git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v2 3/8] packed-backend: check whether the "packed-refs" is regular

From
shejialuo <shejialuo@gmail.com>
Date
Jan 31, 2025, 13:54 UTC
Message-ID
<Z5zWE1M4u3NrROI-@ArchLinux>
In-Reply-To
<xmqqplk4duuk.fsf@gitster.g>
On Thu, Jan 30, 2025 at 10:23:15AM -0800, Junio C Hamano wrote:
Show 15 quoted lines
> shejialuo <shejialuo@gmail.com> writes:
> 
> > It might seems that the method one is much easier than method two.
> > However, method one has a significant drawback. When we have checked the
> > file mode using "lstat", we will need to read the file content, there is
> > a possibility that when finishing reading the file content to the
> > memory, the file could be changed into a symlink and we cannot notice.
> 
> To me, the above sounds like saying:
> 
>     The user can run 'git refs verify' and it may declare that refs
>     are all good, and then somebody else can come in and turn the
>     packed-refs file into a bad one, but the user will not notice
>     the mischeif until the check is run the next time.
> 
Yes, it is.
Show 18 quoted lines
> It is just the time that somebody else comes in becomes a bit
> earlier than the time the 'git refs verify' command finishes, and
> there is no fundamental difference.
> 
> > With method two, we could get the "fd" firstly. Even if the file is
> > changed into a symlink, we could still operate the "fd" in the memory
> > which is consistent across the checking which avoids race condition.
> 
> The end result is the same with the lstat(2) approach, isn't it,
> though?.  'git refs verify' may say "I opened the file without
> following symlink and checked the contents, which turned out to be
> perfectly fine".  But because that somebody else came in just after
> the command did nofollow-open and swapped the packed-refs file, the
> repository has a packed-refs file that is not a regular file after
> the command returns success.  So I am not sure if I am following
> your argument to favor the latter over the former.  What am I
> missing?
> 

Let me give you some background. In the version 1, I used the following way:

```c
lstat(...)
if (!IS_REG(...))
    report_error(...);
strbuf_read(...)
```

Patrick has told me that there is a possibility that between the `IS_REG` and `strbuf_read`, the "packed-refs" could be converted into a symlink. So, my idea is that we could use `open_nofollow`, when we have got the file descriptor, no matter what happens to `packed-refs` file (deleted or changed into a symlink), we could operate the file descriptor and read its content.

However, on a platform with O_NOFOLLOW, this situation will also happen. So, I think we may just use "open_nofollow" now and don't talk about the method one at all to avoid confusing readers.

Show 8 quoted lines
> As long as both approaches are equally portable, I do not think it
> matters which one we pick from correctness point of view, and we can
> pick the one that is easier to use to implement the feature.
> 
> On a platform without O_NOFOLLOW, open_nofollow() falls back to the
> lstat and open, so your "open_nofollow() is better than lstat() and
> open()" argument does not portably work, though.
> 

Yes, actually in my first implementation, I didn't notice this. But the CI told me that and I finally chose "open_nofollow".

Show 6 quoted lines
> > Reuse "FSCK_MSG_BAD_REF_FILETYPE" fsck message id to report the error to
> > the user if "packed-refs" is not a regular file.
> 
> Good.  Say "regular file" on the commit title, too, and it would be
> perfect.
> 
Let me improve this in the next version.
Show 37 quoted lines
> > diff --git a/t/t0602-reffiles-fsck.sh b/t/t0602-reffiles-fsck.sh
> > index cf7a202d0d..42c8d4ca1e 100755
> > --- a/t/t0602-reffiles-fsck.sh
> > +++ b/t/t0602-reffiles-fsck.sh
> > @@ -617,4 +617,26 @@ test_expect_success 'ref content checks should work with worktrees' '
> >  	)
> >  '
> >  
> > +test_expect_success SYMLINKS 'the filetype of packed-refs should be checked' '
> > +	test_when_finished "rm -rf repo" &&
> > +	git init repo &&
> > +	(
> > +		cd repo &&
> > +		test_commit default &&
> > +		git branch branch-1 &&
> > +		git branch branch-2 &&
> > +		git branch branch-3 &&
> > +		git pack-refs --all &&
> > +
> > +		mv .git/packed-refs .git/packed-refs-back &&
> > +		ln -sf packed-refs-bak .git/packed-refs &&
> > +		test_must_fail git refs verify 2>err &&
> > +		cat >expect <<-EOF &&
> > +		error: packed-refs: badRefFiletype: not a regular file
> > +		EOF
> > +		rm .git/packed-refs &&
> > +		test_cmp expect err
> > +	)
> > +'
> > +
> >  test_done
> 
> OK.  I notice that the previous step did not have any new test
> associated with it.  Perhaps we can corrupt "HEAD" *and* replace
> packed-refs file with a symbolic link (or do some other damage
> to the refs) and make sure both breakages are reported?
> 

As I have said in the previous comment, we cannot detect the error if "HEAD" itself is corrupted. However, we will check the referent in the later. So, we don't need to do this.

