git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v2 4/8] packed-backend: add "packed-refs" header consistency check

From
shejialuo <shejialuo@gmail.com>
Date
Jan 31, 2025, 14:23 UTC
Message-ID
<Z5zc_QAqYP-Dg4-K@ArchLinux>
In-Reply-To
<xmqq1pwkdt7r.fsf@gitster.g>
On Thu, Jan 30, 2025 at 10:58:32AM -0800, Junio C Hamano wrote:
Show 16 quoted lines
> shejialuo <shejialuo@gmail.com> writes:
> 
> > In "packed-backend.c::create_snapshot", if there is a header (the line
> > which starts with '#'), we will check whether the line starts with "#
> > pack-refs with:". As we are going to implement the header consistency
> > check, we should port this check into "packed_fsck".
> >
> > However, the above check is not enough, this is because "git pack-refs"
> > will always write "PACKED_REFS_HEADER" which is a constant string to the
> > "packed-refs" file. So, we should check the following things for the
> > header.
> 
> I haven't done history digging in this area for a while, but we
> should make sure we are not flagging a file that was written in
> ancient version of Git whose repository is still supported.
> 
Understood.
Show 12 quoted lines
> > 1. If the header does not exist, we may report an error to the user
> >    because it should exist, but we do allow no header in "packed-refs"
> >    file. So, create a new fsck message "packedRefMissingHeader(INFO)" to
> >    warn the user and also keep compatibility.
> 
> Are we sure "it should exist"?  I think the header did not exist
> before "Git v1.5.0".  I didn't check with other reimplementations of
> Git (like jgit or libgit2), but as long as our reading side of the
> runtime allows a packed-refs file without the header without
> complaint, I do not think it is a good idea to treat it as a
> report-worthy event from "git fsck".
> 
OK, let me improve this in the next version.
Show 36 quoted lines
> > 2. If the header content does not start with "# packed-ref with:", we
> >    should report an error just like what "create_snapshot" does. So,
> >    create a new fsck message "badPackedRefHeader(ERROR)" for this.
> 
> This I can agree with.  If the first line begins with "#" but not
> with that string (with a trailing SP), that is a sign that it may
> not even be a valid packed-refs file, which is a report-worthy
> event.
> 
> > 3. If the header content is not the same as the constant string
> >    "PACKED_REFS_HEADER", ideally, we should report an error to the user.
> 
> NO.  THAT IS NOT IDEAL AT ALL.
> 
> The header was written like this:
> 
>         /* perhaps other traits later as well */
>         fprintf(cbdata.refs_file, "# pack-refs with: peeled \n");
> 
> in the older versions of Git before it was made into a separate
> preprocessor macro and lost the comment (the above excerpt is from
> "git show v1.5.0:builtin-pack-refs.c").
> 
> Notice "other traits later" in the comment?
> 
> The thing is _designed_ to be extensible.  In fact, these days we
> support a few more traits
> 
>         static const char PACKED_REFS_HEADER[] =
>                 "# pack-refs with: peeled fully-peeled sorted \n";
> 
> (an excerpt from the current refs/packed-backend.c).
> 
> Reporting an error when you see something written by an older
> version of Git is far from ideal.
> 
Understood, I think we should be consistency with the runtime check.
Show 14 quoted lines
> >    However, we allow other contents as long as the header content starts
> >    with "# packed-ref with:". To keep compatibility, create a new fsck
> >    message "unknownPackedRefHeader(INFO)" to warn about this. We may
> >    tighten this rule in the future.
> 
> Whatever we do, what we do with an unknown trait should be in line
> with what the runtime does.  If the runtime failed (we do not, but
> this is to illustrate the principle [*]) on a packed-refs file
> without "sorted" trait, noticing that "sorted" is not there and
> flagging as an error is a good thing to do.  But if the runtime
> gracefully degrades and sorts the list of refs read from such a
> packed-refs file before continuing, then a packed-refs file that
> lack "sorted" trait is not a report-worthy event.
> 
Actually, the runtime won't complain about this. I agree with you here.
Show 8 quoted lines
> I do not offhand recall if we introduced the concept of mandatory vs
> optional traits in the packed-refs part of the system (like we have
> in the index extension subsystem, where a version of Git that
> encounters an unknown *and* mandatory index extension must refuse to
> touch the repository), but if there is a mandatory trait declared in
> the header that our version of Git does not understand, it is a
> report-worthy event that must be flagged with "git refs verify".
> 

I don't think any trait in "packed-refs" is mandatory. Because I have done some experiments before implementing the code. We should only check case 2 here.

