git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: "failed to read delta base object at..."

From
Linus Torvalds <torvalds@linux-foundation.org>
Date
Aug 27, 2008, 17:05 UTC
Message-ID
<alpine.LFD.1.10.0808270937340.3363@nehalem.linux-foundation.org>
In-Reply-To
<48B46F46.9090302@gmail.com>
On Tue, 26 Aug 2008, Jason McMullan wrote:
> 
> All bets are off when data=writeback.

Not the way git writes pack-files. It does a fsync() before moving them into place (at least newer git versions do), so the data is stable.

I do worry about wild pointers. I can't recognize the data, and it definitely doesn't look like any git internal data structures, but 16-bit data _is_ what zlib internally uses for things like the decoding tables.

So if there is some use-after-free issue, I could imagine things like this happening inside of git. People do occasionally run valgrind on git, though, and it's been clean in the past, but I don't know if that has ever been done on the threaded packing, for example.

For example, the corrupting data had patterns like this:
	00 f8 bf fe 6b 57 fe ff 55 57 fe ff 97 57 fe ff
where the pattern _could_ be something like
	{ 00 f8 febf },
	{ 6b 57 fffe },
	{ 55 57 fffe },
	{ 97 57 fffe },

assuming that the "fe ff" pattern really is meaningful and is a 16-bit little-endian word.

And the thign is, zlib "code" tables look exactly like that:
	typedef struct {
	    unsigned char op;           /* operation, extra bits, table bits */
	    unsigned char bits;         /* bits in this part of the code */
	    unsigned short val;         /* offset in table or code value */
	} code;
	/* op values as set by inflate_table():
	    00000000 - literal
	    0000tttt - table link, tttt != 0 is the number of table index bits
	    0001eeee - length or distance, eeee is the number of extra bits
	    01100000 - end of block
	    01000000 - invalid code
	 */

but those particular op/val things don't make sense in that context either. But I don't know zlib that well, maybe the deflate routines use some other model.

			Linus
Previous: Jason McMullanNext: Nicolas Pitre
Message 11 of 16 in “"failed to read delta base object at..."”
  1. J. Bruce FieldsAug 25, 2008
  2. Nicolas PitreAug 25, 2008
  3. J. Bruce FieldsAug 25, 2008
  4. Linus TorvaldsAug 25, 2008
  5. J. Bruce FieldsAug 25, 2008
  6. Linus TorvaldsAug 25, 2008
  7. J. Bruce FieldsAug 25, 2008
  8. Linus TorvaldsAug 25, 2008
  9. Jason McMullanAug 26, 2008
  10. Jason McMullanAug 26, 2008
  11. Linus TorvaldsAug 27, 2008
  12. Nicolas PitreAug 27, 2008
  13. Linus TorvaldsAug 27, 2008
  14. Nicolas PitreAug 27, 2008
  15. J. Bruce FieldsAug 26, 2008
  16. Junio C HamanoAug 27, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.