git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v2 2/3] object-file: emit corruption errors when detected

From
Ævar Arnfjörð Bjarmason <avarab@gmail.com>
Date
Dec 7, 2022, 10:33 UTC
Message-ID
<221207.86pmcva2s8.gmgdl@evledraar.gmail.com>
In-Reply-To
<Y5A7qOaxyWxHJiex@coredump.intra.peff.net>
On Wed, Dec 07 2022, Jeff King wrote:
Show 51 quoted lines
> On Wed, Dec 07, 2022 at 05:05:47AM +0100, Ævar Arnfjörð Bjarmason wrote:
>
>> Isn't the below squashed in better? I.e. just always pass the "path",
>> but maybe pass a "fd=0", in which case the function might need to
>> git_open() it.
>> 
>> Then have map_loose_object() and loose_object_info() call
>> open_loose_object(), and pass in the "path" and "fd".
>
> I like this direction, though I'd give a few small suggestions. One is
> to make it unconditional to pass in a valid "fd". These kind of magic
> sentinel values sometimes lead to confusion or bugs, and it's easy
> enough for the caller to use git_open() itself.
>
> In fact, in the one caller who cares, it lets us produce a nicer
> error message:
>
> diff --git a/object-file.c b/object-file.c
> index 24793e1b47..7c2a85132b 100644
> --- a/object-file.c
> +++ b/object-file.c
> @@ -1219,9 +1219,6 @@ static void *map_loose_object_1(struct repository *r, const char *const path,
>  {
>  	void *map;
>  
> -	if (!fd)
> -		fd = git_open(path);
> -
>  	map = NULL;
>  	if (fd >= 0) {
>  		struct stat st;
> @@ -2790,13 +2787,18 @@ int read_loose_object(const char *path,
>  		      struct object_info *oi)
>  {
>  	int ret = -1;
> +	int fd;
>  	void *map = NULL;
>  	unsigned long mapsize;
>  	git_zstream stream;
>  	char hdr[MAX_HEADER_LEN];
>  	unsigned long *size = oi->sizep;
>  
> -	map = map_loose_object_1(the_repository, path, 0, &mapsize);
> +	fd = git_open(path);
> +	if (fd < 0)
> +		error_errno(_("unable to open %s"), path);
> +
> +	map = map_loose_object_1(the_repository, path, fd, &mapsize);
>  	if (!map) {
>  		error_errno(_("unable to mmap %s"), path);
>  		goto out;
Yeah, I think that's even better, although...
Show 41 quoted lines
>> +static void *map_loose_object_1(struct repository *r, const char *const path,
>> +				int fd, unsigned long *size)
>>  {
>>  	void *map;
>> -	int fd;
>>  
>> -	if (path)
>> +	if (!fd)
>>  		fd = git_open(path);
>> -	else
>> -		fd = open_loose_object(r, oid, &path);
>> -	if (mapped_path)
>> -		*mapped_path = xstrdup(path);
>
> The other weird thing here is ownership of "fd". Now some callers pass
> it in, but map_loose_object_1() always closes it. I think that's OK
> (since we want it closed even on success), but definitely surprising
> enough that we'd want to document that in a comment.
>
>> @@ -1251,7 +1245,10 @@ void *map_loose_object(struct repository *r,
>>  		       const struct object_id *oid,
>>  		       unsigned long *size)
>>  {
>> -	return map_loose_object_1(r, NULL, oid, size, NULL);
>> +	const char *path;
>> +	int fd = open_loose_object(r, oid, &path);
>> +
>> +	return map_loose_object_1(r, path,fd, size);
>>  }
>
> It's also kind of weird that map_loose_object_1() is a noop on a
> negative descriptor. That technically makes this correct, but I think it
> would be much less surprising to always take a valid descriptor, and
> this code should do:
>
>   if (fd)
> 	return -1;
>   return map_loose_object_1(r, path, fd, size);
>
> If we are going to make map_loose_object_1() less confusing (and I think
> that is worth doing), let's go all the way.

...maybe we should go further in the other direction. I.e. with my earlier suggestion we're left with the mess that the "fd" ownership isn't clear.

But what I was trying to do was fix up the ownership around the "mapped_path", but we don't need to xstrdup() it in the first place. We already have the caller of open_loose_object() not doing that, we can just say that you're not going to open two loose objects at a time.

