From: Patrick Steinhardt Date: Fri, 02 Oct 2026 07:34:05 GMT Subject: [PATCH 0/2] packfile: fix corruption due to stale delta base cache entries Message-ID: <20261002-pks-packfile-stale-delta-base-cache-v1-0-7592a3e31ae0@pks.im> Hi, this small patch series fixes the bug reported in [1]. To summarize: we never evict delta base cache entries when closing the owning pack. The cache may thus contain stale entries which are keyed by by the memory address of `struct packed_git` and the offset of the entry in the packfile. Now when allocating a new pack that happens to have the exact same address and that has entries sitting at the same offset, we may try to use these stale entries and thus yield corrupted data. This all sounds very unlikely, but the interesting part is that this can be reproduced by using recursive merges with submodules, as we open and close the object databases of each respective submodule. And if they have similar packfiles, then we may trigger the bug. The series is built on top of v2.56.0. Thanks! Patrick [1]: --- Patrick Steinhardt (2): packfile: move around `close_pack()` packfile: fix corruption due to stale delta base cache entries packfile.c | 33 ++++++++++++++++++++++---------- t/t6437-submodule-merge.sh | 47 ++++++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 70 insertions(+), 10 deletions(-) --- base-commit: a018953688f1b10bddf91bff8747068f5f4746a4 change-id: 20261002-pks-packfile-stale-delta-base-cache-0d4730487643