{"thread":{"id":"8036","subject":"git-http-fetch Segmentation fault","startedAt":"2007-05-08T19:27:35Z","lastAt":"2007-05-08T20:23:46Z","messageCount":4,"participants":["Luiz Fernando N. Capitulino","Junio C Hamano"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"41483","messageId":"20070508162735.6c530a70@localhost","threadId":"8036","inReplyTo":null,"subject":"git-http-fetch Segmentation fault","fromName":"Luiz Fernando N. Capitulino","fromEmail":"lcapitulino@mandriva.com.br","sentAt":"2007-05-08T19:27:35Z","receivedAt":"2007-05-08T19:27:35Z","isPatch":false,"sender":{"key":"lcapitulino@mandriva.com.br","avatar":null},"body":"\n Hi,\n\n A friend of mine reported an easy to reproduce segmentation fault\nwhen cloning through http from his repository:\n\n\"\"\"\n~/ git clone http://people.mandriva.com/~boiko/mandrivamenu.git\ngot 299cdadd846913a052df361e973a947622f23198\nwalk 299cdadd846913a052df361e973a947622f23198\n...\ngot 0ecd10d9d6ab020c2469a961777854afda705776\n/home/lcapitulino/git//bin/git-clone: line 33: 22353 Segmentation fault      (core dumped) git-http-fetch $v -a -w \"$tname\" \"$sha1\" \"$1\"\n\"\"\"\n\n Sometimes it shows up as a corrupted double-linked list, detected by\nglibc:\n\n\"\"\"\n*** glibc detected *** git-http-fetch: corrupted double-linked list: 0x080a5680 ***\n\"\"\"\n\n It's reproducible with Junio's master and maint branches (3082ac and\n53a582 respectivelly).\n\n BTW, At line 406 (the trap command), git-clone script removes the\ndirectory it was fetching. This removes the core dump file too.\nWe should not remove the directory if there's a core dump in there.\n\n-- \nLuiz Fernando N. Capitulino\n"},{"id":"41491","messageId":"7vfy672iao.fsf@assigned-by-dhcp.cox.net","threadId":"8036","inReplyTo":"20070508162735.6c530a70@localhost","subject":"Re: git-http-fetch Segmentation fault","fromName":"Junio C Hamano","fromEmail":"junkio@cox.net","sentAt":"2007-05-08T20:04:47Z","receivedAt":"2007-05-08T20:04:47Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"\"Luiz Fernando N. Capitulino\" <lcapitulino@mandriva.com.br> escreveu:\n\n>  A friend of mine reported an easy to reproduce segmentation fault\n> when cloning through http from his repository:\n>\n> \"\"\"\n> ~/ git clone http://people.mandriva.com/~boiko/mandrivamenu.git\n> got 299cdadd846913a052df361e973a947622f23198\n> walk 299cdadd846913a052df361e973a947622f23198\n> ...\n> got 0ecd10d9d6ab020c2469a961777854afda705776\n> /home/lcapitulino/git//bin/git-clone: line 33: 22353 Segmentation fault      (core dumped) git-http-fetch $v -a -w \"$tname\" \"$sha1\" \"$1\"\n> \"\"\"\n>\n>  Sometimes it shows up as a corrupted double-linked list, detected by\n> glibc:\n\nDoes not seem to reproduce for me on my x86_64 box nor an i386\nbox I happened to have access to.  Both run Debian etch.\n\nHere is an excerpt from a valgrind run on the x86_64 box.  It\ndoes seem to find a handful \"problematic\" accesses, but all seem\nto be in the system libraries.  I did not get any errors on the\ni386 box.\n\n: gitster v/master; valgrind git-http-fetch -v -a -w remotes/origin/master 299cdadd846913a052df361e973a947622f23198 http://people.mandriva.com/~boiko/mandrivamenu.git/\n\n==2120== Conditional jump or move depends on uninitialised value(s)\n==2120==    at 0x4010AEE: (within /lib/ld-2.3.6.so)\n==2120==    by 0x4006CB6: (within /lib/ld-2.3.6.so)\n==2120==    by 0x51FF260: (within /lib/libc-2.3.6.so)\n==2120==    by 0x400B7D0: (within /lib/ld-2.3.6.so)\n==2120==    by 0x51FECF7: _dl_open (in /lib/libc-2.3.6.so)\n==2120==    by 0x5201497: (within /lib/libc-2.3.6.so)\n==2120==    by 0x400B7D0: (within /lib/ld-2.3.6.so)\n==2120==    by 0x52014E1: __libc_dlopen_mode (in /lib/libc-2.3.6.so)\n==2120==    