Then this becomes easier, and we can just pass the maybe-NULL "const char **oid_path" all the way to open_loose_object():

diff --git a/object-file.c b/object-file.c
index c7a513d123e..6e900737b76 100644
--- a/object-file.c
+++ b/object-file.c
@@ -1176,7 +1176,7 @@ static int stat_loose_object(struct repository *r, const struct object_id *oid,
  * descriptor. See the caveats on the "path" parameter above.
  */
 static int open_loose_object(struct repository *r,
-			     const struct object_id *oid, const char **path)
+			     const struct object_id *oid, const char **oid_path)
 {
 	int fd;
 	struct object_directory *odb;
@@ -1185,8 +1185,12 @@ static int open_loose_object(struct repository *r,
 
 	prepare_alt_odb(r);
 	for (odb = r->objects->odb; odb; odb = odb->next) {
-		*path = odb_loose_path(odb, &buf, oid);
-		fd = git_open(*path);
+		const char *path;
+
+		path = odb_loose_path(odb, &buf, oid);
+		if (oid_path)
+			*oid_path = path;
+		fd = git_open(path);
 		if (fd >= 0)
 			return fd;
 
@@ -1214,19 +1218,22 @@ static int quick_has_loose(struct repository *r,
  * Map the loose object at "path" if it is not NULL, or the path found by
  * searching for a loose object named "oid".
  */
-static void *map_loose_object_1(struct repository *r, const char *path,
+static void *map_loose_object_1(struct repository *r, const char *const path,
 				const struct object_id *oid, unsigned long *size,
-				char **mapped_path)
+				const char **oid_path)
 {
 	void *map;
 	int fd;
 
+	if (path && oid_path)
+		BUG("don't tell me about the path, and ask me what it is!");
+	else if (!(path || oid))
+		BUG("must get an OID or a path!");
+
 	if (path)
 		fd = git_open(path);
 	else
-		fd = open_loose_object(r, oid, &path);
-	if (mapped_path)
-		*mapped_path = xstrdup(path);
+		fd = open_loose_object(r, oid, oid_path);
 
 	map = NULL;
 	if (fd >= 0) {
@@ -1236,7 +1243,8 @@ static void *map_loose_object_1(struct repository *r, const char *path,
 			*size = xsize_t(st.st_size);
 			if (!*size) {
 				/* mmap() is forbidden on empty files */
-				error(_("object file %s is empty"), path);
+				error(_("object file %s is empty"),
+				      path ? path : *oid_path);
 				close(fd);
 				return NULL;
 			}
@@ -1432,7 +1440,7 @@ static int loose_object_info(struct repository *r,
 {
 	int status = 0;
 	unsigned long mapsize;
-	char *mapped_path = NULL;
+	const char *oid_path;
 	void *map;
 	git_zstream stream;
 	char hdr[MAX_HEADER_LEN];
@@ -1464,11 +1472,9 @@ static int loose_object_info(struct repository *r,
 		return 0;
 	}
 
-	map = map_loose_object_1(r, NULL, oid, &mapsize, &mapped_path);
-	if (!map) {
-		free(mapped_path);
+	map = map_loose_object_1(r, NULL, oid, &mapsize, &oid_path);
+	if (!map)
 		return -1;
-	}
 
 	if (!oi->sizep)
 		oi->sizep = &size_scratch;
@@ -1506,11 +1512,10 @@ static int loose_object_info(struct repository *r,
 
 	if (status && (flags & OBJECT_INFO_DIE_IF_CORRUPT))
 		die(_("loose object %s (stored in %s) is corrupt"),
-		    oid_to_hex(oid), mapped_path);
+		    oid_to_hex(oid), oid_path);
 
