git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v4] pack-bitmap: remove checks before bitmap_free

From
Lidong Yan via GitGitGadget <gitgitgadget@gmail.com>
Date
Jun 3, 2025, 06:20 UTC
Message-ID
<pull.1977.v4.git.git.1748931650166.gitgitgadget@gmail.com>
In-Reply-To
<pull.1977.v3.git.git.1748915181113.gitgitgadget@gmail.com>
From: Lidong Yan <502024330056@smail.nju.edu.cn>

In pack-bitmap.c:find_boundary_objects(), the roots_bitmap is only freed if cascade_pseudo_merges_1() fails. Since cascade_pseudo_merges_1() only use roots_bitmap as a mutable reference but not takes roots_bitmap's ownership. Once cascade_pseudo_merges_1 succeed(), roots_bitmap leaks. And this leak currently lacks a dedicated test to detect it.

To fix this leak, remove if cascade_pseudo_merges_1() succeed check and always calling bitmap_free(roots_bitmap);

To trigger this leak, we need a pseudo-merge whose size is equal to or smaller than roots_bitmap (which corresponds to the set of "haves" commits in prepare_bitmap_walk()). To do this, we can create two commits: A and B. Add A to the pseudo-merge list and perform a traversal over the range A..B. In this scenario, the "haves" set will be {A}, and cascade_pseudo_merges_1() will succeed, thereby exposing the leak due to the missing roots_bitmap cleanup.

Signed-off-by: Lidong Yan <502024330056@smail.nju.edu.cn>
---
    pack-bitmap: remove checks before bitmap_free
    
    In pack-bitmap.c:find_boundary_objects, remove cascade success check and
    always free roots_bitmap afterward to make static analysis tool works
    better.
Published-As: https://github.com/gitgitgadget/git/releases/tag/pr-git-1977%2Fbrandb97%2Fremove-check-before-bitmap-free-v4
Fetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-git-1977/brandb97/remove-check-before-bitmap-free-v4
Pull-Request: https://github.com/git/git/pull/1977
Range-diff vs v3:
 1:  151a7f5dc70 ! 1:  fa443065436 pack-bitmap: remove checks before bitmap_free
     @@ t/t5333-pseudo-merge-bitmaps.sh: test_expect_success 'pseudo-merge closure' '
      +		git config bitmapPseudoMerge.test.pattern refs/ &&
      +		git config bitmapPseudoMerge.test.threshold now &&
      +		git config bitmapPseudoMerge.test.stableThreshold now &&
     -+		GIT_TEST_PACK_USE_BITMAP_BOUNDARY_TRAVERSAL=1 &&
      +
      +		test_commit A &&
      +		git repack -adb &&
      +		test_commit B &&
      +
      +		echo '1' >expect &&
     -+		git rev-list --count --use-bitmap-index HEAD~1..HEAD >actual &&
     ++		GIT_TEST_PACK_USE_BITMAP_BOUNDARY_TRAVERSAL=1 \
     ++			git rev-list --count --use-bitmap-index HEAD~1..HEAD >actual &&
      +		test_cmp expect actual
      +	)
      +'
 pack-bitmap.c                   |  4 ++--
 t/t5333-pseudo-merge-bitmaps.sh | 20 ++++++++++++++++++++
 2 files changed, 22 insertions(+), 2 deletions(-)
diff --git a/pack-bitmap.c b/pack-bitmap.c
index ac6d62b980c..8727f316de9 100644
--- a/pack-bitmap.c
+++ b/pack-bitmap.c
@@ -1363,8 +1363,8 @@ static struct bitmap *find_boundary_objects(struct bitmap_index *bitmap_git,
 			bitmap_set(roots_bitmap, pos);
 		}
 
-		if (!cascade_pseudo_merges_1(bitmap_git, cb.base, roots_bitmap))
-			bitmap_free(roots_bitmap);
+		cascade_pseudo_merges_1(bitmap_git, cb.base, roots_bitmap);
+		bitmap_free(roots_bitmap);
 	}
 
 	/*
diff --git a/t/t5333-pseudo-merge-bitmaps.sh b/t/t5333-pseudo-merge-bitmaps.sh
index 56674db562f..e665001a410 100755
--- a/t/t5333-pseudo-merge-bitmaps.sh
+++ b/t/t5333-pseudo-merge-bitmaps.sh
@@ -445,4 +445,24 @@ test_expect_success 'pseudo-merge closure' '
 	)
 '
 
+test_expect_success 'use pseudo-merge in boundary traversal' '
+	git init pseudo-merge-boundary-traversal &&
+	(
+		cd pseudo-merge-boundary-traversal &&
+
+		git config bitmapPseudoMerge.test.pattern refs/ &&
+		git config bitmapPseudoMerge.test.threshold now &&
+		git config bitmapPseudoMerge.test.stableThreshold now &&
+
+		test_commit A &&
+		git repack -adb &&
+		test_commit B &&
+
+		echo '1' >expect &&
+		GIT_TEST_PACK_USE_BITMAP_BOUNDARY_TRAVERSAL=1 \
+			git rev-list --count --use-bitmap-index HEAD~1..HEAD >actual &&
+		test_cmp expect actual
+	)
+'
+
 test_done

base-commit: 845c48a16a7f7b2c44d8cb137b16a4a1f0140229
-- 
gitgitgadget
Previous: Junio C HamanoNext: Taylor Blau
Message 19 of 28 in “pack-bitmap: remove checks before bitmap_free”
  1. pack-bitmap: remove checks before bitmap_freeLidong Yan via GitGitGadget, May 25, 2025
  2. Patrick SteinhardtMay 26, 2025
  3. lidongyanMay 26, 2025
  4. 0/2 pack-bitmap: remove checks before bitmap_freeLidong Yan via GitGitGadget, May 30, 2025
  5. 2/2 t5333: test memory leak when use pseudo-merge in boundary traversalLidong Yan via GitGitGadget, May 30, 2025
  6. Junio C HamanoMay 30, 2025
  7. Eric SunshineMay 30, 2025
  8. lidongyanMay 31, 2025
  9. 1/2 pack-bitmap: remove checks before bitmap_freeLidong Yan via GitGitGadget, May 30, 2025
  10. Junio C HamanoMay 30, 2025
  11. pack-bitmap: remove checks before bitmap_freeLidong Yan via GitGitGadget, Jun 3, 2025
  12. Junio C HamanoJun 3, 2025
  13. lidongyanJun 3, 2025
  14. Junio C HamanoJun 3, 2025
  15. lidongyanJun 3, 2025
  16. Junio C HamanoJun 4, 2025
  17. lidongyanJun 4, 2025
  18. Junio C HamanoJun 4, 2025
  19. pack-bitmap: remove checks before bitmap_freeLidong Yan via GitGitGadget, Jun 3, 2025
  20. Taylor BlauJun 3, 2025
  21. lidongyanJun 4, 2025
  22. pack-bitmap: remove checks before bitmap_freeLidong Yan via GitGitGadget, Jun 5, 2025
  23. Junio C HamanoJun 5, 2025
  24. lidongyanJun 10, 2025
  25. pack-bitmap: remove checks before bitmap_freeLidong Yan via GitGitGadget, Jun 5, 2025
  26. Junio C HamanoJun 6, 2025
  27. lidongyanJun 6, 2025
  28. pack-bitmap: remove checks before bitmap_freeLidong Yan via GitGitGadget, Jun 9, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.