Go to file
Jeff King 63aca3f7f1 dumb-http: store downloaded pack idx as tempfile
This patch fixes a regression in b1b8dfde69 (finalize_object_file():
implement collision check, 2024-09-26) where fetching a v1 pack idx file
over the dumb-http protocol would cause the fetch to fail.

The core of the issue is that dumb-http stores the idx we fetch from the
remote at the same path that will eventually hold the idx we generate
from "index-pack --stdin". The sequence is something like this:

  0. We realize we need some object X, which we don't have locally, and
     nor does the other side have it as a loose object.

  1. We download the list of remote packs from objects/info/packs.

  2. For each entry in that file, we download each pack index and store
     it locally in .git/objects/pack/pack-$hash.idx (the $hash is not
     something we can verify yet and is given to us by the remote).

  3. We check each pack index we got to see if it has object X. When we
     find a match, we download the matching .pack file from the remote
     to a tempfile. We feed that to "index-pack --stdin", which
     reindexes the pack, rather than trusting that it has what the other
     side claims it does. In most cases, this will end up generating the
     exact same (byte-for-byte) pack index which we'll store at the same
     pack-$hash.idx path, because the index generation and $hash id are
     computed based on what's in the packfile. But:

       a. The other side might have used other options to generate the
          index. For instance we use index v2 by default, but long ago
          it was v1 (and you can still ask for v1 explicitly).

       b. The other side might even use a different mechanism to
          determine $hash. E.g., long ago it was based on the sorted
          list of objects in the packfile, but we switched to using the
          pack checksum in 1190a1acf8 (pack-objects: name pack files
          after trailer hash, 2013-12-05).

The regression we saw in the real world was (3a). A recent client
fetching from a server with a v1 index downloaded that index, then
complained about trying to overwrite it with its own v2 index. This
collision is otherwise harmless; we know we want to replace the remote
version with our local one, but the collision check doesn't realize
that.

There are a few options to fix it:

  - we could teach index-pack a command-line option to ignore only pack
    idx collisions, and use it when the dumb-http code invokes
    index-pack. This would be an awkward thing to expose users to and
    would involve a lot of boilerplate to get the option down to the
    collision code.

  - we could delete the remote .idx file right before running
    index-pack. It should be redundant at that point (since we've just
    downloaded the matching pack). But it feels risky to delete
    something from our own .git/objects based on what the other side has
    said. I'm not entirely positive that a malicious server couldn't lie
    about which pack-$hash.idx it has and get us to delete something
    precious.

  - we can stop co-mingling the downloaded idx files in our local
    objects directory. This is a slightly bigger change but I think
    fixes the root of the problem more directly.

This patch implements the third option. The big design questions are:
where do we store the downloaded files, and how do we manage their
lifetimes?

There are some additional quirks to the dumb-http system we should
consider. Remember that in step 2 we downloaded every pack index, but in
step 3 we may only download some of the matching packs. What happens to
those other idx files now? They sit in the .git/objects/pack directory,
possibly waiting to be used at a later date. That may save bandwidth for
a subsequent fetch, but it also creates a lot of weird corner cases:

  - our local object directory now has semi-untrusted .idx files sitting
    around, without their matching .pack

  - in case 3b, we noted that we might not generate the same hash as the
    other side. In that case even if we download the matching pack,
    our index-pack invocation will store it in a different
    pack-$hash.idx file. And the unmatched .idx will sit there forever.

  - if the server repacks, it may delete the old packs. Now we have
    these orphaned .idx files sitting around locally that will never be
    used (nor deleted).

  - if we repack locally we may delete our local version of the server's
    pack index and not realize we have it. So we'll download it again,
    even though we have all of the objects it mentions.

I think the right solution here is probably some more complex cache
management system: download the remote .idx files to their own storage
directory, mark them as "seen" when we get their matching pack (to avoid
re-downloading even if we repack), and then delete them when the
server's objects/info/refs no longer mentions them.

But since the dumb http protocol is so ancient and so inferior to the
smart http protocol, I don't think it's worth spending a lot of time
creating such a system. For this patch I'm just downloading the idx
files to .git/objects/tmp_pack_*, and marking them as tempfiles to be
deleted when we exit (and due to the name, any we miss due to a crash,
etc, should eventually be removed by "git gc" runs based on timestamps).

That is slightly worse for one case: if we download an idx but not the
matching pack, we won't retain that idx for subsequent runs. But the
flip side is that we're making other cases better (we never hold on to
useless idx files forever). I suspect that worse case does not even come
up often, since it implies that the packs are generated to match
distinct parts of history (i.e., in practice even in a repo with many
packs you're going to end up grabbing all of those packs to do a clone).
If somebody really cares about that, I think the right path forward is a
managed cache directory as above, and this patch is providing the first
step in that direction anyway (by moving things out of the objects/pack/
directory).

There are two test changes. One demonstrates the broken v1 index case
(it double-checks the resulting clone with fsck to be careful, but prior
to this patch it actually fails at the clone step). The other tweaks the
expectation for a test that covers the "slightly worse" case to
accommodate the extra index download.

The code changes are fairly simple. We stop using finalize_object_file()
to copy the remote's index file into place, and leave it as a tempfile.
We give the tempfile a real ".idx" name, since the packfile code expects
that, and thus we make sure it is out of the usual packs/ directory (so
we'd never mistake it for a real local .idx).

We also have to change parse_pack_index(), which creates a temporary
packed_git to access our index (we need this because all of the pack idx
code assumes we have that struct). It reads the index data from the
tempfile, but prior to this patch would speculatively write the
finalized name into the packed_git struct using the pack-$hash we expect
to use.

I was mildly surprised that this worked at all, since we call
verify_pack_index() on the packed_git which mentions the final name
before moving the file into place! But it works because
parse_pack_index() leaves the mmap-ed data in the struct, so the
lazy-open in verify_pack_index() never triggers, and we read from the
tempfile, ignoring the filename in the struct completely. Hacky, but it
works.

