git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v7 0/9] add more ref consistency checks

From
shejialuo <shejialuo@gmail.com>
Date
Feb 26, 2025, 13:48 UTC
Message-ID
<Z78bmBSrDR20GY6g@ArchLinux>
In-Reply-To
<Z73DTwr9RicKMINe@ArchLinux>
Hi All:
This changes enhances the following things:
1. [PATCH v7 3/9]: use "open_nofollow" with "fstat" to check whether the
file is regular. And update the test to improve coverage.
2. [PACTH v7 4/9]: improve the commit message suggested by Patrick.

Thanks, Jialuo

---
This series mainly does the following things:
1. Fix subshell issues
2. Add ref checks for packed-backend.
   1. Check whether the filetype of "packed-refs" is correct.
   2. Check whether the syntax of "packed-refs" is correct by using the
      rules from "packed-backend.c::create_snapshot" and
      "packed-backend.c::next_record".
   3. Check whether the pointed object exists and whether the
      "packed-refs" file is sorted.
3. Call "git refs verify" for "git-fsck(1)".
shejialuo (9):
  t0602: use subshell to ensure working directory unchanged
  builtin/refs: get worktrees without reading head information
  packed-backend: check whether the "packed-refs" is regular file
  packed-backend: check if header starts with "# pack-refs with: "
  packed-backend: add "packed-refs" header consistency check
  packed-backend: check whether the refname contains NUL characters
  packed-backend: add "packed-refs" entry consistency check
  packed-backend: check whether the "packed-refs" is sorted
  builtin/fsck: add `git refs verify` child process
 Documentation/fsck-msgids.adoc |   14 +
 Documentation/git-fsck.adoc    |    7 +-
 builtin/fsck.c                 |   33 +-
 builtin/refs.c                 |    2 +-
 fsck.h                         |    4 +
 refs/packed-backend.c          |  361 +++++++++-
 t/t0602-reffiles-fsck.sh       | 1209 +++++++++++++++++++-------------
 worktree.c                     |    5 +
 worktree.h                     |    8 +
 9 files changed, 1161 insertions(+), 482 deletions(-)
Range-diff against v6:
 1:  b3952d80a2 =  1:  b3952d80a2 t0602: use subshell to ensure working directory unchanged
 2:  fa5ce20bb7 =  2:  fa5ce20bb7 builtin/refs: get worktrees without reading head information
 3:  787645a700 !  3:  861583f417 packed-backend: check whether the "packed-refs" is regular file
    @@ Commit message
         the expected filetype, confirming it is created by "git pack-refs"
         command.
     
    -    Use "lstat" to check the file mode. If we cannot check the file status
    -    due to there is no such file this is OK because there is a possibility
    -    that there is no "packed-refs" in the repo.
    +    We could use "open_nofollow" wrapper to open the raw "packed-refs" file.
    +    If the returned "fd" value is less than 0, we could check whether the
    +    "errno" is "ELOOP" to report an error to the user. And then we use
    +    "fstat" to check whether the "packed-refs" file is a regular file.
     
         Reuse "FSCK_MSG_BAD_REF_FILETYPE" fsck message id to report the error to
         the user if "packed-refs" is not a regular file.
    @@ refs/packed-backend.c: static struct ref_iterator *packed_reflog_iterator_begin(
     +							REF_STORE_READ, "fsck");
     +	struct stat st;
     +	int ret = 0;
    ++	int fd;
      
      	if (!is_main_worktree(wt))
    --		return 0;
    -+		goto cleanup;
    + 		return 0;
      
