pack.c 38.5 KB
Newer Older
1
/*
Edward Thomson committed
2
 * Copyright (C) the libgit2 contributors. All rights reserved.
3
 *
Vicent Marti committed
4 5
 * This file is part of libgit2, distributed under the GNU GPL v2 with
 * a Linking Exception. For full terms see the included COPYING file.
6 7 8
 */

#include "pack.h"
9

10
#include "delta.h"
11
#include "futils.h"
12 13
#include "mwindow.h"
#include "odb.h"
14
#include "oid.h"
lhchavez committed
15
#include "oidarray.h"
16

17 18 19
/* Option to bypass checking existence of '.keep' files */
bool git_disable_pack_keep_file_checks = false;

20 21
static int packfile_open_locked(struct git_pack_file *p);
static off64_t nth_packed_object_offset_locked(struct git_pack_file *p, uint32_t n);
22
static int packfile_unpack_compressed(
23 24 25
		git_rawobj *obj,
		struct git_pack_file *p,
		git_mwindow **w_curs,
26
		off64_t *curpos,
27
		size_t size,
28
		git_object_t type);
29 30 31

/* Can find the offset of an object given
 * a prefix of an identifier.
32
 * Throws GIT_EAMBIGUOUSOIDPREFIX if short oid
33 34 35 36 37
 * is ambiguous within the pack.
 * This method assumes that len is between
 * GIT_OID_MINPREFIXLEN and GIT_OID_HEXSZ.
 */
static int pack_entry_find_offset(
38
		off64_t *offset_out,
39 40 41
		git_oid *found_oid,
		struct git_pack_file *p,
		const git_oid *short_oid,
42
		size_t len);
43

44 45
static int packfile_error(const char *message)
{
46
	git_error_set(GIT_ERROR_ODB, "invalid pack file - %s", message);
47 48 49
	return -1;
}

50 51 52
/********************
 * Delta base cache
 ********************/
53

54
static git_pack_cache_entry *new_cache_object(git_rawobj *source)
55
{
56
	git_pack_cache_entry *e = git__calloc(1, sizeof(git_pack_cache_entry));
57 58 59
	if (!e)
		return NULL;

60
	git_atomic32_inc(&e->refcount);
61 62 63 64 65 66 67 68 69 70 71 72 73 74 75
	memcpy(&e->raw, source, sizeof(git_rawobj));

	return e;
}

static void free_cache_object(void *o)
{
	git_pack_cache_entry *e = (git_pack_cache_entry *)o;

	if (e != NULL) {
		git__free(e->raw.data);
		git__free(e);
	}
}

76 77
static void cache_free(git_pack_cache *cache)
{
78
	git_pack_cache_entry *entry;
79 80

	if (cache->entries) {
81 82 83
		git_offmap_foreach_value(cache->entries, entry, {
			free_cache_object(entry);
		});
84 85

		git_offmap_free(cache->entries);
86
		cache->entries = NULL;
87 88 89 90 91
	}
}

static int cache_init(git_pack_cache *cache)
{
92 93
	if (git_offmap_new(&cache->entries) < 0)
		return -1;
94

95
	cache->memory_limit = GIT_PACK_CACHE_MEMORY_LIMIT;
Russell Belfer committed
96 97

	if (git_mutex_init(&cache->lock)) {
98
		git_error_set(GIT_ERROR_OS, "failed to initialize pack cache mutex");
Russell Belfer committed
99 100 101 102 103 104

		git__free(cache->entries);
		cache->entries = NULL;

		return -1;
	}
105 106 107 108

	return 0;
}

109
static git_pack_cache_entry *cache_get(git_pack_cache *cache, off64_t offset)
110
{
111
	git_pack_cache_entry *entry;
112

113 114 115
	if (git_mutex_lock(&cache->lock) < 0)
		return NULL;

116
	if ((entry = git_offmap_get(cache->entries, offset)) != NULL) {
117
		git_atomic32_inc(&entry->refcount);
118
		entry->last_usage = cache->use_ctr++;
119 120 121 122 123 124
	}
	git_mutex_unlock(&cache->lock);

	return entry;
}

125 126 127
/* Run with the cache lock held */
static void free_lowest_entry(git_pack_cache *cache)
{
128
	off64_t offset;
129 130
	git_pack_cache_entry *entry;

131
	git_offmap_foreach(cache->entries, offset, entry, {
132
		if (entry && git_atomic32_get(&entry->refcount) == 0) {
133
			cache->memory_used -= entry->raw.len;
134
			git_offmap_delete(cache->entries, offset);
135
			free_cache_object(entry);
136
		}
137
	});
138 139
}

140 141 142 143
static int cache_add(
		git_pack_cache_entry **cached_out,
		git_pack_cache *cache,
		git_rawobj *base,
144
		off64_t offset)
145 146
{
	git_pack_cache_entry *entry;
147
	int exists;
148

149 150 151
	if (base->len > GIT_PACK_CACHE_SIZE_LIMIT)
		return -1;

152 153
	entry = new_cache_object(base);
	if (entry) {
154
		if (git_mutex_lock(&cache->lock) < 0) {
155
			git_error_set(GIT_ERROR_OS, "failed to lock cache");
Jacques Germishuys committed
156
			git__free(entry);
157 158
			return -1;
		}
159
		/* Add it to the cache if nobody else has */
160
		exists = git_offmap_exists(cache->entries, offset);
161
		if (!exists) {
162 163 164
			while (cache->memory_used + base->len > cache->memory_limit)
				free_lowest_entry(cache);

165
			git_offmap_set(cache->entries, offset, entry);
166
			cache->memory_used += entry->raw.len;
167 168

			*cached_out = entry;
169 170 171 172 173 174 175 176 177 178 179 180
		}
		git_mutex_unlock(&cache->lock);
		/* Somebody beat us to adding it into the cache */
		if (exists) {
			git__free(entry);
			return -1;
		}
	}

	return 0;
}

181 182 183 184 185 186 187 188
/***********************************************************
 *
 * PACK INDEX METHODS
 *
 ***********************************************************/

static void pack_index_free(struct git_pack_file *p)
{
189 190 191 192
	if (p->oids) {
		git__free(p->oids);
		p->oids = NULL;
	}
193 194 195 196 197 198
	if (p->index_map.data) {
		git_futils_mmap_free(&p->index_map);
		p->index_map.data = NULL;
	}
}

lhchavez committed
199 200
/* Run with the packfile lock held */
static int pack_index_check_locked(const char *path, struct git_pack_file *p)
201 202 203 204 205 206 207
{
	struct git_pack_idx_header *hdr;
	uint32_t version, nr, i, *index;
	void *idx_map;
	size_t idx_size;
	struct stat st;
	int error;
208 209
	/* TODO: properly open the file without access time using O_NOATIME */
	git_file fd = git_futils_open_ro(path);
210
	if (fd < 0)
211
		return fd;
212

213 214
	if (p_fstat(fd, &st) < 0) {
		p_close(fd);
215
		git_error_set(GIT_ERROR_OS, "unable to stat pack index '%s'", path);
216 217 218 219
		return -1;
	}

	if (!S_ISREG(st.st_mode) ||
220 221 222
		!git__is_sizet(st.st_size) ||
		(idx_size = (size_t)st.st_size) < 4 * 256 + 20 + 20)
	{
223
		p_close(fd);
224
		git_error_set(GIT_ERROR_ODB, "invalid pack index '%s'", path);
225
		return -1;
226 227 228
	}

	error = git_futils_mmap_ro(&p->index_map, fd, 0, idx_size);
229

230 231
	p_close(fd);

