From: Junio C Hamano <hidden> Date: 2016-06-15 22:58:16
Brandon Casey [off-list ref] writes:
From: Brandon Casey <redacted>
When the number of open packs exceeds pack_max_fds, unuse_one_window()
is called repeatedly to attempt to release the least-recently-used
pack windows, which, as a side-effect, will also close a pack file
after closing its last open window. If a pack file has been opened,
but no windows have been allocated into it, it will never be selected
by unuse_one_window() and hence its file descriptor will not be
closed. When this happens, git may exceed the number of file
descriptors permitted by the system.
An interesting find. The patch from a cursory look reads OK.
Thanks.
This is not likely to occur during upload-pack since upload-pack
reads each object from the pack so that it can peel tags and
advertise the exposed object.
Another interesting find. Perhaps there is a room for improvements,
as packed-refs file knows what objects the tags peel to? I vaguely
recall Peff was actively reducing the object access during ref
enumeration in not so distant past...
From: Jeff King <hidden> Date: 2016-06-15 22:58:16
On Tue, Jul 30, 2013 at 08:39:48AM -0700, Junio C Hamano wrote:
Brandon Casey [off-list ref] writes:
quoted
From: Brandon Casey <redacted>
When the number of open packs exceeds pack_max_fds, unuse_one_window()
is called repeatedly to attempt to release the least-recently-used
pack windows, which, as a side-effect, will also close a pack file
after closing its last open window. If a pack file has been opened,
but no windows have been allocated into it, it will never be selected
by unuse_one_window() and hence its file descriptor will not be
closed. When this happens, git may exceed the number of file
descriptors permitted by the system.
An interesting find. The patch from a cursory look reads OK.
Yeah. I wonder if unuse_one_window() should actually leave the pack fd
open now in general.
If you close packfile descriptors, you can run into racy situations
where somebody else is repacking and deleting packs, and they go away
while you are trying to access them. If you keep a descriptor open,
you're fine; they last to the end of the process. If you don't, then
they disappear from under you.
For normal object access, this isn't that big a deal; we just rescan the
packs and retry. But if you are packing yourself (e.g., because you are
a pack-objects started by upload-pack for a clone or fetch), it's much
harder to recover (and we print some warnings).
We had our core.packedGitWindowSize lowered on GitHub for a while, and
we ran into this warning on busy repositories when we were running "git
gc" on the server. We solved it by bumping the window size so we never
release memory.
But just not closing the descriptor wouldn't work until Brandon's patch,
because we used the same function to release memory and descriptor
pressure. Now we could do them separately (and progressively if we need
to).
quoted
This is not likely to occur during upload-pack since upload-pack
reads each object from the pack so that it can peel tags and
advertise the exposed object.
Another interesting find. Perhaps there is a room for improvements,
as packed-refs file knows what objects the tags peel to? I vaguely
recall Peff was actively reducing the object access during ref
enumeration in not so distant past...
Yeah, we should be reading almost no objects these days due to the
packed-refs peel lines. I just did a double-check on what "git
upload-pack . </dev/null >/dev/null" reads on my git.git repo, and it is
only three objects: the v1.8.3.3, v1.8.3.4, and v1.8.4-rc0 tag objects.
In other words, the tags I got since the last time I ran "git gc". So I
think all is working as designed.
We could give receive-pack the same treatment; I've spent less time
micro-optimizing it because because we (and most sites, I would think)
get an order of magnitude more fetches than pushes.
-Peff
On Tue, Jul 30, 2013 at 12:52 PM, Jeff King [off-list ref] wrote:
On Tue, Jul 30, 2013 at 08:39:48AM -0700, Junio C Hamano wrote:
quoted
Brandon Casey [off-list ref] writes:
quoted
From: Brandon Casey <redacted>
When the number of open packs exceeds pack_max_fds, unuse_one_window()
is called repeatedly to attempt to release the least-recently-used
pack windows, which, as a side-effect, will also close a pack file
after closing its last open window. If a pack file has been opened,
but no windows have been allocated into it, it will never be selected
by unuse_one_window() and hence its file descriptor will not be
closed. When this happens, git may exceed the number of file
descriptors permitted by the system.
