{"thread":{"id":"36220","subject":"[BUG] Segfault on git describe","startedAt":"2014-03-19T10:48:27Z","lastAt":"2014-03-22T10:18:44Z","messageCount":5,"participants":["Sylvestre Ledru","Dragos Foianu","Jeff King"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"237057","messageId":"532975FB.9030803@mozilla.com","threadId":"36220","inReplyTo":null,"subject":"[BUG] Segfault on git describe","fromName":"Sylvestre Ledru","fromEmail":"sylvestre@mozilla.com","sentAt":"2014-03-19T10:48:27Z","receivedAt":"2014-03-19T10:48:27Z","isPatch":false,"sender":{"key":"sylvestre@mozilla.com","avatar":null},"body":"Hello,\n\nTrying to do some stats using the Firefox git repository\n(https://github.com/mozilla/gecko-dev), I found a bug\non git describe. The following command will segfault:\ngit describe --contains a9ff31aebd6dbda82a3c733a72eeeaa0b0525b96\n\nPlease note that the Firefox history is a pretty long and this commit\ndate is 2001.\n\nI experience this issue with the git version, and Debian packages\n(1.9.0-1 and 2.0~next.20140214-2)\n\nAs attachment, the backtrace. I removed about 87250 calls to the\nname_rev function. I guess that is a potential source of problem.\n\nFull is available here:\nhttp://people.mozilla.org/~sledru/bt-git-on-ff.txt (21 MB)\n\nI am available to test patches if needed.\n\nThanks,\nSylvestre\nPS: I am not registered, please cc me.\n\n\n#0  inflate_table (type=type@entry=CODES, lens=0x178f230, codes=codes@entry=19, table=0x178f228, \n    bits=bits@entry=0x178f210, work=work@entry=0x178f4b0) at inftrees.c:39\n        len = 0\n        sym = <optimized out>\n        min = <optimized out>\n        max = <optimized out>\n        root = <optimized out>\n        curr = <optimized out>\n        drop = <optimized out>\n        left = <optimized out>\n        used = <optimized out>\n        huff = <optimized out>\n        incr = <optimized out>\n        fill = <optimized out>\n        low = <optimized out>\n        mask = <optimized out>\n        here = <optimized out>\n        next = <optimized out>\n        base = <optimized out>\n        extra = <optimized out>\n        end = <optimized out>\n        count = {0, 0, 0, 0, 0, 0, 0, 0, 31046, 360, 0, 0, 62288, 376, 0, 0}\n        offs = {36858, 61615, 32767, 0, 0, 0, 0, 0, 127, 0, 0, 0, 65535, 65535, 0, 0}\n        lbase = {3, 4, 5, 6, 7, 8, 9, 10, 11, 13, 15, 17, 19, 23, 27, 31, 35, 43, 51, 59, 67, 83, 99, 115, 131, \n          163, 195, 227, 258, 0, 0}\n        lext = {16, 16, 16, 16, 16, 16, 16, 16, 17, 17, 17, 17, 18, 18, 18, 18, 19, 19, 19, 19, 20, 20, 20, 20, 21, \n          21, 21, 21, 16, 72, 78}\n        dbase = {1, 2, 3, 4, 5, 7, 9, 13, 17, 25, 33, 49, 65, 97, 129, 193, 257, 385, 513, 769, 1025, 1537, 2049, \n          3073, 4097, 6145, 8193, 12289, 16385, 24577, 0, 0}\n        dext = {16, 16, 16, 16, 17, 17, 18, 18, 19, 19, 20, 20, 21, 21, 22, 22, 23, 23, 24, 24, 25, 25, 26, 26, 27, \n          27, 28, 28, 29, 29, 64, 64}\n#1  0x00007ffff7bce6fd in inflate (strm=0x7fffff7ff190, flush=4) at inflate.c:926\n        state = 0x178f1a0\n        next = 0x7fffb3b7e5b2 \"?\\305-LHU\\355\\070\\315\\271\\002\\006\\220P\\a\\220\\220\\212\\330\\317\\366%\\265\\232ĕ{\\251\\bOOڑ\\221\\177\\270\\341t\\337w\\277\\024f\\360hLͨu\\323\\006\\252\\254\\213\\232\\235\\363\\326qh=\\326\\301\\372M\\353u\\335T\\352D\\205G\\001\\364\\206-\\306\\065\\066M4&Zc\\243%\\215\\036\\071\\022a0\\270qƑ\\v\\212&9\\344\\002\\303|\\274\\033\\362O\\352{Z\\345\\322\\301ß\\305\\023\\350\\305\\345*\\264\\065\\302\\375z\\211\\ny\\030\\222\\b\\377\\vV\\257\\351\\033\\332屟:0\\266v\\306na:E\\022>\\303\\363\\324\\335\\330\\345 _\\375\\222A\\350\\310@\\361B\\243Pǐ[\\330}\\276\\277Y\\240\\061\\302\\313~\\177U\\r$\\222\\306n\\245>H\\302\\001\\374\\f\"...