     -	return 0;
     +	if (o->verbose)
     +		fprintf_ln(stderr, "Checking packed-refs file %s", refs->path);
     +
    -+	if (lstat(refs->path, &st) < 0) {
    ++	fd = open_nofollow(refs->path, O_RDONLY);
    ++	if (fd < 0) {
     +		/*
     +		 * If the packed-refs file doesn't exist, there's nothing
     +		 * to check.
     +		 */
     +		if (errno == ENOENT)
     +			goto cleanup;
    ++
    ++		if (errno == ELOOP) {
    ++			struct fsck_ref_report report = { 0 };
    ++			report.path = "packed-refs";
    ++			ret = fsck_report_ref(o, &report,
    ++					      FSCK_MSG_BAD_REF_FILETYPE,
    ++					      "not a regular file but a symlink");
    ++			goto cleanup;
    ++		}
    ++
    ++		ret = error_errno(_("unable to open '%s'"), refs->path);
    ++		goto cleanup;
    ++	} else if (fstat(fd, &st) < 0) {
     +		ret = error_errno(_("unable to stat '%s'"), refs->path);
     +		goto cleanup;
    -+	}
    -+
    -+	if (!S_ISREG(st.st_mode)) {
    ++	} else if (!S_ISREG(st.st_mode)) {
     +		struct fsck_ref_report report = { 0 };
     +		report.path = "packed-refs";
     +		ret = fsck_report_ref(o, &report,
    @@ refs/packed-backend.c: static struct ref_iterator *packed_reflog_iterator_begin(
     +	}
     +
     +cleanup:
    ++	if (fd >= 0)
    ++		close(fd);
     +	return ret;
      }
      
    @@ t/t0602-reffiles-fsck.sh: test_expect_success 'ref content checks should work wi
     +		ln -sf packed-refs-back .git/packed-refs &&
     +		test_must_fail git refs verify 2>err &&
     +		cat >expect <<-EOF &&
    -+		error: packed-refs: badRefFiletype: not a regular file
    ++		error: packed-refs: badRefFiletype: not a regular file but a symlink
     +		EOF
     +		rm .git/packed-refs &&
    ++		test_cmp expect err &&
    ++
    ++		mkdir .git/packed-refs &&
    ++		test_must_fail git refs verify 2>err &&
    ++		cat >expect <<-EOF &&
    ++		error: packed-refs: badRefFiletype: not a regular file
    ++		EOF
    ++		rm -r .git/packed-refs &&
     +		test_cmp expect err
     +	)
     +'
 4:  f097e0f093 !  4:  5f54cb05c3 packed-backend: check if header starts with "# pack-refs with: "
    @@ Metadata
      ## Commit message ##
         packed-backend: check if header starts with "# pack-refs with: "
     
    -    We always write a space after "# pack-refs with:". However, when
    -    creating the packed-ref snapshot, we only check whether the header
    -    starts with "# pack-refs with:". However, we need to make sure that we
    -    would not break compatibility by tightening the rule. The following is
    -    how some third-party libraries handle the header of "packed-ref" file.
    +    We always write a space after "# pack-refs with:" but we don't align
    +    with this rule in the "create_snapshot" method where we would check
    +    whether header starts with "# pack-refs with:". It might seem that we
    +    should undoubtedly tighten this rule, however, we don't have any
    +    technical documentation about this and there is a possibility that we
    +    would break the compatibility for other third-party libraries.
    +
    +    By investigating influential third-party libraries, we could conclude
    +    how these libraries handle the header of "packed-refs" file:
     
         1. libgit2 is fine and always writes the space. It also expects the
            whitespace to exist.
    @@ Commit message
         3. gitoxide expects the space t exist and writes it.
         4. go-git doesn't create the header by default.
     
    -    So, we are safe to tighten the rule by checking whether the header
    -    starts with "# pack-refs with: ".
    +    As many third-party libraries expect a single space after "# pack-refs
    +    with:", if we forget to write the space after the colon,
    +    "create_snapshot" won't catch this. And we would break other
    +    re-implementations. So, we'd better tighten the rule by checking whether
    +    the header starts with "# pack-refs with: ".
     
