git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v1] read_index_from(): Skip verification of the cache entry order to speed index loading

From
Johannes Schindelin <johannes.schindelin@gmx.de>
Date
Oct 20, 2017, 12:47 UTC
Message-ID
<alpine.DEB.2.21.1.1710201444590.40514@virtualbox>
In-Reply-To
<CAGZ79kZfw7Cb8Qs4BKuESukBL8rCgmYh0=BcNYm9mXJ1LYCg0g@mail.gmail.com>
Hi Stefan,
On Thu, 19 Oct 2017, Stefan Beller wrote:
Show 17 quoted lines
> On Thu, Oct 19, 2017 at 8:12 AM, Ben Peart <peartben@gmail.com> wrote:
> 
> > If we are guarding against "git" writing out an invalid index, we can move
> > this into an assert so that only git developers pay the cost of validating
> > they haven't created a new bug.  I think this is better than just adding a
> > new test case as a new test case would not achieve the same coverage.  This
> > is my preferred solution.
> >
> > If we are guarding against "some other application" writing out an invalid
> > index, then everyone will have to pay the cost as we can't insert the test
> > into "some other applications."  Without user reports of it happening or any
> > telemetry saying it has happened I really have no idea if it every actually
> > happens in the wild anymore and whether the cost on every index load is
> > still justified.
> 
> How well does this play out in the security realm?, c.f.
> https://public-inbox.org/git/20171002234517.GV19555@aiede.mtv.corp.google.com/

That link talks about security implications from administrators accessing Git repositories with maliciously crafted hooks/pagers.

Ben's original mail talks about integrity checks of the index file, and how expensive they get when you talk about any decent-sized index (read: *a lot* larger than Git or even Linux developers will see regularly).

The text you quoted talks about our talking out of our rear ends when we talk about typical user schenarios because we simply have no telemetry or otherwise reliable statistics.

Now, I fail to see any relationship between Jonathan's mail and either of Ben's statements.

Care to enlighten me?

Ciao, Dscho

Previous: Stefan BellerNext: Stefan Beller
Message 7 of 18 in “read_index_from(): Skip verification of the cache entry order to speed index loading”
  1. read_index_from(): Skip verification of the cache entry order to speed index loadingBen Peart, Oct 18, 2017
  2. Junio C HamanoOct 19, 2017
  3. Ben PeartOct 19, 2017
  4. Jeff KingOct 19, 2017
  5. Junio C HamanoOct 20, 2017
  6. Stefan BellerOct 19, 2017
  7. Johannes SchindelinOct 20, 2017
  8. Stefan BellerOct 20, 2017
  9. Junio C HamanoOct 21, 2017
  10. read_index_from(): Skip verification of the cache entry order to speed index loadingBen Peart, Oct 24, 2017
  11. Ben PeartOct 30, 2017
  12. Jeff KingOct 30, 2017
  13. Alex VandiverOct 31, 2017
  14. Ben PeartOct 31, 2017
  15. Jeff KingOct 31, 2017
  16. Junio C HamanoNov 1, 2017
  17. Junio C HamanoOct 31, 2017
  18. Ben PeartOct 31, 2017

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.