by 0x51DC456: __nss_lookup_function (in /lib/libc-2.3.6.so)\n==2120==    by 0x51B6FCE: (within /lib/libc-2.3.6.so)\n==2120==    by 0x51B7C06: getaddrinfo (in /lib/libc-2.3.6.so)\n==2120==    by 0x4ED31E2: (within /usr/lib/libcurl.so.3.0.0)\n==2120== \n==2120== Conditional jump or move depends on uninitialised value(s)\n==2120==    at 0x4010AF9: (within /lib/ld-2.3.6.so)\n==2120==    by 0x4006CB6: (within /lib/ld-2.3.6.so)\n==2120==    by 0x51FF260: (within /lib/libc-2.3.6.so)\n==2120==    by 0x400B7D0: (within /lib/ld-2.3.6.so)\n==2120==    by 0x51FECF7: _dl_open (in /lib/libc-2.3.6.so)\n==2120==    by 0x5201497: (within /lib/libc-2.3.6.so)\n==2120==    by 0x400B7D0: (within /lib/ld-2.3.6.so)\n==2120==    by 0x52014E1: __libc_dlopen_mode (in /lib/libc-2.3.6.so)\n==2120==    by 0x51DC456: __nss_lookup_function (in /lib/libc-2.3.6.so)\n==2120==    by 0x51B6FCE: (within /lib/libc-2.3.6.so)\n==2120==    by 0x51B7C06: getaddrinfo (in /lib/libc-2.3.6.so)\n==2120==    by 0x4ED31E2: (within /usr/lib/libcurl.so.3.0.0)\n==2120== \n==2120== Conditional jump or move depends on uninitialised value(s)\n==2120==    at 0x4010B04: (within /lib/ld-2.3.6.so)\n==2120==    by 0x4006CB6: (within /lib/ld-2.3.6.so)\n==2120==    by 0x51FF260: (within /lib/libc-2.3.6.so)\n==2120==    by 0x400B7D0: (within /lib/ld-2.3.6.so)\n==2120==    by 0x51FECF7: _dl_open (in /lib/libc-2.3.6.so)\n==2120==    by 0x5201497: (within /lib/libc-2.3.6.so)\n==2120==    by 0x400B7D0: (within /lib/ld-2.3.6.so)\n==2120==    by 0x52014E1: __libc_dlopen_mode (in /lib/libc-2.3.6.so)\n==2120==    by 0x51DC456: __nss_lookup_function (in /lib/libc-2.3.6.so)\n==2120==    by 0x51B6FCE: (within /lib/libc-2.3.6.so)\n==2120==    by 0x51B7C06: getaddrinfo (in /lib/libc-2.3.6.so)\n==2120==    by 0x4ED31E2: (within /usr/lib/libcurl.so.3.0.0)\n==2120== \n==2120== Conditional jump or move depends on uninitialised value(s)\n==2120==    at 0x4010C61: (within /lib/ld-2.3.6.so)\n==2120==    by 0x4006E47: (within /lib/ld-2.3.6.so)\n==2120==    by 0x51FF260: (within /lib/libc-2.3.6.so)\n==2120==    by 0x400B7D0: (within /lib/ld-2.3.6.so)\n==2120==    by 0x51FECF7: _dl_open (in /lib/libc-2.3.6.so)\n==2120==    by 0x5201497: (within /lib/libc-2.3.6.so)\n==2120==    by 0x400B7D0: (within /lib/ld-2.3.6.so)\n==2120==    by 0x52014E1: __libc_dlopen_mode (in /lib/libc-2.3.6.so)\n==2120==    by 0x51DC456: __nss_lookup_function (in /lib/libc-2.3.6.so)\n==2120==    by 0x51B6FCE: (within /lib/libc-2.3.6.so)\n==2120==    by 0x51B7C06: getaddrinfo (in /lib/libc-2.3.6.so)\n==2120==    by 0x4ED31E2: (within /usr/lib/libcurl.so.3.0.0)\n==2120== \n==2120== Invalid read of size 8\n==2120==    at 0x4010C54: (within /lib/ld-2.3.6.so)\n==2120==    by 0x4008D38: (within /lib/ld-2.3.6.so)\n==2120==    by 0x4004CF2: (within /lib/ld-2.3.6.so)\n==2120==    by 0x4006D6C: (within /lib/ld-2.3.6.so)\n==2120==    by 0x51FF260: (within /lib/libc-2.3.6.so)\n==2120==    by 0x400B7D0: (within /lib/ld-2.3.6.so)\n==2120==    by 0x51FECF7: _dl_open (in /lib/libc-2.3.6.so)\n==2120==    by 0x5201497: (within /lib/libc-2.3.6.so)\n==2120==    by 0x400B7D0: (within /lib/ld-2.3.6.so)\n==2120==    by 0x52014E1: __libc_dlopen_mode (in /lib/libc-2.3.6.so)\n==2120==    by 0x51DC456: __nss_lookup_function (in /lib/libc-2.3.6.so)\n==2120==    by 0x51B6FCE: (within /lib/libc-2.3.6.so)\n==2120==  Address 0x5F096F0 is 16 bytes inside a block of size 23 alloc'd\n==2120==    at 0x4A1B858: malloc (vg_replace_malloc.c:149)\n==2120==    by 0x4007113: (within /lib/ld-2.3.6.so)\n==2120==    by 0x51FF260: (within /lib/libc-2.3.6.so)\n==2120==    by 0x400B7D0: (within /lib/ld-2.3.6.so)\n==2120==    by 0x51FECF7: _dl_open (in /lib/libc-2.3.6.so)\n==2120==    by 0x5201497: (within /lib/libc-2.3.6.so)\n==2120==    by 0x400B7D0: (within /lib/ld-2.3.6.so)\n==2120==    by 0x52014E1: __libc_dlopen_mode (in /lib/libc-2.3.6.so)\n==2120==    by 0x51DC456: __nss_lookup_function (in /lib/libc-2.3.6.so)\n==2120==    by 0x51B6FCE: (within /lib/libc-2.3.6.so)\n==2120==    by 0x51B7C06: getaddrinfo (in /lib/libc-2.3.6.so)\n==2120==    by 0x4ED31E2: (within /usr/lib/libcurl.so.3.0.0)\n...