From: David Turner <dturner@twopensource.com>
To: git@vger.kernel.org, pclouds@gmail.com
Cc: David Turner <dturner@twopensource.com>
Subject: [PATCH v12 05/20] index-helper: add --strict
Date: Thu, 19 May 2016 17:45:42 -0400 [thread overview]
Message-ID: <1463694357-6503-6-git-send-email-dturner@twopensource.com> (raw)
In-Reply-To: <1463694357-6503-1-git-send-email-dturner@twopensource.com>
From: Nguyễn Thái Ngọc Duy <pclouds@gmail.com>
There are "holes" in the index-helper approach because the shared
memory is not verified again by git. If $USER is compromised, shared
memory could be modified. But anyone who could do this could already
modify $GIT_DIR/index. A more realistic risk is some bugs in
index-helper that produce corrupt shared memory. --strict is added to
avoid that.
Strictly speaking there's still a very small gap where corrupt shared
memory could still be read by git: after we write the trailing SHA-1 in
the shared memory (thus signaling "this shm is ready") and before
verify_shm() detects an error.
Signed-off-by: Nguyễn Thái Ngọc Duy <pclouds@gmail.com>
Signed-off-by: David Turner <dturner@twopensource.com>
---
Documentation/git-index-helper.txt | 9 +++++++
cache.h | 1 +
index-helper.c | 48 ++++++++++++++++++++++++++++++++++++++
read-cache.c | 9 ++++---
4 files changed, 64 insertions(+), 3 deletions(-)
diff --git a/Documentation/git-index-helper.txt b/Documentation/git-index-helper.txt
index f892184..1f92c89 100644
--- a/Documentation/git-index-helper.txt
+++ b/Documentation/git-index-helper.txt
@@ -25,6 +25,15 @@ OPTIONS
Exit if the cached index is not accessed for `<n>`
seconds. Specify 0 to wait forever. Default is 600.
+--strict::
+--no-strict::
+ Strict mode makes index-helper verify the shared memory after
+ it's created. If the result does not match what's read from
+ $GIT_DIR/index, the shared memory is destroyed. This makes
+ index-helper take more than double the amount of time required
+ for reading an index, but because it will happen in the
+ background, it's not noticable. `--strict` is enabled by default.
+
NOTES
-----
diff --git a/cache.h b/cache.h
index 2d7af6f..6cb0d02 100644
--- a/cache.h
+++ b/cache.h
@@ -345,6 +345,7 @@ struct index_state {
* on it.
*/
to_shm : 1,
+ always_verify_trailing_sha1 : 1,
initialized : 1;
struct hashmap name_hash;
struct hashmap dir_hash;
diff --git a/index-helper.c b/index-helper.c
index 260ef4a..a7f8a42 100644
--- a/index-helper.c
+++ b/index-helper.c
@@ -17,6 +17,7 @@ struct shm {
static struct shm shm_index;
static struct shm shm_base_index;
+static int to_verify = 1;
static void release_index_shm(struct shm *is)
{
@@ -114,11 +115,56 @@ static void share_index(struct index_state *istate, struct shm *is)
hashcpy((unsigned char *)new_mmap + istate->mmap_size - 20, is->sha1);
}
+static int verify_shm(void)
+{
+ int i;
+ struct index_state istate;
+ memset(&istate, 0, sizeof(istate));
+ istate.always_verify_trailing_sha1 = 1;
+ istate.to_shm = 1;
+ i = read_index(&istate);
+ if (i != the_index.cache_nr)
+ goto done;
+ for (; i < the_index.cache_nr; i++) {
+ struct cache_entry *base, *ce;
+ /* namelen is checked separately */
+ const unsigned int ondisk_flags =
+ CE_STAGEMASK | CE_VALID | CE_EXTENDED_FLAGS;
+ unsigned int ce_flags, base_flags, ret;
+ base = the_index.cache[i];
+ ce = istate.cache[i];
+ if (ce->ce_namelen != base->ce_namelen ||
+ strcmp(ce->name, base->name)) {
+ warning("mismatch at entry %d", i);
+ break;
+ }
+ ce_flags = ce->ce_flags;
+ base_flags = base->ce_flags;
+ /* only on-disk flags matter */
+ ce->ce_flags &= ondisk_flags;
+ base->ce_flags &= ondisk_flags;
+ ret = memcmp(&ce->ce_stat_data, &base->ce_stat_data,
+ offsetof(struct cache_entry, name) -
+ offsetof(struct cache_entry, ce_stat_data));
+ ce->ce_flags = ce_flags;
+ base->ce_flags = base_flags;
+ if (ret) {
+ warning("mismatch at entry %d", i);
+ break;
+ }
+ }
+done:
+ discard_index(&istate);
+ return i == the_index.cache_nr;
+}
+
static void share_the_index(void)
{
if (the_index.split_index && the_index.split_index->base)
share_index(the_index.split_index->base, &shm_base_index);
share_index(&the_index, &shm_index);
+ if (to_verify && !verify_shm())
+ cleanup_shm();
discard_index(&the_index);
}
@@ -250,6 +296,8 @@ int main(int argc, char **argv)