> It does not have to be done in this step, and certainly not as a
> part of this single test this step adds, but we'd want it tested
> somewhere.
> 

If we need to check the referent of the "HEAD" in the "packed-refs". We could do this in the later test. I could cover this in [PATCH 6/8].

Thanks, Jialuo

Previous: Junio C HamanoNext: Junio C Hamano
Message 50 of 168 in “add more ref consistency checks”
  1. 00/10 add more ref consistency checksshejialuo, Jan 5, 2025
  2. 01/10 files-backend: add object check for regular refshejialuo, Jan 5, 2025
  3. Karthik NayakJan 7, 2025
  4. Patrick SteinhardtJan 16, 2025
  5. shejialuoJan 17, 2025
  6. Patrick SteinhardtJan 24, 2025
  7. 02/10 builtin/refs.h: get worktrees without reading head infoshejialuo, Jan 5, 2025
  8. Karthik NayakJan 7, 2025
  9. shejialuoJan 7, 2025
  10. Karthik NayakJan 8, 2025
  11. Patrick SteinhardtJan 16, 2025
  12. 03/10 packed-backend: check whether the "packed-refs" is regularshejialuo, Jan 5, 2025
  13. Karthik NayakJan 7, 2025
  14. shejialuoJan 17, 2025
  15. Eric SunshineJan 17, 2025
  16. shejialuoJan 18, 2025
  17. Karthik NayakJan 19, 2025
  18. Patrick SteinhardtJan 16, 2025
  19. 04/10 packed-backend: add "packed-refs" header consistency checkshejialuo, Jan 5, 2025
  20. shejialuoJan 8, 2025
  21. Patrick SteinhardtJan 16, 2025
  22. shejialuoJan 17, 2025
  23. Patrick SteinhardtJan 24, 2025
  24. shejialuoFeb 17, 2025
  25. 05/10 packed-backend: check whether the refname contains NULL binariesshejialuo, Jan 5, 2025
  26. Patrick SteinhardtJan 16, 2025
  27. shejialuoJan 17, 2025
  28. 06/10 packed-backend: add "packed-refs" entry consistency checkshejialuo, Jan 5, 2025
  29. Patrick SteinhardtJan 16, 2025
  30. shejialuoJan 17, 2025
  31. 07/10 packed-backend: create "fsck_packed_ref_entry" to store parsing infoshejialuo, Jan 5, 2025
  32. Patrick SteinhardtJan 16, 2025
  33. 08/10 packed-backend: add check for object consistencyshejialuo, Jan 5, 2025
  34. Patrick SteinhardtJan 16, 2025
  35. 09/10 packed-backend: check whether the "packed-refs" is sortedshejialuo, Jan 5, 2025
  36. Patrick SteinhardtJan 16, 2025
  37. 10/10 builtin/fsck: add `git refs verify` child processshejialuo, Jan 5, 2025
  38. Junio C HamanoJan 6, 2025
  39. shejialuoJan 7, 2025
  40. Junio C HamanoJan 7, 2025
  41. 0/8 add more ref consistency checksshejialuo, Jan 30, 2025
  42. 1/8 t0602: use subshell to ensure working directory unchangedshejialuo, Jan 30, 2025
  43. Junio C HamanoJan 30, 2025
  44. 2/8 builtin/refs: get worktrees without reading head infoshejialuo, Jan 30, 2025
  45. Junio C HamanoJan 30, 2025
  46. shejialuoJan 31, 2025
  47. Junio C HamanoJan 31, 2025
  48. 3/8 packed-backend: check whether the "packed-refs" is regularshejialuo, Jan 30, 2025
  49. Junio C HamanoJan 30, 2025
  50. shejialuoJan 31, 2025
  51. Junio C HamanoJan 31, 2025
  52. shejialuoFeb 1, 2025
  53. Junio C HamanoFeb 3, 2025
  54. shejialuoFeb 4, 2025
  55. Patrick SteinhardtFeb 3, 2025
  56. 4/8 packed-backend: add "packed-refs" header consistency checkshejialuo, Jan 30, 2025
  57. Junio C HamanoJan 30, 2025
  58. shejialuoJan 31, 2025
  59. 5/8 packed-backend: check whether the refname contains NUL charactersshejialuo, Jan 30, 2025
  60. Patrick SteinhardtFeb 3, 2025
  61. shejialuoFeb 5, 2025
  62. 6/8 packed-backend: add "packed-refs" entry consistency checkshejialuo, Jan 30, 2025
  63. Patrick SteinhardtFeb 3, 2025
