From d0a081d1cba0543054c6ffb2c04f8d13a4c0a58e Mon Sep 17 00:00:00 2001 From: Johannes Schindelin Date: Wed, 5 Aug 2026 16:14:30 +0000 Subject: [PATCH] pack-objects: widen delta-cache accounting to `size_t` These three are a single accounting tuple (the globals tracking cumulative cached-delta bytes, plus the helper that compares them against an incoming delta size) and are latently 32-bit on Windows where `unsigned long` != `size_t`: a pack with many large cached deltas could wrap silently. The widening is internally consistent on its own: the additions and subtractions against delta_cache_size already come from `size_t` sources (`DELTA_SIZE()` returns `size_t`), and `delta_cacheable()`'s sole caller in `try_delta()` still passes `unsigned long`, which promotes. Prerequisite for dropping `try_delta()`'s `cast_size_t_to_ulong()` shims, which becomes possible once 1create_delta()` and `diff_delta()` are widened in a later commit. Note: since `max_delta_cache_size` changes data type to `size_t`, a pair of new helpers is introduced to parse config values of that type, too. Assisted-by: Opus 4.7 Helped-by: Patrick Steinhardt Signed-off-by: Johannes Schindelin Signed-off-by: Junio C Hamano --- builtin/pack-objects.c | 10 +++++----- config.c | 9 +++++++++ config.h | 3 +++ parse.c | 9 +++++++++ parse.h | 1 + 5 files changed, 27 insertions(+), 5 deletions(-) diff --git a/builtin/pack-objects.c b/builtin/pack-objects.c index 27048bbb4d..ee3eeee7ab 100644 --- a/builtin/pack-objects.c +++ b/builtin/pack-objects.c @@ -260,8 +260,8 @@ static int exclude_promisor_objects_best_effort; static int use_delta_islands; -static unsigned long delta_cache_size = 0; -static unsigned long max_delta_cache_size = DEFAULT_DELTA_CACHE_SIZE; +static size_t delta_cache_size = 0; +static size_t max_delta_cache_size = DEFAULT_DELTA_CACHE_SIZE; static unsigned long cache_max_small_delta_size = 1000; static unsigned long window_memory_limit = 0; @@ -2687,8 +2687,8 @@ struct unpacked { unsigned depth; }; -static int delta_cacheable(unsigned long src_size, unsigned long trg_size, - unsigned long delta_size) +static int delta_cacheable(size_t src_size, size_t trg_size, + size_t delta_size) { if (max_delta_cache_size && delta_cache_size + delta_size > max_delta_cache_size) return 0; @@ -3684,7 +3684,7 @@ static int git_pack_config(const char *k, const char *v, return 0; } if (!strcmp(k, "pack.deltacachesize")) { - max_delta_cache_size = git_config_int(k, v, ctx->kvi); + max_delta_cache_size = git_config_size_t(k, v, ctx->kvi); return 0; } if (!strcmp(k, "pack.deltacachelimit")) { diff --git a/config.c b/config.c index 6a0de86e3a..010a58d307 100644 --- a/config.c +++ b/config.c @@ -1268,6 +1268,15 @@ ssize_t git_config_ssize_t(const char *name, const char *value, return ret; } +size_t git_config_size_t(const char *name, const char *value, + const struct key_value_info *kvi) +{ + size_t ret; + if (!git_parse_size_t(value, &ret)) + die_bad_number(name, value, kvi); + return ret; +} + double git_config_double(const char *name, const char *value, const struct key_value_info *kvi) { diff --git a/config.h b/config.h index 31fe3e2961..b66dd08007 100644 --- a/config.h +++ b/config.h @@ -282,6 +282,9 @@ unsigned long git_config_ulong(const char *, const char *, ssize_t git_config_ssize_t(const char *, const char *, const struct key_value_info *); +size_t git_config_size_t(const char *, const char *, + const struct key_value_info *); + /** * Identically to `git_config_double`, but for double-precision floating point * values. diff --git a/parse.c b/parse.c index d77f28046a..266bbd539b 100644 --- a/parse.c +++ b/parse.c @@ -134,6 +134,15 @@ int git_parse_ssize_t(const char *value, ssize_t *ret) return 1; } +int git_parse_size_t(const char *value, size_t *ret) +{ + uintmax_t tmp; + if (!git_parse_unsigned(value, &tmp, maximum_signed_value_of_type(size_t))) + return 0; + *ret = tmp; + return 1; +} + int git_parse_double(const char *value, double *ret) { char *end; diff --git a/parse.h b/parse.h index a6dd37c4cb..db742f35fb 100644 --- a/parse.h +++ b/parse.h @@ -4,6 +4,7 @@ int git_parse_signed(const char *value, intmax_t *ret, intmax_t max); int git_parse_unsigned(const char *value, uintmax_t *ret, uintmax_t max); int git_parse_ssize_t(const char *, ssize_t *); +int git_parse_size_t(const char *, size_t *); int git_parse_ulong(const char *, unsigned long *); int git_parse_uint(const char *value, unsigned int *ret); int git_parse_int(const char *value, int *ret);