git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v3 3/6] unpack-objects: continue when fail to malloc due to large objects

From
Junio C Hamano <gitster@pobox.com>
Date
Aug 14, 2014, 16:58 UTC
Message-ID
<xmqq7g2b2ele.fsf@gitster.dls.corp.google.com>
In-Reply-To
<1407927454-9268-4-git-send-email-pclouds@gmail.com>
Nguyễn Thái Ngọc Duy  <pclouds@gmail.com> writes:
Show 48 quoted lines
> As a recovery tool, unpack-objects should go on unpacking as many
> objects as it can.
>
> Signed-off-by: Nguyễn Thái Ngọc Duy <pclouds@gmail.com>
> ---
>  builtin/unpack-objects.c | 42 +++++++++++++++++++++++++++++++++++++++++-
>  t/t1050-large.sh         |  7 +++++++
>  2 files changed, 48 insertions(+), 1 deletion(-)
>
> diff --git a/builtin/unpack-objects.c b/builtin/unpack-objects.c
> index 99cde45..8b5c67e 100644
> --- a/builtin/unpack-objects.c
> +++ b/builtin/unpack-objects.c
> @@ -88,10 +88,50 @@ static void use(int bytes)
>  	consumed_bytes += bytes;
>  }
>  
> +static void inflate_and_throw_away(unsigned long size)
> +{
> +	git_zstream stream;
> +	char buf[8192];
> +
> +	memset(&stream, 0, sizeof(stream));
> +	stream.next_out = (unsigned char *)buf;
> +	stream.avail_out = sizeof(buf);
> +	stream.next_in = fill(1);
> +	stream.avail_in = len;
> +	git_inflate_init(&stream);
> +
> +	for (;;) {
> +		int ret = git_inflate(&stream, 0);
> +		use(len - stream.avail_in);
> +		if (stream.total_out == size && ret == Z_STREAM_END)
> +			break;
> +		if (ret != Z_OK) {
> +			error("inflate returned %d", ret);
> +			if (!recover)
> +				exit(1);
> +			has_errors = 1;
> +			break;
> +		}
> +		stream.next_out = (unsigned char *)buf;
> +		stream.avail_out = sizeof(buf);
> +		stream.next_in = fill(1);
> +		stream.avail_in = len;
> +	}
> +	git_inflate_end(&stream);
> +}
This looks wrong in a few ways.

You already know that we saw an error when you get to this function, whether you will see an out-of-sync stream in this loop or not, so there is no reason to copy the assignment to has_errors from the other function. You also know 'recover' is true---otherwise you wouldn't be here.

But more importantly, the basic structure of this loop is the same as the loop we already have in the only caller of this new function, not just the regular "zlib produced this much that is not yet the expected size, go on reading more" and "we are at the end of the stream with Z_STREAM_END, and we are done", but even to "the stream is corrupt, we need to exit the loop", they are identical. Is a copy-and-paste like this the best we can do to add this "skip to the end of the current stream"? We would really want to keep the number of copies of this loop down; we saw a same bug introduced on the termination condition multiple times to different copies X-<.

