git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v2 2/2] fetch-pack: warn if in commit graph but not obj db

From
JTJonathan Tan <jonathantanmy@google.com>
Date
Oct 31, 2024, 21:19 UTC
Message-ID
<631b9a86778f15b7086e5f17fe850ffa151dd341.1730409376.git.jonathantanmy@google.com>
In-Reply-To
<cover.1730409376.git.jonathantanmy@google.com>

When fetching, there is a step in which sought objects are first checked against the local repository; only objects that are not in the local repository are then fetched. This check first looks up the commit graph file, and returns "present" if the object is in there.

However, the action of first looking up the commit graph file is not done everywhere in Git, especially if the type of the object at the time of lookup is not known. This means that in a repo corruption situation, a user may encounter an "object missing" error, attempt to fetch it, and still encounter the same error later when they reattempt their original action, because the object is present in the commit graph file but not in the object DB.

Therefore, make it a fatal error when this occurs. (Note that we cannot proceed to include this object in the list of objects to be fetched without changing at least the fetch negotiation code: what would happen is that the client will send "want X" and "have X" and when I tested at $DAYJOB with a work server that uses JGit, the server reasonably returned an empty packfile. And changing the fetch negotiation code to only use the object DB when deciding what to report as "have" would be an unnecessary slowdown, I think.)

This was discovered when a lazy fetch of a missing commit completed with nothing actually fetched, and the writing of the commit graph file after every fetch then attempted to read said missing commit, triggering a lazy fetch of said missing commit, resulting in an infinite loop with no user-visible indication (until they check the list of processes running on their computer). With this fix, there is no infinite loop. Note that although the repo corruption we discovered was caused by a bug in GC in a partial clone, the behavior that this patch teaches Git to warn about applies to any repo with commit graph enabled and with a missing commit, whether it is a partial clone or not.

t5330, introduced in 3a1ea94a49 (commit-graph.c: no lazy fetch in lookup_commit_in_graph(), 2022-07-01), tests that an interaction between fetch and the commit graph does not cause an infinite loop. This patch changes the exit code in that situation, so that test had to be changed.

Signed-off-by: Jonathan Tan <jonathantanmy@google.com>
---
 fetch-pack.c                               | 19 ++++++++++++++++---
 t/t5330-no-lazy-fetch-with-commit-graph.sh |  2 +-
 2 files changed, 17 insertions(+), 4 deletions(-)
diff --git a/fetch-pack.c b/fetch-pack.c
index 6728a0d2f5..fe1fb3c1b7 100644
--- a/fetch-pack.c
+++ b/fetch-pack.c
@@ -122,16 +122,29 @@ static void for_each_cached_alternate(struct fetch_negotiator *negotiator,
 		cb(negotiator, cache.items[i]);
 }
 
+static void die_in_commit_graph_only(const struct object_id *oid)
+{
+	die(_("You are attempting to fetch %s, which is in the commit graph file but not in the object database.\n"
+	      "This is probably due to repo corruption.\n"
+	      "If you are attempting to repair this repo corruption by refetching the missing object, use 'git fetch --refetch' with the missing object."),
+	      oid_to_hex(oid));
+}
+
 static struct commit *deref_without_lazy_fetch(const struct object_id *oid,
-					       int mark_tags_complete)
+					       int mark_tags_complete_and_check_obj_db)
 {
 	enum object_type type;
 	struct object_info info = { .typep = &type };
 	struct commit *commit;
 
 	commit = lookup_commit_in_graph(the_repository, oid);
-	if (commit)
+	if (commit) {
+		if (mark_tags_complete_and_check_obj_db) {
+			if (!has_object(the_repository, oid, 0))
+				die_in_commit_graph_only(oid);
+		}
 		return commit;
+	}
 
 	while (1) {
 		if (oid_object_info_extended(the_repository, oid, &info,
@@ -143,7 +156,7 @@ static struct commit *deref_without_lazy_fetch(const struct object_id *oid,
 