After this patch, parse_pack_index() now uses the index filename we pass
in to derive a matching .pack name. This is OK to change because there
are only two callers, both in the dumb http code (and the other passes
in an existing pack-$hash.idx name, so the derived name is going to be
pack-$hash.pack, which is what we were using anyway).

I'll follow up with some more cleanups in that area, but this patch is
sufficient to fix the regression.

Reported-by: fox <fox.gbr@townlong-yak.com>
Signed-off-by: Jeff King <peff@peff.net>
Signed-off-by: Taylor Blau <me@ttaylorr.com>
2024-10-25 17:35:46 -04:00
.github ci: create script to set up Git for Windows SDK 2024-10-09 11:33:04 -07:00
Documentation The fifth batch 2024-10-25 14:11:13 -04:00
block-sha1 sha1: do not redefine `platform_SHA_CTX` and friends 2024-09-27 11:27:47 -07:00
builtin Merge branch 'wm/shortlog-hash' 2024-10-25 14:02:49 -04:00
ci Merge branch 'ps/ci-gitlab-windows' 2024-10-25 14:01:21 -04:00
compat Merge branch 'sk/msvc-warnings' 2024-10-25 14:02:44 -04:00
contrib contrib: fix typos 2024-10-10 13:31:12 -07:00
ewah ewah: `bitmap_equals_ewah()` 2024-05-24 11:40:44 -07:00
git-gui Merge https://github.com/j6t/git-gui 2024-07-07 22:50:59 -07:00
gitk-git Makefile(s): avoid recipe prefix in conditional statements 2024-04-08 14:42:32 -07:00
gitweb Merge branch 'am/gitweb-feed-use-committer-date' 2024-07-15 10:11:41 -07:00
mergetools Merge branch 'ak/typofix-2.46-maint' 2024-10-04 14:21:40 -07:00
negotiator Merge branch 'ps/leakfixes-part-6' 2024-09-20 11:16:30 -07:00
oss-fuzz oss-fuzz: mark unused argv/argc argument 2024-08-17 09:46:11 -07:00
perl Merge branch 'ak/typofix-2.46-maint' 2024-10-04 14:21:40 -07:00
po Merge branch 'l10n-de-2.47' of github.com:ralfth/git 2024-10-06 12:06:21 +08:00
refs Merge branch 'ps/reftable-alloc-failures' 2024-10-10 14:22:25 -07:00
reftable Merge branch 'ps/reftable-alloc-failures' 2024-10-10 14:22:25 -07:00
sha1 sha1: do not redefine `platform_SHA_CTX` and friends 2024-09-27 11:27:47 -07:00
sha1collisiondetection@855827c583
sha1dc
sha256
t dumb-http: store downloaded pack idx as tempfile 2024-10-25 17:35:46 -04:00
templates
trace2 Merge branch 'ak/typofix-2.46-maint' 2024-10-04 14:21:40 -07:00
xdiff
.cirrus.yml ci: update FreeBSD image to 13.4 2024-09-20 14:40:41 -07:00
.clang-format Merge branch 'rs/unit-tests-test-run' 2024-08-19 11:07:36 -07:00
.editorconfig editorconfig: add Makefiles to "text files" 2024-03-23 11:42:31 -07:00
.gitattributes Makefile(s): do not enforce "all indents must be done with tab" 2024-05-05 16:54:35 +02:00
.gitignore Makefile: wire up the clar unit testing framework 2024-09-04 08:41:37 -07:00
.gitlab-ci.yml gitlab-ci: exercise Git on Windows 2024-10-09 11:33:05 -07:00
.gitmodules
.mailmap .mailmap document current address. 2024-09-06 09:31:15 -07:00
.tsan-suppressions
CODE_OF_CONDUCT.md
COPYING
GIT-VERSION-GEN Start the 2.48 cycle 2024-10-10 14:22:30 -07:00
INSTALL Sync with 2.42.2 2024-04-19 12:38:50 +02:00
LGPL-2.1
Makefile Merge branch 'pb/clar-build-fix' 2024-10-25 14:02:25 -04:00
README.md git-gui: note the new maintainer 2024-05-11 17:22:17 +02:00
RelNotes Start the 2.48 cycle 2024-10-10 14:22:30 -07:00
SECURITY.md
abspath.c
abspath.h
aclocal.m4
add-interactive.c global: introduce `USE_THE_REPOSITORY_VARIABLE` macro 2024-06-14 10:26:33 -07:00
add-interactive.h
add-patch.c Merge branch 'ps/config-wo-the-repository' 2024-08-23 09:02:34 -07:00
advice.c Merge branch 'ds/advice-sparse-index-expansion' 2024-07-16 11:18:56 -07:00
advice.h Merge branch 'ds/advice-sparse-index-expansion' 2024-07-16 11:18:56 -07:00
alias.c config: make dependency on repo in `read_early_config()` explicit 2024-09-12 10:15:40 -07:00
alias.h
alloc.c
alloc.h
apply.c Merge branch 'ps/apply-leakfix' 2024-09-25 10:37:10 -07:00
apply.h apply: support --ours, --theirs, and --union for three-way merges 2024-09-09 10:07:24 -07:00
archive-tar.c global: introduce `USE_THE_REPOSITORY_VARIABLE` macro 2024-06-14 10:26:33 -07:00
archive-zip.c global: introduce `USE_THE_REPOSITORY_VARIABLE` macro 2024-06-14 10:26:33 -07:00
archive.c Merge branch 'rs/archive-with-attr-pathspec-fix' 2024-10-04 14:21:40 -07:00
archive.h
attr.c Merge branch 'ak/typofixes' 2024-09-23 10:35:07 -07:00
attr.h Merge branch 'jc/varargs-attributes' 2024-06-17 15:55:55 -07:00
banned.h
base85.c
base85.h
bisect.c Merge branch 'ps/pack-refs-auto-heuristics' 2024-09-12 11:47:23 -07:00
bisect.h
blame.c Merge branch 'ps/leakfixes-more' 2024-07-08 14:53:10 -07:00
blame.h
blob.c
blob.h
bloom.c diff: improve lifecycle management of diff queues 2024-09-30 11:23:05 -07:00
bloom.h Merge branch 'ak/typofixes' 2024-09-23 10:35:07 -07:00
branch.c submodule: fix leaking submodule entry list 2024-09-30 11:23:03 -07:00
branch.h typo: replace 'commitish' with 'committish' 2024-04-11 15:14:56 -07:00
builtin.h builtin: remove USE_THE_REPOSITORY_VARIABLE from builtin.h 2024-09-13 14:32:24 -07:00
bulk-checkin.c environment: make `get_object_directory()` accept a repository 2024-09-12 10:15:39 -07:00
bulk-checkin.h
bundle-uri.c bundle-uri: plug leak in unbundle_from_file() 2024-10-10 11:47:24 -07:00
bundle-uri.h