An interesting find. The patch from a cursory look reads OK.
Yeah. I wonder if unuse_one_window() should actually leave the pack fd
open now in general.
If you close packfile descriptors, you can run into racy situations
where somebody else is repacking and deleting packs, and they go away
while you are trying to access them. If you keep a descriptor open,
you're fine; they last to the end of the process. If you don't, then
they disappear from under you.
For normal object access, this isn't that big a deal; we just rescan the
packs and retry. But if you are packing yourself (e.g., because you are
a pack-objects started by upload-pack for a clone or fetch), it's much
harder to recover (and we print some warnings).
We had our core.packedGitWindowSize lowered on GitHub for a while, and
we ran into this warning on busy repositories when we were running "git
gc" on the server. We solved it by bumping the window size so we never
release memory.
But just not closing the descriptor wouldn't work until Brandon's patch,
because we used the same function to release memory and descriptor
pressure. Now we could do them separately (and progressively if we need
to).
I had thought about whether to stop closing the pack file in
unuse_one_window(), but didn't have a reason to do so. I think the
scenario you described provides a justification. If we're not under
file descriptor pressure and we can possibly avoid rescanning the pack
directory, it sounds like a net win.
quoted
quoted
This is not likely to occur during upload-pack since upload-pack
reads each object from the pack so that it can peel tags and
advertise the exposed object.
Another interesting find. Perhaps there is a room for improvements,
as packed-refs file knows what objects the tags peel to? I vaguely
recall Peff was actively reducing the object access during ref
enumeration in not so distant past...
Yeah, we should be reading almost no objects these days due to the
packed-refs peel lines. I just did a double-check on what "git
upload-pack . </dev/null >/dev/null" reads on my git.git repo, and it is
only three objects: the v1.8.3.3, v1.8.3.4, and v1.8.4-rc0 tag objects.
In other words, the tags I got since the last time I ran "git gc". So I
think all is working as designed.
Ok, looks like this has been the case since your 435c8332 which taught
upload-pack to use peel_ref(). So looks like we do avoid reaching
into the pack for any ref that was read from a (modern) packed-refs
file. The repository I was testing with had mostly loose refs.
Indeed, after packing refs, upload-pack encounters the same problem as
receive-pack and runs out of file descriptors.
So my comment about upload-pack is not completely accurate.
Upload-pack _can_ run into this problem, but the refs must be packed,
as well as there being enough of them that exist in enough different
pack files to exceed the processes fd limit.
We could give receive-pack the same treatment; I've spent less time
micro-optimizing it because because we (and most sites, I would think)
get an order of magnitude more fetches than pushes.
I don't think it would need the 435c8332 treatment since receive-pack
doesn't peel refs when it advertises them to the client and hence does
not need to load the ref object from the pack file during ref
advertisement, but possibly some of the other stuff you did would be
applicable. But like you said, the number of fetches far exceed the
number of pushes.
-Brandon
From: Brandon Casey <redacted>
When the number of open packs exceeds pack_max_fds, unuse_one_window()
is called repeatedly to attempt to release the least-recently-used
pack windows, which, as a side-effect, will also close a pack file
after closing its last open window. If a pack file has been opened,
but no windows have been allocated into it, it will never be selected
by unuse_one_window() and hence its file descriptor will not be
closed. When this happens, git may exceed the number of file
descriptors permitted by the system.
This latter situation can occur in show-ref or receive-pack during ref
advertisement. During ref advertisement, receive-pack will iterate
over every ref in the repository and advertise it to the client after
ensuring that the ref exists in the local repository. If the ref is
located inside a pack, then the pack is opened to ensure that it
exists, but since the object is not actually read from the pack, no
mmap windows are allocated. When the number of open packs exceeds
pack_max_fds, unuse_one_window() will not be able to find any windows to
free and will not be able to close any packs. Once the per-process
file descriptor limit is exceeded, receive-pack will produce a warning,
not an error, for each pack it cannot open, and will then most likely
fail with an error to spawn rev-list or index-pack like:
error: cannot create standard input pipe for rev-list: Too many open files
error: Could not run 'git rev-list'
This may also occur during upload-pack when refs are packed (in the
packed-refs file) and the number of packs that must be opened to
verify that these packed refs exist exceeds the file descriptor limit.
