pack.c 26.5 KB
Newer Older
1
/*
Edward Thomson committed
2
 * Copyright (C) the libgit2 contributors. All rights reserved.
3
 *
Vicent Marti committed
4 5
 * This file is part of libgit2, distributed under the GNU GPL v2 with
 * a Linking Exception. For full terms see the included COPYING file.
6 7
 */

8
#include "common.h"
9 10 11
#include "odb.h"
#include "pack.h"
#include "delta-apply.h"
12
#include "sha1_lookup.h"
13 14
#include "mwindow.h"
#include "fileops.h"
15 16

#include "git2/oid.h"
17
#include <zlib.h>
18

19
static int packfile_open(struct git_pack_file *p);
20
static git_off_t nth_packed_object_offset(const struct git_pack_file *p, uint32_t n);
21 22 23 24
int packfile_unpack_compressed(
		git_rawobj *obj,
		struct git_pack_file *p,
		git_mwindow **w_curs,
25
		git_off_t *curpos,
26 27 28 29 30
		size_t size,
		git_otype type);

/* Can find the offset of an object given
 * a prefix of an identifier.
31
 * Throws GIT_EAMBIGUOUSOIDPREFIX if short oid
32 33 34 35 36
 * is ambiguous within the pack.
 * This method assumes that len is between
 * GIT_OID_MINPREFIXLEN and GIT_OID_HEXSZ.
 */
static int pack_entry_find_offset(
37
		git_off_t *offset_out,
38 39 40
		git_oid *found_oid,
		struct git_pack_file *p,
		const git_oid *short_oid,
41
		size_t len);
42

43 44 45 46 47 48
static int packfile_error(const char *message)
{
	giterr_set(GITERR_ODB, "Invalid pack file - %s", message);
	return -1;
}

49 50 51
/********************
 * Delta base cache
 ********************/
52

53
static git_pack_cache_entry *new_cache_object(git_rawobj *source)
54
{
55
	git_pack_cache_entry *e = git__calloc(1, sizeof(git_pack_cache_entry));
56 57 58 59 60 61 62 63 64 65 66 67 68
	if (!e)
		return NULL;

	memcpy(&e->raw, source, sizeof(git_rawobj));

	return e;
}

static void free_cache_object(void *o)
{
	git_pack_cache_entry *e = (git_pack_cache_entry *)o;

	if (e != NULL) {
69
		assert(e->refcount.val == 0);
70 71 72 73 74
		git__free(e->raw.data);
		git__free(e);
	}
}

75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99
static void cache_free(git_pack_cache *cache)
{
	khiter_t k;

	if (cache->entries) {
		for (k = kh_begin(cache->entries); k != kh_end(cache->entries); k++) {
			if (kh_exist(cache->entries, k))
				free_cache_object(kh_value(cache->entries, k));
		}

		git_offmap_free(cache->entries);
	}
}

static int cache_init(git_pack_cache *cache)
{
	memset(cache, 0, sizeof(git_pack_cache));
	cache->entries = git_offmap_alloc();
	GITERR_CHECK_ALLOC(cache->entries);
	cache->memory_limit = GIT_PACK_CACHE_MEMORY_LIMIT;
	git_mutex_init(&cache->lock);

	return 0;
}

100
static git_pack_cache_entry *cache_get(git_pack_cache *cache, git_off_t offset)
101 102 103 104
{
	khiter_t k;
	git_pack_cache_entry *entry = NULL;

105 106 107
	if (git_mutex_lock(&cache->lock) < 0)
		return NULL;

108 109 110 111
	k = kh_get(off, cache->entries, offset);
	if (k != kh_end(cache->entries)) { /* found it */
		entry = kh_value(cache->entries, k);
		git_atomic_inc(&entry->refcount);
112
		entry->last_usage = cache->use_ctr++;
113 114 115 116 117 118
	}
	git_mutex_unlock(&cache->lock);

	return entry;
}

119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143
/* Run with the cache lock held */
static void free_lowest_entry(git_pack_cache *cache)
{
	git_pack_cache_entry *lowest = NULL, *entry;
	khiter_t k, lowest_k;

	for (k = kh_begin(cache->entries); k != kh_end(cache->entries); k++) {
		if (!kh_exist(cache->entries, k))
			continue;

		entry = kh_value(cache->entries, k);
		if (lowest == NULL || entry->last_usage < lowest->last_usage) {
			lowest_k = k;
			lowest = entry;
		}
	}

	if (!lowest) /* there's nothing to free */
		return;

	cache->memory_used -= lowest->raw.len;
	kh_del(off, cache->entries, lowest_k);
	free_cache_object(lowest);
}

144 145 146 147 148 149
static int cache_add(git_pack_cache *cache, git_rawobj *base, git_off_t offset)
{
	git_pack_cache_entry *entry;
	int error, exists = 0;
	khiter_t k;

150 151 152
	if (base->len > GIT_PACK_CACHE_SIZE_LIMIT)
		return -1;

