git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v3 1/2] osxkeychain: exclusive lock to serialize execution of operations

From
Koji Nakamaru via GitGitGadget <gitgitgadget@gmail.com>
Date
May 15, 2024, 19:21 UTC
Message-ID
<3341346c5e6caaad3f222380a82425e1f14b97fa.1715800868.git.gitgitgadget@gmail.com>
In-Reply-To
<pull.1729.v3.git.1715800868.gitgitgadget@gmail.com>
From: Koji Nakamaru <koji.nakamaru@gree.net>

git passes a credential that has been used successfully to the helpers to record. If "git-credential-osxkeychain store" commands run in parallel (with fetch.parallel configuration and/or by running multiple git commands simultaneously), some of them may exit with the error "failed to store: -25299". This is because SecItemUpdate() in add_internet_password() may return errSecDuplicateItem (-25299) in this situation. Apple's documentation [1] also states as below:

  In macOS, some of the functions of this API block while waiting for
  input from the user (for example, when the user is asked to unlock a
  keychain or give permission to change trust settings). In general, it
  is safe to use this API in threads other than your main thread, but
  avoid calling the functions from multiple operations, work queues, or
  threads concurrently. Instead, serialize function calls or confine
  them to a single thread.

The error has not been noticed before, because the former implementation ignored the error.

Introduce an exclusive lock to serialize execution of operations.
[1] https://developer.apple.com/documentation/security/certificate_key_and_trust_services/working_with_concurrency
Signed-off-by: Koji Nakamaru <koji.nakamaru@gree.net>
---
 contrib/credential/osxkeychain/git-credential-osxkeychain.c | 3 +++
 1 file changed, 3 insertions(+)
diff --git a/contrib/credential/osxkeychain/git-credential-osxkeychain.c b/contrib/credential/osxkeychain/git-credential-osxkeychain.c
index 6a40917b1ef..0884db48d0a 100644
--- a/contrib/credential/osxkeychain/git-credential-osxkeychain.c
+++ b/contrib/credential/osxkeychain/git-credential-osxkeychain.c
@@ -414,6 +414,9 @@ int main(int argc, const char **argv)
 	if (!argv[1])
 		die("%s", usage);
 
+	if (open(argv[0], O_RDONLY | O_EXLOCK) == -1)
+		die("failed to lock %s", argv[0]);
+
 	read_credential();
 
 	if (!strcmp(argv[1], "get"))
-- 
gitgitgadget
Previous: Koji Nakamaru via GitGitGadgetNext: Koji Nakamaru via GitGitGadget
Message 18 of 21 in “osxkeychain: lock for exclusive execution”
  1. osxkeychain: lock for exclusive executionKoji Nakamaru via GitGitGadget, May 10, 2024
  2. Bo AndersonMay 10, 2024
  3. Jeff KingMay 10, 2024
  4. brian m. carlsonMay 10, 2024
  5. Jeff KingMay 10, 2024
  6. brian m. carlsonMay 10, 2024
  7. Junio C HamanoMay 10, 2024
  8. Jeff KingMay 10, 2024
  9. Junio C HamanoMay 10, 2024
  10. 0/2 osxkeychain: lock for exclusive executionKoji Nakamaru via GitGitGadget, May 11, 2024
  11. 1/2 osxkeychain: lock for exclusive executionKoji Nakamaru via GitGitGadget, May 11, 2024
  12. Junio C HamanoMay 12, 2024
  13. Koji NakamaruMay 12, 2024
  14. 2/2 osxkeychain: state[] seen=1 to skip unnecessary store operationsKoji Nakamaru via GitGitGadget, May 11, 2024
  15. Junio C HamanoMay 12, 2024
  16. Koji NakamaruMay 12, 2024
  17. 0/2 osxkeychain: lock for exclusive executionKoji Nakamaru via GitGitGadget, May 15, 2024
  18. 1/2 osxkeychain: exclusive lock to serialize execution of operationsKoji Nakamaru via GitGitGadget, May 15, 2024
  19. 2/2 osxkeychain: state to skip unnecessary store operationsKoji Nakamaru via GitGitGadget, May 15, 2024
  20. Koji NakamaruMay 15, 2024
  21. Koji NakamaruMay 10, 2024

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.