232 233
	if (error < 0)
		return error;
234 235 236 237 238 239 240 241

	hdr = idx_map = p->index_map.data;

	if (hdr->idx_signature == htonl(PACK_IDX_SIGNATURE)) {
		version = ntohl(hdr->idx_version);

		if (version < 2 || version > 2) {
			git_futils_mmap_free(&p->index_map);
242
			return packfile_error("unsupported index version");
243 244 245 246 247 248 249 250 251
		}

	} else
		version = 1;

	nr = 0;
	index = idx_map;

	if (version > 1)
Vicent Marti committed
252
		index += 2; /* skip index header */
253 254 255 256 257

	for (i = 0; i < 256; i++) {
		uint32_t n = ntohl(index[i]);
		if (n < nr) {
			git_futils_mmap_free(&p->index_map);
258
			return packfile_error("index is non-monotonic");
259 260 261 262 263 264 265
		}
		nr = n;
	}

	if (version == 1) {
		/*
		 * Total size:
Vicent Marti committed
266 267 268 269
		 * - 256 index entries 4 bytes each
		 * - 24-byte entries * nr (20-byte sha1 + 4-byte offset)
		 * - 20-byte SHA1 of the packfile
		 * - 20-byte SHA1 file checksum
270 271 272
		 */
		if (idx_size != 4*256 + nr * 24 + 20 + 20) {
			git_futils_mmap_free(&p->index_map);
273
			return packfile_error("index is corrupted");
274 275 276 277
		}
	} else if (version == 2) {
		/*
		 * Minimum size:
Vicent Marti committed
278 279 280 281 282 283 284
		 * - 8 bytes of header
		 * - 256 index entries 4 bytes each
		 * - 20-byte sha1 entry * nr
		 * - 4-byte crc entry * nr
		 * - 4-byte offset entry * nr
		 * - 20-byte SHA1 of the packfile
		 * - 20-byte SHA1 file checksum
285 286 287 288 289 290 291 292 293 294 295 296
		 * And after the 4-byte offset table might be a
		 * variable sized table containing 8-byte entries
		 * for offsets larger than 2^31.
		 */
		unsigned long min_size = 8 + 4*256 + nr*(20 + 4 + 4) + 20 + 20;
		unsigned long max_size = min_size;

		if (nr)
			max_size += (nr - 1)*8;

		if (idx_size < min_size || idx_size > max_size) {
			git_futils_mmap_free(&p->index_map);
297
			return packfile_error("wrong index size");
298 299 300 301
		}
	}

	p->num_objects = nr;
302
	p->index_version = version;
303
	return 0;
304 305
}

lhchavez committed
306 307
/* Run with the packfile lock held */
static int pack_index_open_locked(struct git_pack_file *p)
308
{
309
	int error = 0;
310
	size_t name_len;
311
	git_buf idx_name = GIT_BUF_INIT;
312

313
	if (p->index_version > -1)
314
		goto cleanup;
315

Edward Thomson committed
316
	/* checked by git_pack_file alloc */
317
	name_len = strlen(p->pack_name);
Edward Thomson committed
318
	GIT_ASSERT(name_len > strlen(".pack"));
319

320 321
	if ((error = git_buf_init(&idx_name, name_len)) < 0)
		goto cleanup;
322

323 324 325
	git_buf_put(&idx_name, p->pack_name, name_len - strlen(".pack"));
	git_buf_puts(&idx_name, ".idx");
	if (git_buf_oom(&idx_name)) {
326 327
		error = -1;
		goto cleanup;
328
	}
329

330
	if (p->index_version == -1)
lhchavez committed
331
		error = pack_index_check_locked(idx_name.ptr, p);
332

333
cleanup:
334
	git_buf_dispose(&idx_name);
335

336
	return error;
337 338 339 340
}

static unsigned char *pack_window_open(
		struct git_pack_file *p,
341
		git_mwindow **w_cursor,
342
		off64_t offset,
343 344
		unsigned int *left)
{
345 346 347 348
	unsigned char *pack_data = NULL;

	if (git_mutex_lock(&p->lock) < 0) {
		git_error_set(GIT_ERROR_THREAD, "unable to lock packfile");
349
		return NULL;
350 351 352 353 354 355 356 357 358
	}
	if (git_mutex_lock(&p->mwf.lock) < 0) {
		git_mutex_unlock(&p->lock);
		git_error_set(GIT_ERROR_THREAD, "unable to lock packfile");
		return NULL;
	}

	if (p->mwf.fd == -1 && packfile_open_locked(p) < 0)
		goto cleanup;
359 360 361 362 363

	/* Since packfiles end in a hash of their content and it's
	 * pointless to ask for an offset into the middle of that
	 * hash, and the pack_window_contains function above wouldn't match
	 * don't allow an offset too close to the end of the file.
364 365 366
	 *
	 * Don't allow a negative offset, as that means we've wrapped
	 * around.
367 368
	 */
	if (offset > (p->mwf.size - 20))
369
		goto cleanup;
370
	if (offset < 0)
371 372 373
		goto cleanup;

	pack_data = git_mwindow_open(&p->mwf, w_cursor, offset, 20, left);
374

375 376 377 378
cleanup:
	git_mutex_unlock(&p->mwf.lock);
	git_mutex_unlock(&p->lock);
	return pack_data;
379 380
 }

381 382 383 384 385 386 387 388
/*
 * The per-object header is a pretty dense thing, which is
 *  - first byte: low four bits are "size",
 *    then three bits of "type",
 *    with the high bit being "size continues".
 *  - each byte afterwards: low seven bits are size continuation,
 *    with the high bit being "size continues"
 */
Edward Thomson committed
389
int git_packfile__object_header(size_t *out, unsigned char *hdr, size_t size, git_object_t type)
390 391 392 393
{
	unsigned char *hdr_base;
	unsigned char c;

Edward Thomson committed
394
	GIT_ASSERT_ARG(type >= GIT_OBJECT_COMMIT && type <= GIT_OBJECT_REF_DELTA);
395 396 397 398 399 400 401 402 403 404 405 406 407 408

	/* TODO: add support for chunked objects; see git.git 6c0d19b1 */

	c = (unsigned char)((type << 4) | (size & 15));
	size >>= 4;
	hdr_base = hdr;

	while (size) {
		*hdr++ = c | 0x80;
		c = size & 0x7f;
		size >>= 7;
	}
	*hdr++ = c;

Edward Thomson committed
409 410
	*out = (hdr - hdr_base);
	return 0;
411 412 413
}


414 415
static int packfile_unpack_header1(
		unsigned long *usedp,
416
		size_t *sizep,
417
		git_object_t *type,
418 419 420 421 422 423
		const unsigned char *buf,
		unsigned long len)
{
	unsigned shift;
	unsigned long size, c;
	unsigned long used = 0;
424

