git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] xread(): Fix read error when filtering >= 2GB on Mac OS X

From
Jonathan Nieder <jrnieder@gmail.com>
Date
Aug 17, 2013, 21:23 UTC
Message-ID
<20130817212314.GC2904@elie.Belkin>
In-Reply-To
<0EC822B9-E5BB-4FF5-B054-167866EA2075@gmail.com>
Kyle J. McKay wrote:
> According to POSIX [1] for read:
>
> If the value of nbyte is greater than {SSIZE_MAX}, the result is
> implementation-defined.
Sure.
[...]
> Since OS X still supports running 32-bit executables, and SSIZE_MAX is 2GB -
> 1 when running 32-bit it would seem the same limit has been imposed on
> 64-bit executables.  In any case, we should avoid "implementation-defined"
> behavior
Wait --- that's a big leap.

In a 64-bit executable, SSIZE_MAX is 2^63 - 1, so the behavior is not implementation-defined. I'm not sure if Steffen's copy of git is 32-bit or 64-bit --- my guess would be 64-bit. So at first glance this does look like an XNU-specific bug, not a standards thing.

What about the related case where someone does try to "git add" a file with a clean filter producing more than SSIZE_MAX and less than SIZE_MAX bytes?

strbuf_grow() does not directly protect against a strbuf growing to > SSIZE_MAX bytes, but in practice on most machines realloc() does. So in practice we could never read more than SSIZE_MAX characters in the strbuf_read() codepath, but it might be worth a check for paranoia anyway.

While we're here, it's easy to wonder: why is git reading into such a large buffer anyway? Normally git uses the streaming codepath for files larger than big_file_threshold (typically 512 MiB). Unfortunately there are cases where it doesn't. For example:

  - convert_to_git() has not been taught to stream, so paths
    with a clean filter or requiring crlf conversion are read or
    mapped into memory.
  - deflate_to_pack() relies on seeking backward to retry when
    a pack would grow too large, so "git hash-object --stdin"
    cannot use that codepath.
  - a "clean" filter can make a file bigger.
  Perhaps git needs to learn to write to a temporary file
  when asked to keep track of a blob that is larger than fits
  reasonably in memory.  Or maybe not.

So there is room for related work but the codepaths that read() indefinitely large files do seem to be needed, at least in the short term. Working around this Mac OS X-specific limitation at the read() level like you've done still sounds like the right thing to do.

Thanks, both, for your work tracking this down. Hopefully the next version of the patch will be in good shape and then it can be applied quickly.

Thanks and hope that helps, Jonathan

Previous: Kyle J. McKayNext: Steffen Prohaska
Message 7 of 37 in “xread(): Fix read error when filtering >= 2GB on Mac OS X”
  1. xread(): Fix read error when filtering >= 2GB on Mac OS XSteffen Prohaska, Aug 17, 2013
  2. John KeepingAug 17, 2013
  3. Torsten BögershausenAug 17, 2013
  4. Johannes SixtAug 17, 2013
  5. Jonathan NiederAug 17, 2013
  6. Kyle J. McKayAug 17, 2013
  7. Jonathan NiederAug 17, 2013
  8. compat: Fix read() of 2GB and more on Mac OS XSteffen Prohaska, Aug 19, 2013
  9. John KeepingAug 19, 2013
  10. Steffen ProhaskaAug 19, 2013
  11. Johannes SixtAug 19, 2013
  12. Stefan BellerAug 19, 2013
  13. Johannes SixtAug 19, 2013
  14. Steffen ProhaskaAug 19, 2013
  15. compat: Fix read() of 2GB and more on Mac OS XSteffen Prohaska, Aug 19, 2013
  16. Eric SunshineAug 19, 2013
  17. Junio C HamanoAug 19, 2013
  18. compat: Fix read() of 2GB and more on Mac OS XSteffen Prohaska, Aug 19, 2013
  19. Linus TorvaldsAug 19, 2013
  20. Steffen ProhaskaAug 19, 2013
  21. Junio C HamanoAug 19, 2013
  22. Junio C HamanoAug 19, 2013
  23. Linus TorvaldsAug 19, 2013
  24. Kyle J. McKayAug 19, 2013
  25. Linus TorvaldsAug 19, 2013
  26. Junio C HamanoAug 27, 2013
  27. 0/2 Fix IO of >=2GB on Mac OS X by limiting IO chunksSteffen Prohaska, Aug 20, 2013
  28. 1/2 xread, xwrite: Limit size of IO, fixing IO of 2GB and more on Mac OS XSteffen Prohaska, Aug 20, 2013
  29. Junio C HamanoAug 20, 2013
  30. Torsten BögershausenAug 21, 2013
  31. 2/2 Revert "compate/clipped-write.c: large write(2) fails on Mac OS X/XNU"Steffen Prohaska, Aug 20, 2013
  32. 0/2 Fix IO >= 2GB on Mac, fixed typoSteffen Prohaska, Aug 21, 2013
  33. 1/2 xread, xwrite: Limit size of IO, fixing IO of 2GB and more on Mac OS XSteffen Prohaska, Aug 21, 2013
  34. 2/2 Revert "compate/clipped-write.c: large write(2) fails on Mac OS X/XNU"Steffen Prohaska, Aug 21, 2013
  35. Junio C HamanoAug 21, 2013
  36. Johannes SixtAug 19, 2013
  37. Torsten BögershausenAug 19, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.