bundle.c Merge branch 'ps/leakfixes-part-5' 2024-09-03 09:15:00 -07:00
bundle.h unbundle: extend object verification for fetches 2024-06-20 10:30:08 -07:00
cache-tree.c Merge branch 'ps/cache-tree-w-broken-index-entry' 2024-10-22 14:40:38 -04:00
cache-tree.h cache-tree: refactor verification to return error codes 2024-10-07 15:08:11 -07:00
cbtree.c cbtree: fix a typo 2024-09-16 10:46:00 -07:00
cbtree.h
chdir-notify.c
chdir-notify.h
check-builtins.sh
checkout.c global: introduce `USE_THE_REPOSITORY_VARIABLE` macro 2024-06-14 10:26:33 -07:00
checkout.h hash-ll: merge with "hash.h" 2024-06-14 10:26:33 -07:00
chunk-format.c global: introduce `USE_THE_REPOSITORY_VARIABLE` macro 2024-06-14 10:26:33 -07:00
chunk-format.h hash-ll: merge with "hash.h" 2024-06-14 10:26:33 -07:00
color.c color: add support for 12-bit RGB colors 2024-05-02 09:30:38 -07:00
color.h color: add support for 12-bit RGB colors 2024-05-02 09:30:38 -07:00
column.c
column.h
combine-diff.c diff: fix leaking orderfile option 2024-09-27 08:25:35 -07:00
command-list.txt builtin/refs: new command to migrate ref storage formats 2024-06-06 09:04:34 -07:00
commit-graph.c commit-graph: remove unnecessary UNLEAK 2024-09-23 10:03:59 -07:00
commit-graph.h hash-ll: merge with "hash.h" 2024-06-14 10:26:33 -07:00
commit-reach.c Merge branch 'ds/for-each-ref-is-base' 2024-08-26 11:32:24 -07:00
commit-reach.h commit-reach: add get_branch_base_for_tip 2024-08-14 10:10:05 -07:00
commit-slab-decl.h
commit-slab-impl.h
commit-slab.h
commit.c commit: avoid leaking already-saved buffer 2024-09-25 10:24:53 -07:00
commit.h Merge branch 'jc/pass-repo-to-builtins' 2024-09-23 10:35:09 -07:00
common-main.c global: introduce `USE_THE_REPOSITORY_VARIABLE` macro 2024-06-14 10:26:33 -07:00
config.c config: fix evaluating "onbranch" with nonexistent git dir 2024-09-24 09:18:17 -07:00
config.h config: make dependency on repo in `read_early_config()` explicit 2024-09-12 10:15:40 -07:00
config.mak.dev Merge branch 'ak/typofix-2.46-maint' 2024-09-25 10:37:12 -07:00
config.mak.in
config.mak.uname Merge branch 'rj/cygwin-has-dev-tty' into maint-2.46 2024-09-23 10:32:59 -07:00
configure.ac
connect.c connect: clear child process before freeing in diagnostic mode 2024-09-25 10:24:53 -07:00
connect.h
connected.c global: introduce `USE_THE_REPOSITORY_VARIABLE` macro 2024-06-14 10:26:33 -07:00
connected.h
convert.c convert: fix leaks when resetting attributes 2024-08-22 09:18:03 -07:00
convert.h hash-ll: merge with "hash.h" 2024-06-14 10:26:33 -07:00
copy.c Merge branch 'fixes/2.45.1/2.41' into fixes/2.45.1/2.42 2024-05-24 16:57:43 -07:00
copy.h Merge branch 'fixes/2.45.1/2.40' into fixes/2.45.1/2.41 2024-05-24 16:57:02 -07:00
credential.c Merge branch 'ds/background-maintenance-with-credential' 2024-09-30 16:16:16 -07:00
credential.h credential: clear expired c->credential, unify secret clearing 2024-06-06 11:42:40 -07:00
csum-file.c csum-file.c: use unsafe SHA-1 implementation when available 2024-09-27 11:27:47 -07:00
csum-file.h Merge branch 'ps/leakfixes-part-4' 2024-08-23 09:02:33 -07:00
ctype.c
daemon.c Merge branch 'jk/mark-unused-parameters' 2024-08-26 11:32:23 -07:00
date.c date: detect underflow/overflow when parsing dates with timezone offset 2024-06-25 17:07:41 -07:00
date.h date: make DATE_MODE thread-safe 2024-04-05 15:21:14 -07:00
decorate.c
decorate.h t/: migrate helper/test-example-decorate to the unit testing framework 2024-05-28 13:53:36 -07:00
delta-islands.c refs: add referent to each_ref_fn 2024-08-09 08:47:34 -07:00
delta-islands.h
delta.h
detect-compiler
diagnose.c global: introduce `USE_THE_REPOSITORY_VARIABLE` macro 2024-06-14 10:26:33 -07:00
diagnose.h
diff-delta.c
diff-lib.c Merge branch 'jk/output-prefix-cleanup' 2024-10-10 14:22:30 -07:00
diff-merges.c
diff-merges.h
diff-no-index.c remerge-diff: clean up temporary objdir at a central place 2024-08-09 15:42:40 -07:00
diff.c Merge branch 'jk/output-prefix-cleanup' 2024-10-10 14:22:30 -07:00
diff.h Merge branch 'jk/output-prefix-cleanup' 2024-10-10 14:22:30 -07:00
diffcore-break.c diff: improve lifecycle management of diff queues 2024-09-30 11:23:05 -07:00
diffcore-delta.c
diffcore-order.c diffcore-order: fix leaking buffer when parsing orderfiles 2024-09-27 08:25:35 -07:00
diffcore-pickaxe.c diff: improve lifecycle management of diff queues 2024-09-30 11:23:05 -07:00
diffcore-rename.c diff: improve lifecycle management of diff queues 2024-09-30 11:23:05 -07:00
diffcore-rotate.c diff: improve lifecycle management of diff queues 2024-09-30 11:23:05 -07:00
diffcore.h diff: improve lifecycle management of diff queues 2024-09-30 11:23:05 -07:00
dir-iterator.c
dir-iterator.h
dir.c Merge branch 'ps/leakfixes-part-7' 2024-10-02 07:46:26 -07:00
dir.h win32: override `fspathcmp()` with a directory separator-aware version 2024-07-13 16:23:36 -07:00
editor.c global: prepare for hiding away repo-less config functions 2024-08-13 10:01:05 -07:00
editor.h editor: do not rely on `the_repository` for interactive edits 2024-08-13 10:01:00 -07:00
entry.c entry: fix leaking pathnames during delayed checkout 2024-08-01 08:47:37 -07:00
entry.h
environment.c environment: stop storing "core.notesRef" globally 2024-09-12 10:15:44 -07:00