\n==2120== \n==2120== IN SUMMARY: 6 errors from 5 contexts (suppressed: 9 from 1)\n==2120== \n"},{"id":"41493","messageId":"20070508171310.7e21f5ef@localhost","threadId":"8036","inReplyTo":"7vfy672iao.fsf@assigned-by-dhcp.cox.net","subject":"Re: git-http-fetch Segmentation fault","fromName":"Luiz Fernando N. Capitulino","fromEmail":"lcapitulino@mandriva.com.br","sentAt":"2007-05-08T20:13:10Z","receivedAt":"2007-05-08T20:13:10Z","isPatch":false,"sender":{"key":"lcapitulino@mandriva.com.br","avatar":null},"body":"Em Tue, 08 May 2007 13:04:47 -0700\nJunio C Hamano <junkio@cox.net> escreveu:\n\n| \"Luiz Fernando N. Capitulino\" <lcapitulino@mandriva.com.br> escreveu:\n| \n| >  A friend of mine reported an easy to reproduce segmentation fault\n| > when cloning through http from his repository:\n| >\n| > \"\"\"\n| > ~/ git clone http://people.mandriva.com/~boiko/mandrivamenu.git\n| > got 299cdadd846913a052df361e973a947622f23198\n| > walk 299cdadd846913a052df361e973a947622f23198\n| > ...\n| > got 0ecd10d9d6ab020c2469a961777854afda705776\n| > /home/lcapitulino/git//bin/git-clone: line 33: 22353 Segmentation fault      (core dumped) git-http-fetch $v -a -w \"$tname\" \"$sha1\" \"$1\"\n| > \"\"\"\n| >\n| >  Sometimes it shows up as a corrupted double-linked list, detected by\n| > glibc:\n| \n| Does not seem to reproduce for me on my x86_64 box nor an i386\n| box I happened to have access to.  Both run Debian etch.\n\n Forgot to say that you have to try a few times to reproduce.\n\n Boiko, can you try it on another distro? NSL maybe? I only run\nMandriva on my machines.\n\n-- \nLuiz Fernando N. Capitulino\n"},{"id":"41494","messageId":"20070508172346.7a2dd910@localhost","threadId":"8036","inReplyTo":"20070508171310.7e21f5ef@localhost","subject":"Re: git-http-fetch Segmentation fault","fromName":"Luiz Fernando N. Capitulino","fromEmail":"lcapitulino@mandriva.com.br","sentAt":"2007-05-08T20:23:46Z","receivedAt":"2007-05-08T20:23:46Z","isPatch":false,"sender":{"key":"lcapitulino@mandriva.com.br","avatar":null},"body":"Em Tue, 8 May 2007 17:13:10 -0300\n\"Luiz Fernando N. Capitulino\" <lcapitulino@mandriva.com.br> escreveu:\n\n| Em Tue, 08 May 2007 13:04:47 -0700\n| Junio C Hamano <junkio@cox.net> escreveu:\n| \n| | \"Luiz Fernando N. Capitulino\" <lcapitulino@mandriva.com.br> escreveu:\n| | \n| | >  A friend of mine reported an easy to reproduce segmentation fault\n| | > when cloning through http from his repository:\n| | >\n| | > \"\"\"\n| | > ~/ git clone http://people.mandriva.com/~boiko/mandrivamenu.git\n| | > got 299cdadd846913a052df361e973a947622f23198\n| | > walk 299cdadd846913a052df361e973a947622f23198\n| | > ...\n| | > got 0ecd10d9d6ab020c2469a961777854afda705776\n| | > /home/lcapitulino/git//bin/git-clone: line 33: 22353 Segmentation fault      (core dumped) git-http-fetch $v -a -w \"$tname\" \"$sha1\" \"$1\"\n| | > \"\"\"\n| | >\n| | >  Sometimes it shows up as a corrupted double-linked list, detected by\n| | > glibc:\n| | \n| | Does not seem to reproduce for me on my x86_64 box nor an i386\n| | box I happened to have access to.  Both run Debian etch.\n| \n|  Forgot to say that you have to try a few times to reproduce.\n\n And, looks like you need http_proxy set too.\n\n Sorry for the bad report. :-|\n\n-- \nLuiz Fernando N. Capitulino\n"}]}