Show 23 quoted lines
> > +static int packed_fsck_ref_header(struct fsck_options *o, const char *start, const char *eol)
> > +{
> > +	const char *err_fmt = NULL;
> > +	int fsck_msg_id = -1;
> > +
> > +	if (!starts_with(start, "# pack-refs with:")) {
> > +		err_fmt = "'%.*s' does not start with '# pack-refs with:'";
> > +		fsck_msg_id = FSCK_MSG_BAD_PACKED_REF_HEADER;
> > +	} else if (strncmp(start, PACKED_REFS_HEADER, strlen(PACKED_REFS_HEADER))) {
> > +		err_fmt = "'%.*s' is an unknown packed-refs header";
> > +		fsck_msg_id = FSCK_MSG_UNKNOWN_PACKED_REF_HEADER;
> > +	}
> 
> As I outlined above, this is totally unacceptable.  
> 
> Inspecting the header is good, but if this code claims to be a
> checker, it should do at least what the runtime does, i.e. parse the
> header to tell what traits the packed-file declares, not just
> assuming that it is a fixed string.  And error on unknown trait(s)
> if they are mandatory (if such a concept is implemented in the
> runtime reading side).  Informing on an unknown and optional
> trait(s) I can live with, but personally I wouldn't recommend it.
> 
Got it, I don't want to report unknown trait(s) either.
> In other words, report loudly if it is an error, but otherwise stay
> silent if we know we tolerate it well. 
> 
Thanks for this suggestion.
Show 8 quoted lines
> > +static int packed_fsck_ref_content(struct fsck_options *o,
> > +				   const char *start, const char *eof)
> > +{
> > +	struct strbuf packed_entry = STRBUF_INIT;
> > +	int line_number = 1;
> 
> We limit ourselves with about 1 billion refs in the packed-refs
> file, which may be plenty,
Let me change this to `size_t`. This would be better.
> but I do not quite understand the use of
> this variable.  There is no loop inside this so ...
> 

The reason why I define this variable is that I am going to use loop to check each entry in the next patch.

Show 21 quoted lines
> > +	const char *eol;
> > +	int ret = 0;
> > +
> > +	strbuf_addf(&packed_entry, "packed-refs line %d", line_number);
> 
> ... this is always line #1, and then
> 
> > +	ret |= packed_fsck_ref_next_line(o, &packed_entry, start, eof, &eol);
> > +	if (*start == '#') {
> > +		ret |= packed_fsck_ref_header(o, start, eol);
> > +
> > +		start = eol + 1;
> > +		line_number++;
> 
> ... it may be incremented, but upon returning from the funcition, it
> is lost.
> 
> Perhaps you wanted to make it a function-scope static, but then you
> are allowed to read one single packed-refs file during the life of
> your process before you exit, which I am not sure is what you want?
> 

Actually, what I want is use this variable for looping the each ref entry in the "packed-refs" file.

Show 12 quoted lines
> > +	} else {
> > +		struct fsck_ref_report report = { 0 };
> > +		report.path = "packed-refs";
> > +
> > +		ret |= fsck_report_ref(o, &report,
> > +				       FSCK_MSG_PACKED_REF_MISSING_HEADER,
> > +				       "missing header line");
> > +	}
> > +
> > +	strbuf_release(&packed_entry);
> > +	return ret;
> > +}

