# pack-objects: Fix segfault when object count is less than thread count

6 messages from 2008-01-21 to 2008-01-21. Participants: Sergey Vlasov, Johannes Sixt, Nicolas Pitre.
Thread: https://gitlist.dev/t/11692

## Sergey Vlasov, 2008-01-21 14:35

Subject: pack-objects: Fix segfault when object count is less than thread count
Message-ID: <1200926145-14625-1-git-send-email-vsu@altlinux.ru>
URL: https://gitlist.dev/e/1200926145-14625-1-git-send-email-vsu%40altlinux.ru

```
When partitioning the work amongst threads, dividing the number of
objects by the number of threads may return 0 when there are less
objects than threads; this will cause the subsequent code to segfault
when accessing list[sub_size-1].  Fix this by ensuring that sub_size
is not zero if there is at least one object to process.

Signed-off-by: Sergey Vlasov <vsu@altlinux.ru>
---
 builtin-pack-objects.c |    3 +++
 1 files changed, 3 insertions(+), 0 deletions(-)

diff --git a/builtin-pack-objects.c b/builtin-pack-objects.c
index ec10238..cdf8aae 100644
--- a/builtin-pack-objects.c
+++ b/builtin-pack-objects.c
@@ -1665,6 +1665,9 @@ static void ll_find_deltas(struct object_entry **list, unsigned list_size,
 	for (i = 0; i < delta_search_threads; i++) {
 		unsigned sub_size = list_size / (delta_search_threads - i);
 
+		if (sub_size == 0 && list_size >= 1)
+			sub_size = 1;
+
 		p[i].window = window;
 		p[i].depth = depth;
 		p[i].processed = processed;
-- 
1.5.4.rc4.14.gd50a3

```

## Johannes Sixt, 2008-01-21 15:12

Subject: Re: pack-objects: Fix segfault when object count is less than thread count
Message-ID: <4794B65E.5000502@viscovery.net>
URL: https://gitlist.dev/e/4794B65E.5000502%40viscovery.net
In-Reply-To: <1200926145-14625-1-git-send-email-vsu@altlinux.ru>

```
Sergey Vlasov schrieb:
> When partitioning the work amongst threads, dividing the number of
> objects by the number of threads may return 0 when there are less
> objects than threads; this will cause the subsequent code to segfault
> when accessing list[sub_size-1].  Fix this by ensuring that sub_size
> is not zero if there is at least one object to process.
> 
> Signed-off-by: Sergey Vlasov <vsu@altlinux.ru>
> ---
>  builtin-pack-objects.c |    3 +++
>  1 files changed, 3 insertions(+), 0 deletions(-)
> 
> diff --git a/builtin-pack-objects.c b/builtin-pack-objects.c
> index ec10238..cdf8aae 100644
> --- a/builtin-pack-objects.c
> +++ b/builtin-pack-objects.c
> @@ -1665,6 +1665,9 @@ static void ll_find_deltas(struct object_entry **list, unsigned list_size,
>  	for (i = 0; i < delta_search_threads; i++) {
>  		unsigned sub_size = list_size / (delta_search_threads - i);
>  
> +		if (sub_size == 0 && list_size >= 1)
> +			sub_size = 1;
> +
>  		p[i].window = window;
>  		p[i].depth = depth;
>  		p[i].processed = processed;

I think it fits the logic better to include sub_size > 0 in the while loop
that follows, like so:

		/* try to split chunks on "path" boundaries */
		while (0 < sub_size && sub_size < list_size &&
		       list[sub_size]->hash &&
		       list[sub_size]->hash == list[sub_size-1]->hash)
			sub_size++;

because we explicitly want to allow threads to "work" on zero objects
(i.e. do nothing at all), but if a thread does get assigned some work,
then its chunk is extended past the next path boundary. This way you
collapse two special cases - "zero-sized chunk" and "path boundary" - into
one.

-- Hannes