153 154
	entry = new_cache_object(base);
	if (entry) {
155 156 157 158
		if (git_mutex_lock(&cache->lock) < 0) {
			giterr_set(GITERR_OS, "failed to lock cache");
			return -1;
		}
159 160 161
		/* Add it to the cache if nobody else has */
		exists = kh_get(off, cache->entries, offset) != kh_end(cache->entries);
		if (!exists) {
162 163 164
			while (cache->memory_used + base->len > cache->memory_limit)
				free_lowest_entry(cache);

165 166 167
			k = kh_put(off, cache->entries, offset, &error);
			assert(error != 0);
			kh_value(cache->entries, k) = entry;
168
			cache->memory_used += entry->raw.len;
169 170 171 172 173 174 175 176 177 178 179 180
		}
		git_mutex_unlock(&cache->lock);
		/* Somebody beat us to adding it into the cache */
		if (exists) {
			git__free(entry);
			return -1;
		}
	}

	return 0;
}

181 182 183 184 185 186 187 188
/***********************************************************
 *
 * PACK INDEX METHODS
 *
 ***********************************************************/

static void pack_index_free(struct git_pack_file *p)
{
189 190 191 192
	if (p->oids) {
		git__free(p->oids);
		p->oids = NULL;
	}
193 194 195 196 197 198
	if (p->index_map.data) {
		git_futils_mmap_free(&p->index_map);
		p->index_map.data = NULL;
	}
}

Vicent Marti committed
199
static int pack_index_check(const char *path, struct git_pack_file *p)
200 201 202 203 204 205 206
{
	struct git_pack_idx_header *hdr;
	uint32_t version, nr, i, *index;
	void *idx_map;
	size_t idx_size;
	struct stat st;
	int error;
207 208
	/* TODO: properly open the file without access time using O_NOATIME */
	git_file fd = git_futils_open_ro(path);
209
	if (fd < 0)
210
		return fd;
211

212 213 214 215 216
	if (p_fstat(fd, &st) < 0 ||
		!S_ISREG(st.st_mode) ||
		!git__is_sizet(st.st_size) ||
		(idx_size = (size_t)st.st_size) < 4 * 256 + 20 + 20)
	{
217
		p_close(fd);
218 219
		giterr_set(GITERR_OS, "Failed to check pack index.");
		return -1;
220 221 222
	}

	error = git_futils_mmap_ro(&p->index_map, fd, 0, idx_size);
223

224 225
	p_close(fd);

226 227
	if (error < 0)
		return error;
228 229 230 231 232 233 234 235

	hdr = idx_map = p->index_map.data;

	if (hdr->idx_signature == htonl(PACK_IDX_SIGNATURE)) {
		version = ntohl(hdr->idx_version);

		if (version < 2 || version > 2) {
			git_futils_mmap_free(&p->index_map);
236
			return packfile_error("unsupported index version");
237 238 239 240 241 242 243 244 245
		}

	} else
		version = 1;

	nr = 0;
	index = idx_map;

	if (version > 1)
Vicent Marti committed
246
		index += 2; /* skip index header */
247 248 249 250 251

	for (i = 0; i < 256; i++) {
		uint32_t n = ntohl(index[i]);
		if (n < nr) {
			git_futils_mmap_free(&p->index_map);
252
			return packfile_error("index is non-monotonic");
253 254 255 256 257 258 259
		}
		nr = n;
	}

	if (version == 1) {
		/*
		 * Total size:
Vicent Marti committed
260 261 262 263
		 * - 256 index entries 4 bytes each
		 * - 24-byte entries * nr (20-byte sha1 + 4-byte offset)
		 * - 20-byte SHA1 of the packfile
		 * - 20-byte SHA1 file checksum
264 265 266
		 */
		if (idx_size != 4*256 + nr * 24 + 20 + 20) {
			git_futils_mmap_free(&p->index_map);
267
			return packfile_error("index is corrupted");
268 269 270 271
		}
	} else if (version == 2) {
		/*
		 * Minimum size:
Vicent Marti committed
272 273 274 275 276 277 278
		 * - 8 bytes of header
		 * - 256 index entries 4 bytes each
		 * - 20-byte sha1 entry * nr
		 * - 4-byte crc entry * nr
		 * - 4-byte offset entry * nr
		 * - 20-byte SHA1 of the packfile
		 * - 20-byte SHA1 file checksum
279 280 281 282 283 284 285 286 287 288 289 290
		 * And after the 4-byte offset table might be a
		 * variable sized table containing 8-byte entries
		 * for offsets larger than 2^31.
		 */
		unsigned long min_size = 8 + 4*256 + nr*(20 + 4 + 4) + 20 + 20;
		unsigned long max_size = min_size;

		if (nr)
			max_size += (nr - 1)*8;

		if (idx_size < min_size || idx_size > max_size) {
			git_futils_mmap_free(&p->index_map);
291
			return packfile_error("wrong index size");
292 293 294 295 296
		}
	}

	p->index_version = version;
	p->num_objects = nr;
297
	return 0;
298 299 300 301 302 303
}

static int pack_index_open(struct git_pack_file *p)
{
	char *idx_name;
	int error;
304
	size_t name_len, offset;
305 306

	if (p->index_map.data)
307
		return 0;
308 309

	idx_name = git__strdup(p->pack_name);
310 311
	GITERR_CHECK_ALLOC(idx_name);