\n        put = <optimized out>\n        have = 1022863950\n        left = 343\n        hold = 59\n        bits = 7\n        in = 1022863961\n        out = <optimized out>\n        copy = <optimized out>\n        from = <optimized out>\n        here = <optimized out>\n        len = <optimized out>\n        ret = <optimized out>\n        hbuf = \"\\247U\\b\\003\"\n        order = {16, 17, 18, 0, 8, 7, 9, 6, 10, 5, 11, 4, 12, 3, 13, 2, 14, 1, 15}\n#2  0x0000000000559b7d in git_inflate (strm=0x7fffff7ff190, flush=4) at zlib.c:118\n        status = 0\n#3  0x000000000052d73d in unpack_compressed_entry (p=0x850ac0, w_curs=0x7fffff7ff8a8, curpos=50877863, size=342)\n    at sha1_file.c:1933\n        st = 0\n        stream = {z = {\n            next_in = 0x7fffb3b7e5a7 \"x\\234\\235\\216\\261N\\303\\060\\020\\206w?\\305-LHU\\355\\070\\315\\271\\002\\006\\220P\\a\\220\\220\\212\\330\\317\\366%\\265\\232ĕ{\\251\\bOOڑ\\221\\177\\270\\341t\\337w\\277\\024f\\360hLͨu\\323\\006\\252\\254\\213\\232\\235\\363\\326qh=\\326\\301\\372M\\353u\\335T\\352D\\205G\\001\\364\\206-\\306\\065\\066M4&Zc\\243%\\215\\036\\071\\022a0\\270qƑ\\v\\212&9\\344\\002\\303|\\274\\033\\362O\\352{Z\\345\\322\\301ß\\305\\023\\350\\305\\345*\\264\\065\\302\\375z\\211\\ny\\030\\222\\b\\377\\vV\\257\\351\\033\\332屟:0\\266v\\306na:E\\022>\\303\\363\\324\\335\\330\\345 _\\375\\222A\\350\\310@\\361B\\243Pǐ[\\330}\\276\\277Y\\240\\061\\302\\313~\\177U\\r\"..., avail_in = 1022863961, total_in = 0, next_out = 0x178f040 \"\\034\", avail_out = 343, total_out = 0, msg = 0x0, \n            state = 0x178f1a0, zalloc = 0x7ffff7bd3000 <zcalloc>, zfree = 0x7ffff7bd3010 <zcfree>, opaque = 0x0, \n            data_type = 0, adler = 1, reserved = 0}, avail_in = 1022863961, avail_out = 343, total_in = 0, \n          total_out = 0, \n          next_in = 0x7fffb3b7e5a7 \"x\\234\\235\\216\\261N\\303\\060\\020\\206w?\\305-LHU\\355\\070\\315\\271\\002\\006\\220P\\a\\220\\220\\212\\330\\317\\366%\\265\\232ĕ{\\251\\bOOڑ\\221\\177\\270\\341t\\337w\\277\\024f\\360hLͨu\\323\\006\\252\\254\\213\\232\\235\\363\\326qh=\\326\\301\\372M\\353u\\335T\\352D\\205G\\001\\364\\206-\\306\\065\\066M4&Zc\\243%\\215\\036\\071\\022a0\\270qƑ\\v\\212&9\\344\\002\\303|\\274\\033\\362O\\352{Z\\345\\322\\301ß\\305\\023\\350\\305\\345*\\264\\065\\302\\375z\\211\\ny\\030\\222\\b\\377\\vV\\257\\351\\033\\332屟:0\\266v\\306na:E\\022>\\303\\363\\324\\335\\330\\345 _\\375\\222A\\350\\310@\\361B\\243Pǐ[\\330}\\276\\277Y\\240\\061\\302\\313~\\177U\\r\"..., next_out = 0x178f040 \"\\034\"}\n        buffer = 0x178f040 \"\\034\"\n        in = 0x7fffb3b7e5a7 \"x\\234\\235\\216\\261N\\303\\060\\020\\206w?\\305-LHU\\355\\070\\315\\271\\002\\006\\220P\\a\\220\\220\\212\\330\\317\\366%\\265\\232ĕ{\\251\\bOOڑ\\221\\177\\270\\341t\\337w\\277\\024f\\360hLͨu\\323\\006\\252\\254\\213\\232\\235\\363\\326qh=\\326\\301\\372M\\353u\\335T\\352D\\205G\\001\\364\\206-\\306\\065\\066M4&Zc\\243%\\215\\036\\071\\022a0\\270qƑ\\v\\212&9\\344\\002\\303|\\274\\033\\362O\\352{Z\\345\\322\\301ß\\305\\023\\350\\305\\345*\\264\\065\\302\\375z\\211\\ny\\030\\222\\b\\377\\vV\\257\\351\\033\\332屟:0\\266v\\306na:E\\022>\\303\\363\\324\\335\\330\\345 _\\375\\222A\\350\\310@\\361B\\243Pǐ[\\330}\\276\\277Y\\240\\061\\302\\313~\\177U\\r\"...\n#4  0x000000000052e1b7 in unpack_entry (p=0x850ac0, obj_offset=50877861, final_type=0x7fffff7ffb10, \n    final_size=0x7fffff7ffb08) at sha1_file.c:2206\n        w_curs = 0x83e9a0\n        curpos = 50877863\n        data = 0x0\n        size = 342\n        type = OBJ_COMMIT\n        small_delta_stack = {{obj_offset = 4345844982, curpos = 140737479964936, size = 140736208561400}, {\n            obj_offset = 8645024, curpos = 140737479965088, size = 5432450}, {obj_offset = 140737479965544, \n            curpos = 140737479965552, size = 50877686}, {obj_offset = 8719040, curpos = 23623984, size = 0}, {\n            obj_offset = 140737479965184, curpos = 140737479965032, size = 140737488348192}, {obj_offset = 8645024, \n            curpos = 140737479965184, size = 5432450}, {obj_offset = 140737479965640, curpos = 140737479965648, \n            size = 50877567}, {obj_offset = 8719040, curpos = 140736208561279, size = 343}, {obj_offset = 50877567, \n            curpos = 50877573, size = 127}, {obj_offset = 8645024, curpos = 140737479965280, size = 5432450}, {\n            obj_offset = 140737479965736, curpos = 140737479965744, size = 50877376}, {obj_offset = 8719040, \n            curpos = 140736208561088, size = 24703030}, {obj_offset = 4345844450, curpos = 140737479965224, \n            size = 140736208560868}, {obj_offset = 8645024, curpos = 140737479965376, size = 5432450}, {\n            obj_offset = 140737479965832, curpos = 140737479965840, size = 50877154}, {obj_offset = 8719040, \n            curpos = 140736208560866, size = 23620054}, {obj_offset = 4345844261, curpos = 140737479965320, \n            size = 140736208560679}, {obj_offset = 8645024, curpos = 140737479965472, size = 5432450}, {\n            obj_offset = 140737479965928, curpos = 140737479965936, size = 50876965}, {obj_offset = 8719040, \n            curpos = 140736208560677, size = 24703061}, {obj_offset = 4345844003, curpos = 140737479965416, \n            size = 140736208560421}, {obj_offset = 8645024, curpos = 140737479965568, size = 5432450}, {\n            obj_offset = 140737479966024, curpos = 140737479966032, size = 50876707}, {obj_offset = 8719040, \n            curpos = 23619712, size = 0}, {obj_offset = 140737479965664, curpos = 140737479965512, \n            size = 140737488348192}, {obj_offset = 8645024, curpos = 140737479965664, size = 5432450}, {\n            obj_offset = 140737479966120, curpos = 140737479966128, size = 50876591}, {obj_offset = 8719040, \n            curpos = 140736208560303, size = 333}, {obj_offset = 50876591, curpos = 50876595, size = 115}, {\n            obj_offset = 8645024, curpos = 140737479965760, size = 5432450}, {obj_offset = 140737479966216, \n            curpos = 140737479966224, size = 50876385}, {obj_offset = 8719040, curpos = 140736208560097, \n            size = 24702629}, {obj_offset = 4345843495, curpos = 140737479965704, size = 140736208559913}, {\n            obj_offset = 8645024, curpos = 140737479965856, size = 5432450}, {obj_offset = 140737479966312, \n            curpos = 140737479966320, size = 50876199}, {obj_offset = 8719040, curpos = 140736208559911, \n            size = 24702629}, {obj_offset = 4345843309, curpos = 140737479965800, size = 140736208559727}, {\n            obj_offset = 8645024, curpos = 140737479965952, size = 5432450}, {obj_offset = 140737479966408, \n            curpos = 140737479966416, size = 50876013}, {obj_offset = 8719040, curpos = 140736208559725, \n            size = 24490578}, {obj_offset = 4345843162, curpos = 140737479965896, size = 140736208559580}, {\n            obj_offset = 8645024, curpos = 140737479966048, size = 5432450}, {obj_offset = 140737479966504, \n            curpos = 140737479966512, size = 50875866}, {obj_offset = 8719040, curpos = 140736208559578, \n            size = 24490629}, {obj_offset = 4345842975, curpos = 140737479965992, size = 140736208559393}, {\n            obj_offset = 8645024, curpos = 140737479966144, size = 5432450}, {obj_offset = 140737479966600, \n            curpos = 140737479966608, size = 50875679}, {obj_offset = 8719040, curpos = 24490448, size = 0}, {\n            obj_offset = 140737479966240, curpos = 140737479966088, size = 140737488348192}, {obj_offset = 8645024, \n            curpos = 140737479966240, size = 5432450}, {obj_offset = 140737479966696, curpos = 140737479966704, \n            size = 50875558}, {obj_offset = 8719040, curpos = 140736208559270, size = 362}, {obj_offset = 50875558, \n            curpos = 50875564, size = 126}, {obj_offset = 8645024, curpos = 140737479966336, size = 5432450}, {\n            obj_offset = 140737479966792, curpos = 140737479966800, size = 50875395}, {obj_offset = 8719040, \n            curpos = 140736208559107, size = 24702213}, {obj_offset = 4345842526, curpos = 140737479966280, \n            size = 140736208558944}, {obj_offset = 8645024, curpos = 140737479966432, size = 5432450}, {\n            obj_offset = 140737479966888, curpos = 140737479966896, size = 50875230}, {obj_offset = 8719040, \n            curpos = 140736208558942, size = 24702206}, {obj_offset = 4345842359, curpos = 140737479966376, \n            size = 140736208558777}, {obj_offset = 8645024, curpos = 140737479966528, size = 5432450}, {\n            obj_offset = 140737479966984, curpos = 140737479966992, size = 11913437198307314359}, {\n            obj_offset = 