```

## Nicolas Pitre, 2008-01-21 16:07

Subject: Re: pack-objects: Fix segfault when object count is less than thread count
Message-ID: <alpine.LFD.1.00.0801211103480.20753@xanadu.home>
URL: https://gitlist.dev/e/alpine.LFD.1.00.0801211103480.20753%40xanadu.home
In-Reply-To: <1200926145-14625-1-git-send-email-vsu@altlinux.ru>

```
On Mon, 21 Jan 2008, Sergey Vlasov wrote:

> When partitioning the work amongst threads, dividing the number of
> objects by the number of threads may return 0 when there are less
> objects than threads; this will cause the subsequent code to segfault
> when accessing list[sub_size-1].  Fix this by ensuring that sub_size
> is not zero if there is at least one object to process.

No.  Forcing one object in a thread is counter productive since it won't 
have anything to delta against.  Instead, the thread should be allowed 
to have zero objects and let the other threads have more.

This patch would be a proper fix:

diff --git a/builtin-pack-objects.c b/builtin-pack-objects.c
index ec10238..d3efeff 100644
--- a/builtin-pack-objects.c
+++ b/builtin-pack-objects.c
@@ -1672,7 +1672,8 @@ static void ll_find_deltas(struct object_entry **list, unsigned list_size,
 		p[i].data_ready = 0;
 
 		/* try to split chunks on "path" boundaries */
-		while (sub_size < list_size && list[sub_size]->hash &&
+		while (sub_size && sub_size < list_size &&
+		       list[sub_size]->hash &&
 		       list[sub_size]->hash == list[sub_size-1]->hash)
 			sub_size++;
 

```

## Nicolas Pitre, 2008-01-21 16:08

Subject: Re: pack-objects: Fix segfault when object count is less than thread count
Message-ID: <alpine.LFD.1.00.0801211107500.20753@xanadu.home>
URL: https://gitlist.dev/e/alpine.LFD.1.00.0801211107500.20753%40xanadu.home
In-Reply-To: <4794B65E.5000502@viscovery.net>

```
On Mon, 21 Jan 2008, Johannes Sixt wrote:

> Sergey Vlasov schrieb:
> > When partitioning the work amongst threads, dividing the number of
> > objects by the number of threads may return 0 when there are less
> > objects than threads; this will cause the subsequent code to segfault
> > when accessing list[sub_size-1].  Fix this by ensuring that sub_size
> > is not zero if there is at least one object to process.
> > 
> > Signed-off-by: Sergey Vlasov <vsu@altlinux.ru>
> > ---
> >  builtin-pack-objects.c |    3 +++
> >  1 files changed, 3 insertions(+), 0 deletions(-)
> > 
> > diff --git a/builtin-pack-objects.c b/builtin-pack-objects.c
> > index ec10238..cdf8aae 100644
> > --- a/builtin-pack-objects.c
> > +++ b/builtin-pack-objects.c
> > @@ -1665,6 +1665,9 @@ static void ll_find_deltas(struct object_entry **list, unsigned list_size,
> >  	for (i = 0; i < delta_search_threads; i++) {
> >  		unsigned sub_size = list_size / (delta_search_threads - i);
> >  
> > +		if (sub_size == 0 && list_size >= 1)
> > +			sub_size = 1;
> > +
> >  		p[i].window = window;
> >  		p[i].depth = depth;
> >  		p[i].processed = processed;
> 
> I think it fits the logic better to include sub_size > 0 in the while loop
> that follows, like so:
> 
> 		/* try to split chunks on "path" boundaries */
> 		while (0 < sub_size && sub_size < list_size &&
> 		       list[sub_size]->hash &&
> 		       list[sub_size]->hash == list[sub_size-1]->hash)
> 			sub_size++;
> 
> because we explicitly want to allow threads to "work" on zero objects
> (i.e. do nothing at all), but if a thread does get assigned some work,
> then its chunk is extended past the next path boundary. This way you
> collapse two special cases - "zero-sized chunk" and "path boundary" - into
> one.

Exact.


Nicolas

```

## Sergey Vlasov, 2008-01-21 17:40

Subject: Re: pack-objects: Fix segfault when object count is less than thread count
Message-ID: <20080121174052.GA4627@atlas.home>
URL: https://gitlist.dev/e/20080121174052.GA4627%40atlas.home
In-Reply-To: <alpine.LFD.1.00.0801211103480.20753@xanadu.home>

```
On Mon, Jan 21, 2008 at 11:07:15AM -0500, Nicolas Pitre wrote:
> On Mon, 21 Jan 2008, Sergey Vlasov wrote:
> 
> > When partitioning the work amongst threads, dividing the number of
> > objects by the number of threads may return 0 when there are less
> > objects than threads; this will cause the subsequent code to segfault
> > when accessing list[sub_size-1].  Fix this by ensuring that sub_size
> > is not zero if there is at least one object to process.
> 
> No.  Forcing one object in a thread is counter productive since it won't 
> have anything to delta against.  Instead, the thread should be allowed 
> to have zero objects and let the other threads have more.
> 
> This patch would be a proper fix:
> 
> diff --git a/builtin-pack-objects.c b/builtin-pack-objects.c
> index ec10238..d3efeff 100644
> --- a/builtin-pack-objects.c
> +++ b/builtin-pack-objects.c
> @@ -1672,7 +1672,8 @@ static void ll_find_deltas(struct object_entry **list, unsigned list_size,
>  		p[i].data_ready = 0;
>  
>  		/* try to split chunks on "path" boundaries */
> -		while (sub_size < list_size && list[sub_size]->hash &&
> +		while (sub_size && sub_size < list_size &&
> +		       list[sub_size]->hash &&
>  		       list[sub_size]->hash == list[sub_size-1]->hash)
>  			sub_size++;

Actually there will not be any significant differences - with my patch
the object distribution between threads will be 1, 1, ..., 0, 0...,
and with your patch it would be 0, 0, ..., 1, 1, ... (unless the
objects had the same hash, in which case they would be passed to a
single thread in both cases).

We could even introduce some limit on the number of objects below
which multithreaded packing is not attempted, so that packing a small
number of objects would be more efficient.

```

## Nicolas Pitre, 2008-01-21 17:53

Subject: Re: pack-objects: Fix segfault when object count is less than thread count
Message-ID: <alpine.LFD.1.00.0801211248590.20753@xanadu.home>
URL: https://gitlist.dev/e/alpine.LFD.1.00.0801211248590.20753%40xanadu.home
In-Reply-To: <20080121174052.GA4627@atlas.home>

```
On Mon, 21 Jan 2008, Sergey Vlasov wrote:

> On Mon, Jan 21, 2008 at 11:07:15AM -0500, Nicolas Pitre wrote:
> > On Mon, 21 Jan 2008, Sergey Vlasov wrote:
> > 
> > > When partitioning the work amongst threads, dividing the number of
> > > objects by the number of threads may return 0 when there are less
> > > objects than threads; this will cause the subsequent code to segfault
> > > when accessing list[sub_size-1].  Fix this by ensuring that sub_size
> > > is not zero if there is at least one object to process.
> > 
> > No.  Forcing one object in a thread is counter productive since it won't 
> > have anything to delta against.  Instead, the thread should be allowed 
> > to have zero objects and let the other threads have more.
> > 
> > This patch would be a proper fix:
> > 
> > diff --git a/builtin-pack-objects.c b/builtin-pack-objects.c
> > index ec10238..d3efeff 100644
> > --- a/builtin-pack-objects.c
> > +++ b/builtin-pack-objects.c
> > @@ -1672,7 +1672,8 @@ static void ll_find_deltas(struct object_entry **list, unsigned list_size,
> >  		p[i].data_ready = 0;
> >  
> >  		/* try to split chunks on "path" boundaries */
> > -		while (sub_size < list_size && list[sub_size]->hash &&
> > +		while (sub_size && sub_size < list_size &&
> > +		       list[sub_size]->hash &&
> >  		       list[sub_size]->hash == list[sub_size-1]->hash)
> >  			sub_size++;
> 
> Actually there will not be any significant differences - with my patch
> the object distribution between threads will be 1, 1, ..., 0, 0...,
> and with your patch it would be 0, 0, ..., 1, 1, ...

Or more likely 0, 0, ..., 2.

And the code is simpler.

> We could even introduce some limit on the number of objects below
> which multithreaded packing is not attempted, so that packing a small
> number of objects would be more efficient.

Possibly.  But that's not a requirement at this moment.


Nicolas

```