425 426 427 428 429
	c = buf[used++];
	*type = (c >> 4) & 7;
	size = c & 15;
	shift = 4;
	while (c & 0x80) {
430
		if (len <= used) {
431
			git_error_set(GIT_ERROR_ODB, "buffer too small");
432
			return GIT_EBUFS;
433
		}
434 435 436

		if (bitsizeof(long) <= shift) {
			*usedp = 0;
437
			git_error_set(GIT_ERROR_ODB, "packfile corrupted");
438 439
			return -1;
		}
440 441 442 443 444 445 446

		c = buf[used++];
		size += (c & 0x7f) << shift;
		shift += 7;
	}

	*sizep = (size_t)size;
447 448
	*usedp = used;
	return 0;
449 450 451 452
}

int git_packfile_unpack_header(
		size_t *size_p,
453
		git_object_t *type_p,
454
		struct git_pack_file *p,
455
		git_mwindow **w_curs,
456
		off64_t *curpos)
457 458 459 460
{
	unsigned char *base;
	unsigned int left;
	unsigned long used;
461 462 463 464 465 466 467 468 469 470 471 472 473 474
	int error;

	if ((error = git_mutex_lock(&p->lock)) < 0)
		return error;
	if ((error = git_mutex_lock(&p->mwf.lock)) < 0) {
		git_mutex_unlock(&p->lock);
		return error;
	}

	if (p->mwf.fd == -1 && (error = packfile_open_locked(p)) < 0) {
		git_mutex_unlock(&p->lock);
		git_mutex_unlock(&p->mwf.lock);
		return error;
	}
475 476

	/* pack_window_open() assures us we have [base, base + 20) available
Vicent Marti committed
477 478
	 * as a range that we can look at at. (Its actually the hash
	 * size that is assured.) With our object header encoding
479 480 481
	 * the maximum deflated object size is 2^137, which is just
	 * insane, so we know won't exceed what we have been given.
	 */
482 483 484
	base = git_mwindow_open(&p->mwf, w_curs, *curpos, 20, &left);
	git_mutex_unlock(&p->lock);
	git_mutex_unlock(&p->mwf.lock);
485
	if (base == NULL)
486
		return GIT_EBUFS;
487

488
	error = packfile_unpack_header1(&used, size_p, type_p, base, left);
489
	git_mwindow_close(w_curs);
490 491 492
	if (error == GIT_EBUFS)
		return error;
	else if (error < 0)
493
		return packfile_error("header length is zero");
494 495

	*curpos += used;
496
	return 0;
497 498
}

499 500
int git_packfile_resolve_header(
		size_t *size_p,
501
		git_object_t *type_p,
502
		struct git_pack_file *p,
503
		off64_t offset)
504 505
{
	git_mwindow *w_curs = NULL;
506
	off64_t curpos = offset;
507
	size_t size;
508
	git_object_t type;
509
	off64_t base_offset;
510 511
	int error;

512 513 514 515 516 517 518 519 520 521 522 523 524 525 526
	error = git_mutex_lock(&p->lock);
	if (error < 0) {
		git_error_set(GIT_ERROR_OS, "failed to lock packfile reader");
		return error;
	}
	error = git_mutex_lock(&p->mwf.lock);
	if (error < 0) {
		git_error_set(GIT_ERROR_OS, "failed to lock packfile reader");
		git_mutex_unlock(&p->lock);
		return error;
	}

	if (p->mwf.fd == -1 && (error = packfile_open_locked(p)) < 0) {
		git_mutex_unlock(&p->mwf.lock);
		git_mutex_unlock(&p->lock);
527
		return error;
528 529 530
	}
	git_mutex_unlock(&p->mwf.lock);
	git_mutex_unlock(&p->lock);
531

532
	error = git_packfile_unpack_header(&size, &type, p, &w_curs, &curpos);
533 534 535
	if (error < 0)
		return error;

536
	if (type == GIT_OBJECT_OFS_DELTA || type == GIT_OBJECT_REF_DELTA) {
537
		size_t base_size;
538 539
		git_packfile_stream stream;

540
		error = get_delta_base(&base_offset, p, &w_curs, &curpos, type, offset);
541
		git_mwindow_close(&w_curs);
542

543
		if (error < 0)
544 545
			return error;

546
		if ((error = git_packfile_stream_open(&stream, p, curpos)) < 0)
547
			return error;
548
		error = git_delta_read_header_fromstream(&base_size, size_p, &stream);
549
		git_packfile_stream_dispose(&stream);
550 551
		if (error < 0)
			return error;
552
	} else {
553
		*size_p = size;
554 555
		base_offset = 0;
	}
556

557
	while (type == GIT_OBJECT_OFS_DELTA || type == GIT_OBJECT_REF_DELTA) {
558
		curpos = base_offset;
559
		error = git_packfile_unpack_header(&size, &type, p, &w_curs, &curpos);
560 561
		if (error < 0)
			return error;
562
		if (type != GIT_OBJECT_OFS_DELTA && type != GIT_OBJECT_REF_DELTA)
563
			break;
564

565
		error = get_delta_base(&base_offset, p, &w_curs, &curpos, type, base_offset);
566
		git_mwindow_close(&w_curs);
567

568
		if (error < 0)
569
			return error;
570 571 572 573 574 575
	}
	*type_p = type;

	return error;
}

576 577
#define SMALL_STACK_SIZE 64

578 579 580 581 582 583
/**
 * Generate the chain of dependencies which we need to get to the
 * object at `off`. `chain` is used a stack, popping gives the right
 * order to apply deltas on. If an object is found in the pack's base
 * cache, we stop calculating there.
 */
584
static int pack_dependency_chain(git_dependency_chain *chain_out,
585
				 git_pack_cache_entry **cached_out, off64_t *cached_off,
586
				 struct pack_chain_elem *small_stack, size_t *stack_sz,
587
				 struct git_pack_file *p, off64_t obj_offset)
588 589 590
{
	git_dependency_chain chain = GIT_ARRAY_INIT;
	git_mwindow *w_curs = NULL;
591
	off64_t curpos = obj_offset, base_offset;
592 593
	int error = 0, use_heap = 0;
	size_t size, elem_pos;
594
	git_object_t type;
595

596
	elem_pos = 0;
597 598 599 600 601 602 603 604 605 606 607
	while (true) {
		struct pack_chain_elem *elem;
		git_pack_cache_entry *cached = NULL;

		/* if we have a base cached, we can stop here instead */
		if ((cached = cache_get(&p->bases, obj_offset)) != NULL) {
			*cached_out = cached;
			*cached_off = obj_offset;
			break;
		}

608 609 610
		/* if we run out of space on the small stack, use the array */
		if (elem_pos == SMALL_STACK_SIZE) {
			git_array_init_to_size(chain, elem_pos);
611
			GIT_ERROR_CHECK_ARRAY(chain);
612 613 614 615 616
			memcpy(chain.ptr, small_stack, elem_pos * sizeof(struct pack_chain_elem));
			chain.size = elem_pos;
			use_heap = 1;
		}

617
		curpos = obj_offset;
618 619 620 621 622 623 624 625
		if (!use_heap) {
			elem = &small_stack[elem_pos];
		} else {
			elem = git_array_alloc(chain);
			if (!elem) {
				error = -1;
				goto on_error;
			}
626 627 628 629
		}

		elem->base_key = obj_offset;

630
		error = git_packfile_unpack_header(&size, &type, p, &w_curs, &curpos);
631 632 633 634 635 636 637 638
		if (error < 0)
			goto on_error;

		elem->offset = curpos;
		elem->size = size;
		elem->type = type;
		elem->base_key = obj_offset;

639
		if (type != GIT_OBJECT_OFS_DELTA && type != GIT_OBJECT_REF_DELTA)
640 641
			break;

642
		error = get_delta_base(&base_offset, p, &w_curs, &curpos, type, obj_offset);
643 644
		git_mwindow_close(&w_curs);

645
		if (error < 0)
646 647 648 649 650 651 652
			goto on_error;