Thanks, Jialuo

Previous: Junio C HamanoNext: shejialuo
Message 58 of 168 in “add more ref consistency checks”
  1. 00/10 add more ref consistency checksshejialuo, Jan 5, 2025
  2. 01/10 files-backend: add object check for regular refshejialuo, Jan 5, 2025
  3. Karthik NayakJan 7, 2025
  4. Patrick SteinhardtJan 16, 2025
  5. shejialuoJan 17, 2025
  6. Patrick SteinhardtJan 24, 2025
  7. 02/10 builtin/refs.h: get worktrees without reading head infoshejialuo, Jan 5, 2025
  8. Karthik NayakJan 7, 2025
  9. shejialuoJan 7, 2025
  10. Karthik NayakJan 8, 2025
  11. Patrick SteinhardtJan 16, 2025
  12. 03/10 packed-backend: check whether the "packed-refs" is regularshejialuo, Jan 5, 2025
  13. Karthik NayakJan 7, 2025
  14. shejialuoJan 17, 2025
  15. Eric SunshineJan 17, 2025
  16. shejialuoJan 18, 2025
  17. Karthik NayakJan 19, 2025
  18. Patrick SteinhardtJan 16, 2025
  19. 04/10 packed-backend: add "packed-refs" header consistency checkshejialuo, Jan 5, 2025
  20. shejialuoJan 8, 2025
  21. Patrick SteinhardtJan 16, 2025
  22. shejialuoJan 17, 2025
  23. Patrick SteinhardtJan 24, 2025
  24. shejialuoFeb 17, 2025
  25. 05/10 packed-backend: check whether the refname contains NULL binariesshejialuo, Jan 5, 2025
  26. Patrick SteinhardtJan 16, 2025
  27. shejialuoJan 17, 2025
  28. 06/10 packed-backend: add "packed-refs" entry consistency checkshejialuo, Jan 5, 2025
  29. Patrick SteinhardtJan 16, 2025
  30. shejialuoJan 17, 2025
  31. 07/10 packed-backend: create "fsck_packed_ref_entry" to store parsing infoshejialuo, Jan 5, 2025
  32. Patrick SteinhardtJan 16, 2025
  33. 08/10 packed-backend: add check for object consistencyshejialuo, Jan 5, 2025
  34. Patrick SteinhardtJan 16, 2025
  35. 09/10 packed-backend: check whether the "packed-refs" is sortedshejialuo, Jan 5, 2025
  36. Patrick SteinhardtJan 16, 2025
  37. 10/10 builtin/fsck: add `git refs verify` child processshejialuo, Jan 5, 2025
  38. Junio C HamanoJan 6, 2025
  39. shejialuoJan 7, 2025
  40. Junio C HamanoJan 7, 2025
  41. 0/8 add more ref consistency checksshejialuo, Jan 30, 2025
  42. 1/8 t0602: use subshell to ensure working directory unchangedshejialuo, Jan 30, 2025
  43. Junio C HamanoJan 30, 2025
  44. 2/8 builtin/refs: get worktrees without reading head infoshejialuo, Jan 30, 2025
  45. Junio C HamanoJan 30, 2025
  46. shejialuoJan 31, 2025
  47. Junio C HamanoJan 31, 2025
  48. 3/8 packed-backend: check whether the "packed-refs" is regularshejialuo, Jan 30, 2025
  49. Junio C HamanoJan 30, 2025
  50. shejialuoJan 31, 2025
  51. Junio C HamanoJan 31, 2025
  52. shejialuoFeb 1, 2025
  53. Junio C HamanoFeb 3, 2025
  54. shejialuoFeb 4, 2025
  55. Patrick SteinhardtFeb 3, 2025
  56. 4/8 packed-backend: add "packed-refs" header consistency checkshejialuo, Jan 30, 2025
  57. Junio C HamanoJan 30, 2025
  58. shejialuoJan 31, 2025
  59. 5/8 packed-backend: check whether the refname contains NUL charactersshejialuo, Jan 30, 2025
  60. Patrick SteinhardtFeb 3, 2025
  61. shejialuoFeb 5, 2025
  62. 6/8 packed-backend: add "packed-refs" entry consistency checkshejialuo, Jan 30, 2025
  63. Patrick SteinhardtFeb 3, 2025
  64. shejialuoFeb 4, 2025
  65. 7/8 packed-backend: check whether the "packed-refs" is sortedshejialuo, Jan 30, 2025
  66. Junio C HamanoJan 30, 2025
  67. shejialuoJan 31, 2025
  68. Junio C HamanoJan 31, 2025
