git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v2 4/4] bisect--helper: double-check run command on exit code 126 and 127

From
René Scharfe <l.s.r@web.de>
Date
Feb 4, 2022, 17:16 UTC
Message-ID
<0d70e31e-f6d1-dca5-c0e8-e2288e3e1c4e@web.de>
In-Reply-To
<xmqqa6f7pime.fsf@gitster.g>
Am 04.02.22 um 01:42 schrieb Junio C Hamano:
Show 59 quoted lines
> René Scharfe <l.s.r@web.de> writes:
>
>> When a run command cannot be executed or found, shells return exit code
>> 126 or 127, respectively.  Valid run commands are allowed to return
>> these codes as well to indicate bad revisions, though, for historical
>> reasons.  This means typos can cause bogus bisect runs that go over the
>> full distance and end up reporting invalid results.
>>
>> The best solution would be to reserve exit codes 126 and 127, like
>> 71b0251cdd (Bisect run: "skip" current commit if script exit code is
>> 125., 2007-10-26) did for 125, and abort bisect run when we get them.
>> That might be inconvenient for those who relied on the documentation
>> stating that 126 and 127 can be used for bad revisions, though.
>
> I think the basic idea is sound and useful.  How happy are we who
> was involved in the discussion with this result?
>
>> +static int get_first_good(const char *refname, const struct object_id *oid,
>> +			  int flag, void *cb_data)
>> +{
>> +	oidcpy(cb_data, oid);
>> +	return 1;
>> +}
>
> OK, this iterates and stops at the first one.
>
>> +static int verify_good(const struct bisect_terms *terms,
>> +		       const char **quoted_argv)
>> +{
>> +	int rc;
>> +	enum bisect_error res;
>> +	struct object_id good_rev;
>> +	struct object_id current_rev;
>> +	char *good_glob = xstrfmt("%s-*", terms->term_good);
>> +	int no_checkout = ref_exists("BISECT_HEAD");
>> +
>> +	for_each_glob_ref_in(get_first_good, good_glob, "refs/bisect/",
>> +			     &good_rev);
>> +	free(good_glob);
>> +
>> +	if (read_ref(no_checkout ? "BISECT_HEAD" : "HEAD", &current_rev))
>> +		return -1;
>
>  * Could the current_rev already be marked as "good", in which case
>    we can avoid cost of rewriting working tree files to a
>    potentially distant revision?  I often do manual tests to mark
>    "bisect good" or "bisect bad" before using "bisect run".
>
>  * Can we have *no* rev that is marked as "good"?  I think we made
>    it possible to say "my time is more valuable than machine cycles,
>    so I'll only tell you that this revision is broken and give you
>    no limit on the bottom side of the history.  still assume that
>    there was only one good-to-bad transition in the history and find
>    it" by supplying only one "bad" and no "good" when starting to
>    bisect.  And in such a case, ...
>
>> +	res = bisect_checkout(&good_rev, no_checkout);
>
> ... this would feed an uninitialized object_id to bisect_checkout.

bisect_run() starts by calling bisect_next_check() with a current_term parameter value of NULL. It checks if the good rev is missing and calls decide_next(), which returns -1 if current_term is NULL unless both good and bad revs are present. bisect_next_check() passes this value along. bisect_run() exits if it's non-zero.

So AFAICS the uninitialized access would only happen if the good rev ref was deleted between the bisect_next_check() call and the verify_good() call. I considered this scenario to be practically impossible with the current code. We can handle it more gracefully by doing something like in the patch below.

Supporting a bad-only git bisect run would take more work -- perhaps by making verify_good() pick a root commit to check as an assumed good rev (plus fix whatever else caused the current code to pass NULL as current_term).

René
---
 builtin/bisect--helper.c | 3 +++
 1 file changed, 3 insertions(+)
diff --git a/builtin/bisect--helper.c b/builtin/bisect--helper.c
index 50783a586c..e1e58de3b2 100644
--- a/builtin/bisect--helper.c
+++ b/builtin/bisect--helper.c
@@ -1106,9 +1106,12 @@ static int verify_good(const struct bisect_terms *terms,
 	char *good_glob = xstrfmt("%s-*", terms->term_good);
 	int no_checkout = ref_exists("BISECT_HEAD");

+	oidcpy(&good_rev, null_oid());
 	for_each_glob_ref_in(get_first_good, good_glob, "refs/bisect/",
 			     &good_rev);
 	free(good_glob);
+	if (is_null_oid(&good_rev))
+		return -1;

 	if (read_ref(no_checkout ? "BISECT_HEAD" : "HEAD", &current_rev))
 		return -1;
--
2.35.0
Previous: Junio C HamanoNext: Ramkumar Ramachandra
Message 28 of 31 in “git bisect bad @”
  1. Ramkumar RamachandraJan 9, 2022
  2. Junio C HamanoJan 9, 2022
  3. Ramkumar RamachandraJan 9, 2022
  4. bisect: report actual bisect_state() argument on errorRené Scharfe, Jan 10, 2022
  5. Ramkumar RamachandraJan 10, 2022
  6. Junio C HamanoJan 10, 2022
  7. Ramkumar RamachandraJan 10, 2022
  8. René ScharfeJan 12, 2022
  9. Junio C HamanoJan 12, 2022
  10. René ScharfeJan 12, 2022
  11. René ScharfeJan 13, 2022
  12. Ramkumar RamachandraJan 13, 2022
  13. Christian CouderJan 13, 2022
  14. René ScharfeJan 13, 2022
  15. Ramkumar RamachandraJan 13, 2022
  16. René ScharfeJan 14, 2022
  17. Ramkumar RamachandraJan 14, 2022
  18. René ScharfeJan 18, 2022
  19. Junio C HamanoJan 14, 2022
  20. Junio C HamanoJan 13, 2022
  21. 1/4 bisect--helper: report actual bisect_state() argument on errorRené Scharfe, Jan 18, 2022
  22. 2/4 bisect--helper: release strbuf and strvec on run errorRené Scharfe, Jan 18, 2022
  23. 3/4 bisect: document run behavior with exit codes 126 and 127René Scharfe, Jan 18, 2022
  24. 4/4 bisect--helper: double-check run command on exit code 126 and 127René Scharfe, Jan 18, 2022
  25. Junio C HamanoJan 19, 2022
  26. René ScharfeJan 19, 2022
  27. Junio C HamanoFeb 4, 2022
  28. René ScharfeFeb 4, 2022
  29. Ramkumar RamachandraFeb 4, 2022
  30. Junio C HamanoFeb 4, 2022
  31. Ramkumar RamachandraFeb 4, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.