git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Public repro case! Re: [PATCH/RFC] Allow writing loose objects that are corrupted in a pack file

From
Linus Torvalds <torvalds@linux-foundation.org>
Date
Jan 8, 2009, 02:52 UTC
Message-ID
<alpine.LFD.2.00.0901071836290.3283@localhost.localdomain>
In-Reply-To
<1231374514.8870.621.camel@starfruit>
On Wed, 7 Jan 2009, R. Tyler Ballance wrote:
Show 5 quoted lines
>
>         tyler@grapefruit:~/source/git/linux-2.6> git pull
>         error: failed to read object be1b87c70af69acfadb8a27a7a76dfb61de92643 at offset 1850923
>         from .git/objects/pack/pack-dbe154052997a05499eb6b4fd90b924da68e799a.pack
>         fatal: object be1b87c70af69acfadb8a27a7a76dfb61de92643 is corrupted

Btw, this is an interesting error message, mostly because of what is _not_ there.

In particular, it doesn't report any reason _why_ it failed to read the object, which as far as I can tell can happen for only one reason: unpack_compressed_entry() returns NULL, and that path is the only thing that can do so without a message.

And it only does it if zlib fails.

Now, zlib can fail because the unpacking fails, but it can fail for other cases too.

And the thing is, we don't check/report those kinds of failure cases very well. Which really bit us here, because if we had checked the return value of inflateInit(), we'd almost certainly would have gotten a nice big "you ran out of memory" thing, and we wouldn't have been chasing this down as a corruption issue.

We probably should wrap all the "inflateInit()" calls, and do something like

	static void xinflateInit(z_streamp strm)
	{
		const char *err;
		switch (inflateInit(strm)) {
		case Z_OK:
			return;
		case Z_MEM_ERROR:
			err = "out of memory";
			break;
		case Z_VERSION_ERROR:
			err = "wrong version";
			break;
		default:
			err = "error";
		}
		die("inflateInit: %s (%s)", err,
			strm->msg ? strm->msg : "no message");
	}

or similar. That way we'd get good error reports when we run out of memory, rather than consider it to be a corruption issue.

We could also try to make a few of these wrappers actually release some of the memory (the way xmmap() does), but there are likely diminishing returns. And the much more important issue is the proper error reporting: if we had reported "out of memory", we'd not have spent so much time chasing disk corruption etc.

			Linus
Previous: Boyd Stephen Smith Jr.Next: Shawn O. Pearce
Message 32 of 49 in “Allow writing loose objects that are corrupted in a pack file”
  1. Allow writing loose objects that are corrupted in a pack fileJan Krüger, Dec 9, 2008
  2. R. Tyler BallanceDec 9, 2008
  3. Shawn O. PearceDec 9, 2008
  4. R. Tyler BallanceJan 6, 2009
  5. Nicolas PitreJan 7, 2009
  6. R. Tyler BallanceJan 7, 2009
  7. Nicolas PitreJan 7, 2009
  8. R. Tyler BallanceJan 7, 2009
  9. Nicolas PitreJan 7, 2009
  10. Linus TorvaldsJan 7, 2009
  11. R. Tyler BallanceJan 7, 2009
  12. Junio C HamanoJan 7, 2009
  13. R. Tyler BallanceJan 7, 2009
  14. Junio C HamanoJan 7, 2009
  15. R. Tyler BallanceJan 7, 2009
  16. Nicolas PitreJan 7, 2009
  17. Linus TorvaldsJan 7, 2009
  18. Linus TorvaldsJan 7, 2009
  19. R. Tyler BallanceJan 7, 2009
  20. Linus TorvaldsJan 7, 2009
  21. Public repro case! Re: [PATCH/RFC] Allow writing loose objects that are corrupted in a pack fileR. Tyler Ballance, Jan 8, 2009
  22. Linus TorvaldsJan 8, 2009
  23. R. Tyler BallanceJan 8, 2009
  24. Linus TorvaldsJan 8, 2009
  25. Linus TorvaldsJan 8, 2009
  26. Shawn O. PearceJan 8, 2009
  27. James PickensJan 8, 2009
  28. Shawn O. PearceJan 8, 2009
  29. Junio C HamanoJan 8, 2009
  30. Shawn O. PearceJan 8, 2009
  31. Boyd Stephen Smith Jr.Jan 8, 2009
  32. Linus TorvaldsJan 8, 2009
  33. Shawn O. PearceJan 8, 2009
  34. Linus TorvaldsJan 8, 2009
  35. Shawn O. PearceJan 8, 2009
  36. Wrap inflateInit to retry allocation after releasing pack memoryShawn O. Pearce, Jan 8, 2009
  37. Linus TorvaldsJan 8, 2009
  38. Junio C HamanoJan 8, 2009
  39. Linus TorvaldsJan 8, 2009
  40. Shawn O. PearceJan 8, 2009
  41. Linus TorvaldsJan 8, 2009
  42. R. Tyler BallanceJan 8, 2009
  43. Linus TorvaldsJan 8, 2009
  44. R. Tyler BallanceJan 8, 2009
  45. Junio C HamanoJan 9, 2009
  46. Linus TorvaldsJan 8, 2009
  47. R. Tyler BallanceJan 8, 2009
  48. Linus TorvaldsJan 8, 2009
  49. R. Tyler BallanceJan 8, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.