 	git_inflate_end(&stream);
 cleanup:
-	free(mapped_path);
 	munmap(map, mapsize);
 	if (oi->sizep == &size_scratch)
 		oi->sizep = NULL;
Previous: Jeff KingNext: Jonathan Tan
Message 36 of 85 in “Don't lazy-fetch commits when parsing them”
  1. 0/4 Don't lazy-fetch commits when parsing themJonathan Tan, Nov 30, 2022
  2. 1/4 object-file: reread object with exact same argsJonathan Tan, Nov 30, 2022
  3. 2/4 object-file: refactor corrupt object diagnosisJonathan Tan, Nov 30, 2022
  4. Jeff KingNov 30, 2022
  5. Junio C HamanoNov 30, 2022
  6. Jonathan TanDec 1, 2022
  7. 3/4 object-file: refactor replace object lookupJonathan Tan, Nov 30, 2022
  8. Jeff KingNov 30, 2022
  9. 4/4 commit: don't lazy-fetch commitsJonathan Tan, Nov 30, 2022
  10. Jeff KingNov 30, 2022
  11. Jonathan TanDec 1, 2022
  12. Jeff KingDec 1, 2022
  13. Junio C HamanoNov 30, 2022
  14. Jeff KingNov 30, 2022
  15. 0/4 Don't lazy-fetch commits when parsing themJonathan Tan, Dec 1, 2022
  16. 1/4 object-file: reread object with exact same argsJonathan Tan, Dec 1, 2022
  17. 3/4 object-file: refactor replace object lookupJonathan Tan, Dec 1, 2022
  18. 2/4 object-file: refactor corrupt object diagnosisJonathan Tan, Dec 1, 2022
  19. 4/4 commit: don't lazy-fetch commitsJonathan Tan, Dec 1, 2022
  20. Jeff KingDec 1, 2022
  21. Jonathan TanDec 1, 2022
  22. Jeff KingDec 2, 2022
  23. Jonathan TanDec 6, 2022
  24. Jeff KingDec 6, 2022
  25. Junio C HamanoDec 1, 2022
  26. 0/3 Don't lazy-fetch commits when parsing themJonathan Tan, Dec 7, 2022
  27. 1/3 object-file: don't exit early if skipping looseJonathan Tan, Dec 7, 2022
  28. Junio C HamanoDec 7, 2022
  29. Jeff KingDec 7, 2022
  30. Junio C HamanoDec 7, 2022
  31. Jonathan TanDec 7, 2022
  32. 2/3 object-file: emit corruption errors when detectedJonathan Tan, Dec 7, 2022
  33. Junio C HamanoDec 7, 2022
  34. Ævar Arnfjörð BjarmasonDec 7, 2022
  35. Jeff KingDec 7, 2022
  36. Ævar Arnfjörð BjarmasonDec 7, 2022
  37. Jonathan TanDec 7, 2022
  38. Ævar Arnfjörð BjarmasonDec 7, 2022
  39. Jeff KingDec 8, 2022
  40. Jeff KingDec 7, 2022
  41. 3/3 commit: don't lazy-fetch commitsJonathan Tan, Dec 7, 2022
  42. Junio C HamanoDec 7, 2022
  43. Jeff KingDec 7, 2022
  44. 0/4 Don't lazy-fetch commits when parsing themJonathan Tan, Dec 8, 2022
  45. 1/4 object-file: remove OBJECT_INFO_IGNORE_LOOSEJonathan Tan, Dec 8, 2022
  46. 2/4 object-file: refactor map_loose_object_1()Jonathan Tan, Dec 8, 2022
  47. Jeff KingDec 9, 2022
  48. Jonathan TanDec 9, 2022
  49. Jeff KingDec 9, 2022
  50. Jeff KingDec 9, 2022
  51. 3/4 object-file: emit corruption errors when detectedJonathan Tan, Dec 8, 2022
  52. Jeff KingDec 9, 2022
  53. Jonathan TanDec 9, 2022
  54. Ævar Arnfjörð BjarmasonDec 9, 2022
  55. Jonathan TanDec 9, 2022
  56. 4/4 commit: don't lazy-fetch commitsJonathan Tan, Dec 8, 2022
  57. Ævar Arnfjörð BjarmasonDec 9, 2022
  58. 0/4 Don't lazy-fetch commits when parsing themJonathan Tan, Dec 9, 2022
  59. 1/4 object-file: remove OBJECT_INFO_IGNORE_LOOSEJonathan Tan, Dec 9, 2022
  60. 2/4 object-file: refactor map_loose_object_1()Jonathan Tan, Dec 9, 2022
  61. 3/4 object-file: emit corruption errors when detectedJonathan Tan, Dec 9, 2022
  62. Junio C HamanoDec 10, 2022
  63. Jonathan TanDec 12, 2022
  64. Jeff KingDec 12, 2022
  65. Jonathan TanDec 12, 2022
  66. Jeff KingDec 12, 2022
  67. Jonathan TanDec 12, 2022
  68. Jeff KingDec 12, 2022
  69. Jonathan TanDec 12, 2022
  70. Jeff KingDec 13, 2022
  71. 4/4 commit: don't lazy-fetch commitsJonathan Tan, Dec 9, 2022
  72. 0/4 Don't lazy-fetch commits when parsing themJonathan Tan, Dec 12, 2022
  73. 1/4 object-file: remove OBJECT_INFO_IGNORE_LOOSEJonathan Tan, Dec 12, 2022
  74. 2/4 object-file: refactor map_loose_object_1()Jonathan Tan, Dec 12, 2022
  75. 4/4 commit: don't lazy-fetch commitsJonathan Tan, Dec 12, 2022
  76. 3/4 object-file: emit corruption errors when detectedJonathan Tan, Dec 12, 2022
  77. Junio C HamanoDec 13, 2022
  78. Jeff KingDec 13, 2022
  79. 0/4 Don't lazy-fetch commits when parsing themJonathan Tan, Dec 14, 2022
  80. 1/4 object-file: remove OBJECT_INFO_IGNORE_LOOSEJonathan Tan, Dec 14, 2022
  81. 2/4 object-file: refactor map_loose_object_1()Jonathan Tan, Dec 14, 2022
  82. 3/4 object-file: emit corruption errors when detectedJonathan Tan, Dec 14, 2022
  83. 4/4 commit: don't lazy-fetch commitsJonathan Tan, Dec 14, 2022
  84. Jeff KingDec 14, 2022
  85. Junio C HamanoDec 15, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.