From: Junio C Hamano <gitster@pobox.com>
To: Michal Suchanek <msuchanek@suse.de>
Cc: git@vger.kernel.org
Subject: Re: [PATCH 1/2] worktree: fix worktree add race.
Date: Fri, 15 Feb 2019 10:59:33 -0800 [thread overview]
Message-ID: <xmqq8syg6foq.fsf@gitster-ct.c.googlers.com> (raw)
In-Reply-To: <429046b2c9f02c5e4f0af88db51f6c0c099f08a9.1550254374.git.msuchanek@suse.de> (Michal Suchanek's message of "Fri, 15 Feb 2019 19:16:11 +0100")
Michal Suchanek <msuchanek@suse.de> writes:
> Git runs a stat loop to find a worktree name that's available and then does
> mkdir on the found name. Turn it to mkdir loop to avoid another invocation of
> worktree add finding the same free name and creating the directory first.
Yeah, relying on the atomicity of mkdir(2) is much saner approach
than "check -- ah we can use the name -- try to create" that is race
prone.
Thanks for working on this.
> Signed-off-by: Michal Suchanek <msuchanek@suse.de>
> ---
> builtin/worktree.c | 11 ++++++-----
> 1 file changed, 6 insertions(+), 5 deletions(-)
>
> diff --git a/builtin/worktree.c b/builtin/worktree.c
> index 3f9907fcc994..e1a2a56c03c5 100644
> --- a/builtin/worktree.c
> +++ b/builtin/worktree.c
> @@ -268,10 +268,9 @@ static int add_worktree(const char *path, const char *refname,
> struct strbuf sb_git = STRBUF_INIT, sb_repo = STRBUF_INIT;
> struct strbuf sb = STRBUF_INIT;
> const char *name;
> - struct stat st;
> struct child_process cp = CHILD_PROCESS_INIT;
> struct argv_array child_env = ARGV_ARRAY_INIT;
> - int counter = 0, len, ret;
> + int counter = 1, len, ret;
> struct strbuf symref = STRBUF_INIT;
> struct commit *commit = NULL;
> int is_branch = 0;
> @@ -295,19 +294,21 @@ static int add_worktree(const char *path, const char *refname,
> if (safe_create_leading_directories_const(sb_repo.buf))
> die_errno(_("could not create leading directories of '%s'"),
> sb_repo.buf);
> - while (!stat(sb_repo.buf, &st)) {
> +
> + while (mkdir(sb_repo.buf, 0777)) {
> counter++;
> + if(!counter) break; /* don't loop forever */
> strbuf_setlen(&sb_repo, len);
> strbuf_addf(&sb_repo, "%d", counter);
Style:
if (!counter)
break; /* don't loop forever */
More importantly, how long would it take to loop thru all possible
integers (can be simulated by making the parent directory
unwritable)? Don't we want to cut off with more conservative upper
limit, say 1000 rounds or even 100 rounds or so?
Also, is the behaviour for a signed integer wrapping around due to
getting incremented too many times well defined? I'd feel safer,
especially if you are willing to spin for 4 billion times like this
patch does, if you changed the counter to "unsigned int".
I see you changed "counter" to start from 1, but that would mean
that these fallback names would start with suffix 2, not 1. Which
would look funny.
I would have expected ".1", ".2", etc. as suffix, but the original
used "1", "2", etc. so I won't complain on the format, but I do find
it questionable to start counting from 2.
> }
> + if (!counter)
> + die_errno(_("could not create directory of '%s'"), sb_repo.buf);
It would have saved reviewer's time if this die() were inside the
loop where you punted with "break".
> name = strrchr(sb_repo.buf, '/') + 1;
>
> junk_pid = getpid();
> atexit(remove_junk);
> sigchain_push_common(remove_junk_on_signal);
>
> - if (mkdir(sb_repo.buf, 0777))
> - die_errno(_("could not create directory of '%s'"), sb_repo.buf);
> junk_git_dir = xstrdup(sb_repo.buf);
> is_junk = 1;
next prev parent reply other threads:[~2019-02-15 18:59 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2019-02-15 18:16 [PATCH 1/2] worktree: fix worktree add race Michal Suchanek
2019-02-15 18:16 ` [PATCH 2/2] setup: don't fail if commondir is deleted Michal Suchanek
2019-02-17 7:14 ` Eric Sunshine
2019-02-18 8:54 ` Michal Suchánek
2019-02-15 18:59 ` Junio C Hamano [this message]
2019-02-16 0:18 ` [PATCH 1/2] worktree: fix worktree add race Michal Suchánek
2019-02-17 7:05 ` Eric Sunshine
-- strict thread matches above, loose matches on Subject: below --
2019-02-18 17:04 [PATCH 0/2] worktree add race fix Michal Suchanek
2019-02-18 17:04 ` [PATCH 1/2] worktree: fix worktree add race Michal Suchanek
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
List information: http://vger.kernel.org/majordomo-info.html
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=xmqq8syg6foq.fsf@gitster-ct.c.googlers.com \
--to=gitster@pobox.com \
--cc=git@vger.kernel.org \
--cc=msuchanek@suse.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
Code repositories for project(s) associated with this public inbox
https://80x24.org/mirrors/git.git
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).