312 313 314 315 316
	name_len = strlen(idx_name);
	offset = name_len - strlen(".pack");
	assert(offset < name_len); /* make sure no underflow */

	strncpy(idx_name + offset, ".idx", name_len - offset);
317 318

	error = pack_index_check(idx_name, p);
319
	git__free(idx_name);
320

321
	return error;
322 323 324 325
}

static unsigned char *pack_window_open(
		struct git_pack_file *p,
326
		git_mwindow **w_cursor,
327
		git_off_t offset,
328 329
		unsigned int *left)
{
330
	if (p->mwf.fd == -1 && packfile_open(p) < 0)
331 332 333 334 335 336 337 338 339 340 341 342 343
		return NULL;

	/* Since packfiles end in a hash of their content and it's
	 * pointless to ask for an offset into the middle of that
	 * hash, and the pack_window_contains function above wouldn't match
	 * don't allow an offset too close to the end of the file.
	 */
	if (offset > (p->mwf.size - 20))
		return NULL;

	return git_mwindow_open(&p->mwf, w_cursor, offset, 20, left);
 }

344 345
static int packfile_unpack_header1(
		unsigned long *usedp,
346 347 348 349 350 351 352 353
		size_t *sizep,
		git_otype *type,
		const unsigned char *buf,
		unsigned long len)
{
	unsigned shift;
	unsigned long size, c;
	unsigned long used = 0;
354

355 356 357 358 359
	c = buf[used++];
	*type = (c >> 4) & 7;
	size = c & 15;
	shift = 4;
	while (c & 0x80) {
360
		if (len <= used)
361
			return GIT_EBUFS;
362 363 364 365 366

		if (bitsizeof(long) <= shift) {
			*usedp = 0;
			return -1;
		}
367 368 369 370 371 372 373

		c = buf[used++];
		size += (c & 0x7f) << shift;
		shift += 7;
	}

	*sizep = (size_t)size;
374 375
	*usedp = used;
	return 0;
376 377 378 379 380 381 382
}

int git_packfile_unpack_header(
		size_t *size_p,
		git_otype *type_p,
		git_mwindow_file *mwf,
		git_mwindow **w_curs,
383
		git_off_t *curpos)
384 385 386 387
{
	unsigned char *base;
	unsigned int left;
	unsigned long used;
388
	int ret;
389 390

	/* pack_window_open() assures us we have [base, base + 20) available
Vicent Marti committed
391 392
	 * as a range that we can look at at. (Its actually the hash
	 * size that is assured.) With our object header encoding
393 394 395 396 397 398
	 * the maximum deflated object size is 2^137, which is just
	 * insane, so we know won't exceed what we have been given.
	 */
//	base = pack_window_open(p, w_curs, *curpos, &left);
	base = git_mwindow_open(mwf, w_curs, *curpos, 20, &left);
	if (base == NULL)
399
		return GIT_EBUFS;
400 401

		ret = packfile_unpack_header1(&used, size_p, type_p, base, left);
402
	git_mwindow_close(w_curs);
403
	if (ret == GIT_EBUFS)
404 405
		return ret;
	else if (ret < 0)
406
		return packfile_error("header length is zero");
407 408

	*curpos += used;
409
	return 0;
410 411
}

412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461
int git_packfile_resolve_header(
		size_t *size_p,
		git_otype *type_p,
		struct git_pack_file *p,
		git_off_t offset)
{
	git_mwindow *w_curs = NULL;
	git_off_t curpos = offset;
	size_t size;
	git_otype type;
	git_off_t base_offset;
	int error;

	error = git_packfile_unpack_header(&size, &type, &p->mwf, &w_curs, &curpos);
	git_mwindow_close(&w_curs);
	if (error < 0)
		return error;

	if (type == GIT_OBJ_OFS_DELTA || type == GIT_OBJ_REF_DELTA) {
		size_t base_size;
		git_rawobj delta;
		base_offset = get_delta_base(p, &w_curs, &curpos, type, offset);
		git_mwindow_close(&w_curs);
		error = packfile_unpack_compressed(&delta, p, &w_curs, &curpos, size, type);
		git_mwindow_close(&w_curs);
		if (error < 0)
			return error;
		error = git__delta_read_header(delta.data, delta.len, &base_size, size_p);
		git__free(delta.data);
		if (error < 0)
			return error;
	} else
		*size_p = size;