environment.h environment: stop storing "core.notesRef" globally 2024-09-12 10:15:44 -07:00
exec-cmd.c exec_cmd: RUNTIME_PREFIX on z/OS systems 2024-08-22 08:58:46 -07:00
exec-cmd.h
fetch-negotiator.c
fetch-negotiator.h
fetch-pack.c Merge branch 'ps/environ-wo-the-repository' 2024-09-23 10:35:05 -07:00
fetch-pack.h fetch-pack: expose fsckObjects configuration logic 2024-06-20 10:30:07 -07:00
fmt-merge-msg.c Merge branch 'ps/use-the-repository' 2024-07-02 09:59:00 -07:00
fmt-merge-msg.h
fsck.c builtin/refs: add verify subcommand 2024-08-08 09:36:53 -07:00
fsck.h fsck: add ref name check for files backend 2024-08-08 09:36:53 -07:00
fsmonitor--daemon.h
fsmonitor-ipc.c global: introduce `USE_THE_REPOSITORY_VARIABLE` macro 2024-06-14 10:26:33 -07:00
fsmonitor-ipc.h
fsmonitor-ll.h
fsmonitor-path-utils.h
fsmonitor-settings.c fsmonitor-settings: fix a typo 2024-09-19 13:46:00 -07:00
fsmonitor-settings.h
fsmonitor.c environment: make `get_git_work_tree()` accept a repository 2024-09-12 10:15:40 -07:00
fsmonitor.h
generate-cmdlist.sh
generate-configlist.sh
generate-hooklist.sh
gettext.c
gettext.h
git-archimport.perl
git-compat-util.h CodingGuidelines: also mention MAYBE_UNUSED 2024-08-29 11:28:07 -07:00
git-curl-compat.h remote-curl: add Transfer-Encoding header only for older curl 2024-04-10 19:24:48 +02:00
git-cvsexportcommit.perl
git-cvsimport.perl
git-cvsserver.perl
git-difftool--helper.sh
git-filter-branch.sh
git-instaweb.sh git-instaweb: fix a typo 2024-09-19 13:46:00 -07:00
git-merge-octopus.sh
git-merge-one-file.sh
git-merge-resolve.sh
git-mergetool--lib.sh
git-mergetool.sh
git-p4.py git-p4: fix typos 2024-09-19 13:46:00 -07:00
git-quiltimport.sh git-quiltimport: avoid an unnecessary subshell 2024-03-16 11:08:57 -07:00
git-request-pull.sh
git-send-email.perl Merge branch 'jk/send-email-mailmap' 2024-09-06 10:38:49 -07:00
git-sh-i18n.sh
git-sh-setup.sh
git-submodule.sh builtin/submodule: allow "add" to use different ref storage format 2024-08-08 09:22:21 -07:00
git-svn.perl git-svn: mention `svn:global-ignores` in help+docs 2024-08-14 15:10:24 -07:00
git-web--browse.sh
git-zlib.c
git-zlib.h
git.c Merge branch 'jc/a-commands-without-the-repo' 2024-10-25 14:02:36 -04:00
git.rc
gpg-interface.c Merge branch 'ak/typofix-2.46-maint' 2024-09-25 10:37:12 -07:00
gpg-interface.h gpg-interface: fix misdesigned signing key interfaces 2024-09-05 08:49:11 -07:00
graph.c Merge branch 'jk/output-prefix-cleanup' 2024-10-10 14:22:30 -07:00
graph.h
grep.c grep: fix leaking grep pattern 2024-09-27 08:25:36 -07:00
grep.h
hash-lookup.c global: introduce `USE_THE_REPOSITORY_VARIABLE` macro 2024-06-14 10:26:33 -07:00
hash-lookup.h
hash.h hash.h: set NEEDS_CLONE_HELPER_UNSAFE in fallback mode 2024-10-03 11:18:36 -07:00
hashmap.c
hashmap.h
help.c Merge branch 'jc/pass-repo-to-builtins' 2024-09-23 10:35:09 -07:00
help.h builtin/merge: fix leaking `struct cmdnames` in `get_strategy()` 2024-06-11 13:15:07 -07:00
hex-ll.c
hex-ll.h
hex.c global: introduce `USE_THE_REPOSITORY_VARIABLE` macro 2024-06-14 10:26:33 -07:00
hex.h hex: guard declarations with `USE_THE_REPOSITORY_VARIABLE` 2024-06-14 10:26:35 -07:00
hook.c hooks: remove implicit dependency on `the_repository` 2024-08-13 10:01:01 -07:00
hook.h hooks: remove implicit dependency on `the_repository` 2024-08-13 10:01:01 -07:00
http-backend.c environment: make `get_object_directory()` accept a repository 2024-09-12 10:15:39 -07:00
http-fetch.c http-fetch: clear leaking git-index-pack(1) arguments 2024-09-25 10:24:52 -07:00
http-push.c http-push: clean up local_refs at exit 2024-09-25 10:24:58 -07:00
http-walker.c http-walker: free fake packed_git list 2024-09-25 10:24:56 -07:00
http.c dumb-http: store downloaded pack idx as tempfile 2024-10-25 17:35:46 -04:00
http.h http: fix leak of http_object_request struct 2024-09-25 10:24:55 -07:00
ident.c ident: add casts for fallback name and GECOS 2024-06-07 10:30:51 -07:00
ident.h
imap-send.c Merge branch 'jk/no-openssl-with-openssl-sha1' 2024-09-20 11:16:31 -07:00
iterator.h
json-writer.c strbuf: introduce strbuf_addstrings() to repeatedly add a string 2024-05-29 09:09:39 -07:00
json-writer.h
khash.h
kwset.c
kwset.h
levenshtein.c
levenshtein.h
line-log.c Merge branch 'jk/output-prefix-cleanup' 2024-10-10 14:22:30 -07:00
line-log.h
line-range.c line-range: plug leaking find functions 2024-06-11 13:15:08 -07:00
line-range.h
linear-assignment.c
linear-assignment.h
list-objects-filter-options.c global: introduce `USE_THE_REPOSITORY_VARIABLE` macro 2024-06-14 10:26:33 -07:00
list-objects-filter-options.h
list-objects-filter.c Merge branch 'ps/leakfixes-more' 2024-07-08 14:53:10 -07:00
list-objects-filter.h
list-objects.c global: introduce `USE_THE_REPOSITORY_VARIABLE` macro 2024-06-14 10:26:33 -07:00
list-objects.h
list.h
lockfile.c
lockfile.h
log-tree.c Merge branch 'ng/rebase-merges-branch-name-as-label' 2024-10-18 13:56:22 -04:00
log-tree.h rebase-update-refs: extract load_branch_decorations 2024-10-09 10:52:45 -07:00
loose.c loose: don't rely on repository global state 2024-10-09 11:51:31 -07:00
loose.h hash-ll: merge with "hash.h" 2024-06-14 10:26:33 -07:00
