git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH] Fix infinite loop when deleting multiple packed refs.

From
Shawn O. Pearce <spearce@spearce.org>
Date
Jan 2, 2007, 08:17 UTC
Message-ID
<20070102081709.GA28779@spearce.org>
In-Reply-To
<b566b20c0701012244l21f85472k83970c0c573ce105@mail.gmail.com>

Nicholas Miell reported that `git branch -D A B` failed if both refs A and B were packed into .git/packed-refs. This happens because the same pack_lock instance was being enqueued into the lock list twice, causing the linked list to change from a singly linked list with a NULL at the end to a circularly linked list with no termination. This resulted in an infinite loop traversing the list during exit.

Signed-off-by: Shawn O. Pearce <spearce@spearce.org>
---
 Nicholas Miell <nmiell@gmail.com> wrote:
 > # this is with 1.4.4.2, spearce says master is also affected.
 > # (not subscribed, please Cc:)
 > 
 > mkdir test
 > cd test
 > git init-db
 > touch blah
 > git add blah
 > git commit -m "blah"
 > git checkout -b A
 > git checkout -b B
 > git checkout master
 > git pack-refs --all --prune
 > git branch -D A B # --> infinite loop in lockfile.c:remove_lock_file()
 Fixed.  ;-)
 Junio, this applies to master, but hopefully could also apply to
 maint, as the bug also shows up there.
 refs.c |    9 ++++-----
 1 files changed, 4 insertions(+), 5 deletions(-)
diff --git a/refs.c b/refs.c
index e88ed8b..f1d1a5d 100644
--- a/refs.c
+++ b/refs.c
@@ -709,10 +709,9 @@ struct ref_lock *lock_any_ref_for_update(const char *ref, const unsigned char *o
 	return lock_ref_sha1_basic(ref, old_sha1, NULL);
 }
 
-static struct lock_file packlock;
-
 static int repack_without_ref(const char *refname)
 {
+	struct lock_file *packlock;
 	struct ref_list *list, *packed_ref_list;
 	int fd;
 	int found = 0;
@@ -726,8 +725,8 @@ static int repack_without_ref(const char *refname)
 	}
 	if (!found)
 		return 0;
-	memset(&packlock, 0, sizeof(packlock));
-	fd = hold_lock_file_for_update(&packlock, git_path("packed-refs"), 0);
+	packlock = calloc(1, sizeof(*packlock));
+	fd = hold_lock_file_for_update(packlock, git_path("packed-refs"), 0);
 	if (fd < 0)
 		return error("cannot delete '%s' from packed refs", refname);
 
@@ -744,7 +743,7 @@ static int repack_without_ref(const char *refname)
 			die("too long a refname '%s'", list->name);
 		write_or_die(fd, line, len);
 	}
-	return commit_lock_file(&packlock);
+	return commit_lock_file(packlock);
 }
 
 int delete_ref(const char *refname, unsigned char *sha1)
-- 
1.5.0.rc0.gab5a
Previous: Nicholas MiellNext: Junio C Hamano
Message 2 of 6 in “infinite loop with git branch -D and packed-refs”
  1. Nicholas MiellJan 2, 2007
  2. Fix infinite loop when deleting multiple packed refs.Shawn O. Pearce, Jan 2, 2007
  3. Junio C HamanoJan 2, 2007
  4. Shawn O. PearceJan 2, 2007
  5. Junio C HamanoJan 2, 2007
  6. Shawn O. PearceJan 5, 2007

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.