git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 2/2] diff: teach diff to read gitattribute diff-algorithm

From
John Cai <johncai86@gmail.com>
Date
Feb 7, 2023, 17:00 UTC
Message-ID
<65129323-326F-4E4A-B6F8-06DC3BBE7B58@gmail.com>
In-Reply-To
<d18a5c32-2f15-93ad-ccbf-e8f048edb311@dunelm.org.uk>
Hi Phillip,
On 7 Feb 2023, at 9:55, Phillip Wood wrote:
Show 55 quoted lines
> Hi John
>
> On 06/02/2023 20:37, John Cai wrote:
>> On 6 Feb 2023, at 11:39, Ævar Arnfjörð Bjarmason wrote:
>>> On Sun, Feb 05 2023, John Cai via GitGitGadget wrote:
>>> For some non-nitpicking, I do worry about exposing this as a DoS vector,
>>> e.g. here's a diff between two distant points in git.git with the
>>> various algorithms:
>>>
>>> 	$ hyperfine -r 1 -L a patience,minimal,histogram,myers 'git diff --diff-algorithm={a} v2.0.0 v2.28.0'
>>> 	Benchmark 1: git diff --diff-algorithm=patience v2.0.0 v2.28.0
>>> 	  Time (abs ≡):        42.121 s               [User: 41.879 s, System: 0.144 s]
>>> 	
>>> 	Benchmark 2: git diff --diff-algorithm=minimal v2.0.0 v2.28.0
>>> 	  Time (abs ≡):        35.634 s               [User: 35.473 s, System: 0.160 s]
>>> 	
>>> 	Benchmark 3: git diff --diff-algorithm=histogram v2.0.0 v2.28.0
>>> 	  Time (abs ≡):        46.912 s               [User: 46.657 s, System: 0.228 s]
>>> 	
>>> 	Benchmark 4: git diff --diff-algorithm=myers v2.0.0 v2.28.0
>>> 	  Time (abs ≡):        33.233 s               [User: 33.072 s, System: 0.160 s]
>>> 	
>>> 	Summary
>>> 	  'git diff --diff-algorithm=myers v2.0.0 v2.28.0' ran
>>> 	    1.07 times faster than 'git diff --diff-algorithm=minimal v2.0.0 v2.28.0'
>>> 	    1.27 times faster than 'git diff --diff-algorithm=patience v2.0.0 v2.28.0'
>>> 	    1.41 times faster than 'git diff --diff-algorithm=histogram v2.0.0 v2.28.0'
>>
>> Thanks for this analysis. To clarify, .gitconfig's diff.algorithm setting is
>> already an attack vector right?
>
> .gitconfig is under the user's control though whereas .gitattributes is attacker controlled if one clones a malicious repository. Having said the worst results above are for the historgram algorithm that merge-ort uses internally and no one has complained about ort's performance.
>
>> I see how this would be adding another one.
>>
>> That being said, here's a separate issue. I benchmarked the usage of
>> .gitattributes as introduced in this patch series, and indeed it does look like
>> there is additional latency:
>>
>> $ echo "* diff-algorithm=patience >> .gitattributes
>> $ hyperfine -r 5 'git-bin-wrapper diff --diff-algorithm=patience v2.0.0 v2.28.0'                      ✭
>> Benchmark 1: git-bin-wrapper diff --diff-algorithm=patience v2.0.0 v2.28.0
>>    Time (mean ± σ):     889.4 ms ± 113.8 ms    [User: 715.7 ms, System: 65.3 ms]
>>    Range (min … max):   764.1 ms … 1029.3 ms    5 runs
>>
>> $ hyperfine -r 5 'git-bin-wrapper diff v2.0.0 v2.28.0'                                                ✭
>> Benchmark 1: git-bin-wrapper diff v2.0.0 v2.28.0
>>    Time (mean ± σ):      2.146 s ±  0.368 s    [User: 0.827 s, System: 0.243 s]
>>    Range (min … max):    1.883 s …  2.795 s    5 runs
>>
>> and I imagine the latency scales with the size of .gitattributes. Although I'm
>> not familiar with other parts of the codebase and how it deals with the latency
>> introduced by reading attributes files.
>
> Ouch! Thanks for benchmarking that is a suspiciously large slow down. I've a feeling the attributes code parses all the .gitattribute files from scratch for each path that's queried, so there may be scope for making it a bit smarter. I see some slow down but no where near as much
Yes, definitely worth looking into how this can be sped up.
Show 14 quoted lines
>
>
> $ hyperfine -r 3 'bin-wrappers/git diff --diff-algorithm=patience --no-color --no-color-moved v2.0.0 v2.28.0'
> Benchmark 1: bin-wrappers/git diff --diff-algorithm=patience --no-color --no-color-moved v2.0.0 v2.28.0
>   Time (mean ± σ):      1.996 s ±  0.008 s    [User: 1.706 s, System: 0.286 s]
>   Range (min … max):    1.989 s …  2.004 s    3 runs
>
> $ hyperfine -r 5 'bin-wrappers/git diff --no-color --no-color-moved v2.0.0 v2.28.0'
> Benchmark 1: bin-wrappers/git diff --no-color --no-color-moved v2.0.0 v2.28.0
>   Time (mean ± σ):      2.238 s ±  0.037 s    [User: 1.880 s, System: 0.350 s]
>   Range (min … max):    2.216 s …  2.303 s    5 runs
>
>
> Perhaps I'm over simplifying but having read the issue you linked to I couldn't help feeling that the majority of users might be satisfied by just changing gitlab to use the patience algorithm when generating diffs.
Right, I recognize this is a judgment call that may be best left up to the list.