         Mentored-by: Patrick Steinhardt <ps@pks.im>
         Mentored-by: Karthik Nayak <karthik.188@gmail.com>
 5:  a589a38b68 !  5:  7d7dc899ad packed-backend: add "packed-refs" header consistency check
    @@ refs/packed-backend.c: static struct ref_iterator *packed_reflog_iterator_begin(
      							REF_STORE_READ, "fsck");
     +	struct strbuf packed_ref_content = STRBUF_INIT;
      	struct stat st;
    -+	int fd;
      	int ret = 0;
    - 
    - 	if (!is_main_worktree(wt))
    + 	int fd;
     @@ refs/packed-backend.c: static int packed_fsck(struct ref_store *ref_store,
      		goto cleanup;
      	}
      
    -+	/*
    -+	 * There is a chance that "packed-refs" file is removed or converted to
    -+	 * a symlink after filetype check and before open. So we need to avoid
    -+	 * this race condition by opening the file.
    -+	 */
    -+	fd = open_nofollow(refs->path, O_RDONLY);
    -+	if (fd < 0) {
    -+		if (errno == ENOENT)
    -+			goto cleanup;
    -+
    -+		if (errno == ELOOP) {
    -+			struct fsck_ref_report report = { 0 };
    -+			report.path = "packed-refs";
    -+			ret = fsck_report_ref(o, &report,
    -+					      FSCK_MSG_BAD_REF_FILETYPE,
    -+					      "not a regular file");
    -+			goto cleanup;
    -+		}
    -+	}
    -+
     +	if (strbuf_read(&packed_ref_content, fd, 0) < 0) {
    -+		ret = error_errno(_("unable to read %s"), refs->path);
    ++		ret = error_errno(_("unable to read '%s'"), refs->path);
     +		goto cleanup;
     +	}
     +
    @@ refs/packed-backend.c: static int packed_fsck(struct ref_store *ref_store,
     +				      packed_ref_content.buf + packed_ref_content.len);
     +
      cleanup:
    + 	if (fd >= 0)
    + 		close(fd);
     +	strbuf_release(&packed_ref_content);
      	return ret;
      }
 6:  7255c2b597 =  6:  571479d3e7 packed-backend: check whether the refname contains NUL characters
 7:  7794a2ebfd =  7:  e498a57286 packed-backend: add "packed-refs" entry consistency check
 8:  2a9138b14d !  8:  3638cb118d packed-backend: check whether the "packed-refs" is sorted
    @@ refs/packed-backend.c: static int packed_fsck(struct ref_store *ref_store,
      	struct strbuf packed_ref_content = STRBUF_INIT;
     +	unsigned int sorted = 0;
      	struct stat st;
    --	int fd;
      	int ret = 0;
    -+	int fd;
    - 
    - 	if (!is_main_worktree(wt))
    - 		goto cleanup;
    + 	int fd;
     @@ refs/packed-backend.c: static int packed_fsck(struct ref_store *ref_store,
      		goto cleanup;
      	}
    @@ refs/packed-backend.c: static int packed_fsck(struct ref_store *ref_store,
     +					     packed_ref_content.buf + packed_ref_content.len);
      
      cleanup:
    - 	strbuf_release(&packed_ref_content);
    + 	if (fd >= 0)
     
