git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH] pack-check.c::verify_packfile(): don't run SHA-1 update on huge data

From
Junio C Hamano <junkio@cox.net>
Date
Jan 4, 2007, 07:26 UTC
Message-ID
<7vr6ubmewg.fsf_-_@assigned-by-dhcp.cox.net>
In-Reply-To
<7v1wmbnw9x.fsf@assigned-by-dhcp.cox.net>

Running the SHA1_Update() on the whole packfile in a single call revealed an overflow problem we had in the SHA-1 implementation on POWER architecture some time ago, which was fixed with commit b47f509b (June 19, 2006). Other SHA-1 implementations may have a similar problem.

The sliding mmap() series already makes chunked calls to SHA1_Update(), so this patch itself will become moot when it graduates to "master", but in the meantime, run the hash function in smaller chunks to prevent possible future problems.

Signed-off-by: Junio C Hamano <junkio@cox.net>
---
 * Chris, if you have a chance could you try this on the huge
   pack you had trouble with?
   Also whose SHA-1 implementation are you using, if this indeed
   is the problem, I wonder?
 pack-check.c |   20 +++++++++++++++-----
 1 files changed, 15 insertions(+), 5 deletions(-)
diff --git a/pack-check.c b/pack-check.c
index c0caaee..8e123b7 100644
--- a/pack-check.c
+++ b/pack-check.c
@@ -1,16 +1,18 @@
 #include "cache.h"
 #include "pack.h"
 
+#define BATCH (1u<<20)
+
 static int verify_packfile(struct packed_git *p)
 {
 	unsigned long index_size = p->index_size;
 	void *index_base = p->index_base;
 	SHA_CTX ctx;
 	unsigned char sha1[20];
-	unsigned long pack_size = p->pack_size;
-	void *pack_base;
 	struct pack_header *hdr;
 	int nr_objects, err, i;
+	unsigned char *packdata;
+	unsigned long datasize;
 
 	/* Header consistency check */
 	hdr = p->pack_base;
@@ -25,11 +27,19 @@ static int verify_packfile(struct packed_git *p)
 			     "while idx size expects %d", nr_objects,
 			     num_packed_objects(p));
 
+	/* Check integrity of pack data with its SHA-1 checksum */
 	SHA1_Init(&ctx);
-	pack_base = p->pack_base;
-	SHA1_Update(&ctx, pack_base, pack_size - 20);
+	packdata = p->pack_base;
+	datasize = p->pack_size - 20;
+	while (datasize) {
+		unsigned long batch = (datasize < BATCH) ? datasize : BATCH;
+		SHA1_Update(&ctx, packdata, batch);
+		datasize -= batch;
+		packdata += batch;
+	}
 	SHA1_Final(sha1, &ctx);
-	if (hashcmp(sha1, (unsigned char *)pack_base + pack_size - 20))
+
+	if (hashcmp(sha1, (unsigned char *)(p->pack_base) + p->pack_size - 20))
 		return error("Packfile %s SHA1 mismatch with itself",
 			     p->pack_name);
 	if (hashcmp(sha1, (unsigned char *)index_base + index_size - 40))
Previous: Junio C HamanoNext: Chris Lee
Message 21 of 55 in “git-svnimport failed and now git-repack hates me”
  1. Chris LeeJan 3, 2007
  2. Linus TorvaldsJan 4, 2007
  3. Shawn O. PearceJan 4, 2007
  4. Shawn O. PearceJan 4, 2007
  5. Chris LeeJan 4, 2007
  6. Shawn O. PearceJan 4, 2007
  7. Chris LeeJan 4, 2007
  8. Shawn O. PearceJan 4, 2007
  9. Chris LeeJan 4, 2007
  10. Shawn O. PearceJan 4, 2007
  11. Chris LeeJan 4, 2007
  12. Chris LeeJan 4, 2007
  13. Chris LeeJan 4, 2007
  14. Linus TorvaldsJan 4, 2007
  15. Chris LeeJan 4, 2007
  16. Eric WongJan 4, 2007
  17. Randal L. SchwartzJan 4, 2007
  18. Eric WongJan 4, 2007
  19. git-svn: make --repack work consistently between fetch and multi-fetchEric Wong, Jan 5, 2007
  20. Junio C HamanoJan 4, 2007
  21. pack-check.c::verify_packfile(): don't run SHA-1 update on huge dataJunio C Hamano, Jan 4, 2007
  22. Chris LeeJan 4, 2007
  23. Junio C HamanoJan 4, 2007
  24. Chris LeeJan 5, 2007
  25. Junio C HamanoJan 5, 2007
  26. Chris LeeJan 5, 2007
  27. Shawn O. PearceJan 5, 2007
  28. Chris LeeJan 5, 2007
  29. Junio C HamanoJan 5, 2007
  30. Linus TorvaldsJan 5, 2007
  31. alanJan 5, 2007
  32. Eric WongJan 7, 2007
  33. Linus TorvaldsJan 5, 2007
  34. Junio C HamanoJan 5, 2007
  35. Linus TorvaldsJan 5, 2007
  36. Linus TorvaldsJan 5, 2007
  37. Junio C HamanoJan 5, 2007
  38. Linus TorvaldsJan 5, 2007
  39. Johannes SchindelinJan 6, 2007
  40. Chris LeeJan 5, 2007
  41. Junio C HamanoJan 5, 2007
  42. Linus TorvaldsJan 5, 2007
  43. Junio C HamanoJan 5, 2007
  44. Linus TorvaldsJan 6, 2007
  45. Linus TorvaldsJan 6, 2007
  46. Junio C HamanoJan 6, 2007
  47. Linus TorvaldsJan 6, 2007
  48. Chris LeeJan 4, 2007
  49. Linus TorvaldsJan 4, 2007
  50. Sasha KhapyorskyJan 4, 2007
  51. Chris LeeJan 4, 2007
  52. git-svnimport: support for incremental importSasha Khapyorsky, Jan 7, 2007
  53. Chris LeeJan 7, 2007
  54. Sasha KhapyorskyJan 7, 2007
  55. git-svnimport: fix edge revisions double importingSasha Khapyorsky, Jan 8, 2007

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.