ls-refs.c refs: add referent to each_ref_fn 2024-08-09 08:47:34 -07:00
ls-refs.h
mailinfo.c Merge branch 'jc/mailinfo-header-cleanup' 2024-09-12 11:47:22 -07:00
mailinfo.h
mailmap.c Merge branch 'jk/send-email-mailmap' 2024-09-06 10:38:49 -07:00
mailmap.h check-mailmap: add options for additional mailmap sources 2024-08-27 14:51:29 -07:00
match-trees.c match-trees: fix leaking prefixes in `shift_tree()` 2024-09-05 08:49:12 -07:00
match-trees.h
mem-pool.c don't report vsnprintf(3) error as bug 2024-04-21 12:27:07 -07:00
mem-pool.h __attribute__: add a few missing format attributes 2024-06-10 09:16:30 -07:00
merge-blobs.c global: introduce `USE_THE_REPOSITORY_VARIABLE` macro 2024-06-14 10:26:33 -07:00
merge-blobs.h
merge-ll.c Merge branch 'ak/typofix-2.46-maint' 2024-09-25 10:37:12 -07:00
merge-ll.h merge options: add a conflict style member 2024-03-14 10:08:52 -07:00
merge-ort-wrappers.c merge: fix leaking merge bases 2024-06-11 13:15:08 -07:00
merge-ort-wrappers.h merge: fix leaking merge bases 2024-06-11 13:15:08 -07:00
merge-ort.c diff: improve lifecycle management of diff queues 2024-09-30 11:23:05 -07:00
merge-ort.h Merge branch 'ps/leakfixes-more' 2024-07-08 14:53:10 -07:00
merge-recursive.c merge-recursive: honor diff.algorithm 2024-07-13 18:10:49 -07:00
merge-recursive.h merge-recursive: honor diff.algorithm 2024-07-13 18:10:49 -07:00
merge.c global: introduce `USE_THE_REPOSITORY_VARIABLE` macro 2024-06-14 10:26:33 -07:00
merge.h
mergesort.h
midx-write.c pack-write: fix return parameter of `write_rev_file_order()` 2024-09-30 11:23:08 -07:00
midx.c midx: avoid duplicate packed_git entries 2024-10-25 17:35:46 -04:00
midx.h midx: implement support for writing incremental MIDX chains 2024-08-06 12:01:39 -07:00
name-hash.c environment: guard state depending on a repository 2024-09-12 10:15:42 -07:00
name-hash.h
notes-cache.c global: introduce `USE_THE_REPOSITORY_VARIABLE` macro 2024-06-14 10:26:33 -07:00
notes-cache.h
notes-merge.c Merge branch 'ps/leakfixes-more' 2024-07-08 14:53:10 -07:00
notes-merge.h
notes-utils.c Merge branch 'ps/leakfixes-more' 2024-07-08 14:53:10 -07:00
notes-utils.h commit: fix leaking parents when calling `commit_tree_extended()` 2024-06-11 13:15:07 -07:00
notes.c environment: stop storing "core.notesRef" globally 2024-09-12 10:15:44 -07:00
notes.h environment: stop storing "core.notesRef" globally 2024-09-12 10:15:44 -07:00
object-file-convert.c hash-ll: merge with "hash.h" 2024-06-14 10:26:33 -07:00
object-file-convert.h
object-file.c Merge branch 'tb/weak-sha1-for-tail-sum' 2024-10-02 07:46:27 -07:00
object-file.h finalize_object_file(): implement collision check 2024-09-27 11:27:47 -07:00
object-name.c environment: stop storing "core.warnAmbiguousRefs" globally 2024-09-12 10:15:44 -07:00
object-name.h object-name: free leaking object contexts 2024-06-11 13:15:05 -07:00
object-store-ll.h environment: move object database functions into object layer 2024-09-12 10:15:40 -07:00
object-store.h
object.c object: clear grafts when clearing parsed object pool 2024-09-05 08:49:11 -07:00
object.h object: clear grafts when clearing parsed object pool 2024-09-05 08:49:11 -07:00
oid-array.c global: introduce `USE_THE_REPOSITORY_VARIABLE` macro 2024-06-14 10:26:33 -07:00
oid-array.h
oidmap.c
oidmap.h hash-ll: merge with "hash.h" 2024-06-14 10:26:33 -07:00
oidset.c oidset: pass hash algorithm when parsing file 2024-06-14 10:26:34 -07:00
oidset.h oidset: pass hash algorithm when parsing file 2024-06-14 10:26:34 -07:00
oidtree.c global: ensure that object IDs are always padded 2024-06-14 10:26:32 -07:00
oidtree.h hash-ll: merge with "hash.h" 2024-06-14 10:26:33 -07:00
pack-bitmap-write.c pack-bitmap-write: fix leaking OID array 2024-09-30 11:23:07 -07:00
pack-bitmap.c pseudo-merge: fix various memory leaks 2024-09-30 11:23:06 -07:00
pack-bitmap.h pack-bitmap: tag bitmapped packs with their corresponding MIDX 2024-08-27 14:50:26 -07:00
pack-check.c global: introduce `USE_THE_REPOSITORY_VARIABLE` macro 2024-06-14 10:26:33 -07:00
pack-mtimes.c
pack-mtimes.h
pack-objects.c
pack-objects.h
pack-revindex.c Merge branch 'ps/use-the-repository' 2024-07-02 09:59:00 -07:00
pack-revindex.h
pack-write.c Merge branch 'ps/leakfixes-part-8' 2024-10-10 14:22:29 -07:00
pack.h pack-write: fix return parameter of `write_rev_file_order()` 2024-09-30 11:23:08 -07:00
packfile.c dumb-http: store downloaded pack idx as tempfile 2024-10-25 17:35:46 -04:00
packfile.h midx: implement support for writing incremental MIDX chains 2024-08-06 12:01:39 -07:00
pager.c config: make dependency on repo in `read_early_config()` explicit 2024-09-12 10:15:40 -07:00
pager.h pager: introduce wait_for_pager 2024-07-25 09:03:00 -07:00
parallel-checkout.c global: prepare for hiding away repo-less config functions 2024-08-13 10:01:05 -07:00
parallel-checkout.h
parse-options-cb.c Merge branch 'ps/use-the-repository' 2024-07-02 09:59:00 -07:00
parse-options.c parse-options: free previous value of `OPTION_FILENAME` 2024-09-27 08:25:35 -07:00
parse-options.h parse-options: cast long name for OPTION_ALIAS 2024-06-07 10:30:53 -07:00
parse.c config: introduce `git_config_double()` 2024-05-24 11:40:42 -07:00