If the refs are loose, then upload-pack will read each ref from the
pack (allocating one or more mmap windows) so it can peel tags and
advertise the underlying object. If the refs are packed and peeled,
then upload-pack will use the peeled sha1 in the packed-refs file and
will not need to read from the pack files, so no mmap windows will be
allocated and just like with receive-pack, unuse_one_window() will
never select these opened packs to close.
When we have file descriptor pressure, in contrast to memory pressure,
we need to free all windows and close the pack file descriptor so that
a new pack can be opened. Let's introduce a new function
close_one_pack() designed specifically for this purpose to search
for and close the least-recently-used pack, where LRU is defined as
* pack with oldest mtime and no allocated mmap windows or
* pack with the least-recently-used windows, i.e. the pack
with the oldest most-recently-used window
Signed-off-by: Brandon Casey <redacted>
---
The commit message was updated to fix the grammatical error that Eric
Sunshine pointed out, and to correct the paragraph about upload-pack.
-Brandon
sha1_file.c | 63 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++-
1 file changed, 62 insertions(+), 1 deletion(-)
@@ -682,6 +682,67 @@ void close_pack_windows(struct packed_git *p)}}+/*+*TheLRUpackistheonewiththeoldestMRUwindowortheoldestmtime+*ifithasnowindowsallocated.+*/+staticvoidfind_lru_pack(structpacked_git*p,structpacked_git**lru_p,structpack_window**mru_w)+{+structpack_window*w,*this_mru_w;++/*+*Rejectthispackifithaswindowsandthepreviouslyselected+*onedoesnot.Ifthispackdoesnothavewindows,reject+*itifthepackfileisnewerthanthepreviouslyselectedone.+*/+if(*lru_p&&!*mru_w&&(p->windows||p->mtime>(*lru_p)->mtime))+return;++for(w=this_mru_w=p->windows;w;w=w->next){+/* Reject this pack if any of its windows are in use */+if(w->inuse_cnt)+return;+/*+*Rejectthispackifithaswindowsthathavebeen+*usedmorerecentlythanthepreviouslyselectedpack.+*/+if(*mru_w&&w->last_used>(*mru_w)->last_used)+return;+if(w->last_used>this_mru_w->last_used)+this_mru_w=w;+}++/*+*Selectthispack.+*/+*mru_w=this_mru_w;+*lru_p=p;+}++staticintclose_one_pack(void)+{+structpacked_git*p,*lru_p=NULL;+structpack_window*mru_w=NULL;++for(p=packed_git;p;p=p->next){+if(p->pack_fd==-1)+continue;+find_lru_pack(p,&lru_p,&mru_w);+}++if(lru_p){+close_pack_windows(lru_p);+close(lru_p->pack_fd);+pack_open_fds--;+lru_p->pack_fd=-1;+if(lru_p==last_found_pack)+last_found_pack=NULL;+return1;+}++return0;+}+voidunuse_pack(structpack_window**w_cursor){structpack_window*w=*w_cursor;
--
1.8.4.rc0.2.g6cf5c31
-----------------------------------------------------------------------------------
This email message is for the sole use of the intended recipient(s) and may contain
confidential information. Any unauthorized review, use, disclosure or distribution
is prohibited. If you are not the intended recipient, please contact the sender by
reply email and destroy all copies of the original message.
-----------------------------------------------------------------------------------
From: Brandon Casey <redacted>
Now that close_one_pack() has been introduced to handle file
descriptor pressure, it is not strictly necessary to close the
pack file descriptor in unuse_one_window() when we're under memory
pressure.
Jeff King provided a justification for leaving the pack file open:
If you close packfile descriptors, you can run into racy situations
where somebody else is repacking and deleting packs, and they go away
while you are trying to access them. If you keep a descriptor open,
you're fine; they last to the end of the process. If you don't, then
they disappear from under you.