 			if (!tag->tagged)
 				return NULL;
-			if (mark_tags_complete)
+			if (mark_tags_complete_and_check_obj_db)
 				tag->object.flags |= COMPLETE;
 			oid = &tag->tagged->oid;
 		} else {
diff --git a/t/t5330-no-lazy-fetch-with-commit-graph.sh b/t/t5330-no-lazy-fetch-with-commit-graph.sh
index 5eb28f0512..feccd58324 100755
--- a/t/t5330-no-lazy-fetch-with-commit-graph.sh
+++ b/t/t5330-no-lazy-fetch-with-commit-graph.sh
@@ -39,7 +39,7 @@ test_expect_success 'fetch any commit from promisor with the usage of the commit
 	test_commit -C with-commit any-commit &&
 	anycommit=$(git -C with-commit rev-parse HEAD) &&
 	GIT_TRACE="$(pwd)/trace.txt" \
-		git -C with-commit-graph fetch origin $anycommit 2>err &&
+		test_must_fail git -C with-commit-graph fetch origin $anycommit 2>err &&
 	! grep "fatal: promisor-remote: unable to fork off fetch subprocess" err &&
 	grep "git fetch origin" trace.txt >actual &&
 	test_line_count = 1 actual
-- 
2.47.0.163.g1226f6d8fa-goog
Previous: Jonathan TanNext: Junio C Hamano
Message 24 of 38 in “promisor-remote: always JIT fetch with --refetch”
  1. promisor-remote: always JIT fetch with --refetchEmily Shaffer, Oct 3, 2024
  2. Junio C HamanoOct 6, 2024
  3. Robert CoupOct 7, 2024
  4. Junio C HamanoOct 7, 2024
  5. Emily ShafferOct 11, 2024
  6. Junio C HamanoOct 11, 2024
  7. fetch-pack: don't mark COMPLETE unless we have the full objectEmily Shaffer, Oct 23, 2024
  8. Emily ShafferOct 23, 2024
  9. Taylor BlauOct 23, 2024
  10. Jonathan TanOct 28, 2024
  11. 0/2 When fetching, warn if in commit graph but not obj dbJonathan Tan, Oct 29, 2024
  12. 1/2 Revert "fetch-pack: add a deref_without_lazy_fetch_extended()"Jonathan Tan, Oct 29, 2024
  13. Josh SteadmonOct 30, 2024
  14. 2/2 fetch-pack: warn if in commit graph but not obj dbJonathan Tan, Oct 29, 2024
  15. Josh SteadmonOct 30, 2024
  16. Jonathan TanOct 31, 2024
  17. Taylor BlauOct 31, 2024
  18. Jonathan TanOct 31, 2024
  19. Taylor BlauNov 1, 2024
  20. Jonathan TanNov 1, 2024
  21. Josh SteadmonOct 30, 2024
  22. 0/2 When fetching, die if in commit graph but not obj dbJonathan Tan, Oct 31, 2024
  23. 1/2 Revert "fetch-pack: add a deref_without_lazy_fetch_extended()"Jonathan Tan, Oct 31, 2024
  24. 2/2 fetch-pack: warn if in commit graph but not obj dbJonathan Tan, Oct 31, 2024
  25. Junio C HamanoNov 1, 2024
  26. Junio C HamanoNov 1, 2024
  27. Han XinNov 1, 2024
  28. Jonathan TanNov 1, 2024
  29. Jonathan TanNov 1, 2024
  30. Junio C HamanoNov 2, 2024
  31. Jonathan TanNov 1, 2024
  32. Taylor BlauNov 1, 2024
  33. Jonathan TanNov 1, 2024
  34. Josh SteadmonOct 31, 2024
  35. 0/2 When fetching, die if in commit graph but not obj dbJonathan Tan, Nov 5, 2024
  36. 1/2 Revert "fetch-pack: add a deref_without_lazy_fetch_extended()"Jonathan Tan, Nov 5, 2024
  37. 2/2 fetch-pack: die if in commit graph but not obj dbJonathan Tan, Nov 5, 2024
  38. Junio C HamanoNov 6, 2024

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.