git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Recovering from repository corruption

From
Nicolas Pitre <nico@cam.org>
Date
Jun 11, 2008, 00:43 UTC
Message-ID
<alpine.LFD.1.10.0806102026430.23110@xanadu.home>
In-Reply-To
<alpine.LFD.1.10.0806101518590.3101@woody.linux-foundation.org>
On Tue, 10 Jun 2008, Linus Torvalds wrote:
Show 13 quoted lines
> Anyway, I'll think about sane ways to add a "safe" mode without making it 
> _too_ painful. In the meantime, here's a trial patch that you should 
> probably use. It does slow things down, but hopefully not too much.
> 
> (I really don't much like it - but I think this is a good change, and I 
> just need to come up with a better way to do the fsync() than to be 
> totally synchronous about it.)
> 
> It's going to make big "git add" calls *much* slower, so I'm not very 
> happy about it (especially since we don't actually care that deeply about 
> the files really being there until much later, so doing something 
> asynchronous would be perfectly acceptable), but for you this is 
> definitely worth-while.
I don't like it at all.

I think this only gives a false sense of security with a huge performance cost. If the machine crashes at the right moment, the object will still be half written/fsync'd and you'll be in the same situation again.

And because we don't overwrite existing objects (again for performance reasons), then a corrupted blob object will remain corrupted even if you reattempt the commit later. So doing the fsync only when the commit object is written isn't a good solution either.

I wonder if supporting crashy systems is worth that cost. If Denis' laptop is the odd case then a sync in the commit hook might be plenty sufficient. Personally I'd simply replace the OS or the machine for something more reliable.

Nicolas
Previous: Linus TorvaldsNext: Linus Torvalds
Message 18 of 31 in “Recovering from repository corruption”
  1. Denis BuenoJun 10, 2008
  2. Jakub NarebskiJun 10, 2008
  3. Denis BuenoJun 10, 2008
  4. Jakub NarebskiJun 10, 2008
  5. Denis BuenoJun 10, 2008
  6. Jakub NarebskiJun 10, 2008
  7. Denis BuenoJun 10, 2008
  8. Linus TorvaldsJun 10, 2008
  9. Denis BuenoJun 10, 2008
  10. Linus TorvaldsJun 10, 2008
  11. Denis BuenoJun 10, 2008
  12. Linus TorvaldsJun 10, 2008
  13. Denis BuenoJun 10, 2008
  14. TarmiganJun 10, 2008
  15. Denis BuenoJun 10, 2008
  16. Linus TorvaldsJun 10, 2008
  17. Linus TorvaldsJun 10, 2008
  18. Nicolas PitreJun 11, 2008
  19. Linus TorvaldsJun 11, 2008
  20. Nicolas PitreJun 11, 2008
  21. Denis BuenoJun 10, 2008
  22. Junio C HamanoJun 10, 2008
  23. To graft or not to graft... (Re: Recovering from repository corruption)Stephen R. van den Berg, Jun 11, 2008
  24. Jakub NarebskiJun 11, 2008
  25. Linus TorvaldsJun 11, 2008
  26. Johan HerlandJun 12, 2008
  27. Jeff KingJun 12, 2008
  28. Johan HerlandJun 12, 2008
  29. Stephen R. van den BergJun 12, 2008
  30. Nicolas PitreJun 10, 2008
  31. Denis BuenoJun 10, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.