      ## t/t0602-reffiles-fsck.sh ##
     @@ t/t0602-reffiles-fsck.sh: test_expect_success 'packed-refs content should be checked' '
 9:  ccde32491f =  9:  5d87e76d28 builtin/fsck: add `git refs verify` child process
-- 
2.48.1
Previous: shejialuoNext: shejialuo
Message 144 of 168 in “add more ref consistency checks”
  1. 00/10 add more ref consistency checksshejialuo, Jan 5, 2025
  2. 01/10 files-backend: add object check for regular refshejialuo, Jan 5, 2025
  3. Karthik NayakJan 7, 2025
  4. Patrick SteinhardtJan 16, 2025
  5. shejialuoJan 17, 2025
  6. Patrick SteinhardtJan 24, 2025
  7. 02/10 builtin/refs.h: get worktrees without reading head infoshejialuo, Jan 5, 2025
  8. Karthik NayakJan 7, 2025
  9. shejialuoJan 7, 2025
  10. Karthik NayakJan 8, 2025
  11. Patrick SteinhardtJan 16, 2025
  12. 03/10 packed-backend: check whether the "packed-refs" is regularshejialuo, Jan 5, 2025
  13. Karthik NayakJan 7, 2025
  14. shejialuoJan 17, 2025
  15. Eric SunshineJan 17, 2025
  16. shejialuoJan 18, 2025
  17. Karthik NayakJan 19, 2025
  18. Patrick SteinhardtJan 16, 2025
  19. 04/10 packed-backend: add "packed-refs" header consistency checkshejialuo, Jan 5, 2025
  20. shejialuoJan 8, 2025
  21. Patrick SteinhardtJan 16, 2025
  22. shejialuoJan 17, 2025
  23. Patrick SteinhardtJan 24, 2025
  24. shejialuoFeb 17, 2025
  25. 05/10 packed-backend: check whether the refname contains NULL binariesshejialuo, Jan 5, 2025
  26. Patrick SteinhardtJan 16, 2025
  27. shejialuoJan 17, 2025
  28. 06/10 packed-backend: add "packed-refs" entry consistency checkshejialuo, Jan 5, 2025
  29. Patrick SteinhardtJan 16, 2025
  30. shejialuoJan 17, 2025
  31. 07/10 packed-backend: create "fsck_packed_ref_entry" to store parsing infoshejialuo, Jan 5, 2025
  32. Patrick SteinhardtJan 16, 2025
  33. 08/10 packed-backend: add check for object consistencyshejialuo, Jan 5, 2025
  34. Patrick SteinhardtJan 16, 2025
  35. 09/10 packed-backend: check whether the "packed-refs" is sortedshejialuo, Jan 5, 2025
  36. Patrick SteinhardtJan 16, 2025
  37. 10/10 builtin/fsck: add `git refs verify` child processshejialuo, Jan 5, 2025
  38. Junio C HamanoJan 6, 2025
  39. shejialuoJan 7, 2025
  40. Junio C HamanoJan 7, 2025
  41. 0/8 add more ref consistency checksshejialuo, Jan 30, 2025
  42. 1/8 t0602: use subshell to ensure working directory unchangedshejialuo, Jan 30, 2025
  43. Junio C HamanoJan 30, 2025
  44. 2/8 builtin/refs: get worktrees without reading head infoshejialuo, Jan 30, 2025
  45. Junio C HamanoJan 30, 2025
  46. shejialuoJan 31, 2025
  47. Junio C HamanoJan 31, 2025
  48. 3/8 packed-backend: check whether the "packed-refs" is regularshejialuo, Jan 30, 2025
  49. Junio C HamanoJan 30, 2025
  50. shejialuoJan 31, 2025
  51. Junio C HamanoJan 31, 2025
  52. shejialuoFeb 1, 2025
  53. Junio C HamanoFeb 3, 2025
  54. shejialuoFeb 4, 2025
  55. Patrick SteinhardtFeb 3, 2025
  56. 4/8 packed-backend: add "packed-refs" header consistency checkshejialuo, Jan 30, 2025
  57. Junio C HamanoJan 30, 2025
  58. shejialuoJan 31, 2025
  59. 5/8 packed-backend: check whether the refname contains NUL charactersshejialuo, Jan 30, 2025
  60. Patrick SteinhardtFeb 3, 2025
  61. shejialuoFeb 5, 2025
  62. 6/8 packed-backend: add "packed-refs" entry consistency checkshejialuo, Jan 30, 2025
  63. Patrick SteinhardtFeb 3, 2025
  64. shejialuoFeb 4, 2025