		/* we need to pass the pos *after* the delta-base bit */
		elem->offset = curpos;

		/* go through the loop again, but with the new object */
		obj_offset = base_offset;
653
		elem_pos++;
654 655
	}

656

657
	*stack_sz = elem_pos + 1;
658 659 660 661 662 663 664 665
	*chain_out = chain;
	return error;

on_error:
	git_array_clear(chain);
	return error;
}

666
int git_packfile_unpack(
667 668
	git_rawobj *obj,
	struct git_pack_file *p,
669
	off64_t *obj_offset)
670 671
{
	git_mwindow *w_curs = NULL;
672
	off64_t curpos = *obj_offset;
673 674
	int error, free_base = 0;
	git_dependency_chain chain = GIT_ARRAY_INIT;
675
	struct pack_chain_elem *elem = NULL, *stack;
676
	git_pack_cache_entry *cached = NULL;
677
	struct pack_chain_elem small_stack[SMALL_STACK_SIZE];
678
	size_t stack_size = 0, elem_pos, alloclen;
679
	git_object_t base_type;
680

681 682 683 684 685 686 687 688 689 690 691 692 693 694 695 696 697
	error = git_mutex_lock(&p->lock);
	if (error < 0) {
		git_error_set(GIT_ERROR_OS, "failed to lock packfile reader");
		return error;
	}
	error = git_mutex_lock(&p->mwf.lock);
	if (error < 0) {
		git_error_set(GIT_ERROR_OS, "failed to lock packfile reader");
		git_mutex_unlock(&p->lock);
		return error;
	}

	if (p->mwf.fd == -1)
		error = packfile_open_locked(p);
	git_mutex_unlock(&p->mwf.lock);
	git_mutex_unlock(&p->lock);
	if (error < 0)
698 699
		return error;

700 701 702 703
	/*
	 * TODO: optionally check the CRC on the packfile
	 */

704
	error = pack_dependency_chain(&chain, &cached, obj_offset, small_stack, &stack_size, p, *obj_offset);
705 706 707
	if (error < 0)
		return error;

708 709
	obj->data = NULL;
	obj->len = 0;
710
	obj->type = GIT_OBJECT_INVALID;
711

712 713 714 715
	/* let's point to the right stack */
	stack = chain.ptr ? chain.ptr : small_stack;

	elem_pos = stack_size;
716
	if (cached) {
717
		memcpy(obj, &cached->raw, sizeof(git_rawobj));
718
		base_type = obj->type;
719
		elem_pos--;	/* stack_size includes the base, which isn't actually there */
720
	} else {
721
		elem = &stack[--elem_pos];
722
		base_type = elem->type;
723
	}
724

725
	switch (base_type) {
726 727 728 729
	case GIT_OBJECT_COMMIT:
	case GIT_OBJECT_TREE:
	case GIT_OBJECT_BLOB:
	case GIT_OBJECT_TAG:
730
		if (!cached) {
731 732 733
			curpos = elem->offset;
			error = packfile_unpack_compressed(obj, p, &w_curs, &curpos, elem->size, elem->type);
			git_mwindow_close(&w_curs);
734
			base_type = elem->type;
735 736 737 738
		}
		if (error < 0)
			goto cleanup;
		break;
739 740
	case GIT_OBJECT_OFS_DELTA:
	case GIT_OBJECT_REF_DELTA:
741 742 743 744 745 746 747
		error = packfile_error("dependency chain ends in a delta");
		goto cleanup;
	default:
		error = packfile_error("invalid packfile type in header");
		goto cleanup;
	}

748
	/*
749
	 * Finding the object we want a cached base element is
750 751 752 753
	 * problematic, as we need to make sure we don't accidentally
	 * give the caller the cached object, which it would then feel
	 * free to free, so we need to copy the data.
	 */
754
	if (cached && stack_size == 1) {
755
		void *data = obj->data;
756

757
		GIT_ERROR_CHECK_ALLOC_ADD(&alloclen, obj->len, 1);
758
		obj->data = git__malloc(alloclen);
759
		GIT_ERROR_CHECK_ALLOC(obj->data);
760

761
		memcpy(obj->data, data, obj->len + 1);
762
		git_atomic32_dec(&cached->refcount);
763 764 765
		goto cleanup;
	}

766
	/* we now apply each consecutive delta until we run out */
767
	while (elem_pos > 0 && !error) {
768 769
		git_rawobj base, delta;

770 771 772 773 774
		/*
		 * We can now try to add the base to the cache, as
		 * long as it's not already the cached one.
		 */
		if (!cached)
775
			free_base = !!cache_add(&cached, &p->bases, obj, elem->base_key);
776

777
		elem = &stack[elem_pos - 1];
778 779 780 781
		curpos = elem->offset;
		error = packfile_unpack_compressed(&delta, p, &w_curs, &curpos, elem->size, elem->type);
		git_mwindow_close(&w_curs);

lhchavez committed
782 783 784
		if (error < 0) {
			/* We have transferred ownership of the data to the cache. */
			obj->data = NULL;
785
			break;
lhchavez committed
786
		}
787 788 789 790 791

		/* the current object becomes the new base, on which we apply the delta */
		base = *obj;
		obj->data = NULL;
		obj->len = 0;
792
		obj->type = GIT_OBJECT_INVALID;
793

794
		error = git_delta_apply(&obj->data, &obj->len, base.data, base.len, delta.data, delta.len);
795
		obj->type = base_type;
796

797 798 799 800 801 802
		/*
		 * We usually don't want to free the base at this
		 * point, as we put it into the cache in the previous
		 * iteration. free_base lets us know that we got the
		 * base object directly from the packfile, so we can free it.
		 */
803
		git__free(delta.data);
804 805 806 807 808 809
		if (free_base) {
			free_base = 0;
			git__free(base.data);
		}

		if (cached) {
810
			git_atomic32_dec(&cached->refcount);
811 812
			cached = NULL;
		}
813 814 815

		if (error < 0)
			break;
816

817
		elem_pos--;
818 819
	}

820
cleanup:
821
	if (error < 0) {
822
		git__free(obj->data);
823
		if (cached)
824
			git_atomic32_dec(&cached->refcount);
825
	}
826

827
	if (elem)
828
		*obj_offset = curpos;
829

830
	git_array_clear(chain);
831
	return error;
832 833
}

834
int git_packfile_stream_open(git_packfile_stream *obj, struct git_pack_file *p, off64_t curpos)
835 836 837 838
{
	memset(obj, 0, sizeof(git_packfile_stream));
	obj->curpos = curpos;
	obj->p = p;
839 840

	if (git_zstream_init(&obj->zstream, GIT_ZSTREAM_INFLATE) < 0) {
841
		git_error_set(GIT_ERROR_ZLIB, "failed to init packfile stream");
842 843 844 845 846 847 848 849
		return -1;
	}

	return 0;
}

ssize_t git_packfile_stream_read(git_packfile_stream *obj, void *buffer, size_t len)
{
850
	unsigned int window_len;
851
	unsigned char *in;
852
	int error;
853 854 855 856

	if (obj->done)
		return 0;

857
	if ((in = pack_window_open(obj->p, &obj->mw, obj->curpos, &window_len)) == NULL)
858 859
		return GIT_EBUFS;