8719040, curpos = 218518752100604599, size = 140737479964864}}\n        delta_stack = 0x7fffff7ff290\n        delta_stack_nr = 0\n        delta_stack_alloc = 64\n        base_from_cache = 0\n#5  0x000000000052d971 in cache_or_unpack_entry (p=0x850ac0, base_offset=50877861, base_size=0x7fffff7ffb08, \n    type=0x7fffff7ffb10, keep_cache=1) at sha1_file.c:2011\n        ent = 0x821cb0 <delta_base_cache+4592>\n        ret = 0x1687930\n#6  0x000000000052f000 in read_packed_sha1 (\n    sha1=0x1773e14 \"k\\360\\205\\331\\004\\314\\063\\321\\024\\006\\231'\\031\\260\\067\\266\\336M\\212j\", type=0x7fffff7ffb10, \n    size=0x7fffff7ffb08) at sha1_file.c:2614\n        e = {offset = 50877861, sha1 = \"k\\360\\205\\331\\004\\314\\063\\321\\024\\006\\231'\\031\\260\\067\\266\\336M\\212j\", \n          p = 0x850ac0}\n        data = 0x1773e14\n#7  0x000000000052f285 in read_object (\n    sha1=0x1773e14 \"k\\360\\205\\331\\004\\314\\063\\321\\024\\006\\231'\\031\\260\\067\\266\\336M\\212j\", type=0x7fffff7ffb10, \n    size=0x7fffff7ffb08) at sha1_file.c:2662\n        mapsize = 140737479965264\n        map = 0x5295b6 <lookup_replace_object_extended+43>\n        buf = 0x100000000\n        co = 0x0\n#8  0x000000000052f35d in read_sha1_file_extended (\n    sha1=0x1773e14 \"k\\360\\205\\331\\004\\314\\063\\321\\024\\006\\231'\\031\\260\\067\\266\\336M\\212j\", type=0x7fffff7ffb10, \n    size=0x7fffff7ffb08, flag=1) at sha1_file.c:2690\n        data = 0x0\n        p = 0x7fffffffe420\n        repl = 0x1773e14 \"k\\360\\205\\331\\004\\314\\063\\321\\024\\006\\231'\\031\\260\\067\\266\\336M\\212j\"\n#9  0x000000000049ee7c in read_sha1_file (\n    sha1=0x1773e14 \"k\\360\\205\\331\\004\\314\\063\\321\\024\\006\\231'\\031\\260\\067\\266\\336M\\212j\", type=0x7fffff7ffb10, \n    size=0x7fffff7ffb08) at cache.h:819\nNo locals.\n#10 0x000000000049fb19 in parse_commit (item=0x1773e10) at commit.c:316\n        type = 16\n        buffer = 0x4043e0 <_start>\n        size = 140737343325728\n        ret = 0\n#11 0x000000000045c9e7 in name_rev (commit=0x1773e10, tip_name=0x87a240 \"B2G_1_0_0_20130115070201\", \n    generation=87265, distance=87265, deref=0) at builtin/name-rev.c:30\n        name = 0x0\n        parents = 0x1\n        parent_number = 1\n#12 0x000000000045cbed in name_rev (commit=0x1773dc8, tip_name=0x87a240 \"B2G_1_0_0_20130115070201\", \n    generation=87264, distance=87264, deref=0) at builtin/name-rev.c:79\n        name = 0x1687a70\n        parents = 0x1687a50\n        parent_number = 1\n#13 0x000000000045cbed in name_rev (commit=0x1773d80, tip_name=0x87a240 \"B2G_1_0_0_20130115070201\", \n    generation=87263, distance=87263, deref=0) at builtin/name-rev.c:79\n        name = 0x1686900\n        parents = 0x1687a90\n        parent_number = 1\n#14 0x000000000045cbed in name_rev (commit=0x1773d38, tip_name=0x87a240 \"B2G_1_0_0_20130115070201\", \n    generation=87262, distance=87262, deref=0) at builtin/name-rev.c:79\n        name = 0x16868e0\n        parents = 0x16868c0\n        parent_number = 1\n#15 0x000000000045cbed in name_rev (commit=0x1773cf0, tip_name=0x87a240 \"B2G_1_0_0_20130115070201\", \n    generation=87261, distance=87261, deref=0) at builtin/name-rev.c:79\n        name = 0x16868a0\n        parents = 0x175b220\n        parent_number = 1\n#16 0x000000000045cbed in name_rev (commit=0x1773ca8, tip_name=0x87a240 \"B2G_1_0_0_20130115070201\", \n    generation=87260, distance=87260, deref=0) at builtin/name-rev.c:79\n        name = 0x175b200\n        parents = 0x16869e0\n        parent_number = 1\n#17 0x000000000045cbed in name_rev (commit=0x1773c60, tip_name=0x87a240 \"B2G_1_0_0_20130115070201\", \n    generation=87259, distance=87259, deref=0) at builtin/name-rev.c:79\n        name = 0x175b1e0\n        parents = 0x175b1c0\n        parent_number = 1\n#18 0x000000000045cbed in name_rev (commit=0x1773c18, tip_name=0x87a240 \"B2G_1_0_0_20130115070201\", \n    generation=87258, distance=87258, deref=0) at builtin/name-rev.c:79\n        name = 0x1686880\n        parents = 0x175b240\n        parent_number = 1\n#19 0x000000000045cbed in name_rev (commit=0x1773bd0, tip_name=0x87a240 \"B2G_1_0_0_20130115070201\", \n    generation=87257, distance=87257, deref=0) at builtin/name-rev.c:79\n        name = 0x175b1a0\n        parents = 0x175b180\n        parent_number = 1\n#20 0x000000000045cbed in name_rev (commit=0x1773b88, tip_name=0x87a240 \"B2G_1_0_0_20130115070201\", \n    generation=87256, distance=87256, deref=0) at builtin/name-rev.c:79\n        name = 0x175b160\n        parents = 0x175b330\n        parent_number = 1\n#21 0x000000000045cbed in name_rev (commit=0x1773b40, tip_name=0x87a240 \"B2G_1_0_0_20130115070201\", \n    generation=87255, distance=87255, deref=0) at builtin/name-rev.c:79\n        name = 0x175b310\n        parents = 0x175b2f0\n        parent_number = 1\n\n\n=================\n\nRemove most of the name_rev calls.\nSee \nhttp://people.mozilla.org/~sledru/bt-git-on-ff.txt\nfor the full list\n=================\n\n\n#87275 0x000000000045cbed in name_rev (commit=0x85d828, tip_name=0x87a240 \"B2G_1_0_0_20130115070201\", generation=1, \n    distance=1, deref=0) at builtin/name-rev.c:79\n        name = 0x87a290\n        parents = 0x87a3c0\n        parent_number = 1\n#87276 0x000000000045cbed in name_rev (commit=0x85d7e0, tip_name=0x87a240 \"B2G_1_0_0_20130115070201\", generation=0, \n    distance=0, deref=0) at builtin/name-rev.c:79\n        name = 0x87a270\n        parents = 0x879df0\n        parent_number = 1\n#87277 0x000000000045cfca in name_ref (path=0x87a210 \"B2G_1_0_0_20130115070201\", \n    sha1=0x843ec8 \"\\f\\337Bk\\006\\356n}\\275\\347\\217\\325ݛ\\350\\346\\001.\\324\\006\", flags=10, cb_data=0x7fffffffdda0)\n    at builtin/name-rev.c:179\n        commit = 0x85d7e0\n        o = 0x85d7e0\n        data = 0x7fffffffdda0\n        can_abbreviate_output = 1\n        deref = 0\n#87278 0x0000000000508ffd in do_one_ref (entry=0x843ec0, cb_data=0x7fffffffd290) at refs.c:650\n        data = 0x7fffffffd290\n        old_current_ref = 0x0\n        retval = 0\n#87279 0x0000000000509387 in do_for_each_entry_in_dirs (dir1=0x843f28, dir2=0x83d888, fn=0x508f46 <do_one_ref>, \n    cb_data=0x7fffffffd290) at refs.c:748\n        e = 0x843ec0\n        e1 = 0x843ec0\n        e2 = 0x84a600\n        cmp = -1\n        retval = 5\n        i1 = 1\n        i2 = 0\n        __PRETTY_FUNCTION__ = \"do_for_each_entry_in_dirs\"\n#87280 0x0000000000509299 in do_for_each_entry_in_dirs (dir1=0x83d948, dir2=0x83d6d8, fn=0x508f46 <do_one_ref>, \n    cb_data=0x7fffffffd290) at refs.c:720\n        subdir1 = 0x843f28\n        subdir2 = 0x83d888\n        e1 = 0x843f20\n        e2 = 0x83d880\n        cmp = 0\n        retval = 0\n        i1 = 1\n        i2 = 2\n        __PRETTY_FUNCTION__ = \"do_for_each_entry_in_dirs\"\n#87281 0x0000000000509299 in do_for_each_entry_in_dirs (dir1=0x83d658, dir2=0x83d698, fn=0x508f46 <do_one_ref>, \n    cb_data=0x7fffffffd290) at refs.c:720\n        subdir1 = 0x83d948\n        subdir2 = 0x83d6d8\n        e1 = 0x83d940\n        e2 = 0x83d6d0\n        cmp = 0\n        retval = 0\n        i1 = 0\n        i2 = 0\n        __PRETTY_FUNCTION__ = \"do_for_each_entry_in_dirs\"\n#87282 0x000000000050ad97 in do_for_each_entry (refs=0x816ea0 <ref_cache>, base=0x599616 \"\", \n    fn=0x508f46 <do_one_ref>, cb_data=0x7fffffffd290) at refs.c:1686\n        packed_ref_cache = 0x83d1c0\n        loose_dir = 0x83d698\n        packed_dir = 0x83d658\n        retval = 0\n#87283 0x000000000050ae6c in do_for_each_ref (refs=0x816ea0 <ref_cache>, base=0x599616 \"\", fn=0x45ce44 <name_ref>, \n    trim=0, flags=0, cb_data=0x7fffffffdda0) at refs.c:1721\n        data = {base = 0x599616 \"\", trim = 0, flags = 0, fn = 0x45ce44 <name_ref>, cb_data = 0x7fffffffdda0}\n#87284 0x000000000050af92 in for_each_ref (fn=0x45ce44 <name_ref>, cb_data=0x7fffffffdda0) at refs.c:1754\nNo locals.