  65. 7/8 packed-backend: check whether the "packed-refs" is sortedshejialuo, Jan 30, 2025
  66. Junio C HamanoJan 30, 2025
  67. shejialuoJan 31, 2025
  68. Junio C HamanoJan 31, 2025
  69. shejialuoFeb 1, 2025
  70. Patrick SteinhardtFeb 3, 2025
  71. Patrick SteinhardtFeb 3, 2025
  72. 8/8 builtin/fsck: add `git refs verify` child processshejialuo, Jan 30, 2025
  73. Junio C HamanoJan 30, 2025
  74. shejialuoJan 31, 2025
  75. Patrick SteinhardtFeb 3, 2025
  76. shejialuoFeb 4, 2025
  77. 0/8 add more ref consistency checksshejialuo, Feb 6, 2025
  78. 1/8 t0602: use subshell to ensure working directory unchangedshejialuo, Feb 6, 2025
  79. 2/8 builtin/refs: get worktrees without reading head informationshejialuo, Feb 6, 2025
  80. 3/8 packed-backend: check whether the "packed-refs" is regular fileshejialuo, Feb 6, 2025
  81. 4/8 packed-backend: add "packed-refs" header consistency checkshejialuo, Feb 6, 2025
  82. Patrick SteinhardtFeb 12, 2025
  83. shejialuoFeb 12, 2025
  84. Junio C HamanoFeb 12, 2025
  85. shejialuoFeb 14, 2025
  86. 5/8 packed-backend: check whether the refname contains NUL charactersshejialuo, Feb 6, 2025
  87. 6/8 packed-backend: add "packed-refs" entry consistency checkshejialuo, Feb 6, 2025
  88. Patrick SteinhardtFeb 12, 2025
  89. shejialuoFeb 12, 2025
  90. 7/8 packed-backend: check whether the "packed-refs" is sortedshejialuo, Feb 6, 2025
  91. Patrick SteinhardtFeb 12, 2025
  92. shejialuoFeb 12, 2025
  93. Patrick SteinhardtFeb 12, 2025
  94. shejialuoFeb 12, 2025
  95. 8/8 builtin/fsck: add `git refs verify` child processshejialuo, Feb 6, 2025
  96. Patrick SteinhardtFeb 12, 2025
  97. shejialuoFeb 12, 2025
  98. 0/8 add more ref consistency checksshejialuo, Feb 14, 2025
  99. 1/8 t0602: use subshell to ensure working directory unchangedshejialuo, Feb 14, 2025
  100. 2/8 builtin/refs: get worktrees without reading head informationshejialuo, Feb 14, 2025
  101. Karthik NayakFeb 14, 2025
  102. shejialuoFeb 14, 2025
  103. 3/8 packed-backend: check whether the "packed-refs" is regular fileshejialuo, Feb 14, 2025
  104. Karthik NayakFeb 14, 2025
  105. shejialuoFeb 14, 2025
  106. 4/8 packed-backend: add "packed-refs" header consistency checkshejialuo, Feb 14, 2025
  107. Karthik NayakFeb 14, 2025
  108. shejialuoFeb 14, 2025
  109. Junio C HamanoFeb 14, 2025
  110. 5/8 packed-backend: check whether the refname contains NUL charactersshejialuo, Feb 14, 2025
  111. 6/8 packed-backend: add "packed-refs" entry consistency checkshejialuo, Feb 14, 2025
  112. 7/8 packed-backend: check whether the "packed-refs" is sortedshejialuo, Feb 14, 2025
  113. 8/8 builtin/fsck: add `git refs verify` child processshejialuo, Feb 14, 2025
  114. Karthik NayakFeb 14, 2025
  115. shejialuoFeb 14, 2025
  116. 0/8 add more ref consistency checksshejialuo, Feb 17, 2025
  117. 1/8 t0602: use subshell to ensure working directory unchangedshejialuo, Feb 17, 2025
  118. 2/8 builtin/refs: get worktrees without reading head informationshejialuo, Feb 17, 2025
  119. Patrick SteinhardtFeb 25, 2025
  120. 3/8 packed-backend: check whether the "packed-refs" is regular fileshejialuo, Feb 17, 2025
  121. Patrick SteinhardtFeb 25, 2025
  122. 4/8 packed-backend: add "packed-refs" header consistency checkshejialuo, Feb 17, 2025
  123. Patrick SteinhardtFeb 25, 2025
  124. shejialuoFeb 25, 2025
  125. 5/8 packed-backend: check whether the refname contains NUL charactersshejialuo, Feb 17, 2025
