]> git.ipfire.org Git - thirdparty/git.git/commitdiff
midx repack: avoid potential integer overflow on 64 bit systems
authorPhillip Wood <phillip.wood@dunelm.org.uk>
Thu, 22 May 2025 15:55:21 +0000 (16:55 +0100)
committerJunio C Hamano <gitster@pobox.com>
Thu, 22 May 2025 21:48:36 +0000 (14:48 -0700)
On a 64 bit system the calculation

    p->pack_size * pack_info[i].referenced_objects

could overflow. If a pack file contains 2^28 objects with an average
compressed size of 1KB then the pack size will be 2^38B. If all of the
objects are referenced by the multi-pack index the sum above will
overflow. Avoid this by using shifted integer arithmetic and changing
the order of the calculation so that the pack size is divided by the
total number of objects in the pack before multiplying by the number of
objects referenced by the multi-pack index. Using a shift of 14 bits
should give reasonable accuracy while avoiding overflow for pack sizes
less that 1PB.

Signed-off-by: Phillip Wood <phillip.wood@dunelm.org.uk>
Signed-off-by: Junio C Hamano <gitster@pobox.com>
midx-write.c

index 105014a2792266193e82b759a997f1a81de6dcb4..8121e96f4fda009f3b75d44d4b78973efc8ec25b 100644 (file)
@@ -1704,9 +1704,15 @@ static void fill_included_packs_batch(struct repository *r,
                if (!want_included_pack(r, m, pack_kept_objects, pack_int_id))
                        continue;
 
-               expected_size = uint64_mult(p->pack_size,
-                                           pack_info[i].referenced_objects);
+               /*
+                * Use shifted integer arithmetic to calculate the
+                * expected pack size to ~4 significant digits without
+                * overflow for packsizes less that 1PB.
+                */
+               expected_size = (uint64_t)pack_info[i].referenced_objects << 14;
                expected_size /= p->num_objects;
+               expected_size = u64_mult(expected_size, p->pack_size);
+               expected_size = u64_add(expected_size, 1u << 13) >> 14;
 
                if (expected_size >= batch_size)
                        continue;