git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v2 3/4] packfile: recover object lookups racing a concurrent repack

From
Jeff King <peff@peff.net>
Date
Aug 27, 2026, 05:57 UTC
Message-ID
<20260827055743.GB189659@coredump.intra.peff.net>
In-Reply-To
<fc98f48ddb4d46cad66a40ecdd96c139e1397784.1787684429.git.gitgitgadget@gmail.com>
On Tue, Aug 25, 2026 at 07:00:28PM +0000, Elijah Newren via GitGitGadget wrote:
Show 19 quoted lines
>   1. open_pack_index() fails, so we print
> 
>         error: packfile <path> index unavailable
> 
>      and report the pack as unusable, even though the object still lives
>      in the replacement pack.
> 
>   2. A normal lookup recovers: odb_read_object_info_extended() issues a
>      second read that reloads the on-disk pack state and finds the object
>      in its new home, making the message above mere noise.  But an
>      OBJECT_INFO_QUICK lookup deliberately skips that second read to stay
>      fast on a genuine miss, so it does *not* recover: it reports the
>      object as absent even though it still lives in the replacement pack.
>      A resident reader that resolves objects with a QUICK lookup -- such
>      as the `git mktree --batch` process the tests below drive -- then
>      produces wrong results.  Even where a spurious miss is not fatal it
>      is not harmless: `git upload-pack` checks a client's "have" lines
>      with a QUICK lookup, and a dropped "have" removes a common object
>      from the negotiation, so the client is sent more than it needs.

Maybe I am still being dense, but this description does not make any sense to me at all.

The _point_ of QUICK is to accept those false negatives. It is the right thing for upload-pack to do, to avoid re-scans for objects which we simply don't have (and don't necessarily expect to have).

It sounds like mktree is wrong to be using QUICK at all. It comes from 817b0f6027 (mktree: do not check type of remote objects, 2022-06-21) which rewrote a call to vanilla oid_object_info(). From the description there it probably should be using SKIP_FETCH_OBJECT but not QUICK. Or possibly it should use neither unless --missing is given.

So I don't see QUICK itself here violating any contract (even if it _could_ find the object in some cases with just a little more work, as in the case that we were discussing for v1).

The much more interesting case is the non-QUICK one that Patrick outlined earlier in the thread. Where we say "nope, we don't have that object" even though we could find it with a little more work. But that doesn't seem to be described here either. But I think that is not even what this patch is about; that's in patch 4.

If the "error:" message is scary and gross (especially because we may retry and correct it anyway) and happens due to routine races, we might consider suppressing it.

Show 10 quoted lines
> +	/*
> +	 * Set when a lookup finds that a pack we already know about has
> +	 * vanished -- its ".idx" or ".pack" removed out from under us, the
> +	 * signature of a concurrent "git repack".  It tells
> +	 * odb_read_object_info_extended() to reprepare and retry even for an
> +	 * OBJECT_INFO_QUICK lookup, which normally skips that rescan to stay
> +	 * fast on a genuine miss.  Reset when the packfiles are reprepared
> +	 * (see odb_source_packed_prepare()).
> +	 */
> +	unsigned stale_packs_detected : 1;

So this is a way of hackily triggering SECOND_READ for QUICK queries, even though the point of QUICK is to suppress that second read! Again, maybe I'm just being dense, but I don't get it.

Show 19 quoted lines
> @@ -535,8 +550,20 @@ static int open_packed_git_1(struct packed_git *p)
>  	ssize_t read_result;
>  	const unsigned hashsz = p->repo->hash_algo->rawsz;
>  
> -	if (open_pack_index(p))
> +	if (open_pack_index(p)) {
> +		/*
> +		 * A concurrent repack may have removed this pack, deleting its
> +		 * ".idx" before its ".pack" (see unlink_pack_path()).  If the
> +		 * index simply vanished, note the stale pack set and stay
> +		 * quiet; the pack is still reported unusable.  Only a
> +		 * still-present but unreadable index is worth an error.
> +		 */
> +		if (pack_index_is_missing(p)) {
> +			p->repo->objects->stale_packs_detected = 1;
> +			return -1;
> +		}
>  		return error("packfile %s index unavailable", p->pack_name);
> +	}

And this seems racy. We might catch the .idx but miss the .pack file. That would cause a failed read, but not trigger sale_packs_detected.

-Peff
Previous: Elijah Newren via GitGitGadgetNext: Elijah Newren
Message 28 of 49 in “Objects treated as missing despite being present, due to race with geometric repacking”
  1. 0/2 Objects treated as missing despite being present, due to race with geometric repackingElijah Newren via GitGitGadget, Aug 18, 2026
  2. 1/2 replay: fail gracefully when a merge input is unreadableElijah Newren via GitGitGadget, Aug 18, 2026
  3. Junio C HamanoAug 19, 2026
  4. Elijah NewrenAug 21, 2026
  5. Junio C HamanoAug 21, 2026
  6. 2/2 packfile: recover when a multi-pack-index names a removed packElijah Newren via GitGitGadget, Aug 18, 2026
  7. Junio C HamanoAug 19, 2026
  8. Patrick SteinhardtAug 20, 2026
  9. Elijah NewrenAug 21, 2026
  10. Jeff KingAug 24, 2026
  11. Patrick SteinhardtAug 24, 2026
  12. Jeff KingAug 24, 2026
  13. Jeff KingAug 24, 2026
  14. Jeff KingAug 24, 2026
  15. Elijah NewrenAug 25, 2026
  16. Jeff KingAug 24, 2026
  17. Patrick SteinhardtAug 24, 2026
  18. Jeff KingAug 24, 2026
  19. Elijah NewrenAug 25, 2026
  20. Derrick StoleeAug 24, 2026
  21. Elijah NewrenAug 25, 2026
  22. Derrick StoleeAug 24, 2026
  23. 0/4 Objects treated as missing despite being present, due to race with geometric repackingElijah Newren via GitGitGadget, Aug 25, 2026
  24. 1/4 replay: fail gracefully when a merge input is unreadableElijah Newren via GitGitGadget, Aug 25, 2026
  25. 2/4 mktree: plug per-tree leak in --batch modeElijah Newren via GitGitGadget, Aug 25, 2026
  26. Jeff KingAug 27, 2026
  27. 3/4 packfile: recover object lookups racing a concurrent repackElijah Newren via GitGitGadget, Aug 25, 2026
  28. Jeff KingAug 27, 2026
  29. Elijah NewrenAug 27, 2026
  30. Jeff KingAug 29, 2026
  31. 4/4 packfile: recover when a multi-pack-index names a removed packElijah Newren via GitGitGadget, Aug 25, 2026
  32. Jeff KingAug 27, 2026
  33. Elijah NewrenAug 28, 2026
  34. Jeff KingAug 29, 2026
  35. 0/4 Objects treated as missing despite being present, due to race with geometric repackingElijah Newren via GitGitGadget, Aug 29, 2026
  36. 1/4 replay: fail gracefully when a merge input is unreadableElijah Newren via GitGitGadget, Aug 29, 2026
  37. 2/4 mktree: plug per-tree leak in --batch modeElijah Newren via GitGitGadget, Aug 29, 2026
  38. 3/4 mktree: do not use OBJECT_INFO_QUICK when checking objectsElijah Newren via GitGitGadget, Aug 29, 2026
  39. Jeff KingAug 29, 2026
  40. 4/4 packfile: recover when a multi-pack-index names a removed packElijah Newren via GitGitGadget, Aug 29, 2026
  41. Jeff KingAug 29, 2026
  42. Junio C HamanoAug 30, 2026
  43. Patrick SteinhardtAug 31, 2026
  44. Jeff KingAug 31, 2026
  45. Derrick StoleeSep 1, 2026
  46. Junio C HamanoSep 1, 2026
  47. Derrick StoleeSep 1, 2026
  48. Elijah NewrenSep 1, 2026
  49. Derrick StoleeSep 1, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.