Show 32 quoted lines
>  static void *get_data(unsigned long size)
>  {
>  	git_zstream stream;
> -	void *buf = xmalloc(size);
> +	void *buf = xmalloc_gentle(size);
> +
> +	if (!buf) {
> +		if (!recover)
> +			exit(1);
> +		has_errors = 1;
> +		inflate_and_throw_away(size);
> +		return NULL;
> +	}
>  
>  	memset(&stream, 0, sizeof(stream));
>  
> diff --git a/t/t1050-large.sh b/t/t1050-large.sh
> index 5642f84..eec2cca 100755
> --- a/t/t1050-large.sh
> +++ b/t/t1050-large.sh
> @@ -169,4 +169,11 @@ test_expect_success 'fsck' '
>  	test "$n" -gt 1
>  '
>  
> +test_expect_success 'unpack-objects' '
> +	P=`ls .git/objects/pack/*.pack` &&
> +	git unpack-objects -n -r <$P 2>err
> +	test $? = 1 &&
> +	grep "error: attempting to allocate .* over limit" err
> +'
> +
>  test_done
Previous: Nguyễn Thái Ngọc DuyNext: Duy Nguyen
Message 34 of 49 in “Git chokes on large file”
  1. Dale R. WorleyMay 27, 2014
  2. Duy NguyenMay 28, 2014
  3. Junio C HamanoMay 28, 2014
  4. Dale R. WorleyMay 28, 2014
  5. Dale R. WorleyMay 28, 2014
  6. David LangMay 28, 2014
  7. Dale R. WorleyMay 28, 2014
  8. David LangMay 28, 2014
  9. Dale R. WorleyMay 29, 2014
  10. Junio C HamanoMay 28, 2014
  11. David LangMay 28, 2014
  12. 1/4 wrapper.c: introduce gentle xmallocz that does not die()Nguyễn Thái Ngọc Duy, May 29, 2014
  13. 2/4 fsck: do not die when not enough memory to examine a pack entryNguyễn Thái Ngọc Duy, May 29, 2014
  14. 3/4 diff.c: allow to pass more flags to diff_populate_filespecNguyễn Thái Ngọc Duy, May 29, 2014
  15. 4/4 diff: mark any file larger than core.bigfilethreshold binaryNguyễn Thái Ngọc Duy, May 29, 2014
  16. Thomas BraunJun 19, 2014
  17. Duy NguyenJun 23, 2014
  18. Thomas BraunJun 23, 2014
  19. 1/4 wrapper.c: introduce gentle xmallocz that does not die()Nguyễn Thái Ngọc Duy, Jun 24, 2014
  20. 2/4 fsck: do not die when not enough memory to examine a pack entryNguyễn Thái Ngọc Duy, Jun 24, 2014
  21. Junio C HamanoJun 26, 2014
  22. Duy NguyenJun 29, 2014
  23. 3/4 diff.c: allow to pass more flags to diff_populate_filespecNguyễn Thái Ngọc Duy, Jun 24, 2014
  24. 4/4 diff: mark any file larger than core.bigfilethreshold binaryNguyễn Thái Ngọc Duy, Jun 24, 2014
  25. Junio C HamanoJun 26, 2014
  26. Thomas BraunJun 27, 2014
  27. Duy NguyenJun 29, 2014
  28. 0/6 Large file improvementsNguyễn Thái Ngọc Duy, Aug 13, 2014
  29. 1/6 wrapper.c: introduce gentle xmalloc(z) that does not die()Nguyễn Thái Ngọc Duy, Aug 13, 2014
  30. Junio C HamanoAug 14, 2014
  31. 2/6 sha1_file.c: do not die failing to malloc in unpack_compressed_entryNguyễn Thái Ngọc Duy, Aug 13, 2014
  32. Junio C HamanoAug 13, 2014
  33. 3/6 unpack-objects: continue when fail to malloc due to large objectsNguyễn Thái Ngọc Duy, Aug 13, 2014
  34. Junio C HamanoAug 14, 2014
  35. Duy NguyenAug 15, 2014
  36. 4/6 diff.c: allow to pass more flags to diff_populate_filespecNguyễn Thái Ngọc Duy, Aug 13, 2014
  37. 5/6 diff --stat: mark any file larger than core.bigfilethreshold binaryNguyễn Thái Ngọc Duy, Aug 13, 2014
  38. Eric SunshineAug 13, 2014
  39. 6/6 diff: shortcut for diff'ing two binary SHA-1 objectsNguyễn Thái Ngọc Duy, Aug 13, 2014
  40. Junio C HamanoAug 14, 2014
  41. Duy NguyenAug 15, 2014
  42. Junio C HamanoAug 14, 2014
  43. 0/5 Large file improvementsNguyễn Thái Ngọc Duy, Aug 16, 2014
  44. 1/5 wrapper.c: introduce gentle xmallocz that does not die()Nguyễn Thái Ngọc Duy, Aug 16, 2014
  45. 2/5 sha1_file.c: do not die failing to malloc in unpack_compressed_entryNguyễn Thái Ngọc Duy, Aug 16, 2014
  46. 3/5 diff.c: allow to pass more flags to diff_populate_filespecNguyễn Thái Ngọc Duy, Aug 16, 2014
  47. 4/5 diff --stat: mark any file larger than core.bigfilethreshold binaryNguyễn Thái Ngọc Duy, Aug 16, 2014
  48. 5/5 diff: shortcut for diff'ing two binary SHA-1 objectsNguyễn Thái Ngọc Duy, Aug 16, 2014
  49. Thomas BraunMay 28, 2014

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.