	while (type == GIT_OBJ_OFS_DELTA || type == GIT_OBJ_REF_DELTA) {
		curpos = base_offset;
		error = git_packfile_unpack_header(&size, &type, &p->mwf, &w_curs, &curpos);
		git_mwindow_close(&w_curs);
		if (error < 0)
			return error;
		if (type != GIT_OBJ_OFS_DELTA && type != GIT_OBJ_REF_DELTA)
			break;
		base_offset = get_delta_base(p, &w_curs, &curpos, type, base_offset);
		git_mwindow_close(&w_curs);
	}
	*type_p = type;

	return error;
}

462
static int packfile_unpack_delta(
463
		git_rawobj *obj,
464
		struct git_pack_file *p,
465
		git_mwindow **w_curs,
466
		git_off_t *curpos,
467 468
		size_t delta_size,
		git_otype delta_type,
469
		git_off_t obj_offset)
470
{
471
	git_off_t base_offset, base_key;
472
	git_rawobj base, delta;
473
	git_pack_cache_entry *cached = NULL;
474
	int error, found_base = 0;
475

476
	base_offset = get_delta_base(p, w_curs, curpos, delta_type, obj_offset);
477
	git_mwindow_close(w_curs);
478
	if (base_offset == 0)
479 480 481
		return packfile_error("delta offset is zero");
	if (base_offset < 0) /* must actually be an error code */
		return (int)base_offset;
482

483 484
	if (!p->bases.entries && (cache_init(&p->bases) < 0))
		return -1;
485

486
	base_key = base_offset; /* git_packfile_unpack modifies base_offset */
487
	if ((cached = cache_get(&p->bases, base_offset)) != NULL) {
488
		memcpy(&base, &cached->raw, sizeof(git_rawobj));
489
		found_base = 1;
490 491 492
	}

	if (!cached) { /* have to inflate it */
493 494 495 496 497 498 499 500 501 502 503
		error = git_packfile_unpack(&base, p, &base_offset);

		/*
		 * TODO: git.git tries to load the base from other packfiles
		 * or loose objects.
		 *
		 * We'll need to do this in order to support thin packs.
		 */
		if (error < 0)
			return error;
	}
504 505

	error = packfile_unpack_compressed(&delta, p, w_curs, curpos, delta_size, delta_type);
506
	git_mwindow_close(w_curs);
507

508
	if (error < 0) {
509 510
		if (!found_base)
			git__free(base.data);
511
		return error;
512 513 514
	}

	obj->type = base.type;
515
	error = git__delta_apply(obj, base.data, base.len, delta.data, delta.len);
516 517 518
	if (error < 0)
		goto on_error;

519
	if (found_base)
520
		git_atomic_dec(&cached->refcount);
521 522
	else if (cache_add(&p->bases, &base, base_key) < 0)
		git__free(base.data);
523

524
on_error:
525
	git__free(delta.data);
526 527 528 529

	return error; /* error set by git__delta_apply */
}

530
int git_packfile_unpack(
531 532 533
	git_rawobj *obj,
	struct git_pack_file *p,
	git_off_t *obj_offset)
534 535
{
	git_mwindow *w_curs = NULL;
536
	git_off_t curpos = *obj_offset;
537 538 539 540 541 542 543 544 545 546 547 548 549 550
	int error;

	size_t size = 0;
	git_otype type;

	/*
	 * TODO: optionally check the CRC on the packfile
	 */

	obj->data = NULL;
	obj->len = 0;
	obj->type = GIT_OBJ_BAD;

	error = git_packfile_unpack_header(&size, &type, &p->mwf, &w_curs, &curpos);
551 552
	git_mwindow_close(&w_curs);

553 554
	if (error < 0)
		return error;
555 556 557 558 559

	switch (type) {
	case GIT_OBJ_OFS_DELTA:
	case GIT_OBJ_REF_DELTA:
		error = packfile_unpack_delta(
560 561
				obj, p, &w_curs, &curpos,
				size, type, *obj_offset);
562 563 564 565 566 567 568
		break;

	case GIT_OBJ_COMMIT:
	case GIT_OBJ_TREE:
	case GIT_OBJ_BLOB:
	case GIT_OBJ_TAG:
		error = packfile_unpack_compressed(
569
				obj, p, &w_curs, &curpos,
570 571 572 573
				size, type);
		break;

	default:
574
		error = packfile_error("invalid packfile type in header");;
575 576 577
		break;
	}

578
	*obj_offset = curpos;
579
	return error;
580 581
}

Russell Belfer committed
582 583 584 585 586 587 588 589 590 591 592 593
static void *use_git_alloc(void *opaq, unsigned int count, unsigned int size)
{
	GIT_UNUSED(opaq);
	return git__calloc(count, size);
}

static void use_git_free(void *opaq, void *ptr)
{
	GIT_UNUSED(opaq);
	git__free(ptr);
}