  69. shejialuoFeb 1, 2025
  70. Patrick SteinhardtFeb 3, 2025
  71. Patrick SteinhardtFeb 3, 2025
  72. 8/8 builtin/fsck: add `git refs verify` child processshejialuo, Jan 30, 2025
  73. Junio C HamanoJan 30, 2025
  74. shejialuoJan 31, 2025
  75. Patrick SteinhardtFeb 3, 2025
  76. shejialuoFeb 4, 2025
  77. 0/8 add more ref consistency checksshejialuo, Feb 6, 2025
  78. 1/8 t0602: use subshell to ensure working directory unchangedshejialuo, Feb 6, 2025
  79. 2/8 builtin/refs: get worktrees without reading head informationshejialuo, Feb 6, 2025
  80. 3/8 packed-backend: check whether the "packed-refs" is regular fileshejialuo, Feb 6, 2025
  81. 4/8 packed-backend: add "packed-refs" header consistency checkshejialuo, Feb 6, 2025
  82. Patrick SteinhardtFeb 12, 2025
  83. shejialuoFeb 12, 2025
  84. Junio C HamanoFeb 12, 2025
  85. shejialuoFeb 14, 2025
  86. 5/8 packed-backend: check whether the refname contains NUL charactersshejialuo, Feb 6, 2025
  87. 6/8 packed-backend: add "packed-refs" entry consistency checkshejialuo, Feb 6, 2025
  88. Patrick SteinhardtFeb 12, 2025
  89. shejialuoFeb 12, 2025
  90. 7/8 packed-backend: check whether the "packed-refs" is sortedshejialuo, Feb 6, 2025
  91. Patrick SteinhardtFeb 12, 2025
  92. shejialuoFeb 12, 2025
  93. Patrick SteinhardtFeb 12, 2025
  94. shejialuoFeb 12, 2025
  95. 8/8 builtin/fsck: add `git refs verify` child processshejialuo, Feb 6, 2025
  96. Patrick SteinhardtFeb 12, 2025
  97. shejialuoFeb 12, 2025
  98. 0/8 add more ref consistency checksshejialuo, Feb 14, 2025
  99. 1/8 t0602: use subshell to ensure working directory unchangedshejialuo, Feb 14, 2025
  100. 2/8 builtin/refs: get worktrees without reading head informationshejialuo, Feb 14, 2025
  101. Karthik NayakFeb 14, 2025
  102. shejialuoFeb 14, 2025
  103. 3/8 packed-backend: check whether the "packed-refs" is regular fileshejialuo, Feb 14, 2025
  104. Karthik NayakFeb 14, 2025
  105. shejialuoFeb 14, 2025
  106. 4/8 packed-backend: add "packed-refs" header consistency checkshejialuo, Feb 14, 2025
  107. Karthik NayakFeb 14, 2025
  108. shejialuoFeb 14, 2025
  109. Junio C HamanoFeb 14, 2025
  110. 5/8 packed-backend: check whether the refname contains NUL charactersshejialuo, Feb 14, 2025
  111. 6/8 packed-backend: add "packed-refs" entry consistency checkshejialuo, Feb 14, 2025
  112. 7/8 packed-backend: check whether the "packed-refs" is sortedshejialuo, Feb 14, 2025
  113. 8/8 builtin/fsck: add `git refs verify` child processshejialuo, Feb 14, 2025
  114. Karthik NayakFeb 14, 2025
  115. shejialuoFeb 14, 2025
  116. 0/8 add more ref consistency checksshejialuo, Feb 17, 2025
  117. 1/8 t0602: use subshell to ensure working directory unchangedshejialuo, Feb 17, 2025
  118. 2/8 builtin/refs: get worktrees without reading head informationshejialuo, Feb 17, 2025
  119. Patrick SteinhardtFeb 25, 2025
  120. 3/8 packed-backend: check whether the "packed-refs" is regular fileshejialuo, Feb 17, 2025
  121. Patrick SteinhardtFeb 25, 2025
  122. 4/8 packed-backend: add "packed-refs" header consistency checkshejialuo, Feb 17, 2025
  123. Patrick SteinhardtFeb 25, 2025
  124. shejialuoFeb 25, 2025
  125. 5/8 packed-backend: check whether the refname contains NUL charactersshejialuo, Feb 17, 2025
  126. 6/8 packed-backend: add "packed-refs" entry consistency checkshejialuo, Feb 17, 2025