parse.h config: introduce `git_config_double()` 2024-05-24 11:40:42 -07:00
patch-delta.c
patch-ids.c
patch-ids.h
path.c environment: guard state depending on a repository 2024-09-12 10:15:42 -07:00
path.h path: hide functions using `the_repository` by default 2024-08-13 10:01:01 -07:00
pathspec.c environment: make `get_git_work_tree()` accept a repository 2024-09-12 10:15:40 -07:00
pathspec.h Merge branch 'as/pathspec-h-typofix' 2024-07-12 08:41:57 -07:00
pkt-line.c
pkt-line.h
preload-index.c environment: guard state depending on a repository 2024-09-12 10:15:42 -07:00
preload-index.h
pretty.c Merge branch 'ak/typofix-2.46-maint' 2024-09-25 10:37:12 -07:00
pretty.h Merge branch 'rs/date-mode-pass-by-value' 2024-04-16 14:50:29 -07:00
prio-queue.c
prio-queue.h
progress.c global: introduce `USE_THE_REPOSITORY_VARIABLE` macro 2024-06-14 10:26:33 -07:00
progress.h
promisor-remote.c promisor-remote: fix leaking partial clone filter 2024-09-27 08:25:36 -07:00
promisor-remote.h config: clarify memory ownership in `git_config_string()` 2024-05-27 11:20:00 -07:00
prompt.c environment: guard state depending on a repository 2024-09-12 10:15:42 -07:00
prompt.h
protocol-caps.c protocol-caps: use hash algorithm from passed-in repository 2024-06-14 10:26:34 -07:00
protocol-caps.h
protocol.c global: prepare for hiding away repo-less config functions 2024-08-13 10:01:05 -07:00
protocol.h
prune-packed.c environment: make `get_object_directory()` accept a repository 2024-09-12 10:15:39 -07:00
prune-packed.h
pseudo-merge.c pseudo-merge: fix leaking strmap keys 2024-09-30 11:23:06 -07:00
pseudo-merge.h pseudo-merge: fix various memory leaks 2024-09-30 11:23:06 -07:00
quote.c
quote.h
range-diff.c Merge branch 'jk/output-prefix-cleanup' 2024-10-10 14:22:30 -07:00
range-diff.h format-patch: run range-diff with larger creation-factor 2024-05-06 11:57:22 -07:00
reachable.c refs: add referent to each_ref_fn 2024-08-09 08:47:34 -07:00
reachable.h
read-cache-ll.h read-cache-ll: fix a typo 2024-09-19 13:46:00 -07:00
read-cache.c Merge branch 'ps/cache-tree-w-broken-index-entry' 2024-10-22 14:40:38 -04:00
read-cache.h
rebase-interactive.c Merge branch 'ps/use-the-repository' 2024-07-02 09:59:00 -07:00
rebase-interactive.h rebase -i: pass struct replay_opts to parse_insn_line() 2024-05-30 10:02:56 -07:00
rebase.c rebase: fix a typo 2024-09-19 13:46:01 -07:00
rebase.h
ref-filter.c Merge branch 'ak/refs-symref-referent-typofix' 2024-09-25 10:37:12 -07:00
ref-filter.h ref-filter: add ref_format_clear() function 2024-09-09 16:26:11 -07:00
reflog-walk.c global: introduce `USE_THE_REPOSITORY_VARIABLE` macro 2024-06-14 10:26:33 -07:00
reflog-walk.h date: make DATE_MODE thread-safe 2024-04-05 15:21:14 -07:00
reflog.c Merge branch 'jc/reflog-expire-lookup-commit-fix' into maint-2.46 2024-08-26 11:10:21 -07:00
reflog.h
refs.c Merge branch 'ps/reftable-exclude' 2024-09-25 10:37:11 -07:00
refs.h Merge branch 'ak/typofix-2.46-maint' 2024-09-25 10:37:12 -07:00
refspec.c fetch: free "raw" string when shrinking refspec 2024-09-25 10:24:54 -07:00
refspec.h fetch: free "raw" string when shrinking refspec 2024-09-25 10:24:54 -07:00
remote-curl.c remote-curl: free HEAD ref with free_one_ref() 2024-09-25 10:24:56 -07:00
remote.c Merge branch 'xx/remote-server-option-config' 2024-10-15 16:56:43 -04:00
remote.h Merge branch 'xx/remote-server-option-config' 2024-10-15 16:56:43 -04:00
replace-object.c refs: add referent to each_ref_fn 2024-08-09 08:47:34 -07:00
replace-object.h
repo-settings.c environment: stop storing "core.warnAmbiguousRefs" globally 2024-09-12 10:15:44 -07:00
repo-settings.h environment: stop storing "core.warnAmbiguousRefs" globally 2024-09-12 10:15:44 -07:00
repository.c Merge branch 'ps/environ-wo-the-repository' 2024-09-23 10:35:05 -07:00
repository.h repo-settings: split out declarations into a standalone header 2024-09-12 10:15:42 -07:00
rerere.c Merge branch 'ps/config-wo-the-repository' 2024-08-23 09:02:34 -07:00
rerere.h
reset.c hooks: remove implicit dependency on `the_repository` 2024-08-13 10:01:01 -07:00
reset.h hash-ll: merge with "hash.h" 2024-06-14 10:26:33 -07:00
resolve-undo.c global: introduce `USE_THE_REPOSITORY_VARIABLE` macro 2024-06-14 10:26:33 -07:00
resolve-undo.h hash-ll: merge with "hash.h" 2024-06-14 10:26:33 -07:00
revision.c revision: fix leaking saved parents 2024-09-30 11:23:07 -07:00
revision.h revision: fix a typo 2024-09-19 13:46:12 -07:00
run-command.c run-command: fix detaching when running auto maintenance 2024-08-16 09:46:26 -07:00
run-command.h run-command: fix a typo 2024-09-19 13:46:12 -07:00
sane-ctype.h
scalar.c Merge branch 'ps/leakfixes-part-8' 2024-10-10 14:22:29 -07:00
send-pack.c Merge branch 'ps/leakfixes-part-6' 2024-09-20 11:16:30 -07:00
send-pack.h
sequencer.c rebase-merges: try and use branch names as labels 2024-10-09 10:52:46 -07:00
sequencer.h Merge branch 'pw/rebase-i-error-message' into maint-2.45 2024-07-02 09:27:56 -07:00
serve.c drop trailing newline from warning/error/die messages 2024-09-05 09:07:12 -07:00
serve.h
server-info.c environment: make `get_object_directory()` accept a repository 2024-09-12 10:15:39 -07:00