860 861 862
	if ((error = git_zstream_set_input(&obj->zstream, in, window_len)) < 0 ||
	    (error = git_zstream_get_output_chunk(buffer, &len, &obj->zstream)) < 0) {
		git_mwindow_close(&obj->mw);
863
		git_error_set(GIT_ERROR_ZLIB, "error reading from the zlib stream");
864 865 866
		return -1;
	}

867
	git_mwindow_close(&obj->mw);
868

869 870 871 872
	obj->curpos += window_len - obj->zstream.in_len;

	if (git_zstream_eos(&obj->zstream))
		obj->done = 1;
873 874

	/* If we didn't write anything out but we're not done, we need more data */
875
	if (!len && !git_zstream_eos(&obj->zstream))
876 877
		return GIT_EBUFS;

878
	return len;
879 880 881

}

882
void git_packfile_stream_dispose(git_packfile_stream *obj)
883
{
884
	git_zstream_free(&obj->zstream);
885 886
}

887
static int packfile_unpack_compressed(
888 889
	git_rawobj *obj,
	struct git_pack_file *p,
890 891
	git_mwindow **mwindow,
	off64_t *position,
892
	size_t size,
893
	git_object_t type)
894
{
895 896 897 898
	git_zstream zstream = GIT_ZSTREAM_INIT;
	size_t buffer_len, total = 0;
	char *data = NULL;
	int error;
899

900 901 902
	GIT_ERROR_CHECK_ALLOC_ADD(&buffer_len, size, 1);
	data = git__calloc(1, buffer_len);
	GIT_ERROR_CHECK_ALLOC(data);
903

904
	if ((error = git_zstream_init(&zstream, GIT_ZSTREAM_INFLATE)) < 0) {
905
		git_error_set(GIT_ERROR_ZLIB, "failed to init zlib stream on unpack");
906
		goto out;
907 908 909
	}

	do {
910
		size_t bytes = buffer_len - total;
911
		unsigned int window_len, consumed;
912
		unsigned char *in;
913

914 915 916 917
		if ((in = pack_window_open(p, mwindow, *position, &window_len)) == NULL) {
			error = -1;
			goto out;
		}
918

919 920 921 922
		if ((error = git_zstream_set_input(&zstream, in, window_len)) < 0 ||
		    (error = git_zstream_get_output_chunk(data + total, &bytes, &zstream)) < 0) {
			git_mwindow_close(mwindow);
			goto out;
923 924
		}

925
		git_mwindow_close(mwindow);
926

927 928 929 930 931 932 933
		consumed = window_len - (unsigned int)zstream.in_len;

		if (!bytes && !consumed) {
			git_error_set(GIT_ERROR_ZLIB, "error inflating zlib stream");
			error = -1;
			goto out;
		}
934

935
		*position += consumed;
936
		total += bytes;
937
	} while (!git_zstream_eos(&zstream));
938

939
	if (total != size || !git_zstream_eos(&zstream)) {
940
		git_error_set(GIT_ERROR_ZLIB, "error inflating zlib stream");
941 942
		error = -1;
		goto out;
943 944 945 946
	}

	obj->type = type;
	obj->len = size;
947 948 949 950 951 952 953 954
	obj->data = data;

out:
	git_zstream_free(&zstream);
	if (error)
		git__free(data);

	return error;
955 956
}

957 958 959 960
/*
 * curpos is where the data starts, delta_obj_offset is the where the
 * header starts
 */
961 962 963 964 965 966 967
int get_delta_base(
		off64_t *delta_base_out,
		struct git_pack_file *p,
		git_mwindow **w_curs,
		off64_t *curpos,
		git_object_t type,
		off64_t delta_obj_offset)
968
{
969 970
	unsigned int left = 0;
	unsigned char *base_info;
971
	off64_t base_offset;
972 973
	git_oid unused;

Edward Thomson committed
974
	GIT_ASSERT_ARG(delta_base_out);
975

976 977 978
	base_info = pack_window_open(p, w_curs, *curpos, &left);
	/* Assumption: the only reason this would fail is because the file is too small */
	if (base_info == NULL)
979
		return GIT_EBUFS;
980 981
	/* pack_window_open() assured us we have [base_info, base_info + 20)
	 * as a range that we can look at without walking off the
Vicent Marti committed
982 983
	 * end of the mapped window. Its actually the hash size
	 * that is assured. An OFS_DELTA longer than the hash size
984 985
	 * is stupid, as then a REF_DELTA would be smaller to store.
	 */
986
	if (type == GIT_OBJECT_OFS_DELTA) {
987 988
		unsigned used = 0;
		unsigned char c = base_info[used++];
lhchavez committed
989
		size_t unsigned_base_offset = c & 127;
990
		while (c & 128) {
991
			if (left <= used)
992
				return GIT_EBUFS;
lhchavez committed
993 994
			unsigned_base_offset += 1;
			if (!unsigned_base_offset || MSB(unsigned_base_offset, 7))
995
				return packfile_error("overflow");
996
			c = base_info[used++];
lhchavez committed
997
			unsigned_base_offset = (unsigned_base_offset << 7) + (c & 127);
998
		}
999
		if (unsigned_base_offset == 0 || (size_t)delta_obj_offset <= unsigned_base_offset)
1000
			return packfile_error("out of bounds");
lhchavez committed
1001
		base_offset = delta_obj_offset - unsigned_base_offset;
1002
		*curpos += used;
1003
	} else if (type == GIT_OBJECT_REF_DELTA) {
1004 1005
		/* If we have the cooperative cache, search in it first */
		if (p->has_cache) {
1006
			struct git_pack_entry *entry;
1007
			git_oid oid;
1008

1009
			git_oid_fromraw(&oid, base_info);
1010
			if ((entry = git_oidmap_get(p->idx_cache, &oid)) != NULL) {
1011 1012 1013
				if (entry->offset == 0)
					return packfile_error("delta offset is zero");

1014
				*curpos += 20;
1015 1016
				*delta_base_out = entry->offset;
				return 0;
1017 1018 1019 1020 1021 1022
			} else {
				/* If we're building an index, don't try to find the pack
				 * entry; we just haven't seen it yet.  We'll make
				 * progress again in the next loop.
				 */
				return GIT_PASSTHROUGH;
1023 1024
			}
		}
1025

1026
		/* The base entry _must_ be in the same pack */
1027 1028
		if (pack_entry_find_offset(&base_offset, &unused, p, (git_oid *)base_info, GIT_OID_HEXSZ) < 0)
			return packfile_error("base entry delta is not in the same pack");
1029 1030
		*curpos += 20;
	} else
1031
		return packfile_error("unknown object type");
1032

1033 1034 1035
	if (base_offset == 0)
		return packfile_error("delta offset is zero");

1036 1037
	*delta_base_out = base_offset;
	return 0;
1038
}
1039 1040 1041 1042 1043 1044 1045

/***********************************************************
 *
 * PACKFILE METHODS
 *
 ***********************************************************/

1046
void git_packfile_free(struct git_pack_file *p, bool unlink_packfile)
1047
{
1048 1049 1050 1051 1052 1053 1054 1055 1056 1057 1058
	bool locked = true;

	if (!p)
		return;

	cache_free(&p->bases);

	if (git_mutex_lock(&p->lock) < 0) {
		git_error_set(GIT_ERROR_OS, "failed to lock packfile");
		locked = false;
	}
1059
	if (p->mwf.fd >= 0) {
1060
		git_mwindow_free_all(&p->mwf);
1061 1062 1063
		p_close(p->mwf.fd);
		p->mwf.fd = -1;
	}
1064 1065
	if (locked)
		git_mutex_unlock(&p->lock);
1066 1067 1068

	if (unlink_packfile)
		p_unlink(p->pack_name);
1069 1070 1071

	pack_index_free(p);

