{"thread":{"id":"20890","subject":"[ JGIT ] incompatiblity found in DirCache","startedAt":"2009-09-09T18:55:39Z","lastAt":"2009-09-11T15:05:23Z","messageCount":3,"participants":["Adam W. Hawks","Robin Rosenberg","Shawn O. Pearce"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"122770","messageId":"4AA7FA2B.4090707@writeme.com","threadId":"20890","inReplyTo":null,"subject":"[ JGIT ] incompatiblity found in DirCache","fromName":"Adam W. Hawks","fromEmail":"awhawks@writeme.com","sentAt":"2009-09-09T18:55:39Z","receivedAt":"2009-09-09T18:55:39Z","isPatch":false,"sender":{"key":"awhawks@writeme.com","avatar":null},"body":"When using the DirCache interface to the index you can create a invalid/corrupt tree for git 1.6.5.\n\nThe problem seems to be you can add a path to the index that starts with a \"/\" and DirCache creates a entry with a mode but no path.\nThis causes git 1.6.5 to fail with a corrupt tree.\n\nThe following code will create the problem\n\nimport java.io.File;\nimport java.io.IOException;\nimport java.util.Calendar;\nimport java.util.Date;\nimport java.util.TimeZone;\n\nimport org.spearce.jgit.dircache.DirCache;\nimport org.spearce.jgit.dircache.DirCacheBuilder;\nimport org.spearce.jgit.dircache.DirCacheEntry;\nimport org.spearce.jgit.lib.Commit;\nimport org.spearce.jgit.lib.FileMode;\nimport org.spearce.jgit.lib.ObjectId;\nimport org.spearce.jgit.lib.ObjectWriter;\nimport org.spearce.jgit.lib.PersonIdent;\nimport org.spearce.jgit.lib.RefUpdate;\nimport org.spearce.jgit.lib.Repository;\nimport org.spearce.jgit.lib.RefUpdate.Result;\n\npublic class BuildTest\n{\n\tprivate Repository db;\n\t\n\tpublic static void main(String[] args)\n\t{\n\t\tBuildTest bt = new BuildTest();\n\t\tbt.doit();\n\t}\n\t\n\tpublic void doit()\n\t{\t\t\n\t\tDate when = Calendar.getInstance().getTime();\n\t\tFile gitDir = new File(\"gitProblem/.git\");\n\t\tgitDir.mkdirs();\n\t\ttry\n\t\t{\n\t\t\tdb = new Repository(gitDir);\n\t\t\tdb.create(true);\n\t\t\tDirCache dirc = DirCache.newInCore();\n\t\t\tDirCacheBuilder dcb = dirc.builder();\n\t\t\tbyte[] data = \"Some File data\".getBytes();\n\t\t\tObjectWriter ow = new ObjectWriter(db);\n\t\t\tObjectId dataId = ow.writeBlob(data);\n\t\t\tDirCacheEntry newEntry = new DirCacheEntry(\"/someDir/someFile\");\n\t\t\tnewEntry.setAssumeValid(false);\n\t\t\tnewEntry.setFileMode(FileMode.REGULAR_FILE);\n\t\t\tnewEntry.setLastModified(when.getTime());\n\t\t\tnewEntry.setLength(data.length);\n\t\t\tnewEntry.setObjectId(dataId);\n\t\t\tdcb.add(newEntry );\n\t\t\tdcb.finish();\n\t\t\tdirc = dcb.getDirCache();\n\t\t\tPersonIdent pi = new PersonIdent(\"someonw\",\"someone@somewhere\",when,TimeZone.getDefault());\n\t\t\tObjectId tree = dirc.writeTree(new ObjectWriter(db));\n\t\t\tCommit commit = new Commit(db);\n\t\t\tcommit.setAuthor(pi);\n\t\t\tcommit.setCommitter(pi);\n\t\t\tcommit.setMessage(\"This causes a corrupt tree\");\n\t\t\tcommit.setTreeId(tree);\n\t\t\tcommit.commit();\n\t\t\tObjectId cid = commit.getCommitId();\n\t\t\tRefUpdate ru = db.updateRef(\"refs/heads/master\");\t\t\n\t\t\tru.setExpectedOldObjectId(ObjectId.zeroId());\n\t\t\tru.setNewObjectId(cid);\n\t\t\tru.setRefLogIdent(pi);\n\t\t\tru.setRefLogMessage(\"some reflog message\", true);\n\t\t\tResult result = ru.update();\n\t\t\tSystem.out.println(\"Result = \"+result.toString());\n\t\t}\n\t\tcatch (IOException e)\n\t\t{\n\t\t\tSystem.out.println(e);\n\t\t\te.printStackTrace();\n\t\t\tSystem.exit(1);\n\t\t}\n\t}\t\n}\n"},{"id":"122776","messageId":"200909092311.07145.robin.rosenberg.lists@dewire.com","threadId":"20890","inReplyTo":"4AA7FA2B.4090707@writeme.com","subject":"Re: [ JGIT ] incompatiblity found in DirCache","fromName":"Robin Rosenberg","fromEmail":"robin.rosenberg.lists@dewire.com","sentAt":"2009-09-09T21:11:06Z","receivedAt":"2009-09-09T21:11:06Z","isPatch":false,"sender":{"key":"robin.rosenberg@dewire.com","avatar":"https://avatars.githubusercontent.com/u/46357?v=4"},"body":"onsdag 09 september 2009 20:55:39 skrev \"Adam W. Hawks\" <awhawks@writeme.com>:\n> When using the DirCache interface to the index you can create a invalid/corrupt tree for git 1.6.5.\n> \n> The problem seems to be you can add a path to the index that starts with a \"/\" and DirCache creates a entry with a mode but no path.\n> This causes git 1.6.5 to fail with a corrupt tree.\n\nI think there are more ways of entering bad stuff. Preventing a deliberate programmatic creation of invalid trees is probably not the most important\nthing, but then again, validating the data to prevent e.g. the EGit plugin from doing it by mistake due to bugs could probably\nbe worthwhile.\n\n-- robin\n"},{"id":"122893","messageId":"20090911150522.GI1033@spearce.org","threadId":"20890","inReplyTo":"200909092311.07145.robin.rosenberg.lists@dewire.com","subject":"Re: [ JGIT ] incompatiblity found in DirCache","fromName":"Shawn O. Pearce","fromEmail":"spearce@spearce.org","sentAt":"2009-09-11T15:05:23Z","receivedAt":"2009-09-11T15:05:23Z","isPatch":false,"sender":{"key":"spearce@spearce.org","avatar":"https://avatars.githubusercontent.com/u/34844?v=4"},"body":"Robin Rosenberg <robin.rosenberg.lists@dewire.com> wrote:\n> onsdag 09 september 2009 20:55:39 skrev \"Adam W. Hawks\" <awhawks@writeme.com>:\n> > When using the DirCache interface to the index you can create a\n> > invalid/corrupt tree for git 1.6.5.\n> > \n> > The problem seems to be you can add a path to the index that starts\n> > with a \"/\" and DirCache creates a entry with a mode but no path.\n> > This causes git 1.6.5 to fail with a corrupt tree.\n> \n> I think there are more ways of entering bad stuff. Preventing a\n> deliberate programmatic creation of invalid trees is probably not\n> the most important thing, but then again, validating the data to\n> prevent e.g. the EGit plugin from doing it by mistake due to bugs\n> could probably be worthwhile.\n\nWe already check for and fail fast on a 0 mode in DirCache, as this\nmode is also not valid in the index, or in a git tree.\n\nWe should be doing the same thing for an empty path name.  \"a//b\" is\nnot a valid path in the index, as \"\" is not a valid tree entry path.\nFor the same reason, \"/a\" is not a valid path in the index.\n\nUnfortunately our API also allows you to try and create a name of\n\"a\\u0000b\", which is a valid Java string, but will create a corrupt\ntree.  \\u0000 in a name with more than 4095 bytes will also create\na corrupt index (shorter strings are semi-valid because shorter\nstrings use a Pascal like string format, and longer ones use a C\nlike string format).  Though C git is unable to access a path whose\nname contains \"\\u0000\", no matter how long the string is.\n\nI think we should try a bit harder in DirCache to prevent these sorts\nof really bad entries from being constructed by application code.\nYes, applications should not do this, but I think the library also\nshould not write known bogus trash to the disk and claim it is OK.\n\nI'll try to work up a patch for this today.\n\n-- \nShawn.\n"}]}