  127. 7/8 packed-backend: check whether the "packed-refs" is sortedshejialuo, Feb 17, 2025
  128. 8/8 builtin/fsck: add `git refs verify` child processshejialuo, Feb 17, 2025
  129. Patrick SteinhardtFeb 25, 2025
  130. 0/9 add more ref consistency checksshejialuo, Feb 25, 2025
  131. 1/9 t0602: use subshell to ensure working directory unchangedshejialuo, Feb 25, 2025
  132. 2/9 builtin/refs: get worktrees without reading head informationshejialuo, Feb 25, 2025
  133. 3/9 packed-backend: check whether the "packed-refs" is regular fileshejialuo, Feb 25, 2025
  134. Junio C HamanoFeb 25, 2025
  135. shejialuoFeb 26, 2025
  136. 4/9 packed-backend: check if header starts with "# pack-refs with: "shejialuo, Feb 25, 2025
  137. Patrick SteinhardtFeb 26, 2025
  138. shejialuoFeb 26, 2025
  139. 5/9 packed-backend: add "packed-refs" header consistency checkshejialuo, Feb 25, 2025
  140. 6/9 packed-backend: check whether the refname contains NUL charactersshejialuo, Feb 25, 2025
  141. 7/9 packed-backend: add "packed-refs" entry consistency checkshejialuo, Feb 25, 2025
  142. 8/9 packed-backend: check whether the "packed-refs" is sortedshejialuo, Feb 25, 2025
  143. 9/9 builtin/fsck: add `git refs verify` child processshejialuo, Feb 25, 2025
  144. 0/9 add more ref consistency checksshejialuo, Feb 26, 2025
  145. 1/9 t0602: use subshell to ensure working directory unchangedshejialuo, Feb 26, 2025
  146. 2/9 builtin/refs: get worktrees without reading head informationshejialuo, Feb 26, 2025
  147. 3/9 packed-backend: check whether the "packed-refs" is regular fileshejialuo, Feb 26, 2025
  148. Junio C HamanoFeb 26, 2025
  149. shejialuoFeb 27, 2025
  150. Patrick SteinhardtFeb 27, 2025
  151. Junio C HamanoFeb 27, 2025
  152. shejialuoFeb 28, 2025
  153. 4/9 packed-backend: check if header starts with "# pack-refs with: "shejialuo, Feb 26, 2025
  154. 5/9 packed-backend: add "packed-refs" header consistency checkshejialuo, Feb 26, 2025
  155. 6/9 packed-backend: check whether the refname contains NUL charactersshejialuo, Feb 26, 2025
  156. 7/9 packed-backend: add "packed-refs" entry consistency checkshejialuo, Feb 26, 2025
  157. 8/9 packed-backend: check whether the "packed-refs" is sortedshejialuo, Feb 26, 2025
  158. 9/9 builtin/fsck: add `git refs verify` child processshejialuo, Feb 26, 2025
  159. 0/9 add more ref consistency checksshejialuo, Feb 27, 2025
  160. 1/9 t0602: use subshell to ensure working directory unchangedshejialuo, Feb 27, 2025
  161. 2/9 builtin/refs: get worktrees without reading head informationshejialuo, Feb 27, 2025
  162. 3/9 packed-backend: check whether the "packed-refs" is regular fileshejialuo, Feb 27, 2025
  163. 4/9 packed-backend: check if header starts with "# pack-refs with: "shejialuo, Feb 27, 2025
  164. 5/9 packed-backend: add "packed-refs" header consistency checkshejialuo, Feb 27, 2025
  165. 6/9 packed-backend: check whether the refname contains NUL charactersshejialuo, Feb 27, 2025
  166. 7/9 packed-backend: add "packed-refs" entry consistency checkshejialuo, Feb 27, 2025
  167. 8/9 packed-backend: check whether the "packed-refs" is sortedshejialuo, Feb 27, 2025
  168. 9/9 builtin/fsck: add `git refs verify` child processshejialuo, Feb 27, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.