1072
	git__free(p->bad_object_sha1);
1073

1074
	git_mutex_free(&p->bases.lock);
1075 1076
	git_mutex_free(&p->mwf.lock);
	git_mutex_free(&p->lock);
1077
	git__free(p);
1078 1079
}

1080 1081
/* Run with the packfile and mwf locks held */
static int packfile_open_locked(struct git_pack_file *p)
1082 1083 1084 1085 1086 1087
{
	struct stat st;
	struct git_pack_header hdr;
	git_oid sha1;
	unsigned char *idx_sha1;

1088
	if (pack_index_open_locked(p) < 0)
lhchavez committed
1089 1090
		return git_odb__error_notfound("failed to open packfile", NULL, 0);

1091
	if (p->mwf.fd >= 0)
1092 1093
		return 0;

1094
	/* TODO: open with noatime */
1095
	p->mwf.fd = git_futils_open_ro(p->pack_name);
1096 1097
	if (p->mwf.fd < 0)
		goto cleanup;
1098

1099 1100
	if (p_fstat(p->mwf.fd, &st) < 0) {
		git_error_set(GIT_ERROR_OS, "could not stat packfile");
1101
		goto cleanup;
1102
	}
1103 1104 1105 1106 1107

	/* If we created the struct before we had the pack we lack size. */
	if (!p->mwf.size) {
		if (!S_ISREG(st.st_mode))
			goto cleanup;
1108
		p->mwf.size = (off64_t)st.st_size;
1109 1110 1111 1112 1113 1114 1115 1116 1117
	} else if (p->mwf.size != st.st_size)
		goto cleanup;

#if 0
	/* We leave these file descriptors open with sliding mmap;
	 * there is no point keeping them open across exec(), though.
	 */
	fd_flag = fcntl(p->mwf.fd, F_GETFD, 0);
	if (fd_flag < 0)
1118
		goto cleanup;
1119 1120 1121

	fd_flag |= FD_CLOEXEC;
	if (fcntl(p->pack_fd, F_SETFD, fd_flag) == -1)
1122
		goto cleanup;
1123 1124 1125
#endif

	/* Verify we recognize this pack file format. */
1126 1127 1128
	if (p_read(p->mwf.fd, &hdr, sizeof(hdr)) < 0 ||
		hdr.hdr_signature != htonl(PACK_SIGNATURE) ||
		!pack_version_ok(hdr.hdr_version))
1129 1130 1131
		goto cleanup;

	/* Verify the pack matches its index. */
1132
	if (p->num_objects != ntohl(hdr.hdr_entries) ||
1133
		p_pread(p->mwf.fd, sha1.id, GIT_OID_RAWSZ, p->mwf.size - GIT_OID_RAWSZ) < 0)
1134 1135 1136 1137
		goto cleanup;

	idx_sha1 = ((unsigned char *)p->index_map.data) + p->index_map.len - 40;

1138 1139 1140
	if (git_oid__cmp(&sha1, (git_oid *)idx_sha1) != 0)
		goto cleanup;

1141 1142 1143
	if (git_mwindow_file_register(&p->mwf) < 0)
		goto cleanup;

1144
	return 0;
1145 1146

cleanup:
1147
	git_error_set(GIT_ERROR_OS, "invalid packfile '%s'", p->pack_name);
1148

1149 1150
	if (p->mwf.fd >= 0)
		p_close(p->mwf.fd);
1151
	p->mwf.fd = -1;
1152

1153
	return -1;
1154 1155
}

1156 1157 1158 1159 1160 1161 1162 1163
int git_packfile__name(char **out, const char *path)
{
	size_t path_len;
	git_buf buf = GIT_BUF_INIT;

	path_len = strlen(path);

	if (path_len < strlen(".idx"))
1164
		return git_odb__error_notfound("invalid packfile path", NULL, 0);
1165 1166 1167 1168 1169 1170 1171 1172

	if (git_buf_printf(&buf, "%.*s.pack", (int)(path_len - strlen(".idx")), path) < 0)
		return -1;

	*out = git_buf_detach(&buf);
	return 0;
}

1173
int git_packfile_alloc(struct git_pack_file **pack_out, const char *path)
1174 1175 1176
{
	struct stat st;
	struct git_pack_file *p;
1177
	size_t path_len = path ? strlen(path) : 0, alloc_len;
1178 1179

	*pack_out = NULL;
1180

1181
	if (path_len < strlen(".idx"))
1182
		return git_odb__error_notfound("invalid packfile path", NULL, 0);
1183

1184 1185
	GIT_ERROR_CHECK_ALLOC_ADD(&alloc_len, sizeof(*p), path_len);
	GIT_ERROR_CHECK_ALLOC_ADD(&alloc_len, alloc_len, 2);
1186

1187
	p = git__calloc(1, alloc_len);
1188
	GIT_ERROR_CHECK_ALLOC(p);
1189

1190 1191
	memcpy(p->pack_name, path, path_len + 1);

1192 1193 1194 1195
	/*
	 * Make sure a corresponding .pack file exists and that
	 * the index looks sane.
	 */
1196 1197 1198
	if (git__suffixcmp(path, ".idx") == 0) {
		size_t root_len = path_len - strlen(".idx");

1199 1200 1201 1202 1203
		if (!git_disable_pack_keep_file_checks) {
			memcpy(p->pack_name + root_len, ".keep", sizeof(".keep"));
			if (git_path_exists(p->pack_name) == true)
				p->pack_keep = 1;
		}
1204

1205 1206
		memcpy(p->pack_name + root_len, ".pack", sizeof(".pack"));
	}
1207

1208
	if (p_stat(p->pack_name, &st) < 0 || !S_ISREG(st.st_mode)) {
1209
		git__free(p);
1210
		return git_odb__error_notfound("packfile not found", NULL, 0);
1211 1212 1213 1214 1215
	}

	/* ok, it looks sane as far as we can check without
	 * actually mapping the pack file.
	 */
1216
	p->mwf.fd = -1;
1217
	p->mwf.size = st.st_size;
1218 1219
	p->pack_local = 1;
	p->mtime = (git_time_t)st.st_mtime;
1220
	p->index_version = -1;
1221

1222
	if (git_mutex_init(&p->lock) < 0) {
1223
		git_error_set(GIT_ERROR_OS, "failed to initialize packfile mutex");
Russell Belfer committed
1224 1225 1226
		git__free(p);
		return -1;
	}
1227

1228 1229 1230 1231 1232 1233 1234
	if (git_mutex_init(&p->mwf.lock) < 0) {
		git_error_set(GIT_ERROR_OS, "failed to initialize packfile window mutex");
		git_mutex_free(&p->lock);
		git__free(p);
		return -1;
	}

1235
	if (cache_init(&p->bases) < 0) {
1236 1237
		git_mutex_free(&p->mwf.lock);
		git_mutex_free(&p->lock);
1238 1239 1240 1241
		git__free(p);
		return -1;
	}

1242
	*pack_out = p;
1243 1244

	return 0;
1245 1246 1247 1248 1249 1250 1251 1252
}

/***********************************************************
 *
 * PACKFILE ENTRY SEARCH INTERNALS
 *
 ***********************************************************/

