@woody.linux-foundation.org","subject":"Re: Segmentation fault in git read-tree","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2008-03-14T04:48:56Z","receivedAt":"2008-03-14T04:48:56Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Linus Torvalds <torvalds@linux-foundation.org> writes:\n\n> On Thu, 13 Mar 2008, Linus Torvalds wrote:\n>> \n>> Ok, I can reproduce this, I'm on it like a maggot on a two-week-dead baby \n>> donkey.\n>\n> Ok, that was embarrassing.\n>\n> This should fix it. Spot the stupid stack corruption..\n>\n> \t\tLinus\n\n> diff --git a/unpack-trees.c b/unpack-trees.c\n> index be89d52..b62b054 100644\n> --- a/unpack-trees.c\n> +++ b/unpack-trees.c\n> @@ -8,6 +8,8 @@\n>  #include \"progress.h\"\n>  #include \"refs.h\"\n>  \n> +#define MAX_UNPACK_TREES 4\n\nSomehow this reminds me of a9ab200 (Clean-up read-tree error condition.,\nAug 16, 2007) and f34f2b0 (Fix read-tree merging more than 3 trees using\n3-way merge, Aug 15, 2007).\n"},{"id":"72033","messageId":"7vskytuc55.fsf@gitster.siamese.dyndns.org","threadId":"12678","inReplyTo":"7vejadvrk7.fsf@gitster.siamese.dyndns.org","subject":"Re: Segmentation fault in git read-tree","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2008-03-14T05:07:18Z","receivedAt":"2008-03-14T05:07:18Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Thanks for the fix.\n\nLet's do this right, as the two limits should be in sync.\n\n-- >8 --\nread-tree() and unpack_trees(): use consistent limit\n\nread-tree -m can read up to MAX_TREES, which was arbitrarily set to 8 since\nAugust 2007 (4 is needed to deal with 2 merge-base case).\n\nHowever, the updated unpack_trees() code had an advertised limit of 4\n(which it enforced).  In reality the code was prepared to take only 3\ntrees and giving 4 caused it to stomp on its stack.  Rename the MAX_TREES\nconstant to MAX_UNPACK_TREES, move it to the unpack-trees.h common header\nfile, and use it from both places to avoid future confusion.\n\nBug-reintroduced-and-fixed-by: Linus Torvalds <torvalds@linux-foundation.org>\nPatch-munged-and-tested-by: Junio C Hamano <gitster@pobox.com>\n---\n builtin-read-tree.c |    9 ++++-----\n unpack-trees.c      |    6 +++---\n unpack-trees.h      |    2 ++\n 3 files changed, 9 insertions(+), 8 deletions(-)\n\ndiff --git a/builtin-read-tree.c b/builtin-read-tree.c\nindex 160456d..e9cfd2b 100644\n--- a/builtin-read-tree.c\n+++ b/builtin-read-tree.c\n@@ -13,16 +13,15 @@\n #include \"dir.h\"\n #include \"builtin.h\"\n \n-#define MAX_TREES 8\n static int nr_trees;\n-static struct tree *trees[MAX_TREES];\n+static struct tree *trees[MAX_UNPACK_TREES];\n \n static int list_tree(unsigned char *sha1)\n {\n \tstruct tree *tree;\n \n-\tif (nr_trees >= MAX_TREES)\n-\t\tdie(\"I cannot read more than %d trees\", MAX_TREES);\n+\tif (nr_trees >= MAX_UNPACK_TREES)\n+\t\tdie(\"I cannot read more than %d trees\", MAX_UNPACK_TREES);\n \ttree = parse_tree_indirect(sha1);\n \tif (!tree)\n \t\treturn -1;\n@@ -97,7 +96,7 @@ int cmd_read_tree(int argc, const char **argv, const char *unused_prefix)\n {\n \tint i, newfd, stage = 0;\n \tunsigned char sha1[20];\n-\tstruct tree_desc t[MAX_TREES];\n+\tstruct tree_desc t[MAX_UNPACK_TREES];\n \tstruct unpack_trees_options opts;\n \n \tmemset(&opts, 0, sizeof(opts));\ndiff --git a/unpack-trees.c b/unpack-trees.c\nindex