  126. 6/8 packed-backend: add "packed-refs" entry consistency checkshejialuo, Feb 17, 2025
  127. 7/8 packed-backend: check whether the "packed-refs" is sortedshejialuo, Feb 17, 2025
  128. 8/8 builtin/fsck: add `git refs verify` child processshejialuo, Feb 17, 2025
  129. Patrick SteinhardtFeb 25, 2025
  130. 0/9 add more ref consistency checksshejialuo, Feb 25, 2025
  131. 1/9 t0602: use subshell to ensure working directory unchangedshejialuo, Feb 25, 2025
  132. 2/9 builtin/refs: get worktrees without reading head informationshejialuo, Feb 25, 2025
  133. 3/9 packed-backend: check whether the "packed-refs" is regular fileshejialuo, Feb 25, 2025
  134. Junio C HamanoFeb 25, 2025
  135. shejialuoFeb 26, 2025
  136. 4/9 packed-backend: check if header starts with "# pack-refs with: "shejialuo, Feb 25, 2025
  137. Patrick SteinhardtFeb 26, 2025
  138. shejialuoFeb 26, 2025
  139. 5/9 packed-backend: add "packed-refs" header consistency checkshejialuo, Feb 25, 2025
  140. 6/9 packed-backend: check whether the refname contains NUL charactersshejialuo, Feb 25, 2025
  141. 7/9 packed-backend: add "packed-refs" entry consistency checkshejialuo, Feb 25, 2025
  142. 8/9 packed-backend: check whether the "packed-refs" is sortedshejialuo, Feb 25, 2025
  143. 9/9 builtin/fsck: add `git refs verify` child processshejialuo, Feb 25, 2025
  144. 0/9 add more ref consistency checksshejialuo, Feb 26, 2025
  145. 1/9 t0602: use subshell to ensure working directory unchangedshejialuo, Feb 26, 2025
  146. 2/9 builtin/refs: get worktrees without reading head informationshejialuo, Feb 26, 2025
  147. 3/9 packed-backend: check whether the "packed-refs" is regular fileshejialuo, Feb 26, 2025
  148. Junio C HamanoFeb 26, 2025
  149. shejialuoFeb 27, 2025
  150. Patrick SteinhardtFeb 27, 2025
  151. Junio C HamanoFeb 27, 2025
  152. shejialuoFeb 28, 2025
  153. 4/9 packed-backend: check if header starts with "# pack-refs with: "shejialuo, Feb 26, 2025
  154. 5/9 packed-backend: add "packed-refs" header consistency checkshejialuo, Feb 26, 2025
  155. 6/9 packed-backend: check whether the refname contains NUL charactersshejialuo, Feb 26, 2025
  156. 7/9 packed-backend: add "packed-refs" entry consistency checkshejialuo, Feb 26, 2025
  157. 8/9 packed-backend: check whether the "packed-refs" is sortedshejialuo, Feb 26, 2025
  158. 9/9 builtin/fsck: add `git refs verify` child processshejialuo, Feb 26, 2025
  159. 0/9 add more ref consistency checksshejialuo, Feb 27, 2025
  160. 1/9 t0602: use subshell to ensure working directory unchangedshejialuo, Feb 27, 2025
  161. 2/9 builtin/refs: get worktrees without reading head informationshejialuo, Feb 27, 2025
  162. 3/9 packed-backend: check whether the "packed-refs" is regular fileshejialuo, Feb 27, 2025
  163. 4/9 packed-backend: check if header starts with "# pack-refs with: "shejialuo, Feb 27, 2025
  164. 5/9 packed-backend: add "packed-refs" header consistency checkshejialuo, Feb 27, 2025
  165. 6/9 packed-backend: check whether the refname contains NUL charactersshejialuo, Feb 27, 2025
  166. 7/9 packed-backend: add "packed-refs" entry consistency checkshejialuo, Feb 27, 2025
  167. 8/9 packed-backend: check whether the "packed-refs" is sortedshejialuo, Feb 27, 2025
  168. 9/9 builtin/fsck: add `git refs verify` child processshejialuo, Feb 27, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.