\n#87285 0x000000000045d930 in cmd_name_rev (argc=0, argv=0x83d4c8, prefix=0x0) at builtin/name-rev.c:383\n        revs = {nr = 1, alloc = 64, objects = 0x848cb0}\n        all = 0\n        transform_stdin = 0\n        allow_undefined = 0\n        always = 0\n        peel_tag = 1\n        data = {tags_only = 1, name_only = 1, ref_filter = 0x0}\n        opts = {{type = OPTION_SET_INT, short_name = 0, long_name = 0x57f171 \"name-only\", value = 0x7fffffffdda4, \n            argh = 0x0, help = 0x57f17b \"print only names (no SHA-1)\", flags = 2, callback = 0x0, defval = 1}, {\n            type = OPTION_SET_INT, short_name = 0, long_name = 0x57f197 \"tags\", value = 0x7fffffffdda0, argh = 0x0, \n            help = 0x57f1a0 \"only use tags to name the commits\", flags = 2, callback = 0x0, defval = 1}, {\n            type = OPTION_STRING, short_name = 0, long_name = 0x57f1c2 \"refs\", value = 0x7fffffffdda8, \n            argh = 0x57f1c7 \"pattern\", help = 0x57f1d0 \"only use refs matching <pattern>\", flags = 0, \n            callback = 0x0, defval = 0}, {type = OPTION_GROUP, short_name = 0, long_name = 0x0, value = 0x0, \n            argh = 0x0, help = 0x57f1f1 \"\", flags = 0, callback = 0x0, defval = 0}, {type = OPTION_SET_INT, \n            short_name = 0, long_name = 0x57f1f2 \"all\", value = 0x7fffffffddcc, argh = 0x0, \n            help = 0x57f1f8 \"list all commits reachable from all refs\", flags = 2, callback = 0x0, defval = 1}, {\n            type = OPTION_SET_INT, short_name = 0, long_name = 0x57f221 \"stdin\", value = 0x7fffffffddc8, \n            argh = 0x0, help = 0x57f227 \"read from stdin\", flags = 2, callback = 0x0, defval = 1}, {\n            type = OPTION_SET_INT, short_name = 0, long_name = 0x57f0ba \"undefined\", value = 0x7fffffffddc4, \n            argh = 0x0, help = 0x57f238 \"allow to print `undefined` names (default)\", flags = 2, callback = 0x0, \n            defval = 1}, {type = OPTION_SET_INT, short_name = 0, long_name = 0x57f263 \"always\", \n            value = 0x7fffffffddc0, argh = 0x0, help = 0x57f270 \"show abbreviated commit object as fallback\", \n            flags = 2, callback = 0x0, defval = 1}, {type = OPTION_SET_INT, short_name = 0, \n            long_name = 0x57f29b \"peel-tag\", value = 0x7fffffffddbc, argh = 0x0, \n            help = 0x57f2a8 \"dereference tags in the input (internal use)\", flags = 10, callback = 0x0, \n            defval = 1}, {type = OPTION_END, short_name = 0, long_name = 0x0, value = 0x0, argh = 0x0, help = 0x0, \n            flags = 0, callback = 0x0, defval = 0}}\n#87286 0x000000000042f6ec in cmd_describe (argc=1, argv=0x7fffffffe438, prefix=0x0) at builtin/describe.c:458\n        args = {argv = 0x83d4c0, argc = 6, alloc = 24}\n        contains = 1\n        options = {{type = OPTION_SET_INT, short_name = 0, long_name = 0x574b1d \"contains\", value = 0x7fffffffe1a8, \n            argh = 0x0, help = 0x574b28 \"find the tag that comes after the commit\", flags = 2, callback = 0x0, \n            defval = 1}, {type = OPTION_SET_INT, short_name = 0, long_name = 0x574b51 \"debug\", \n            value = 0x7e8320 <debug>, argh = 0x0, help = 0x574b58 \"debug search strategy on stderr\", flags = 2, \n            callback = 0x0, defval = 1}, {type = OPTION_SET_INT, short_name = 0, long_name = 0x574b78 \"all\", \n            value = 0x7e8324 <all>, argh = 0x0, help = 0x574b7c \"use any ref\", flags = 2, callback = 0x0, \n            defval = 1}, {type = OPTION_SET_INT, short_name = 0, long_name = 0x574b88 \"tags\", \n            value = 0x7e8328 <tags>, argh = 0x0, help = 0x574b8d \"use any tag, even unannotated\", flags = 2, \n            callback = 0x0, defval = 1}, {type = OPTION_SET_INT, short_name = 0, long_name = 0x574bab \"long\", \n            value = 0x7e832c <longformat>, argh = 0x0, help = 0x574bb0 \"always use long format\", flags = 2, \n            callback = 0x0, defval = 1}, {type = OPTION_SET_INT, short_name = 0, \n            long_name = 0x574bc7 \"first-parent\", value = 0x7e8330 <first_parent>, argh = 0x0, \n            help = 0x574bd4 \"only follow first parent\", flags = 2, callback = 0x0, defval = 1}, {\n            type = OPTION_CALLBACK, short_name = 0, long_name = 0x574bed \"abbrev\", value = 0x7dd560 <abbrev>, \n            argh = 0x574bf4 \"n\", help = 0x574bf8 \"use <n> digits to display SHA-1s\", flags = 1, \n            callback = 0x4f706c <parse_opt_abbrev_cb>, defval = 0}, {type = OPTION_SET_INT, short_name = 0, \n            long_name = 0x574c19 \"exact-match\", value = 0x7dd564 <max_candidates>, argh = 0x0, \n            help = 0x574c25 \"only output exact matches\", flags = 2, callback = 0x0, defval = 0}, {\n            type = OPTION_INTEGER, short_name = 0, long_name = 0x574c3f \"candidates\", \n            value = 0x7dd564 <max_candidates>, argh = 0x574bf4 \"n\", \n            help = 0x574c50 \"consider <n> most recent tags (default: 10)\", flags = 0, callback = 0x0, defval = 0}, {\n            type = OPTION_STRING, short_name = 0, long_name = 0x574c7c \"match\", value = 0x7e8368 <pattern>, \n            argh = 0x574c82 \"pattern\", help = 0x574c90 \"only consider tags matching <pattern>\", flags = 0, \n            callback = 0x0, defval = 0}, {type = OPTION_SET_INT, short_name = 0, long_name = 0x574cb6 \"always\", \n            value = 0x7e8370 <always>, argh = 0x0, help = 0x574cc0 \"show abbreviated commit object as fallback\", \n            flags = 2, callback = 0x0, defval = 1}, {type = OPTION_STRING, short_name = 0, \n            long_name = 0x574ceb \"dirty\", value = 0x7e8378 <dirty>, argh = 0x574cf1 \"mark\", \n            help = 0x574cf8 \"append <mark> on dirty working tree (default: \\\"-dirty\\\")\", flags = 1, callback = 0x0, \n            defval = 5721392}, {type = OPTION_END, short_name = 0, long_name = 0x0, value = 0x0, argh = 0x0, \n            help = 0x0, flags = 0, callback = 0x0, defval = 0}}\n#87287 0x000000000040528a in run_builtin (p=0x7dab78 <commands+600>, argc=3, argv=0x7fffffffe430) at git.c:314\n        status = 980314466\n        help = 0\n        st = {st_dev = 0, st_ino = 0, st_nlink = 140737488347856, st_mode = 4158565948, st_uid = 32767, st_gid = 1, \n          __pad0 = 0, st_rdev = 0, st_size = 140737488347856, st_blksize = 140737339576408, st_blocks = 0, \n          st_atim = {tv_sec = 140737488347856, tv_nsec = 4211680}, st_mtim = {tv_sec = 140737351979637, \n            tv_nsec = 140737488348907}, st_ctim = {tv_sec = 8638752, tv_nsec = 140737488348208}, __unused = {\n            5676260, 140737488348907, 1}}\n        prefix = 0x0\n#87288 0x0000000000405483 in handle_builtin (argc=3, argv=0x7fffffffe430) at git.c:487\n        p = 0x7dab78 <commands+600>\n        cmd = 0x7fffffffe6e2 \"describe\"\n        i = 25\n        ext = \"\"\n#87289 0x000000000040559d in run_argv (argcp=0x7fffffffe31c, argv=0x7fffffffe320) at git.c:533\n        done_alias = 0\n#87290 0x0000000000405739 in main (argc=3, av=0x7fffffffe428) at git.c:616\n        done_help = 0\n        was_alias = 0\n        argv = 0x7fffffffe430\n        cmd = 0x7fffffffe6e2 \"describe\"\n"},{"id":"237168","messageId":"loom.20140319T130131-192@post.gmane.org","threadId":"36220","inReplyTo":"532975FB.9030803@mozilla.com","subject":"Re: [BUG] Segfault on git describe","fromName":"Sylvestre Ledru","fromEmail":"sylvestre@mozilla.com","sentAt":"2014-03-19T12:03:06Z","receivedAt":"2014-03-19T12:03:06Z","isPatch":false,"sender":{"key":"sylvestre@mozilla.com","avatar":null},"body":"Sylvestre Ledru <sylvestre <at> mozilla.com> writes:\n\n\n> As attachment, the backtrace. I removed about 87250 calls to the\n> name_rev function. I guess that is a potential source of problem.\nFYI, ulimit -s 100000 (increase the stack size) fixes the issue.\n\nSylvestre\n"},{"id":"237128","messageId":"loom.20140319T224201-156@post.gmane.org","threadId":"36220","inReplyTo":"532975FB.9030803@mozilla.com","subject":"Re: [BUG] Segfault on git describe","fromName":"Dragos Foianu","fromEmail":"dragos.foianu@gmail.com","sentAt":"2014-03-19T22:34:29Z","receivedAt":"2014-03-19T22:34:29Z","isPatch":false,"sender":{"key":"dragos.foianu@gmail.com","avatar":null},"body":"Sylvestre Ledru <sylvestre <at> mozilla.com> writes:\n\n> \n> Hello,\n> \n> Trying to do some stats using the Firefox git repository\n> (https://github.com/mozilla/gecko-dev), I found a bug\n> on git describe. The following command will segfault:\n> git describe --contains a9ff31aebd6dbda82a3c733a72eeeaa0b0525b96\n> \n> Please note that the Firefox history is a pretty long and this commit\n> date is 2001.