fsck: return error code when verify_pack() goes wrong
[git/git.git] / pack-check.c
CommitLineData
f9253394
JH
1#include "cache.h"
2#include "pack.h"
70f5d5d3 3#include "pack-revindex.h"
f9253394 4
9cba13ca 5struct idx_entry {
3af51928 6 off_t offset;
c41a4a94
NP
7 const unsigned char *sha1;
8 unsigned int nr;
3af51928
AJ
9};
10
11static int compare_entries(const void *e1, const void *e2)
12{
13 const struct idx_entry *entry1 = e1;
14 const struct idx_entry *entry2 = e2;
15 if (entry1->offset < entry2->offset)
16 return -1;
17 if (entry1->offset > entry2->offset)
18 return 1;
19 return 0;
20}
21
c41a4a94
NP
22int check_pack_crc(struct packed_git *p, struct pack_window **w_curs,
23 off_t offset, off_t len, unsigned int nr)
24{
25 const uint32_t *index_crc;
1e4cd68c 26 uint32_t data_crc = crc32(0, NULL, 0);
c41a4a94
NP
27
28 do {
ef49a7a0 29 unsigned long avail;
c41a4a94
NP
30 void *data = use_pack(p, w_curs, offset, &avail);
31 if (avail > len)
32 avail = len;
33 data_crc = crc32(data_crc, data, avail);
34 offset += avail;
35 len -= avail;
36 } while (len);
37
38 index_crc = p->index_data;
39 index_crc += 2 + 256 + p->num_objects * (20/4) + nr;
40
41 return data_crc != ntohl(*index_crc);
42}
43
03e79c88
SP
44static int verify_packfile(struct packed_git *p,
45 struct pack_window **w_curs)
f9253394 46{
c4001d92 47 off_t index_size = p->index_size;
42873078 48 const unsigned char *index_base = p->index_data;
9126f009 49 git_SHA_CTX ctx;
62413604 50 unsigned char sha1[20], *pack_sig;
4277c670 51 off_t offset = 0, pack_sig_ofs = 0;
326bf396 52 uint32_t nr_objects, i;
62413604 53 int err = 0;
3af51928 54 struct idx_entry *entries;
f9253394 55
079afb18
SP
56 /* Note that the pack header checks are actually performed by
57 * use_pack when it first opens the pack file. If anything
58 * goes wrong during those checks then the call will die out
59 * immediately.
60 */
f9253394 61
9126f009 62 git_SHA1_Init(&ctx);
4277c670 63 do {
ef49a7a0 64 unsigned long remaining;
079afb18
SP
65 unsigned char *in = use_pack(p, w_curs, offset, &remaining);
66 offset += remaining;
4277c670
MH
67 if (!pack_sig_ofs)
68 pack_sig_ofs = p->pack_size - 20;
62413604
NP
69 if (offset > pack_sig_ofs)
70 remaining -= (unsigned int)(offset - pack_sig_ofs);
9126f009 71 git_SHA1_Update(&ctx, in, remaining);
4277c670 72 } while (offset < pack_sig_ofs);
9126f009 73 git_SHA1_Final(sha1, &ctx);
62413604
NP
74 pack_sig = use_pack(p, w_curs, pack_sig_ofs, NULL);
75 if (hashcmp(sha1, pack_sig))
76 err = error("%s SHA1 checksum mismatch",
77 p->pack_name);
78 if (hashcmp(index_base + index_size - 40, pack_sig))
22e5e58a 79 err = error("%s SHA1 does not match its index",
62413604 80 p->pack_name);
079afb18 81 unuse_pack(w_curs);
f3bf9224
JH
82
83 /* Make sure everything reachable from idx is valid. Since we
84 * have verified that nr_objects matches between idx and pack,
85 * we do not do scan-streaming check on the pack file.
86 */
57059091 87 nr_objects = p->num_objects;
c41a4a94
NP
88 entries = xmalloc((nr_objects + 1) * sizeof(*entries));
89 entries[nr_objects].offset = pack_sig_ofs;
3af51928
AJ
90 /* first sort entries by pack offset, since unpacking them is more efficient that way */
91 for (i = 0; i < nr_objects; i++) {
92 entries[i].sha1 = nth_packed_object_sha1(p, i);
93 if (!entries[i].sha1)
94 die("internal error pack-check nth-packed-object");
99093238 95 entries[i].offset = nth_packed_object_offset(p, i);
c41a4a94 96 entries[i].nr = i;
3af51928
AJ
97 }
98 qsort(entries, nr_objects, sizeof(*entries), compare_entries);
99
62413604 100 for (i = 0; i < nr_objects; i++) {
f3bf9224 101 void *data;
21666f1a 102 enum object_type type;
c4001d92 103 unsigned long size;
f3bf9224 104
c41a4a94
NP
105 if (p->index_version > 1) {
106 off_t offset = entries[i].offset;
107 off_t len = entries[i+1].offset - offset;
108 unsigned int nr = entries[i].nr;
109 if (check_pack_crc(p, w_curs, offset, len, nr))
110 err = error("index CRC mismatch for object %s "
111 "from %s at offset %"PRIuMAX"",
112 sha1_to_hex(entries[i].sha1),
113 p->pack_name, (uintmax_t)offset);
114 }
3af51928 115 data = unpack_entry(p, entries[i].offset, &type, &size);
f3bf9224 116 if (!data) {
62413604
NP
117 err = error("cannot unpack %s from %s at offset %"PRIuMAX"",
118 sha1_to_hex(entries[i].sha1), p->pack_name,
119 (uintmax_t)entries[i].offset);
120 break;
f3bf9224 121 }
3af51928 122 if (check_sha1_signature(entries[i].sha1, data, size, typename(type))) {
1038f0c0 123 err = error("packed %s from %s is corrupt",
3af51928 124 sha1_to_hex(entries[i].sha1), p->pack_name);
f3bf9224 125 free(data);
62413604 126 break;
f3bf9224
JH
127 }
128 free(data);
129 }
3af51928 130 free(entries);
f3bf9224
JH
131
132 return err;
f9253394
JH
133}
134
9b0aa728 135int verify_pack_index(struct packed_git *p)
f9253394 136{
d079837e
SP
137 off_t index_size;
138 const unsigned char *index_base;
9126f009 139 git_SHA_CTX ctx;
f9253394 140 unsigned char sha1[20];
62413604 141 int err = 0;
f9253394 142
d079837e
SP
143 if (open_pack_index(p))
144 return error("packfile %s index not opened", p->pack_name);
145 index_size = p->index_size;
146 index_base = p->index_data;
147
f9253394 148 /* Verify SHA1 sum of the index file */
9126f009
NP
149 git_SHA1_Init(&ctx);
150 git_SHA1_Update(&ctx, index_base, (unsigned int)(index_size - 20));
151 git_SHA1_Final(sha1, &ctx);
42873078 152 if (hashcmp(sha1, index_base + index_size - 20))
62413604 153 err = error("Packfile index for %s SHA1 mismatch",
f3bf9224 154 p->pack_name);
9b0aa728
SP
155 return err;
156}
157
158int verify_pack(struct packed_git *p)
159{
160 int err = 0;
161 struct pack_window *w_curs = NULL;
162
163 err |= verify_pack_index(p);
164 if (!p->index_data)
165 return -1;
f3bf9224 166
62413604
NP
167 err |= verify_packfile(p, &w_curs);
168 unuse_pack(&w_curs);
f3bf9224 169
62413604 170 return err;
f9253394 171}