We don't have a way in GitLab to change the diff algorithm currently. Of course that can be implemented outside of Git, but having it as part of Git may have a wider benefit for users who would appreciate the convenience of automatically having certain files use one diff algorithm and other files use another, without having to pass in the diff algorithm through the command line each time.

>
> The idea to use .gitattributes seems to have come from Patrick rather than a user request.
>
> This is slightly off topic but one thing I'd really like is a way to tell diff use automatically use --diff-words on some files (e.g. Documentation/*)
I think it's a bit similar to the spirit of this desired feature.

thanks John

Show 67 quoted lines
>
> Best Wishes
>
> Phillip
>
>>> Now, all of those are very slow overall, but some much more than
>>> others. I seem to recall that the non-default ones also had some
>>> pathological cases.
>>>
>>> Another thing to think about is that we've so far considered the diff
>>> algorithm to be purely about presentation, with some notable exceptions
>>> such as "patch-id".
>>>
>>> I've advocated for us getting to the point of having an in-repo
>>> .gitconfig or .gitattributes before with a whitelist of settings like
>>> diff.context for certain paths, or a diff.orderFile.
>>>
>>> But those seem easy to promise future behavior for, v.s. an entire diff
>>> algorithm (which we of course had before, but now we'd have it in
>>> repository data).
>>>
>>> Maybe that's not a distinction worth worrying about, just putting that
>>> out there.
>>>
>>> I think if others are concerned about the above something that would
>>> neatly side-step those is to have it opt-in via the .git/config somehow,
>>> similar to e.g. how you can commit *.gpg content, put this in
>>> .gitattributes:
>>>
>>> 	*.gpg diff=gpg
>>>
>>> But not have it do anything until this is in the repo's .git/config (or
>>> similar):
>>>
>>> 	[diff "gpg"]
>>>          	textconv = gpg --no-tty --decrypt
>>>
>>> For that you could still keep the exact .gitattributes format you have
>>> here, i.e.:
>>>
>>> 	file* diff-algorithm=$STRATEGY
>>>
>>> But we to pick it up we'd need either:
>>>
>>> 	[diff-algorithm]
>>>          	histogram = myers
>>>
>>> Or:
>>>
>>> 	[diff-algorithm "histogram"]
>>>          	allow = true
>>
>> This would help address slowness from the diff algorithm itself. I'm not opposed
>> to adding this config if this attack vector is concerning to people.
>>
>> However, it wouldn't help address the additional latency of scanning
>> .gitattributes to find the diff algorithm.
>>
>> Would a separate config to allow gitattributes be helpful here?
>>
>> [diff-algorithm]
>> 	attributes = true
>>
>>>
>>> The former form being one that would allow you to map the .gitattributes
>>> of the repo (but maybe that would be redundant to
>>> .git/info/attributes)...
Previous: Phillip WoodNext: Elijah Newren
Message 16 of 78 in “Teach diff to honor diff algorithms set through git attributes”
  1. 0/2 Teach diff to honor diff algorithms set through git attributesJohn Cai via GitGitGadget, Feb 5, 2023
  2. 1/2 diff: consolidate diff algorithm option parsingJohn Cai via GitGitGadget, Feb 5, 2023