  64. shejialuoFeb 4, 2025
  65. 7/8 packed-backend: check whether the "packed-refs" is sortedshejialuo, Jan 30, 2025
  66. Junio C HamanoJan 30, 2025
  67. shejialuoJan 31, 2025
  68. Junio C HamanoJan 31, 2025
  69. shejialuoFeb 1, 2025
  70. Patrick SteinhardtFeb 3, 2025
  71. Patrick SteinhardtFeb 3, 2025
  72. 8/8 builtin/fsck: add `git refs verify` child processshejialuo, Jan 30, 2025
  73. Junio C HamanoJan 30, 2025
  74. shejialuoJan 31, 2025
  75. Patrick SteinhardtFeb 3, 2025
  76. shejialuoFeb 4, 2025
  77. 0/8 add more ref consistency checksshejialuo, Feb 6, 2025
  78. 1/8 t0602: use subshell to ensure working directory unchangedshejialuo, Feb 6, 2025
  79. 2/8 builtin/refs: get worktrees without reading head informationshejialuo, Feb 6, 2025
  80. 3/8 packed-backend: check whether the "packed-refs" is regular fileshejialuo, Feb 6, 2025
  81. 4/8 packed-backend: add "packed-refs" header consistency checkshejialuo, Feb 6, 2025
  82. Patrick SteinhardtFeb 12, 2025
  83. shejialuoFeb 12, 2025
  84. Junio C HamanoFeb 12, 2025
  85. shejialuoFeb 14, 2025
  86. 5/8 packed-backend: check whether the refname contains NUL charactersshejialuo, Feb 6, 2025
  87. 6/8 packed-backend: add "packed-refs" entry consistency checkshejialuo, Feb 6, 2025
  88. Patrick SteinhardtFeb 12, 2025
  89. shejialuoFeb 12, 2025
  90. 7/8 packed-backend: check whether the "packed-refs" is sortedshejialuo, Feb 6, 2025
  91. Patrick SteinhardtFeb 12, 2025
  92. shejialuoFeb 12, 2025
  93. Patrick SteinhardtFeb 12, 2025
  94. shejialuoFeb 12, 2025
  95. 8/8 builtin/fsck: add `git refs verify` child processshejialuo, Feb 6, 2025
  96. Patrick SteinhardtFeb 12, 2025
  97. shejialuoFeb 12, 2025
  98. 0/8 add more ref consistency checksshejialuo, Feb 14, 2025
  99. 1/8 t0602: use subshell to ensure working directory unchangedshejialuo, Feb 14, 2025
  100. 2/8 builtin/refs: get worktrees without reading head informationshejialuo, Feb 14, 2025
  101. Karthik NayakFeb 14, 2025
  102. shejialuoFeb 14, 2025
  103. 3/8 packed-backend: check whether the "packed-refs" is regular fileshejialuo, Feb 14, 2025
  104. Karthik NayakFeb 14, 2025
  105. shejialuoFeb 14, 2025
  106. 4/8 packed-backend: add "packed-refs" header consistency checkshejialuo, Feb 14, 2025
  107. Karthik NayakFeb 14, 2025
  108. shejialuoFeb 14, 2025
  109. Junio C HamanoFeb 14, 2025
  110. 5/8 packed-backend: check whether the refname contains NUL charactersshejialuo, Feb 14, 2025
  111. 6/8 packed-backend: add "packed-refs" entry consistency checkshejialuo, Feb 14, 2025
  112. 7/8 packed-backend: check whether the "packed-refs" is sortedshejialuo, Feb 14, 2025
  113. 8/8 builtin/fsck: add `git refs verify` child processshejialuo, Feb 14, 2025
  114. Karthik NayakFeb 14, 2025
  115. shejialuoFeb 14, 2025
  116. 0/8 add more ref consistency checksshejialuo, Feb 17, 2025
  117. 1/8 t0602: use subshell to ensure working directory unchangedshejialuo, Feb 17, 2025
  118. 2/8 builtin/refs: get worktrees without reading head informationshejialuo, Feb 17, 2025
  119. Patrick SteinhardtFeb 25, 2025
  120. 3/8 packed-backend: check whether the "packed-refs" is regular fileshejialuo, Feb 17, 2025
  121. Patrick SteinhardtFeb 25, 2025
  122. 4/8 packed-backend: add "packed-refs" header consistency checkshejialuo, Feb 17, 2025
  123. Patrick SteinhardtFeb 25, 2025
  124. shejialuoFeb 25, 2025
  125. 5/8 packed-backend: check whether the refname contains NUL charactersshejialuo, Feb 17, 2025