struct option options[] = {
OPT_INTEGER(0, "exit-after", &idle_in_seconds,
N_("exit if not used after some seconds")),
+ OPT_BOOL(0, "strict", &to_verify,
+ "verify shared memory after creating"),
OPT_END()
};
diff --git a/read-cache.c b/read-cache.c
index e3c8f3e..41647ea 100644
--- a/read-cache.c
+++ b/read-cache.c
@@ -1674,9 +1674,12 @@ int do_read_index(struct index_state *istate, const char *path, int must_exist)
istate->mmap = mmap;
istate->mmap_size = mmap_size;
- if (try_shm(istate) &&
- verify_hdr(istate->mmap, istate->mmap_size) < 0)
- goto unmap;
+ if (try_shm(istate)) {
+ if (verify_hdr(istate->mmap, istate->mmap_size) < 0)
+ goto unmap;
+ } else if (istate->always_verify_trailing_sha1 &&
+ verify_hdr(istate->mmap, istate->mmap_size) < 0)
+ goto unmap;
hdr = mmap = istate->mmap;
mmap_size = istate->mmap_size;
if (!istate->keep_mmap)
--
2.4.2.767.g62658d5-twtrsrc
next prev parent reply other threads:[~2016-05-19 21:47 UTC|newest]
Thread overview: 49+ messages / expand[flat|nested] mbox.gz Atom feed top
2016-05-19 21:45 [PATCH v12 00/20] index-helper/watchman David Turner
2016-05-19 21:45 ` [PATCH v12 01/20] read-cache.c: fix constness of verify_hdr() David Turner
2016-05-19 21:45 ` [PATCH v12 02/20] read-cache: allow to keep mmap'd memory after reading David Turner
2016-05-19 21:45 ` [PATCH v12 03/20] pkt-line: add gentle version of packet_write David Turner
2016-06-25 14:01 ` Duy Nguyen
2016-05-19 21:45 ` [PATCH v12 04/20] index-helper: new daemon for caching index and related stuff David Turner
2016-06-17 16:43 ` Christian Couder
2016-06-25 14:15 ` Duy Nguyen
2016-06-25 14:33 ` Duy Nguyen
2016-06-25 19:21 ` David Turner
2016-06-26 4:27 ` Duy Nguyen
2016-06-26 19:29 ` David Turner
2016-06-27 5:50 ` Duy Nguyen
2016-06-26 8:53 ` Eric Wong
2016-06-26 17:49 ` David Turner
2016-06-26 23:25 ` Eric Wong
2016-05-19 21:45 ` David Turner [this message]
2016-06-25 14:43 ` [PATCH v12 05/20] index-helper: add --strict Duy Nguyen
2016-05-19 21:45 ` [PATCH v12 06/20] daemonize(): set a flag before exiting the main process David Turner
2016-05-19 21:45 ` [PATCH v12 07/20] index-helper: add --detach David Turner
2016-06-25 14:46 ` Duy Nguyen
2016-05-19 21:45 ` [PATCH v12 08/20] index-helper: log warnings David Turner
2016-05-19 21:45 ` [PATCH v12 09/20] read-cache: add watchman 'WAMA' extension David Turner
2016-06-25 14:59 ` Duy Nguyen
2016-05-19 21:45 ` [PATCH v12 10/20] watchman: support watchman to reduce index refresh cost David Turner
2016-06-17 16:01 ` Christian Couder
2016-05-19 21:45 ` [PATCH v12 11/20] index-helper: use watchman to avoid refreshing index with lstat() David Turner
2016-06-17 13:02 ` Duy Nguyen
2016-06-17 21:39 ` David Turner
2016-06-19 5:07 ` [PATCH v12 11/20] index-helper: use watchman to avoid refreshing, " David Turner
2016-06-23 6:24 ` David Turner
2016-06-23 15:33 ` Duy Nguyen
2016-06-25 16:27 ` [PATCH v12 11/20] index-helper: use watchman to avoid refreshing " Duy Nguyen
2016-05-19 21:45 ` [PATCH v12 12/20] update-index: enable/disable watchman support David Turner
2016-06-25 16:31 ` Duy Nguyen
2016-05-19 21:45 ` [PATCH v12 13/20] unpack-trees: preserve index extensions David Turner
2016-05-19 21:45 ` [PATCH v12 14/20] watchman: add a config option to enable the extension David Turner
2016-05-19 21:45 ` [PATCH v12 15/20] index-helper: kill mode David Turner
2016-05-19 21:45 ` [PATCH v12 16/20] index-helper: don't run if already running David Turner
2016-06-17 16:18 ` Christian Couder
2016-05-19 21:45 ` [PATCH v12 17/20] index-helper: autorun mode David Turner
2016-06-25 16:35 ` Duy Nguyen
2016-05-19 21:45 ` [PATCH v12 18/20] index-helper: optionally automatically run David Turner
2016-06-25 16:38 ` Duy Nguyen
2016-05-19 21:45 ` [PATCH v12 19/20] trace: measure where the time is spent in the index-heavy operations David Turner
2016-05-19 21:45 ` [PATCH v12 20/20] index-helper: indexhelper.exitafter config David Turner
2016-06-25 13:28 ` [PATCH v12 00/20] index-helper/watchman Duy Nguyen
2016-06-25 16:42 ` Duy Nguyen
2016-06-26 4:08 ` David Turner
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1463694357-6503-6-git-send-email-dturner@twopensource.com \
--to=dturner@twopensource.com \
--cc=git@vger.kernel.org \
--cc=pclouds@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.