git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 2/2] packfile: fix corruption due to stale delta base cache entries

From
Patrick Steinhardt <ps@pks.im>
Date
Oct 5, 2026, 05:32 UTC
Message-ID
<asM2YoImN8bHLHj8@pks.im>
In-Reply-To
<20261002222335.GC833115@coredump.intra.peff.net>
On Fri, Oct 02, 2026 at 06:23:35PM -0400, Jeff King wrote:
Show 12 quoted lines
> On Fri, Oct 02, 2026 at 09:34:07AM +0200, Patrick Steinhardt wrote:
> 
> > Note that the added test reliably reproduces the above bug on my machine
> > that uses NixOS at c59305bab206 (cosmic-applets: add missing runtime
> > dependency (#566040), 2026-10-01) with glibc 2.44-25. But as we rely on
> > specific allocation behaviour of glibc it is very likely that the test
> > will not work on other platforms.
> 
> At its core this is a user-after-free bug, isn't it? If so, I think it
> would be fine to say that ASan will reliably find it (and we don't even
> really need to demonstrate the complex case where the packed_git has the
> same address; all bets are off once we access the freed pointer).

It doesn't though. The key of the cache is the address of the freed object, but the value is a still-live object:

	struct delta_base_cache_key {
		struct packed_git *p;
		off_t base_offset;
	};
	
	struct delta_base_cache_entry {
		struct hashmap_entry ent;
		struct delta_base_cache_key key;
		struct list_head lru;
		void *data;
		size_t size;
		enum object_type type;
	};

We only use the value of `p`, but never dereference it. In fact, when I enable ASan I cannot reproduce the bug at all anymore because it will hand out unique addresses.

Patrick
Previous: Jeff KingNext: Jeff King
Message 11 of 18 in “packfile: fix corruption due to stale delta base cache entries”
  1. 0/2 packfile: fix corruption due to stale delta base cache entriesPatrick Steinhardt, Oct 2, 2026
  2. 1/2 packfile: move around `close_pack()`Patrick Steinhardt, Oct 2, 2026
  3. Mark C. Chu-CarrollOct 2, 2026
  4. Patrick SteinhardtOct 2, 2026
  5. 2/2 packfile: fix corruption due to stale delta base cache entriesPatrick Steinhardt, Oct 2, 2026
  6. Guillaume ChauvelOct 2, 2026
  7. Patrick SteinhardtOct 2, 2026
  8. Philippe BlainOct 2, 2026
  9. Patrick SteinhardtOct 2, 2026
  10. Jeff KingOct 2, 2026
  11. Patrick SteinhardtOct 5, 2026
  12. Jeff KingOct 7, 2026
  13. Junio C HamanoOct 7, 2026
  14. 0/2 packfile: fix corruption due to stale delta base cache entriesPatrick Steinhardt, Oct 6, 2026
  15. 1/2 packfile: move around `close_pack()`Patrick Steinhardt, Oct 6, 2026
  16. 2/2 packfile: fix corruption due to stale delta base cache entriesPatrick Steinhardt, Oct 6, 2026
  17. Junio C HamanoOct 6, 2026
  18. Patrick SteinhardtOct 7, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.