git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v2] receive-pack: not receive pack file with large object

From
Junio C Hamano <gitster@pobox.com>
Date
Sep 30, 2021, 16:49 UTC
Message-ID
<xmqqczoqdn4m.fsf@gitster.g>
In-Reply-To
<20210930132004.16075-1-chiyutianyi@gmail.com>
Han Xin <chiyutianyi@gmail.com> writes:
Show 9 quoted lines
> @@ -519,6 +520,8 @@ static void *unpack_raw_entry(struct object_entry *obj,
>  		shift += 7;
>  	}
>  	obj->size = size;
> +	if (max_input_object_size && size > max_input_object_size)
> +		die(_("object exceeds maximum allowed size "));
>  
>  	switch (obj->type) {
>  	case OBJ_REF_DELTA:

Here obj->size is the inflated payload size of a single entry in the packfile. If it happens to be represented as a base object (i.e. without delta, just deflated), it would be close to the size of the blob in the working tree (but LF->CRLF conversion and the like may further inflate it), but if it is a delta object, this size is just the size of the delta data we feed patch_delta() with, and has no relevance to the actual "file size".

Sure, it is called max_INPUT_object_size and we can say we are not limiting the final disk size, and that might be a workable excuse to check based on the obj->size here, but then its usefulness from the point of view of end users, who decide to set the variable to limit "some" usage, becomes dubious.

So...
Previous: Junio C HamanoNext: Jiang Xin
Message 8 of 10 in “receive-pack: allow a maximum input object size specified”
  1. receive-pack: allow a maximum input object size specifiedHan Xin, Sep 30, 2021
  2. receive-pack: not receive pack file with large objectHan Xin, Sep 30, 2021
  3. Ævar Arnfjörð BjarmasonSep 30, 2021
  4. Jiang XinOct 1, 2021
  5. Jeff KingOct 1, 2021
  6. Jeff KingOct 1, 2021
  7. Junio C HamanoOct 1, 2021
  8. Junio C HamanoSep 30, 2021
  9. Jiang XinOct 1, 2021
  10. Jeff KingOct 1, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.