From: "Johannes Schindelin via GitGitGadget" <gitgitgadget@gmail.com>
To: git@vger.kernel.org
Cc: Johannes Schindelin <johannes.schindelin@gmx.de>,
Johannes Schindelin <johannes.schindelin@gmx.de>
Subject: [PATCH 3/7] midx: validate incremental MIDX pack IDs
Date: Thu, 17 Sep 2026 17:52:32 +0000 [thread overview]
Message-ID: <1cf4e5ddb5996423478b7543f7978e58cfcc4eb1.1789667556.git.gitgitgadget@gmail.com> (raw)
In-Reply-To: <pull.2231.git.1789667556.gitgitgadget@gmail.com>
From: Johannes Schindelin <johannes.schindelin@gmx.de>
Incremental MIDX support made object-offset pack IDs local to each layer
and then converted them to chain-global IDs by adding
`num_packs_in_base`. The conversion was introduced by 19419821bac5
(midx: teach `nth_midxed_pack_int_id()` about incremental MIDXs,
2024-08-06). Chain-aware pack preparation followed in 1820bd878c62
(midx: teach `prepare_midx_pack()` about incremental MIDXs, 2024-08-06),
but the final `midx_fill_entry()` lookup remained tied to the original
layer. Only with 8f909ff4e9e8 (packfile: recover when a multi-pack-index
names a removed pack, 2026-08-29) did Coverity point out this issue: a
local ID such as `UINT32_MAX` could wrap when the base-pack count was
added, producing a plausible but incorrect global ID. After
`prepare_midx_pack()` resolved the chain, `midx_fill_entry()` could then
underflow or address the wrong layer while indexing the current layer's
pack array, causing an invalid memory access and crashing Git.
Validate each local pack ID against its layer's pack count before adding
the base count, and obtain the final pack through `nth_midxed_pack()`,
which resolves the correct MIDX layer. This prevents an invalid local ID
from wrapping during conversion and ensures that the lookup uses the
layer identified by the resolved chain-global ID.
Assisted-by: GPT-5.6 Luna
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
---
midx.c | 12 +++++++++---
1 file changed, 9 insertions(+), 3 deletions(-)
diff --git a/midx.c b/midx.c
index 6d1c548e3d..6968fc1c00 100644
--- a/midx.c
+++ b/midx.c
@@ -583,10 +583,16 @@ off_t nth_midxed_offset(struct multi_pack_index *m, uint32_t pos)
uint32_t nth_midxed_pack_int_id(struct multi_pack_index *m, uint32_t pos)
{
+ uint32_t pack_int_id;
+
pos = midx_for_object(&m, pos);
+ pack_int_id = get_be32(m->chunk_object_offsets +
+ (off_t)pos * MIDX_CHUNK_OFFSET_WIDTH);
+ if (pack_int_id >= m->num_packs)
+ die(_("bad pack-int-id: %"PRIu32" (%"PRIu32" total packs)"),
+ pack_int_id, m->num_packs);
- return m->num_packs_in_base + get_be32(m->chunk_object_offsets +
- (off_t)pos * MIDX_CHUNK_OFFSET_WIDTH);
+ return m->num_packs_in_base + pack_int_id;
}
enum midx_fill_result midx_fill_entry(struct multi_pack_index *m,
@@ -606,7 +612,7 @@ enum midx_fill_result midx_fill_entry(struct multi_pack_index *m,
if (prepare_midx_pack(m, pack_int_id))
return MIDX_FILL_OWNER_UNAVAILABLE;
- p = m->packs[pack_int_id - m->num_packs_in_base];
+ p = nth_midxed_pack(m, pack_int_id);
/*
* We are about to tell the caller where they can locate the
--
gitgitgadget
next prev parent reply other threads:[~2026-09-17 17:52 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-17 17:52 [PATCH 0/7] Fix issues pointed out in Git for Windows by Coverity after merging v2.56.0-rc0 Johannes Schindelin via GitGitGadget
2026-09-17 17:52 ` [PATCH 1/7] wrapper: guard writev_in_full() against signed overflow Johannes Schindelin via GitGitGadget
2026-09-17 17:52 ` [PATCH 2/7] gpg-interface: make signature-prefix matching length-aware Johannes Schindelin via GitGitGadget
2026-09-17 19:32 ` Junio C Hamano
2026-09-18 7:12 ` Johannes Schindelin
2026-09-18 8:59 ` Junio C Hamano
2026-09-17 17:52 ` Johannes Schindelin via GitGitGadget [this message]
2026-09-17 17:52 ` [PATCH 4/7] rerere: do not record failed conflict resolution data Johannes Schindelin via GitGitGadget
2026-09-17 19:34 ` Junio C Hamano
2026-09-17 17:52 ` [PATCH 5/7] t/unit-tests: check reftable iterator initialization Johannes Schindelin via GitGitGadget
2026-09-17 17:52 ` [PATCH 6/7] oss-fuzz: handle reftable iterator initialization failures Johannes Schindelin via GitGitGadget
2026-09-17 17:52 ` [PATCH 7/7] test-read-midx: check midx_fill_entry() result Johannes Schindelin via GitGitGadget
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1cf4e5ddb5996423478b7543f7978e58cfcc4eb1.1789667556.git.gitgitgadget@gmail.com \
--to=gitgitgadget@gmail.com \
--cc=git@vger.kernel.org \
--cc=johannes.schindelin@gmx.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox