# >4GiB source delta assertion failure

2 messages from 2010-07-21 to 2010-08-21. Participants: Ilari Liusvaara, Nicolas Pitre.
Thread: https://gitlist.dev/t/24462

## Ilari Liusvaara, 2010-07-21 23:16

Subject: >4GiB source delta assertion failure
Message-ID: <20100721231635.GA6387@LK-Perkele-V2.elisa-laajakaista.fi>
URL: https://gitlist.dev/e/20100721231635.GA6387%40LK-Perkele-V2.elisa-laajakaista.fi

```
Yes, I know trying to delta-compress with 4GiB files is insane, but OTOH,
assertion failures are bugs by defintion.

Delta source: <4GiB of zeroes> <random 64KiB block>
Delta destination: <the same 64KiB block>

This was created using:
$ dd if=/dev/urandom of=test-delta-target bs=64k count=1
$ dd if=test-delta-target of=test-delta-source bs=64k seek=64k

Now running

$ ./test-delta -d test-delta-source test-delta-target test-delta-delta

Crashes with (v1.7.2):

test-delta: diff-delta.c:285: create_delta_index: Assertion `packed_entry - (struct index_entry *)mem == entries' failed.
Aborted


As note: The delta compression format does not allow delta compression to 
properly work in this case (since source offset would need to be 2^32 and
biggest possible offset is 2^32-1), and thus the size of output should be on
order of 66kB.

-Ilari

```

## Nicolas Pitre, 2010-08-21 05:00

Subject: [PATCH] fix >4GiB source delta assertion failure
Message-ID: <alpine.LFD.2.00.1008202349500.622@xanadu.home>
URL: https://gitlist.dev/e/alpine.LFD.2.00.1008202349500.622%40xanadu.home
In-Reply-To: <20100721231635.GA6387@LK-Perkele-V2.elisa-laajakaista.fi>

```
When people try insane things such as delta-compressing 4GiB files, they
get this assertion:

diff-delta.c:285: create_delta_index: Assertion `packed_entry - (struct index_entry *)mem == entries' failed.

This happens because:

1) the 'entries' variable is an unsigned int

2) it is assigned with entries = (bufsize - 1) / RABIN_WINDOW
   (that itself is not a problem unless bufsize > 4G * RABIN_WINDOW)

3) the buffer is indexed from top to bottom starting at
   "data = buffer + entries * RABIN_WINDOW" and the multiplication
   here does indeed overflows, making the resulting top of the buffer 
   much lower than expected.

This makes the number of actually produced index entries smaller than 
what was computed initially, hence the assertion.

Furthermore, the current delta encoding format cannot represent offsets
into a reference buffer with more than 32 bits anyway.  So let's just 
limit the number of entries to what the delta format can encode.

Reported-by: Ilari Liusvaara <ilari.liusvaara@elisanet.fi>
Signed-off-by: Nicolas Pitre <nico@fluxnic.net>
---
diff --git a/diff-delta.c b/diff-delta.c
index 464ac3f..73acf8a 100644
--- a/diff-delta.c
+++ b/diff-delta.c
@@ -146,7 +146,14 @@ struct delta_index * create_delta_index(const void *buf, unsigned long bufsize)
 	/* Determine index hash size.  Note that indexing skips the
 	   first byte to allow for optimizing the Rabin's polynomial
 	   initialization in create_delta(). */
-	entries = (bufsize - 1)  / RABIN_WINDOW;
+	entries = (bufsize - 1) / RABIN_WINDOW;
+	if (bufsize >= 0xffffffffUL) {
+		/* 
+		 * Current delta format can't encode offsets into
+		 * reference buffer with more than 32 bits.
+		 */
+		entries = 0xfffffffeU / RABIN_WINDOW;
+	}
 	hsize = entries / 4;
 	for (i = 4; (1u << i) < hsize && i < 31; i++);
 	hsize = 1 << i;

```