server-info.h
setup.c worktree: link worktrees with relative paths 2024-10-08 11:49:22 -07:00
setup.h environment: move `set_git_dir()` and related into setup layer 2024-09-12 10:15:41 -07:00
sh-i18n--envsubst.c
sha1dc_git.c
sha1dc_git.h sha1: do not redefine `platform_SHA_CTX` and friends 2024-09-27 11:27:47 -07:00
shallow.c shallow: fix leak when unregistering last shallow root 2024-09-25 10:24:52 -07:00
shallow.h
shared.mak
shell.c shell: fix leaking strings 2024-09-30 11:23:03 -07:00
shortlog.h
sideband.c Merge branch 'ak/typofix-2.46-maint' 2024-09-25 10:37:12 -07:00
sideband.h
sigchain.c
sigchain.h
simple-ipc.h simple-ipc: split async server initialization and running 2024-10-08 12:03:56 -07:00
sparse-index.c Merge branch 'ds/sparse-checkout-expansion-advice' 2024-10-02 07:46:25 -07:00
sparse-index.h sparse-checkout: disable advice in 'disable' 2024-09-23 13:19:01 -07:00
split-index.c global: introduce `USE_THE_REPOSITORY_VARIABLE` macro 2024-06-14 10:26:33 -07:00
split-index.h hash-ll: merge with "hash.h" 2024-06-14 10:26:33 -07:00
stable-qsort.c
statinfo.c environment: guard state depending on a repository 2024-09-12 10:15:42 -07:00
statinfo.h
strbuf.c Merge branch 'gt/t-hash-unit-test' 2024-06-12 13:37:15 -07:00
strbuf.h strbuf: introduce strbuf_addstrings() to repeatedly add a string 2024-05-29 09:09:39 -07:00
streaming.c global: introduce `USE_THE_REPOSITORY_VARIABLE` macro 2024-06-14 10:26:33 -07:00
streaming.h
string-list.c
string-list.h
strmap.c
strmap.h
strvec.c strvec: declare the `strvec_push_nodup()` function globally 2024-07-13 16:23:36 -07:00
strvec.h strvec: declare the `strvec_push_nodup()` function globally 2024-07-13 16:23:36 -07:00
sub-process.c
sub-process.h
submodule-config.c submodule: fix leaking submodule entry list 2024-09-30 11:23:03 -07:00
submodule-config.h submodule: fix leaking submodule entry list 2024-09-30 11:23:03 -07:00
submodule.c Merge branch 'ps/leakfixes-part-7' 2024-10-02 07:46:26 -07:00
submodule.h submodule: fix leaking update strategy 2024-09-27 08:25:34 -07:00
symlinks.c
symlinks.h
tag.c global: introduce `USE_THE_REPOSITORY_VARIABLE` macro 2024-06-14 10:26:33 -07:00
tag.h refs: pass repo when peeling objects 2024-05-17 10:33:39 -07:00
tar.h
tempfile.c
tempfile.h
thread-utils.c
thread-utils.h
tmp-objdir.c Merge branch 'tb/weak-sha1-for-tail-sum' 2024-10-02 07:46:27 -07:00
tmp-objdir.h
trace.c environment: make `get_git_work_tree()` accept a repository 2024-09-12 10:15:40 -07:00
trace.h
trace2.c
trace2.h refs/reftable: wire up support for exclude patterns 2024-09-16 13:57:19 -07:00
trailer.c global: prepare for hiding away repo-less config functions 2024-08-13 10:01:05 -07:00
trailer.h Merge branch 'la/hide-trailer-info' 2024-05-23 11:04:27 -07:00
transport-helper.c transport-helper: fix leak of dummy refs_list 2024-09-25 10:24:54 -07:00
transport-internal.h
transport.c transport.c:🤝 make use of server options from remote 2024-10-08 10:22:08 -07:00
transport.h transport: introduce parse_transport_option() method 2024-10-08 10:22:06 -07:00
tree-diff.c environment: guard state depending on a repository 2024-09-12 10:15:42 -07:00
tree-walk.c global: introduce `USE_THE_REPOSITORY_VARIABLE` macro 2024-06-14 10:26:33 -07:00
tree-walk.h hash-ll: merge with "hash.h" 2024-06-14 10:26:33 -07:00
tree.c global: introduce `USE_THE_REPOSITORY_VARIABLE` macro 2024-06-14 10:26:33 -07:00
tree.h
unicode-width.h unicode: update the width tables to Unicode 16 2024-09-12 14:20:44 -07:00
unimplemented.sh
unix-socket.c
unix-socket.h
unix-stream-server.c
unix-stream-server.h
unpack-trees.c unpack-trees: detect mismatching number of cache-tree/index entries 2024-10-07 15:08:11 -07:00
unpack-trees.h
upload-pack.c Merge branch 'ak/typofix-2.46-maint' 2024-09-25 10:37:12 -07:00
upload-pack.h
url.c
url.h
urlmatch.c
urlmatch.h
usage.c usage: report vsnprintf(3) failure 2024-04-05 15:16:27 -07:00
userdiff.c environment: guard state depending on a repository 2024-09-12 10:15:42 -07:00
userdiff.h userdiff: fix leaking memory for configured diff drivers 2024-08-14 10:08:01 -07:00
utf8.c
utf8.h utf8.h: squelch unused-parameter warnings with NO_ICONV 2024-10-02 15:52:48 -07:00
varint.c
varint.h
version.c
version.h
versioncmp.c global: prepare for hiding away repo-less config functions 2024-08-13 10:01:05 -07:00
versioncmp.h
walker.c refs: add referent to each_ref_fn 2024-08-09 08:47:34 -07:00
walker.h
wildmatch.c
wildmatch.h
worktree.c worktree: link worktrees with relative paths 2024-10-08 11:49:22 -07:00
worktree.h worktree: link worktrees with relative paths 2024-10-08 11:49:22 -07:00
wrap-for-bin.sh
wrapper.c don't report vsnprintf(3) error as bug 2024-04-21 12:27:07 -07:00
wrapper.h wrapper: introduce `log2u()` 2024-09-04 08:03:24 -07:00
write-or-die.c
write-or-die.h
ws.c
ws.h
wt-status.c wt-status: fix leaking buffer with sparse directories 2024-09-30 11:23:03 -07:00
wt-status.h status: unify parsing of --untracked= and status.showUntrackedFiles 2024-03-13 10:43:32 -07:00
xdiff-interface.c global: introduce `USE_THE_REPOSITORY_VARIABLE` macro 2024-06-14 10:26:33 -07:00
xdiff-interface.h hash-ll: merge with "hash.h" 2024-06-14 10:26:33 -07:00

