git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Unaligned accesses in sha1dc

From
Junio C Hamano <gitster@pobox.com>
Date
Jun 2, 2017, 00:15 UTC
Message-ID
<xmqq37bj454a.fsf@gitster.mtv.corp.google.com>
In-Reply-To
<CAN0heSp9DpW4_0QL57_oAHGu+os8k6yd=Z5+0MJnaL6iXTa-qQ@mail.gmail.com>
Martin Ågren <martin.agren@gmail.com> writes:
Show 21 quoted lines
> I looked into this some more. It turns out it is possible to trigger
> undefined behavior on "next". Here's what I did:
> ...
>
> This "fixes" the problem:
> ...
> diff --git a/sha1dc/sha1.c b/sha1dc/sha1.c
> index 3dff80a..d6f4c44 100644
> --- a/sha1dc/sha1.c
> +++ b/sha1dc/sha1.c
> @@ -66,9 +66,9 @@
> ...
> With this diff, various tests which seem relevant for SHA-1 pass,
> including t0013, and the UBSan-error is gone. The second diff is just
> a monkey-patch. I have no reason to believe I will be able to come up
> with a proper and complete patch for sha1dc. And I guess such a thing
> would not really be Git's patch to carry, either. But at least Git
> could consider whether to keep relying on undefined behavior or not.
>
> There's a fair chance I've mangled the whitespace. I'm using gmail's
> web interface... Sorry about that.

Thanks. I see Marc Stevens is CC'ed in the thread, so I'd expect that the final "fix" would come from his sha1collisiondetection repository via Ævar.

In the meantime, I am wondering if it makes sense to merge the earlier update with #ifdef ALLOW_UNALIGNED_ACCESS and #ifdef SHA1DC_FORCE_LITTLEENDIAN for the v2.13.x maintenance track, which would at least unblock those on platforms v2.13.0 did not work correctly at all.

Ævar, thoughts?
Previous: Martin ÅgrenNext: Ævar Arnfjörð Bjarmason
Message 14 of 28 in “Unaligned accesses in sha1dc”
  1. Andreas SchwabJun 1, 2017
  2. Junio C HamanoJun 1, 2017
  3. Andreas SchwabJun 1, 2017
  4. Junio C HamanoJun 1, 2017
  5. brian m. carlsonJun 1, 2017
  6. Andreas SchwabJun 1, 2017
  7. Lars SchneiderJun 1, 2017
  8. Junio C HamanoJun 1, 2017
  9. Andreas SchwabJun 1, 2017
  10. Martin ÅgrenJun 1, 2017
  11. Ævar Arnfjörð BjarmasonJun 1, 2017
  12. Martin ÅgrenJun 1, 2017
  13. Martin ÅgrenJun 1, 2017
  14. Junio C HamanoJun 2, 2017
  15. Ævar Arnfjörð BjarmasonJun 2, 2017
  16. Martin ÅgrenJun 2, 2017
  17. Ævar Arnfjörð BjarmasonJun 2, 2017
  18. Martin ÅgrenJun 2, 2017
  19. Ævar Arnfjörð BjarmasonJun 2, 2017
  20. demerphqJun 2, 2017
  21. demerphqJun 2, 2017
  22. Ævar Arnfjörð BjarmasonJun 2, 2017
  23. Linus TorvaldsJun 2, 2017
  24. Junio C HamanoJun 3, 2017
  25. Liam R. HowlettJun 2, 2017
  26. Ævar Arnfjörð BjarmasonJun 2, 2017
  27. Junio C HamanoJun 3, 2017
  28. Andreas SchwabJun 1, 2017

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.