\n> \n> I experience this issue with the git version, and Debian packages\n> (1.9.0-1 and 2.0~next.20140214-2)\n> \n> As attachment, the backtrace. I removed about 87250 calls to the\n> name_rev function. I guess that is a potential source of problem.\n> \n> Full is available here:\n> http://people.mozilla.org/~sledru/bt-git-on-ff.txt (21 MB)\n> \n> I am available to test patches if needed.\n> \n> Thanks,\n> Sylvestre\n> PS: I am not registered, please cc me.\n\nHello,\n\nThe name_rev function recursively calls itself which is why the backtrace is\nso big. Unfortunately, for repos with long histories it can lead to Stack\nOverflows. This is pretty much what happened in your case.\n\nI tested it on my computer and I get the same results. I managed to get it\nworking by doubling my default stacksize:\n\nulimit -S -s 16192\n\nConsidering your project is a very large one and merely allocating a few\nmore resources fixes the problem, I'm not sure it warrants rewriting the\nfunction to use less stack. You will have to wait for one of the maintainers\nto give you a definitive answer.\n\nAll the best,\nDragos\n"},{"id":"237240","messageId":"20140320233307.GB7774@sigill.intra.peff.net","threadId":"36220","inReplyTo":"loom.20140319T224201-156@post.gmane.org","subject":"Re: [BUG] Segfault on git describe","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2014-03-20T23:33:08Z","receivedAt":"2014-03-20T23:33:08Z","isPatch":false,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Wed, Mar 19, 2014 at 10:34:29PM +0000, Dragos Foianu wrote:\n\n> The name_rev function recursively calls itself which is why the backtrace is\n> so big. Unfortunately, for repos with long histories it can lead to Stack\n> Overflows. This is pretty much what happened in your case.\n> \n> I tested it on my computer and I get the same results. I managed to get it\n> working by doubling my default stacksize:\n> \n> ulimit -S -s 16192\n> \n> Considering your project is a very large one and merely allocating a few\n> more resources fixes the problem, I'm not sure it warrants rewriting the\n> function to use less stack. You will have to wait for one of the maintainers\n> to give you a definitive answer.\n\nThanks for looking into the problem.\n\nAs a general rule, I think we are interested in reducing recursion in\nfunctions which can go O(depth of history) or deeper. I'd say that\nO(lg(depth of history)) is probably OK.\n\nThere is some precedent in 941ba8d (Eliminate recursion in\nsetting/clearing marks in commit list, 2012-01-14), for example.\n\nAlso, in:\n\n  abe601b (sha1_file: remove recursion in unpack_entry, 2013-03-27)\n\n  790d96c (sha1_file: remove recursion in packed_object_info,\n  2013-03-25)\n\n  2baad22 (index-pack: eliminate recursion in find_unresolved_deltas,\n  2012-01-14)\n\nthough I think those recurse in the size of delta chain, which is not\nnearly so big.\n\nSo I think we'd be happy to see it converted to an iterative process\n(probably with a stack on the heap). In addition to name-rev, I believe\nthat \"tag --contains\" will recurse down the longest history path, too (I\nthink there may have been experimental patches for the latter, but you'd\nhave to search the list archive).\n\n-Peff\n"},{"id":"237390","messageId":"loom.20140322T111539-312@post.gmane.org","threadId":"36220","inReplyTo":"20140320233307.GB7774@sigill.intra.peff.net","subject":"Re: [BUG] Segfault on git describe","fromName":"Dragos Foianu","fromEmail":"dragos.foianu@gmail.com","sentAt":"2014-03-22T10:18:44Z","receivedAt":"2014-03-22T10:18:44Z","isPatch":false,"sender":{"key":"dragos.foianu@gmail.com","avatar":null},"body":"Jeff King <peff <at> peff.net> writes:\n\n> \n> So I think we'd be happy to see it converted to an iterative process\n> (probably with a stack on the heap). In addition to name-rev, I believe\n> that \"tag --contains\" will recurse down the longest history path, too (I\n> think there may have been experimental patches for the latter, but you'd\n> have to search the list archive).\n> \n> -Peff\n> \n\nAlright. I'll look into it and hopefully have a patch by the end of the weekend.\n\n-Dragos\n"}]}