be89d52..91649f3 100644\n--- a/unpack-trees.c\n+++ b/unpack-trees.c\n@@ -123,7 +123,7 @@ static int unpack_index_entry(struct cache_entry *ce, struct unpack_trees_option\n int traverse_trees_recursive(int n, unsigned long dirmask, unsigned long df_conflicts, struct name_entry *names, struct traverse_info *info)\n {\n \tint i;\n-\tstruct tree_desc t[3];\n+\tstruct tree_desc t[MAX_UNPACK_TREES];\n \tstruct traverse_info newinfo;\n \tstruct name_entry *p;\n \n@@ -327,8 +327,8 @@ int unpack_trees(unsigned len, struct tree_desc *t, struct unpack_trees_options\n {\n \tstatic struct cache_entry *dfc;\n \n-\tif (len > 4)\n-\t\tdie(\"unpack_trees takes at most four trees\");\n+\tif (len > MAX_UNPACK_TREES)\n+\t\tdie(\"unpack_trees takes at most %d trees\", MAX_UNPACK_TREES);\n \tmemset(&state, 0, sizeof(state));\n \tstate.base_dir = \"\";\n \tstate.force = 1;\ndiff --git a/unpack-trees.h b/unpack-trees.h\nindex e8abbcd..50453ed 100644\n--- a/unpack-trees.h\n+++ b/unpack-trees.h\n@@ -1,6 +1,8 @@\n #ifndef UNPACK_TREES_H\n #define UNPACK_TREES_H\n \n+#define MAX_UNPACK_TREES 8\n+\n struct unpack_trees_options;\n \n typedef int (*merge_fn_t)(struct cache_entry **src,\n"},{"id":"72119","messageId":"alpine.LFD.1.00.0803141037000.3557@woody.linux-foundation.org","threadId":"12678","inReplyTo":"7vejadvrk7.fsf@gitster.siamese.dyndns.org","subject":"Re: Segmentation fault in git read-tree","fromName":"Linus Torvalds","fromEmail":"torvalds@linux-foundation.org","sentAt":"2008-03-14T17:37:41Z","receivedAt":"2008-03-14T17:37:41Z","isPatch":false,"sender":{"key":"torvalds@linux-foundation.org","avatar":"https://avatars.githubusercontent.com/u/1024025?v=4"},"body":"\n\nOn Thu, 13 Mar 2008, Junio C Hamano wrote:\n> \n> Somehow this reminds me of a9ab200 (Clean-up read-tree error condition.,\n> Aug 16, 2007) and f34f2b0 (Fix read-tree merging more than 3 trees using\n> 3-way merge, Aug 15, 2007).\n\nYeah. I think we don't actually have any test for more than three trees. \nIf we really are supposed to do eight trees, maybe we should test for it.\n\n\t\tLinus\n"},{"id":"72125","messageId":"200803141424.28034.lenb@kernel.org","threadId":"12678","inReplyTo":"7vskytuc55.fsf@gitster.siamese.dyndns.org","subject":"Re: Segmentation fault in git read-tree","fromName":"Len Brown","fromEmail":"lenb@kernel.org","sentAt":"2008-03-14T18:24:27Z","receivedAt":"2008-03-14T18:24:27Z","isPatch":false,"sender":{"key":"lenb@kernel.org","avatar":null},"body":"confirmed fixed.\n\nthanks guys, for the great support!\n\nI'm pleased that I can (almost fearlessly) update git on a daily basis.\nOn the rare occasion I run into issues, you kill 'em quick.\n\n-Len\n\n[lenb@t61 acpi (test)]$ git merge test suspend\nAlready up-to-date with 5dceb6d3377c3cbd06f7b3282fec0e201273c302\nTrying simple merge with c68a5009ab9938af22af668e0e2d646d2482c866\nMerge made by octopus.\n arch/frv/kernel/pm.c            |    8 --\n arch/mips/au1000/common/power.c |   35 +-------\n arch/x86/kernel/apm_32.c        |   15 ---\n kernel/power/Kconfig            |   10 --\n kernel/power/Makefile           |    1 -\n kernel/power/pm.c               |  205 ---------------------------------------\n 6 files changed, 1 insertions(+), 273 deletions(-)\n delete mode 100644 kernel/power/pm.c\n[lenb@t61 acpi (test)]$ git version\ngit version 1.5.4.4.551.g1658\n"}]}