git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 0/4] Fix various integer overflows

From
ILIlari Liusvaara <ilari.liusvaara@elisanet.fi>
Date
Jan 27, 2010, 09:57 UTC
Message-ID
<20100127095748.GA9992@Knoppix>
In-Reply-To
<20100127085952.GA21535@cuci.nl>
On Wed, Jan 27, 2010 at 09:59:52AM +0100, Stephen R. van den Berg wrote:
Show 5 quoted lines
> Junio C Hamano wrote:
> >Looks trivially correct; thanks.
> 
> I'm just curious, but is this based on an actual bug which someone
> experienced, or is this just based on mere theoretical code analysis?

Theoretical at first, but I did construct packfile that hits one of those overflows (the one in patch_delta(), 32 bits only).

In real world, hitting this bug would require hitting exactly 2^32-1 byte file, and that is quite rare size for file.

And what can happen with them in real world git usage is different than what can happen with them if packs are suitably manipulated ("transport streams" and bundles both contain packs in them).

-Ilari
Previous: Stephen R. van den Berg
Message 13 of 13 in “Fix various integer overflows”
  1. 0/4 Fix various integer overflowsIlari Liusvaara, Jan 26, 2010
  2. 1/4 Add xmallocz()Ilari Liusvaara, Jan 26, 2010
  3. Bill LearJan 26, 2010
  4. Junio C HamanoJan 26, 2010
  5. Junio C HamanoJan 26, 2010
  6. Ilari LiusvaaraJan 26, 2010
  7. Bill LearJan 26, 2010
  8. 2/4 Fix integer overflow in patch_delta()Ilari Liusvaara, Jan 26, 2010
  9. 3/4 Fix integer overflow in unpack_sha1_rest()Ilari Liusvaara, Jan 26, 2010
  10. 4/4 Fix integer overflow in unpack_compressed_entry()Ilari Liusvaara, Jan 26, 2010
  11. Junio C HamanoJan 26, 2010
  12. Stephen R. van den BergJan 27, 2010
  13. Ilari LiusvaaraJan 27, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.