Re: What's cooking in git.git (Nov 2025, #10; Sun, 30)
- From
Adrian Ratiu <adrian.ratiu@collabora.com>
- Date
- Dec 8, 2025, 08:44 UTC
- Message-ID
- <87wm2xuzv9.fsf@gentoo.mail-host-address-is-not-set>
- In-Reply-To
- <20251201114336.GA1559453@coredump.intra.peff.net>
On Mon, 01 Dec 2025, Jeff King <peff@peff.net> wrote:
Show 40 quoted lines
> On Sun, Nov 30, 2025 at 09:05:07PM -0800, Junio C Hamano wrote: > >> * ar/submodule-gitdir-tweak (2025-11-19) 7 commits >> - meson/Makefile: allow setting submodule encoding at build time >> - submodule: use hashed name for gitdir >> - submodule: fix case-folding gitdir filesystem colisions >> - submodule: add extension to encode gitdir paths >> - submodule: always validate gitdirs inside submodule_name_to_gitdir >> - builtin/credential-store: move is_rfc3986_unreserved to url.[ch] >> - submodule--helper: use submodule_name_to_gitdir in add_submodule >> >> Avoid local submodule repository directory paths overlapping with >> each other by encoding submodule names before using them as path >> components. >> >> Will merge to 'next'? >> source: <20251119211030.2008441-1-adrian.ratiu@collabora.com> > > This topic seems to introduce a race in t7450. Running: > > make && (cd t && ./t7450-bad-git-dotfiles.sh --stress-limit=50) > > usually fails within 10 or so iterations, whereas without this topic I > can reliably get through 50 iterations (since it's racy, nothing is for > sure, but it seems to trigger pretty easily). > > The failing test is the parallel one added by 9cf8547320 (clone: prevent > clashing git dirs when cloning submodule in parallel, 2024-01-28), which > is making sure we catch nested modules during a parallel checkout. The > race seems to be in Git itself, and not an artifact of the test (so this > isn't a race we want to wave away, but probably a real bug, perhaps even > one with security implications, according to that commit). > > Bisection points to 099fe37397 (submodule: always validate gitdirs > inside submodule_name_to_gitdir, 2025-11-19). Which seems plausible, > given that it tries to move those same checks from 9cf8547320 around. > > It's also possible that the race was always there and this simply makes > it worse, but I wasn't ever able to trigger it on a pre-099fe37397 > commit.
Hi and sorry for the delayed response.
After a conversation I had with Patrick on the patch series, I think I understand what caused this: we need to keep one of the validation checks outside submodule_name_to_gitdir(), to prevent the race.
Will fix in v6.