594 595 596 597 598 599 600 601 602 603 604 605 606 607 608 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628
int git_packfile_stream_open(git_packfile_stream *obj, struct git_pack_file *p, git_off_t curpos)
{
	int st;

	memset(obj, 0, sizeof(git_packfile_stream));
	obj->curpos = curpos;
	obj->p = p;
	obj->zstream.zalloc = use_git_alloc;
	obj->zstream.zfree = use_git_free;
	obj->zstream.next_in = Z_NULL;
	obj->zstream.next_out = Z_NULL;
	st = inflateInit(&obj->zstream);
	if (st != Z_OK) {
		git__free(obj);
		giterr_set(GITERR_ZLIB, "Failed to inflate packfile");
		return -1;
	}

	return 0;
}

ssize_t git_packfile_stream_read(git_packfile_stream *obj, void *buffer, size_t len)
{
	unsigned char *in;
	size_t written;
	int st;

	if (obj->done)
		return 0;

	in = pack_window_open(obj->p, &obj->mw, obj->curpos, &obj->zstream.avail_in);
	if (in == NULL)
		return GIT_EBUFS;

	obj->zstream.next_out = buffer;
629
	obj->zstream.avail_out = (unsigned int)len;
630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 651 652 653 654 655 656 657 658 659
	obj->zstream.next_in = in;

	st = inflate(&obj->zstream, Z_SYNC_FLUSH);
	git_mwindow_close(&obj->mw);

	obj->curpos += obj->zstream.next_in - in;
	written = len - obj->zstream.avail_out;

	if (st != Z_OK && st != Z_STREAM_END) {
		giterr_set(GITERR_ZLIB, "Failed to inflate packfile");
		return -1;
	}

	if (st == Z_STREAM_END)
		obj->done = 1;


	/* If we didn't write anything out but we're not done, we need more data */
	if (!written && st != Z_STREAM_END)
		return GIT_EBUFS;

	return written;

}

void git_packfile_stream_free(git_packfile_stream *obj)
{
	inflateEnd(&obj->zstream);
}

660
int packfile_unpack_compressed(
661 662 663 664 665 666
	git_rawobj *obj,
	struct git_pack_file *p,
	git_mwindow **w_curs,
	git_off_t *curpos,
	size_t size,
	git_otype type)
667 668 669 670 671
{
	int st;
	z_stream stream;
	unsigned char *buffer, *in;

672 673
	buffer = git__calloc(1, size + 1);
	GITERR_CHECK_ALLOC(buffer);
674 675 676

	memset(&stream, 0, sizeof(stream));
	stream.next_out = buffer;
677
	stream.avail_out = (uInt)size + 1;
Russell Belfer committed
678 679
	stream.zalloc = use_git_alloc;
	stream.zfree = use_git_free;
680 681 682

	st = inflateInit(&stream);
	if (st != Z_OK) {
683
		git__free(buffer);
684
		giterr_set(GITERR_ZLIB, "Failed to inflate packfile");
685

686
		return -1;
687 688 689
	}

	do {
690
		in = pack_window_open(p, w_curs, *curpos, &stream.avail_in);
691 692
		stream.next_in = in;
		st = inflate(&stream, Z_FINISH);
693
		git_mwindow_close(w_curs);
694 695 696 697

		if (!stream.avail_out)
			break; /* the payload is larger than it should be */

698 699 700
		if (st == Z_BUF_ERROR && in == NULL) {
			inflateEnd(&stream);
			git__free(buffer);
701
			return GIT_EBUFS;
702 703
		}

704
		*curpos += stream.next_in - in;
705 706 707 708 709
	} while (st == Z_OK || st == Z_BUF_ERROR);

	inflateEnd(&stream);

	if ((st != Z_STREAM_END) || stream.total_out != size) {
710
		git__free(buffer);
711 712
		giterr_set(GITERR_ZLIB, "Failed to inflate packfile");
		return -1;
713 714 715 716 717
	}

	obj->type = type;
	obj->len = size;
	obj->data = buffer;
718
	return 0;
719 720
}

721 722 723 724
/*
 * curpos is where the data starts, delta_obj_offset is the where the
 * header starts
 */
725 726 727 728 729 730
git_off_t get_delta_base(
	struct git_pack_file *p,
	git_mwindow **w_curs,
	git_off_t *curpos,
	git_otype type,
	git_off_t delta_obj_offset)
731
{
732 733
	unsigned int left = 0;
	unsigned char *base_info;
734
	git_off_t base_offset;
735 736
	git_oid unused;

737 738 739
	base_info = pack_window_open(p, w_curs, *curpos, &left);
	/* Assumption: the only reason this would fail is because the file is too small */
	if (base_info == NULL)
740
		return GIT_EBUFS;
741 742
	/* pack_window_open() assured us we have [base_info, base_info + 20)
	 * as a range that we can look at without walking off the
Vicent Marti committed
743 744
	 * end of the mapped window. Its actually the hash size
	 * that is assured. An OFS_DELTA longer than the hash size
745 746 747 748 749 750 751
	 * is stupid, as then a REF_DELTA would be smaller to store.
	 */
	if (type == GIT_OBJ_OFS_DELTA) {
		unsigned used = 0;
		unsigned char c = base_info[used++];
		base_offset = c & 127;
		while (c & 128) {
752
			if (left <= used)
753
				return GIT_EBUFS;
754 755
			base_offset += 1;
			if (!base_offset || MSB(base_offset, 7))
Vicent Marti committed
756
				return 0; /* overflow */
757 758 759 760 761
			c = base_info[used++];
			base_offset = (base_offset << 7) + (c & 127);
		}
		base_offset = delta_obj_offset - base_offset;
		if (base_offset <= 0 || base_offset >= delta_obj_offset)
Vicent Marti committed
762
			return 0; /* out of bound */
763 764
		*curpos += used;
	} else if (type == GIT_OBJ_REF_DELTA) {
765 766 767 768 769 770 771 772 773 774 775 776
		/* If we have the cooperative cache, search in it first */
		if (p->has_cache) {
			int pos;
			struct git_pack_entry key;

