git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH/RFC] Allow writing loose objects that are corrupted in a pack file

From
Shawn O. Pearce <spearce@spearce.org>
Date
Dec 9, 2008, 16:24 UTC
Message-ID
<20081209162402.GP31551@spearce.org>
In-Reply-To
<20081209093627.77039a1f@perceptron>
Jan Krüger <jk@jk.gs> wrote:
> For fixing a corrupted repository by using backup copies of individual
> files, allow write_sha1_file() to write loose files even if the object
> already exists in a pack file, but only if the existing entry is marked
> as corrupted.

Huh. So I'm digging around sha1_file.c and I'm not yet sure why your patch makes a difference.

has_sha1_file() calls find_pack_entry() to determine which pack has the object, and at what offset (if found). It doesn't care about the offset, but it does care about the successful match.

find_pack_entry() already considers the bad_object_sha1 for each pack, before it even tries the binary search within the index. So if the entry was known to be bad has_sha1_file() will return 0, unless the object is loose.

Where this breaks down is if the object is being created, its very likely we didn't attempt to read it in this process. The bad_object_sha1 table is transient and populated only when unpacking an object entry fails. So for example during a merge if a tree was stored in a pack and is corrupt and the merge result produces that same tree object we won't write it out with write_sha1_file() because it exists in a pack, but since we never read it we also don't know the pack entry is corrupt.

Its horribly inefficient to read every object before we write it back out. The best thing to do when faced with corruption is to stop and repack, overlaying the object database from a known good copy of the repository so pack-objects can use the good copy when a corrupt object is identified.

So I agree with you that changing this in write_sha1_file() is a bad idea for the normal good cases, but I also don't see how this patch changes anything at all... the code path you introduced is already implemented.

Show 26 quoted lines
> diff --git a/sha1_file.c b/sha1_file.c
> index 6c0e251..17085cc 100644
> --- a/sha1_file.c
> +++ b/sha1_file.c
> @@ -2373,14 +2373,17 @@ int write_sha1_file(void *buf, unsigned long len, const char *type, unsigned cha
>  	char hdr[32];
>  	int hdrlen;
>  
> -	/* Normally if we have it in the pack then we do not bother writing
> -	 * it out into .git/objects/??/?{38} file.
> -	 */
>  	write_sha1_file_prepare(buf, len, type, sha1, hdr, &hdrlen);
>  	if (returnsha1)
>  		hashcpy(returnsha1, sha1);
> -	if (has_sha1_file(sha1))
> -		return 0;
> +	/* Normally if we have it in the pack then we do not bother writing
> +	 * it out into .git/objects/??/?{38} file. We do, though, if there
> +	 * is no chance that we have an uncorrupted version of the object.
> +	 */
> +	if (has_sha1_file(sha1)) {
> +		if (has_loose_object(sha1) || !has_packed_and_bad(sha1))
> +			return 0;
> +	}
>  	return write_loose_object(sha1, hdr, hdrlen, buf, len, 0);
>  }
-- 
Shawn.
Previous: R. Tyler BallanceNext: R. Tyler Ballance
Message 3 of 49 in “Allow writing loose objects that are corrupted in a pack file”
  1. Allow writing loose objects that are corrupted in a pack fileJan Krüger, Dec 9, 2008
  2. R. Tyler BallanceDec 9, 2008
  3. Shawn O. PearceDec 9, 2008
  4. R. Tyler BallanceJan 6, 2009
  5. Nicolas PitreJan 7, 2009
  6. R. Tyler BallanceJan 7, 2009
  7. Nicolas PitreJan 7, 2009
  8. R. Tyler BallanceJan 7, 2009
  9. Nicolas PitreJan 7, 2009
  10. Linus TorvaldsJan 7, 2009
  11. R. Tyler BallanceJan 7, 2009
  12. Junio C HamanoJan 7, 2009
  13. R. Tyler BallanceJan 7, 2009
  14. Junio C HamanoJan 7, 2009
  15. R. Tyler BallanceJan 7, 2009
  16. Nicolas PitreJan 7, 2009
  17. Linus TorvaldsJan 7, 2009
  18. Linus TorvaldsJan 7, 2009
  19. R. Tyler BallanceJan 7, 2009
  20. Linus TorvaldsJan 7, 2009
  21. Public repro case! Re: [PATCH/RFC] Allow writing loose objects that are corrupted in a pack fileR. Tyler Ballance, Jan 8, 2009
  22. Linus TorvaldsJan 8, 2009
  23. R. Tyler BallanceJan 8, 2009
  24. Linus TorvaldsJan 8, 2009
  25. Linus TorvaldsJan 8, 2009
  26. Shawn O. PearceJan 8, 2009
  27. James PickensJan 8, 2009
  28. Shawn O. PearceJan 8, 2009
  29. Junio C HamanoJan 8, 2009
  30. Shawn O. PearceJan 8, 2009
  31. Boyd Stephen Smith Jr.Jan 8, 2009
  32. Linus TorvaldsJan 8, 2009
  33. Shawn O. PearceJan 8, 2009
  34. Linus TorvaldsJan 8, 2009
  35. Shawn O. PearceJan 8, 2009
  36. Wrap inflateInit to retry allocation after releasing pack memoryShawn O. Pearce, Jan 8, 2009
  37. Linus TorvaldsJan 8, 2009
  38. Junio C HamanoJan 8, 2009
  39. Linus TorvaldsJan 8, 2009
  40. Shawn O. PearceJan 8, 2009
  41. Linus TorvaldsJan 8, 2009
  42. R. Tyler BallanceJan 8, 2009
  43. Linus TorvaldsJan 8, 2009
  44. R. Tyler BallanceJan 8, 2009
  45. Junio C HamanoJan 9, 2009
  46. Linus TorvaldsJan 8, 2009
  47. R. Tyler BallanceJan 8, 2009
  48. Linus TorvaldsJan 8, 2009
  49. R. Tyler BallanceJan 8, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.