  126. 6/8 packed-backend: add "packed-refs" entry consistency checkshejialuo, Feb 17, 2025
  127. 7/8 packed-backend: check whether the "packed-refs" is sortedshejialuo, Feb 17, 2025
  128. 8/8 builtin/fsck: add `git refs verify` child processshejialuo, Feb 17, 2025
  129. Patrick SteinhardtFeb 25, 2025
  130. 0/9 add more ref consistency checksshejialuo, Feb 25, 2025
  131. 1/9 t0602: use subshell to ensure working directory unchangedshejialuo, Feb 25, 2025
  132. 2/9 builtin/refs: get worktrees without reading head informationshejialuo, Feb 25, 2025
  133. 3/9 packed-backend: check whether the "packed-refs" is regular fileshejialuo, Feb 25, 2025
  134. Junio C HamanoFeb 25, 2025
  135. shejialuoFeb 26, 2025
  136. 4/9 packed-backend: check if header starts with "# pack-refs with: "shejialuo, Feb 25, 2025
  137. Patrick SteinhardtFeb 26, 2025
  138. shejialuoFeb 26, 2025
  139. 5/9 packed-backend: add "packed-refs" header consistency checkshejialuo, Feb 25, 2025
  140. 6/9 packed-backend: check whether the refname contains NUL charactersshejialuo, Feb 25, 2025
  141. 7/9 packed-backend: add "packed-refs" entry consistency checkshejialuo, Feb 25, 2025
  142. 8/9 packed-backend: check whether the "packed-refs" is sortedshejialuo, Feb 25, 2025
  143. 9/9 builtin/fsck: add `git refs verify` child processshejialuo, Feb 25, 2025
  144. 0/9 add more ref consistency checksshejialuo, Feb 26, 2025
  145. 1/9 t0602: use subshell to ensure working directory unchangedshejialuo, Feb 26, 2025
  146. 2/9 builtin/refs: get worktrees without reading head informationshejialuo, Feb 26, 2025
  147. 3/9 packed-backend: check whether the "packed-refs" is regular fileshejialuo, Feb 26, 2025
  148. Junio C HamanoFeb 26, 2025
  149. shejialuoFeb 27, 2025
  150. Patrick SteinhardtFeb 27, 2025
  151. Junio C HamanoFeb 27, 2025
  152. shejialuoFeb 28, 2025
  153. 4/9 packed-backend: check if header starts with "# pack-refs with: "shejialuo, Feb 26, 2025
  154. 5/9 packed-backend: add "packed-refs" header consistency checkshejialuo, Feb 26, 2025
  155. 6/9 packed-backend: check whether the refname contains NUL charactersshejialuo, Feb 26, 2025
  156. 7/9 packed-backend: add "packed-refs" entry consistency checkshejialuo, Feb 26, 2025
  157. 8/9 packed-backend: check whether the "packed-refs" is sortedshejialuo, Feb 26, 2025
  158. 9/9 builtin/fsck: add `git refs verify` child processshejialuo, Feb 26, 2025
  159. 0/9 add more ref consistency checksshejialuo, Feb 27, 2025
  160. 1/9 t0602: use subshell to ensure working directory unchangedshejialuo, Feb 27, 2025
  161. 2/9 builtin/refs: get worktrees without reading head informationshejialuo, Feb 27, 2025
  162. 3/9 packed-backend: check whether the "packed-refs" is regular fileshejialuo, Feb 27, 2025
  163. 4/9 packed-backend: check if header starts with "# pack-refs with: "shejialuo, Feb 27, 2025
  164. 5/9 packed-backend: add "packed-refs" header consistency checkshejialuo, Feb 27, 2025
  165. 6/9 packed-backend: check whether the refname contains NUL charactersshejialuo, Feb 27, 2025
  166. 7/9 packed-backend: add "packed-refs" entry consistency checkshejialuo, Feb 27, 2025
  167. 8/9 packed-backend: check whether the "packed-refs" is sortedshejialuo, Feb 27, 2025
  168. 9/9 builtin/fsck: add `git refs verify` child processshejialuo, Feb 27, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.