			git_oid_fromraw(&key.sha1, base_info);
			pos = git_vector_bsearch(&p->cache, &key);
			if (pos >= 0) {
				*curpos += 20;
				return ((struct git_pack_entry *)git_vector_get(&p->cache, pos))->offset;
			}
		}
777
		/* The base entry _must_ be in the same pack */
778 779
		if (pack_entry_find_offset(&base_offset, &unused, p, (git_oid *)base_info, GIT_OID_HEXSZ) < 0)
			return packfile_error("base entry delta is not in the same pack");
780 781 782 783 784 785
		*curpos += 20;
	} else
		return 0;

	return base_offset;
}
786 787 788 789 790 791 792

/***********************************************************
 *
 * PACKFILE METHODS
 *
 ***********************************************************/

793
static struct git_pack_file *packfile_alloc(size_t extra)
794
{
795 796 797
	struct git_pack_file *p = git__calloc(1, sizeof(*p) + extra);
	if (p != NULL)
		p->mwf.fd = -1;
798 799 800 801
	return p;
}


802
void git_packfile_free(struct git_pack_file *p)
803 804 805
{
	assert(p);

806
	cache_free(&p->bases);
807

808
	git_mwindow_free_all(&p->mwf);
809
	git_mwindow_file_deregister(&p->mwf);
810 811 812 813 814 815

	if (p->mwf.fd != -1)
		p_close(p->mwf.fd);

	pack_index_free(p);

816 817
	git__free(p->bad_object_sha1);
	git__free(p);
818 819 820 821 822 823 824 825 826
}

static int packfile_open(struct git_pack_file *p)
{
	struct stat st;
	struct git_pack_header hdr;
	git_oid sha1;
	unsigned char *idx_sha1;

827 828
	assert(p->index_map.data);

829
	if (!p->index_map.data && pack_index_open(p) < 0)
Russell Belfer committed
830
		return git_odb__error_notfound("failed to open packfile", NULL);
831 832

	/* TODO: open with noatime */
833
	p->mwf.fd = git_futils_open_ro(p->pack_name);
834 835 836 837
	if (p->mwf.fd < 0) {
		p->mwf.fd = -1;
		return -1;
	}
838

839 840 841
	if (p_fstat(p->mwf.fd, &st) < 0 ||
		git_mwindow_file_register(&p->mwf) < 0)
		goto cleanup;
842 843 844 845 846

	/* If we created the struct before we had the pack we lack size. */
	if (!p->mwf.size) {
		if (!S_ISREG(st.st_mode))
			goto cleanup;
847
		p->mwf.size = (git_off_t)st.st_size;
848 849 850 851 852 853 854 855 856
	} else if (p->mwf.size != st.st_size)
		goto cleanup;

#if 0
	/* We leave these file descriptors open with sliding mmap;
	 * there is no point keeping them open across exec(), though.
	 */
	fd_flag = fcntl(p->mwf.fd, F_GETFD, 0);
	if (fd_flag < 0)
857
		goto cleanup;
858 859 860

	fd_flag |= FD_CLOEXEC;
	if (fcntl(p->pack_fd, F_SETFD, fd_flag) == -1)
861
		goto cleanup;
862 863 864
#endif

	/* Verify we recognize this pack file format. */
865 866 867
	if (p_read(p->mwf.fd, &hdr, sizeof(hdr)) < 0 ||
		hdr.hdr_signature != htonl(PACK_SIGNATURE) ||
		!pack_version_ok(hdr.hdr_version))
868 869 870
		goto cleanup;

	/* Verify the pack matches its index. */
871 872 873
	if (p->num_objects != ntohl(hdr.hdr_entries) ||
		p_lseek(p->mwf.fd, p->mwf.size - GIT_OID_RAWSZ, SEEK_SET) == -1 ||
		p_read(p->mwf.fd, sha1.id, GIT_OID_RAWSZ) < 0)
874 875 876 877
		goto cleanup;

	idx_sha1 = ((unsigned char *)p->index_map.data) + p->index_map.len - 40;

