Bug Fixes
-
reject incomplete delta traversals and overlapping offsets
A Report describes indexed delta components that cannot be reached from
any base object yet pass delta-tree verification. Require every indexed item
to have been inspected before returning success, using the existing object
counter. Legitimate forward references remain supported.Return corruption errors for duplicate or overlapping index offsets and for
an entry at or past the pack end, instead of panicking. The reported decoder
cycle and allocation problem is handled by the fix.Three regressions failed before the fix: an unresolved cycle was accepted,
while duplicate offsets and an invalid pack end panicked. Coverage includes
self and multi-node components with and without a valid root, plus a valid
forward delta base.Git reference:
builtin/index-pack.c::conclude_pack()at
d38352cd43ab9745686d697872408bc3249a153frejects unresolved deltas. -
reject cyclic delta chains and bound chain allocations
A report describes delta base cycles that never terminate in header
lookups and keep allocating during object decoding. Track a constant-space
cycle checkpoint in both loops, without relying on the untrusted pack
object count or rejecting valid forward references.Account for heap-backed delta-chain metadata in the existing per-allocation
limit and reserve it fallibly, including when delta payloads are empty.
The regressions failed before the fix and cover self, multi-entry, mixed
REF/OFS cycles, empty deltas, and valid forward chains.Git reference:
t/t5309-pack-delta-cycles.shat
d38352cd43ab9745686d697872408bc3249a153frejects cycles while allowing
forward delta bases. -
map packs read-only on Windows so large ones can be opened
On Windows if you memory map with copyonwrite (which is what map_copy_read_only does) it charges against the commit limit for that. As such, when opening extremely large packs, i.e. 40GB, This can fail with an out of memory error:ERROR_COMMITMENT_LIMIT(os error 1455, "The paging file is too small for this operation to complete")The fix is to memory map it plainly. Which is otherwise pretty much the same as it is on other operating systems for read-only memory mapping.
Bug Fixes (BREAKING)
-
validate multi-pack-index references on access
Looked at everything in detail and added error handling in callbacks
that didn't have them. Reduced the scope of this commit to not overlap
withodb-parallelismbranch which makes many changes additionally.Many of the newly added tests are very specific about error handling,
one might call them overkill, but I left them in for good measure.
Further, errors.rs ingix-odbI just skimmed the test titles off
as everything else would be too time consuming - better have them than
not have them I thought, particularly to supportodb-paralellism.A report describes object lookup panics caused by unchecked pack IDs
and large-offset ordinals in otherwise structurally valid MIDX files.Validate these references when reading an object entry, before indexing
pack arrays or dereferencing the optional LOFF (Large Offsets) table.
Bound LOFF ordinals by the chunk itself, not by the remaining file.
Keep MIDX loading limited to structural validation: an eager scan of
every offset entry adds linear startup work and faults in memory-mapped
pages even when a command needs only a handful of objects. Git likewise
checks these references on access.Make
pack_id_and_pack_offset_at_index()returngix_error::Result
anditer()yield fallible entries. Propagate corruption errors through
object and header lookup, delta-base resolution, integrity verification,
and CLI entry listing. ID-only iteration remains available without valid
offset references. Preserve literal high-bit 32-bit offsets when LOFF
is absent.Return
Result<Option<_>>fromFind::location_by_oid()and
Find::pack_offsets_and_oid(): absence and lookup failure are different
outcomes, and callers must be able to distinguish them. Propagate errors
through forwarding implementations, object counting, pack-entry iterator
construction, and thin-pack base lookup rather than treating corruption
as a missing object or a reason to recompress. Report a pack that becomes
unavailable during construction as an error instead of panicking.Retain failed index loads separately from missing files so repeated
lookups cannot silently turn corruption into absence. Load pending
indices before retrying failures, retry all failed slots, and reconcile
disk state when refreshing. This keeps independent valid packs usable
and permits recovery after repair or removal without endless refresh
loops on persistent failures.Regressions cover boundary and extreme invalid references, lazy loading,
valid LOFF ordinals and literal offsets, integrity verification,
corruption propagation through object lookup and pack generation, and
repeated, shared, concurrent, repaired, and removed index-load failures.Git reference:
d38352cd43ab9745686d697872408bc3249a153f,
midx.c::midx_for_pack()andnth_midxed_offset().
Commit Statistics
- 15 commits contributed to the release over the course of 13 calendar days.
- 13 days passed between releases.
- 4 commits were understood as conventional.
- 0 issues like '(#ID)' were seen in commit messages
Commit Details
view details
- Uncategorized
- Prepare changelogs prior to release (794eeef)
- Merge pull request #3032 from GitoxideLabs/sec-audit (1d7bac7)
- Validate multi-pack-index references on access (5b6522a)
- Reject incomplete delta traversals and overlapping offsets (781b606)
- Reject cyclic delta chains and bound chain allocations (89a12d4)
- Merge pull request #3044 from special-bread/bread/pack-readonly-mmap-windows (9d5d934)
- Review (4ddbe11)
- Merge pull request #3033 from GitoxideLabs/gix-cli-progress-cleanup (80f4b03)
- Map packs read-only on Windows so large ones can be opened (b41b1a5)
- Merge pull request #3035 from any-victor/fix/clone-ignores-caller-repository-env (d2d078f)
- Review (95043b9)
- Merge pull request #3022 from GitoxideLabs/release-testtools (f819565)
- Use existing error helpers for guards and conversions (1c25831)
- Use
or_error()at public exception boundaries (535672e) - Merge pull request #3020 from GitoxideLabs/report-september (5fb3dcf)