  3. Phillip WoodFeb 6, 2023
  4. 2/2 diff: teach diff to read gitattribute diff-algorithmJohn Cai via GitGitGadget, Feb 5, 2023
  5. Eric SunshineFeb 5, 2023
  6. John CaiFeb 6, 2023
  7. Phillip WoodFeb 6, 2023
  8. Eric SunshineFeb 6, 2023
  9. John CaiFeb 6, 2023
  10. Elijah NewrenFeb 9, 2023
  11. "bad" diffs (was: [PATCH 2/2] diff: teach diff to read gitattribute diff-algorithm)Ævar Arnfjörð Bjarmason, Feb 9, 2023
  12. John CaiFeb 9, 2023
  13. Ævar Arnfjörð BjarmasonFeb 6, 2023
  14. John CaiFeb 6, 2023
  15. Phillip WoodFeb 7, 2023
  16. John CaiFeb 7, 2023
  17. Elijah NewrenFeb 9, 2023
  18. Phillip WoodFeb 9, 2023
  19. Elijah NewrenFeb 10, 2023
  20. Phillip WoodFeb 11, 2023
  21. Jeff KingFeb 11, 2023
  22. Elijah NewrenFeb 15, 2023
  23. Jeff KingFeb 15, 2023
  24. Junio C HamanoFeb 15, 2023
  25. Phillip WoodFeb 15, 2023
  26. Jeff KingFeb 15, 2023
  27. Ævar Arnfjörð BjarmasonFeb 7, 2023
  28. Phillip WoodFeb 15, 2023
  29. Elijah NewrenFeb 9, 2023
  30. John CaiFeb 14, 2023
  31. Elijah NewrenFeb 15, 2023
  32. Elijah NewrenFeb 9, 2023
  33. Ævar Arnfjörð BjarmasonFeb 9, 2023
  34. Jeff KingFeb 11, 2023
  35. Jeff KingFeb 7, 2023
  36. Ævar Arnfjörð BjarmasonFeb 7, 2023
  37. Junio C HamanoFeb 7, 2023
  38. Ævar Arnfjörð BjarmasonFeb 7, 2023
  39. Junio C HamanoFeb 7, 2023
  40. Ævar Arnfjörð BjarmasonFeb 7, 2023
  41. John CaiFeb 9, 2023
  42. Jeff KingFeb 11, 2023
  43. 0/2 Teach diff to honor diff algorithms set through git attributesJohn Cai via GitGitGadget, Feb 14, 2023
  44. 1/2 diff: consolidate diff algorithm option parsingJohn Cai via GitGitGadget, Feb 14, 2023
  45. Junio C HamanoFeb 15, 2023
  46. John CaiFeb 15, 2023
  47. Junio C HamanoFeb 15, 2023
  48. Jeff KingFeb 16, 2023
  49. Junio C HamanoFeb 16, 2023
  50. John CaiFeb 16, 2023
  51. 2/2 diff: teach diff to read gitattribute diff-algorithmJohn Cai via GitGitGadget, Feb 14, 2023
  52. Junio C HamanoFeb 15, 2023
  53. Junio C HamanoFeb 15, 2023
  54. John CaiFeb 16, 2023
  55. 0/2 Teach diff to honor diff algorithms set through git attributesJohn Cai via GitGitGadget, Feb 17, 2023
  56. 1/2 diff: consolidate diff algorithm option parsingJohn Cai via GitGitGadget, Feb 17, 2023
  57. Junio C HamanoFeb 17, 2023
  58. Elijah NewrenFeb 18, 2023
  59. 2/2 diff: teach diff to read algorithm from diff driverJohn Cai via GitGitGadget, Feb 17, 2023
  60. Junio C HamanoFeb 17, 2023
  61. Elijah NewrenFeb 18, 2023
  62. John CaiFeb 20, 2023
  63. Elijah NewrenFeb 20, 2023
  64. John CaiFeb 20, 2023
  65. Elijah NewrenFeb 20, 2023
  66. John CaiFeb 20, 2023
  67. Jeff KingFeb 22, 2023
  68. John CaiFeb 24, 2023
  69. Elijah NewrenFeb 18, 2023
  70. John CaiFeb 20, 2023
  71. 0/2 Teach diff to honor diff algorithms set through git attributesJohn Cai via GitGitGadget, Feb 20, 2023
  72. 1/2 diff: consolidate diff algorithm option parsingJohn Cai via GitGitGadget, Feb 20, 2023
  73. 2/2 diff: teach diff to read algorithm from diff driverJohn Cai via GitGitGadget, Feb 20, 2023
  74. Junio C HamanoFeb 21, 2023
  75. Elijah NewrenFeb 21, 2023
  76. Junio C HamanoFeb 21, 2023
  77. John CaiFeb 21, 2023
  78. Elijah NewrenFeb 21, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.