878 879
	if (git_oid_cmp(&sha1, (git_oid *)idx_sha1) == 0)
		return 0;
880 881

cleanup:
882
	giterr_set(GITERR_OS, "Invalid packfile '%s'", p->pack_name);
883 884
	p_close(p->mwf.fd);
	p->mwf.fd = -1;
885
	return -1;
886 887 888 889 890 891 892 893 894 895 896
}

int git_packfile_check(struct git_pack_file **pack_out, const char *path)
{
	struct stat st;
	struct git_pack_file *p;
	size_t path_len;

	*pack_out = NULL;
	path_len = strlen(path);
	p = packfile_alloc(path_len + 2);
897
	GITERR_CHECK_ALLOC(p);
898 899 900 901 902

	/*
	 * Make sure a corresponding .pack file exists and that
	 * the index looks sane.
	 */
903
	path_len -= strlen(".idx");
904
	if (path_len < 1) {
905
		git__free(p);
Russell Belfer committed
906
		return git_odb__error_notfound("invalid packfile path", NULL);
907 908 909 910 911
	}

	memcpy(p->pack_name, path, path_len);

	strcpy(p->pack_name + path_len, ".keep");
912
	if (git_path_exists(p->pack_name) == true)
913 914 915
		p->pack_keep = 1;

	strcpy(p->pack_name + path_len, ".pack");
916
	if (p_stat(p->pack_name, &st) < 0 || !S_ISREG(st.st_mode)) {
917
		git__free(p);
Russell Belfer committed
918
		return git_odb__error_notfound("packfile not found", NULL);
919 920 921 922 923
	}

	/* ok, it looks sane as far as we can check without
	 * actually mapping the pack file.
	 */
924
	p->mwf.size = st.st_size;
925 926 927 928 929
	p->pack_local = 1;
	p->mtime = (git_time_t)st.st_mtime;

	/* see if we can parse the sha1 oid in the packfile name */
	if (path_len < 40 ||
930
		git_oid_fromstr(&p->sha1, path + path_len - GIT_OID_HEXSZ) < 0)
931 932 933
		memset(&p->sha1, 0x0, GIT_OID_RAWSZ);

	*pack_out = p;
934 935

	return 0;
936 937 938 939 940 941 942 943
}

/***********************************************************
 *
 * PACKFILE ENTRY SEARCH INTERNALS
 *
 ***********************************************************/

944
static git_off_t nth_packed_object_offset(const struct git_pack_file *p, uint32_t n)
945 946 947 948 949 950 951 952 953 954 955 956 957
{
	const unsigned char *index = p->index_map.data;
	index += 4 * 256;
	if (p->index_version == 1) {
		return ntohl(*((uint32_t *)(index + 24 * n)));
	} else {
		uint32_t off;
		index += 8 + p->num_objects * (20 + 4);
		off = ntohl(*((uint32_t *)(index + 4 * n)));
		if (!(off & 0x80000000))
			return off;
		index += p->num_objects * 4 + (off & 0x7fffffff) * 8;
		return (((uint64_t)ntohl(*((uint32_t *)(index + 0)))) << 32) |
Vicent Marti committed
958
					ntohl(*((uint32_t *)(index + 4)));
959 960 961
	}
}

962 963 964 965
static int git__memcmp4(const void *a, const void *b) {
	return memcmp(a, b, 4);
}

966
int git_pack_foreach_entry(
967
	struct git_pack_file *p,
968
	git_odb_foreach_cb cb,
969
	void *data)
970 971 972 973 974 975 976 977 978 979 980 981 982 983 984 985 986 987 988 989 990
{
	const unsigned char *index = p->index_map.data, *current;
	uint32_t i;

	if (index == NULL) {
		int error;

		if ((error = pack_index_open(p)) < 0)
			return error;

		assert(p->index_map.data);

		index = p->index_map.data;
	}

	if (p->index_version > 1) {
		index += 8;
	}

	index += 4 * 256;

991 992 993
	if (p->oids == NULL) {
		git_vector offsets, oids;
		int error;
994

995 996 997 998 999
		if ((error = git_vector_init(&oids, p->num_objects, NULL)))
			return error;

		if ((error = git_vector_init(&offsets, p->num_objects, git__memcmp4)))
			return error;
1000

1001 1002 1003 1004 1005 1006 1007 1008 1009 1010 1011 1012 1013 1014 1015 1016
		if (p->index_version > 1) {
			const unsigned char *off = index + 24 * p->num_objects;
			for (i = 0; i < p->num_objects; i++)
				git_vector_insert(&offsets, (void*)&off[4 * i]);
			git_vector_sort(&offsets);
			git_vector_foreach(&offsets, i, current)
				git_vector_insert(&oids, (void*)&index[5 * (current - off)]);
		} else {
			for (i = 0; i < p->num_objects; i++)
				git_vector_insert(&offsets, (void*)&index[24 * i]);
			git_vector_sort(&offsets);
			git_vector_foreach(&offsets, i, current)
				git_vector_insert(&oids, (void*)&current[4]);
		}
		git_vector_free(&offsets);
		p->oids = (git_oid **)oids.contents;
1017 1018
	}