1253
static off64_t nth_packed_object_offset_locked(struct git_pack_file *p, uint32_t n)
1254
{
1255 1256 1257 1258 1259
	const unsigned char *index, *end;
	uint32_t off32;

	index = p->index_map.data;
	end = index + p->index_map.len;
1260
	index += 4 * 256;
1261
	if (p->index_version == 1)
1262
		return ntohl(*((uint32_t *)(index + 24 * n)));
1263

1264 1265 1266 1267 1268 1269 1270 1271 1272 1273 1274 1275
	index += 8 + p->num_objects * (20 + 4);
	off32 = ntohl(*((uint32_t *)(index + 4 * n)));
	if (!(off32 & 0x80000000))
		return off32;
	index += p->num_objects * 4 + (off32 & 0x7fffffff) * 8;

	/* Make sure we're not being sent out of bounds */
	if (index >= end - 8)
		return -1;

	return (((uint64_t)ntohl(*((uint32_t *)(index + 0)))) << 32) |
				ntohl(*((uint32_t *)(index + 4)));
1276 1277
}

1278 1279 1280 1281
static int git__memcmp4(const void *a, const void *b) {
	return memcmp(a, b, 4);
}

1282
int git_pack_foreach_entry(
1283
	struct git_pack_file *p,
1284
	git_odb_foreach_cb cb,
1285
	void *data)
1286
{
lhchavez committed
1287
	const unsigned char *index, *current;
1288
	uint32_t i;
1289
	int error = 0;
lhchavez committed
1290 1291
	git_array_oid_t oids = GIT_ARRAY_INIT;
	git_oid *oid;
1292

lhchavez committed
1293 1294
	if (git_mutex_lock(&p->lock) < 0)
		return packfile_error("failed to get lock for git_pack_foreach_entry");
1295

lhchavez committed
1296 1297 1298
	if ((error = pack_index_open_locked(p)) < 0) {
		git_mutex_unlock(&p->lock);
		return error;
1299 1300
	}

1301 1302 1303 1304 1305 1306
	if (!p->index_map.data) {
		git_error_set(GIT_ERROR_INTERNAL, "internal error: p->index_map.data == NULL");
		git_mutex_unlock(&p->lock);
		return -1;
	}

lhchavez committed
1307 1308 1309
	index = p->index_map.data;

	if (p->index_version > 1)
1310 1311 1312 1313
		index += 8;

	index += 4 * 256;

1314 1315
	if (p->oids == NULL) {
		git_vector offsets, oids;
1316

lhchavez committed
1317 1318
		if ((error = git_vector_init(&oids, p->num_objects, NULL))) {
			git_mutex_unlock(&p->lock);
1319
			return error;
lhchavez committed
1320
		}
1321

lhchavez committed
1322 1323
		if ((error = git_vector_init(&offsets, p->num_objects, git__memcmp4))) {
			git_mutex_unlock(&p->lock);
1324
			return error;
lhchavez committed
1325
		}
1326

1327 1328 1329 1330 1331 1332 1333 1334 1335 1336 1337 1338 1339 1340
		if (p->index_version > 1) {
			const unsigned char *off = index + 24 * p->num_objects;
			for (i = 0; i < p->num_objects; i++)
				git_vector_insert(&offsets, (void*)&off[4 * i]);
			git_vector_sort(&offsets);
			git_vector_foreach(&offsets, i, current)
				git_vector_insert(&oids, (void*)&index[5 * (current - off)]);
		} else {
			for (i = 0; i < p->num_objects; i++)
				git_vector_insert(&offsets, (void*)&index[24 * i]);
			git_vector_sort(&offsets);
			git_vector_foreach(&offsets, i, current)
				git_vector_insert(&oids, (void*)&current[4]);
		}
1341

1342
		git_vector_free(&offsets);
1343
		p->oids = (git_oid **)git_vector_detach(NULL, NULL, &oids);
1344 1345
	}

lhchavez committed
1346 1347 1348 1349 1350 1351 1352 1353 1354 1355 1356 1357 1358 1359 1360 1361 1362 1363 1364 1365 1366 1367 1368 1369 1370
	/* We need to copy the OIDs to another array before we relinquish the lock to avoid races. */
	git_array_init_to_size(oids, p->num_objects);
	if (!oids.ptr) {
		git_mutex_unlock(&p->lock);
		git_array_clear(oids);
		GIT_ERROR_CHECK_ARRAY(oids);
	}
	for (i = 0; i < p->num_objects; i++) {
		oid = git_array_alloc(oids);
		if (!oid) {
			git_mutex_unlock(&p->lock);
			git_array_clear(oids);
			GIT_ERROR_CHECK_ALLOC(oid);
		}
		git_oid_cpy(oid, p->oids[i]);
	}

	git_mutex_unlock(&p->lock);

	git_array_foreach(oids, i, oid) {
		if ((error = cb(oid, data)) != 0) {
			git_error_set_after_callback(error);
			break;
		}
	}
1371

lhchavez committed
1372
	git_array_clear(oids);
1373
	return error;
1374 1375 1376 1377 1378 1379 1380 1381 1382 1383 1384 1385 1386 1387 1388 1389 1390 1391 1392 1393 1394
}

int git_pack_foreach_entry_offset(
	struct git_pack_file *p,
	git_pack_foreach_entry_offset_cb cb,
	void *data)
{
	const unsigned char *index;
	off64_t current_offset;
	const git_oid *current_oid;
	uint32_t i;
	int error = 0;

	if (git_mutex_lock(&p->lock) < 0)
		return packfile_error("failed to get lock for git_pack_foreach_entry_offset");

	index = p->index_map.data;
	if (index == NULL) {
		if ((error = pack_index_open_locked(p)) < 0)
			goto cleanup;

1395 1396 1397 1398 1399
		if (!p->index_map.data) {
			git_error_set(GIT_ERROR_INTERNAL, "internal error: p->index_map.data == NULL");
			goto cleanup;
		}

1400 1401 1402 1403 1404 1405 1406 1407
		index = p->index_map.data;
	}

	if (p->index_version > 1)
		index += 8;

	index += 4 * 256;

lhchavez committed
1408
	/* all offsets should have been validated by pack_index_check_locked */
1409 1410 1411 1412 1413 1414 1415 1416 1417 1418
	if (p->index_version > 1) {
		const unsigned char *offsets = index + 24 * p->num_objects;
		const unsigned char *large_offset_ptr;
		const unsigned char *large_offsets = index + 28 * p->num_objects;
		const unsigned char *large_offsets_end = ((const unsigned char *)p->index_map.data) + p->index_map.len - 20;
		for (i = 0; i < p->num_objects; i++) {
			current_offset = ntohl(*(const uint32_t *)(offsets + 4 * i));
			if (current_offset & 0x80000000) {
				large_offset_ptr = large_offsets + (current_offset & 0x7fffffff) * 8;
				if (large_offset_ptr >= large_offsets_end) {
lhchavez committed
1419
					error = packfile_error("invalid large offset");
1420 1421 1422 1423 1424 1425 1426 1427 1428 1429 1430 1431 1432 1433 1434 1435 1436 1437 1438 1439 1440 1441 1442 1443 1444
					goto cleanup;
				}
				current_offset = (((off64_t)ntohl(*((uint32_t *)(large_offset_ptr + 0)))) << 32) |
						ntohl(*((uint32_t *)(large_offset_ptr + 4)));
			}
			current_oid = (const git_oid *)(index + 20 * i);
			if ((error = cb(current_oid, current_offset, data)) != 0) {
				error = git_error_set_after_callback(error);
				goto cleanup;
			}
		}
	} else {
		for (i = 0; i < p->num_objects; i++) {
			current_offset = ntohl(*(const uint32_t *)(index + 24 * i));
			current_oid = (const git_oid *)(index + 24 * i + 4);
			if ((error = cb(current_oid, current_offset, data)) != 0) {
				error = git_error_set_after_callback(error);
				goto cleanup;
			}
		}
	}