README.md

Build status

Git - fast, scalable, distributed revision control system

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals.

Git is an Open Source project covered by the GNU General Public License version 2 (some parts of it are under different licenses, compatible with the GPLv2). It was originally written by Linus Torvalds with help of a group of hackers around the net.

Please read the file INSTALL for installation instructions.

Many Git online resources are accessible from https://git-scm.com/ including full documentation and Git related tools.

See Documentation/gittutorial.txt to get started, then see Documentation/giteveryday.txt for a useful minimum set of commands, and Documentation/git-<commandname>.txt for documentation of each command. If git has been correctly installed, then the tutorial can also be read with man gittutorial or git help tutorial, and the documentation of each command with man git-<commandname> or git help <commandname>.

CVS users may also want to read Documentation/gitcvs-migration.txt (man gitcvs-migration or git help cvs-migration if git is installed).

The user discussion and development of Git take place on the Git mailing list -- everyone is welcome to post bug reports, feature requests, comments and patches to git@vger.kernel.org (read Documentation/SubmittingPatches for instructions on patch submission and Documentation/CodingGuidelines).

Those wishing to help with error message, usage and informational message string translations (localization l10) should see po/README.md (a po file is a Portable Object file that holds the translations).

To subscribe to the list, send an email to git+subscribe@vger.kernel.org (see https://subspace.kernel.org/subscribing.html for details). The mailing list archives are available at https://lore.kernel.org/git/, https://marc.info/?l=git and other archival sites.

Issues which are security relevant should be disclosed privately to the Git Security mailing list git-security@googlegroups.com.

The maintainer frequently sends the "What's cooking" reports that list the current status of various development topics to the mailing list. The discussion following them give a good reference for project status, development direction and remaining tasks.

The name "git" was given by Linus Torvalds when he wrote the very first version. He described the tool as "the stupid content tracker" and the name as (depending on your mood):

  • random three-letter combination that is pronounceable, and not actually used by any common UNIX command. The fact that it is a mispronunciation of "get" may or may not be relevant.
  • stupid. contemptible and despicable. simple. Take your pick from the dictionary of slang.
  • "global information tracker": you're in a good mood, and it actually works for you. Angels sing, and a light suddenly fills the room.
  • "goddamn idiotic truckload of sh*t": when it breaks