1019 1020 1021 1022
	for (i = 0; i < p->num_objects; i++)
		if (cb(p->oids[i], data))
			return GIT_EUSER;

1023 1024 1025
	return 0;
}

1026
static int pack_entry_find_offset(
1027 1028 1029 1030
	git_off_t *offset_out,
	git_oid *found_oid,
	struct git_pack_file *p,
	const git_oid *short_oid,
1031
	size_t len)
1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043
{
	const uint32_t *level1_ofs = p->index_map.data;
	const unsigned char *index = p->index_map.data;
	unsigned hi, lo, stride;
	int pos, found = 0;
	const unsigned char *current = 0;

	*offset_out = 0;

	if (index == NULL) {
		int error;

1044 1045
		if ((error = pack_index_open(p)) < 0)
			return error;
1046 1047 1048 1049 1050 1051 1052 1053 1054 1055 1056 1057 1058 1059 1060 1061 1062 1063 1064 1065 1066 1067 1068 1069 1070 1071 1072 1073 1074

		assert(p->index_map.data);

		index = p->index_map.data;
		level1_ofs = p->index_map.data;
	}

	if (p->index_version > 1) {
		level1_ofs += 2;
		index += 8;
	}

	index += 4 * 256;
	hi = ntohl(level1_ofs[(int)short_oid->id[0]]);
	lo = ((short_oid->id[0] == 0x0) ? 0 : ntohl(level1_ofs[(int)short_oid->id[0] - 1]));

	if (p->index_version > 1) {
		stride = 20;
	} else {
		stride = 24;
		index += 4;
	}

#ifdef INDEX_DEBUG_LOOKUP
	printf("%02x%02x%02x... lo %u hi %u nr %d\n",
		short_oid->id[0], short_oid->id[1], short_oid->id[2], lo, hi, p->num_objects);
#endif

	/* Use git.git lookup code */
Vicent Marti committed
1075
	pos = sha1_entry_pos(index, stride, 0, lo, hi, p->num_objects, short_oid->id);
1076 1077 1078 1079 1080 1081 1082 1083 1084 1085 1086 1087

	if (pos >= 0) {
		/* An object matching exactly the oid was found */
		found = 1;
		current = index + pos * stride;
	} else {
		/* No object was found */
		/* pos refers to the object with the "closest" oid to short_oid */
		pos = - 1 - pos;
		if (pos < (int)p->num_objects) {
			current = index + pos * stride;

Russell Belfer committed
1088
			if (!git_oid_ncmp(short_oid, (const git_oid *)current, len))
1089 1090 1091 1092
				found = 1;
		}
	}

1093
	if (found && len != GIT_OID_HEXSZ && pos + 1 < (int)p->num_objects) {
1094 1095 1096 1097 1098 1099 1100 1101
		/* Check for ambiguousity */
		const unsigned char *next = current + stride;

		if (!git_oid_ncmp(short_oid, (const git_oid *)next, len)) {
			found = 2;
		}
	}

1102
	if (!found)
Russell Belfer committed
1103
		return git_odb__error_notfound("failed to find offset for pack entry", short_oid);
1104 1105 1106 1107
	if (found > 1)
		return git_odb__error_ambiguous("found multiple offsets for pack entry");
	*offset_out = nth_packed_object_offset(p, pos);
	git_oid_fromraw(found_oid, current);
1108 1109

#ifdef INDEX_DEBUG_LOOKUP
1110
	{
1111 1112 1113 1114 1115
		unsigned char hex_sha1[GIT_OID_HEXSZ + 1];
		git_oid_fmt(hex_sha1, found_oid);
		hex_sha1[GIT_OID_HEXSZ] = '\0';
		printf("found lo=%d %s\n", lo, hex_sha1);
	}
1116 1117
#endif
	return 0;
1118 1119 1120 1121 1122 1123
}

int git_pack_entry_find(
		struct git_pack_entry *e,
		struct git_pack_file *p,
		const git_oid *short_oid,
1124
		size_t len)
1125
{
1126
	git_off_t offset;
1127 1128 1129 1130 1131 1132 1133 1134 1135
	git_oid found_oid;
	int error;

	assert(p);

	if (len == GIT_OID_HEXSZ && p->num_bad_objects) {
		unsigned i;
		for (i = 0; i < p->num_bad_objects; i++)
			if (git_oid_cmp(short_oid, &p->bad_object_sha1[i]) == 0)
1136
				return packfile_error("bad object found in packfile");
1137 1138 1139
	}

	error = pack_entry_find_offset(&offset, &found_oid, p, short_oid, len);
1140 1141
	if (error < 0)
		return error;
1142 1143 1144 1145

	/* we found a unique entry in the index;
	 * make sure the packfile backing the index
	 * still exists on disk */
1146 1147
	if (p->mwf.fd == -1 && (error = packfile_open(p)) < 0)
		return error;
1148 1149 1150 1151 1152

	e->offset = offset;
	e->p = p;

	git_oid_cpy(&e->sha1, &found_oid);
1153
	return 0;
1154
}