git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH 1/2] Skip SHA-1 collision test on "index-pack --verify"

From
Nguyễn Thái Ngọc Duy <pclouds@gmail.com>
Date
Feb 24, 2012, 12:23 UTC
Message-ID
<1330086201-13916-1-git-send-email-pclouds@gmail.com>

index-pack --verify (or verify-pack) is about verifying the pack itself. SHA-1 collision test is about outside (probably malicious) objects with the same SHA-1 entering current repo.

SHA-1 collision test is currently done unconditionally. Which means if you verify an in-repo pack, all objects from the pack will be checked against objects in repo, which are themselves.

Skip this test for --verify, unless --strict is also specified.

linux-2.6 $ ls -sh .git/objects/pack/pack-e7732c98a8d54840add294c3c562840f78764196.pack 401M .git/objects/pack/pack-e7732c98a8d54840add294c3c562840f78764196.pack

Without the patch (and with another patch to cut out second pass in index-pack):

linux-2.6 $ time ~/w/git/old index-pack -v --verify .git/objects/pack/pack-e7732c98a8d54840add294c3c562840f78764196.pack Indexing objects: 100% (1944656/1944656), done. fatal: pack has 1617280 unresolved deltas

real 1m1.223s user 0m55.028s sys 0m0.828s

With the patch:

linux-2.6 $ time ~/w/git/git index-pack -v --verify .git/objects/pack/pack-e7732c98a8d54840add294c3c562840f78764196.pack Indexing objects: 100% (1944656/1944656), done. fatal: pack has 1617280 unresolved deltas

real 0m41.714s user 0m40.994s sys 0m0.550s

Signed-off-by: Nguyễn Thái Ngọc Duy <pclouds@gmail.com>
---
 builtin/index-pack.c |    5 +++--
 1 files changed, 3 insertions(+), 2 deletions(-)
diff --git a/builtin/index-pack.c b/builtin/index-pack.c
index dd1c5c9..cee83b9 100644
--- a/builtin/index-pack.c
+++ b/builtin/index-pack.c
@@ -62,6 +62,7 @@ static int nr_resolved_deltas;
 
 static int from_stdin;
 static int strict;
+static int verify;
 static int verbose;
 
 static struct progress *progress;
@@ -461,7 +462,7 @@ static void sha1_object(const void *data, unsigned long size,
 			enum object_type type, unsigned char *sha1)
 {
 	hash_sha1_file(data, size, typename(type), sha1);
-	if (has_sha1_file(sha1)) {
+	if ((strict || !verify) && has_sha1_file(sha1)) {
 		void *has_data;
 		enum object_type has_type;
 		unsigned long has_size;
@@ -1078,7 +1079,7 @@ static void show_pack_info(int stat_only)
 
 int cmd_index_pack(int argc, const char **argv, const char *prefix)
 {
-	int i, fix_thin_pack = 0, verify = 0, stat_only = 0, stat = 0;
+	int i, fix_thin_pack = 0, stat_only = 0, stat = 0;
 	const char *curr_pack, *curr_index;
 	const char *index_name = NULL, *pack_name = NULL;
 	const char *keep_name = NULL, *keep_msg = NULL;
-- 
1.7.8.36.g69ee2
Next: Nguyễn Thái Ngọc Duy
Message 1 of 11 in “Skip SHA-1 collision test on "index-pack --verify"”
  1. 1/2 Skip SHA-1 collision test on "index-pack --verify"Nguyễn Thái Ngọc Duy, Feb 24, 2012
  2. 2/2 index-pack: reduce memory usage when the pack has large blobsNguyễn Thái Ngọc Duy, Feb 24, 2012
  3. Ian KumlienFeb 24, 2012
  4. Ian KumlienFeb 24, 2012
  5. Ian KumlienFeb 24, 2012
  6. Ian KumlienFeb 24, 2012
  7. Nguyen Thai Ngoc DuyFeb 25, 2012
  8. Ian KumlienFeb 25, 2012
  9. Ian KumlienFeb 25, 2012
  10. Nguyen Thai Ngoc DuyFeb 26, 2012
  11. Ian KumlienFeb 26, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.