cleanup:
	git_mutex_unlock(&p->lock);
	return error;
1445 1446
}

1447 1448
int git_pack__lookup_sha1(const void *oid_lookup_table, size_t stride, unsigned lo,
		unsigned hi, const unsigned char *oid_prefix)
1449
{
1450
	const unsigned char *base = oid_lookup_table;
1451 1452 1453

	while (lo < hi) {
		unsigned mi = (lo + hi) / 2;
1454
		int cmp = git_oid__hashcmp(base + mi * stride, oid_prefix);
1455 1456 1457 1458 1459 1460 1461 1462 1463 1464 1465 1466 1467

		if (!cmp)
			return mi;

		if (cmp > 0)
			hi = mi;
		else
			lo = mi+1;
	}

	return -((int)lo)-1;
}

1468
static int pack_entry_find_offset(
1469
	off64_t *offset_out,
1470 1471 1472
	git_oid *found_oid,
	struct git_pack_file *p,
	const git_oid *short_oid,
1473
	size_t len)
1474
{
1475 1476
	const uint32_t *level1_ofs;
	const unsigned char *index;
1477 1478
	unsigned hi, lo, stride;
	int pos, found = 0;
1479
	off64_t offset;
1480
	const unsigned char *current = 0;
lhchavez committed
1481
	int error = 0;
1482 1483 1484

	*offset_out = 0;

lhchavez committed
1485 1486
	if (git_mutex_lock(&p->lock) < 0)
		return packfile_error("failed to get lock for pack_entry_find_offset");
Edward Thomson committed
1487

lhchavez committed
1488 1489
	if ((error = pack_index_open_locked(p)) < 0)
		goto cleanup;
1490

1491 1492 1493 1494 1495
	if (!p->index_map.data) {
		git_error_set(GIT_ERROR_INTERNAL, "internal error: p->index_map.data == NULL");
		goto cleanup;
	}

1496 1497 1498
	index = p->index_map.data;
	level1_ofs = p->index_map.data;

1499 1500 1501 1502 1503 1504 1505 1506 1507 1508 1509 1510 1511 1512 1513 1514 1515 1516 1517 1518 1519
	if (p->index_version > 1) {
		level1_ofs += 2;
		index += 8;
	}

	index += 4 * 256;
	hi = ntohl(level1_ofs[(int)short_oid->id[0]]);
	lo = ((short_oid->id[0] == 0x0) ? 0 : ntohl(level1_ofs[(int)short_oid->id[0] - 1]));

	if (p->index_version > 1) {
		stride = 20;
	} else {
		stride = 24;
		index += 4;
	}

#ifdef INDEX_DEBUG_LOOKUP
	printf("%02x%02x%02x... lo %u hi %u nr %d\n",
		short_oid->id[0], short_oid->id[1], short_oid->id[2], lo, hi, p->num_objects);
#endif

1520
	pos = git_pack__lookup_sha1(index, stride, lo, hi, short_oid->id);
1521 1522 1523 1524 1525 1526 1527 1528 1529 1530 1531 1532

	if (pos >= 0) {
		/* An object matching exactly the oid was found */
		found = 1;
		current = index + pos * stride;
	} else {
		/* No object was found */
		/* pos refers to the object with the "closest" oid to short_oid */
		pos = - 1 - pos;
		if (pos < (int)p->num_objects) {
			current = index + pos * stride;

Russell Belfer committed
1533
			if (!git_oid_ncmp(short_oid, (const git_oid *)current, len))
1534 1535 1536 1537
				found = 1;
		}
	}

1538
	if (found && len != GIT_OID_HEXSZ && pos + 1 < (int)p->num_objects) {
1539 1540 1541 1542 1543 1544 1545 1546
		/* Check for ambiguousity */
		const unsigned char *next = current + stride;

		if (!git_oid_ncmp(short_oid, (const git_oid *)next, len)) {
			found = 2;
		}
	}

lhchavez committed
1547 1548 1549 1550 1551 1552 1553 1554
	if (!found) {
		error = git_odb__error_notfound("failed to find offset for pack entry", short_oid, len);
		goto cleanup;
	}
	if (found > 1) {
		error = git_odb__error_ambiguous("found multiple offsets for pack entry");
		goto cleanup;
	}
1555

1556
	if ((offset = nth_packed_object_offset_locked(p, pos)) < 0) {
1557
		git_error_set(GIT_ERROR_ODB, "packfile index is corrupt");
lhchavez committed
1558 1559
		error = -1;
		goto cleanup;
1560 1561 1562
	}

	*offset_out = offset;
1563
	git_oid_fromraw(found_oid, current);
1564 1565

#ifdef INDEX_DEBUG_LOOKUP
1566
	{
1567 1568 1569 1570 1571
		unsigned char hex_sha1[GIT_OID_HEXSZ + 1];
		git_oid_fmt(hex_sha1, found_oid);
		hex_sha1[GIT_OID_HEXSZ] = '\0';
		printf("found lo=%d %s\n", lo, hex_sha1);
	}
1572
#endif
1573

lhchavez committed
1574 1575 1576
cleanup:
	git_mutex_unlock(&p->lock);
	return error;
1577 1578 1579 1580 1581 1582
}

int git_pack_entry_find(
		struct git_pack_entry *e,
		struct git_pack_file *p,
		const git_oid *short_oid,
1583
		size_t len)
1584
{
1585
	off64_t offset;
1586 1587 1588
	git_oid found_oid;
	int error;

Edward Thomson committed
1589
	GIT_ASSERT_ARG(p);
1590 1591 1592 1593

	if (len == GIT_OID_HEXSZ && p->num_bad_objects) {
		unsigned i;
		for (i = 0; i < p->num_bad_objects; i++)
1594
			if (git_oid__cmp(short_oid, &p->bad_object_sha1[i]) == 0)
1595
				return packfile_error("bad object found in packfile");
1596 1597 1598
	}

	error = pack_entry_find_offset(&offset, &found_oid, p, short_oid, len);
1599 1600
	if (error < 0)
		return error;
1601

1602 1603 1604 1605 1606 1607 1608 1609 1610 1611 1612 1613
	error = git_mutex_lock(&p->lock);
	if (error < 0) {
		git_error_set(GIT_ERROR_OS, "failed to lock packfile reader");
		return error;
	}
	error = git_mutex_lock(&p->mwf.lock);
	if (error < 0) {
		git_mutex_unlock(&p->lock);
		git_error_set(GIT_ERROR_OS, "failed to lock packfile reader");
		return error;
	}

1614 1615 1616
	/* we found a unique entry in the index;
	 * make sure the packfile backing the index
	 * still exists on disk */
1617 1618 1619 1620 1621
	if (p->mwf.fd == -1)
		error = packfile_open_locked(p);
	git_mutex_unlock(&p->mwf.lock);
	git_mutex_unlock(&p->lock);
	if (error < 0)
1622
		return error;
1623 1624 1625 1626 1627

	e->offset = offset;
	e->p = p;

	git_oid_cpy(&e->sha1, &found_oid);
1628
	return 0;
1629
}