For normal object access, this isn't that big a deal; we just rescan
the packs and retry. But if you are packing yourself (e.g., because
you are a pack-objects started by upload-pack for a clone or fetch),
it's much harder to recover (and we print some warnings).
Let's do so (or uh, not do so).
Signed-off-by: Brandon Casey <redacted>
---
builtin/pack-objects.c | 2 +-
git-compat-util.h | 2 +-
sha1_file.c | 21 +++++++--------------
3 files changed, 9 insertions(+), 16 deletions(-)
--
1.8.4.rc0.2.g6cf5c31
-----------------------------------------------------------------------------------
This email message is for the sole use of the intended recipient(s) and may contain
confidential information. Any unauthorized review, use, disclosure or distribution
is prohibited. If you are not the intended recipient, please contact the sender by
reply email and destroy all copies of the original message.
-----------------------------------------------------------------------------------
From: Antoine Pelisse <hidden> Date: 2016-06-15 22:58:17
On Wed, Jul 31, 2013 at 9:51 PM, Brandon Casey [off-list ref] wrote:
-----------------------------------------------------------------------------------
This email message is for the sole use of the intended recipient(s) and may contain
confidential information. Any unauthorized review, use, disclosure or distribution
is prohibited. If you are not the intended recipient, please contact the sender by
reply email and destroy all copies of the original message.
-----------------------------------------------------------------------------------
I'm certainly not a lawyer, and I'm sorry for not reviewing the
content of the patch instead, but is that not a problem from a legal
point of view ?
I remember a video of Greg Kroah-Hartman where he talked about that
(the video was posted by Junio on G+).
From: Fredrik Gustafsson <hidden> Date: 2016-06-15 22:58:17
On Wed, Jul 31, 2013 at 11:08:21PM +0200, Antoine Pelisse wrote:
On Wed, Jul 31, 2013 at 9:51 PM, Brandon Casey [off-list ref] wrote:
quoted
-----------------------------------------------------------------------------------
This email message is for the sole use of the intended recipient(s) and may contain
confidential information. Any unauthorized review, use, disclosure or distribution
is prohibited. If you are not the intended recipient, please contact the sender by
reply email and destroy all copies of the original message.
-----------------------------------------------------------------------------------
I'm certainly not a lawyer, and I'm sorry for not reviewing the
content of the patch instead, but is that not a problem from a legal
point of view ?
Talking about legal, is it a problem if a commit isn't signed-off by
it's committer or author e-mail? Like in this case where the sign-off is
from gmail.com and the committer from nvidia.com?
--
Med vänliga hälsningar
Fredrik Gustafsson
tel: 0733-608274
e-post: iveqy@iveqy.com
On Wed, Jul 31, 2013 at 2:08 PM, Antoine Pelisse [off-list ref] wrote:
On Wed, Jul 31, 2013 at 9:51 PM, Brandon Casey [off-list ref] wrote:
quoted
-----------------------------------------------------------------------------------
This email message is for the sole use of the intended recipient(s) and may contain
confidential information. Any unauthorized review, use, disclosure or distribution
is prohibited. If you are not the intended recipient, please contact the sender by
reply email and destroy all copies of the original message.
-----------------------------------------------------------------------------------
I'm certainly not a lawyer, and I'm sorry for not reviewing the
content of the patch instead, but is that not a problem from a legal
point of view ?
I remember a video of Greg Kroah-Hartman where he talked about that
(the video was posted by Junio on G+).
Me either thank God. Are those footers even enforceable? I mean,
really, if someone mistakenly sends me their corporate financial
numbers am I supposed to be under some legal obligation not to share
it? I always assumed it was a scare tactic that lawyers like to use.
To address the text of the footer, I'd say the "intended recipient(s)"
are those on the "to" line which includes git@vger.kernel.org and the
implicit use is for inclusion and distribution in the git source code.
Anyway, I doubt I would have any influence on getting the footer
removed. If Junio would rather me not submit patches with that
footer, then I'd try to find a workaround.
-Brandon
On Wed, Jul 31, 2013 at 2:21 PM, Fredrik Gustafsson [off-list ref] wrote:
On Wed, Jul 31, 2013 at 11:08:21PM +0200, Antoine Pelisse wrote:
quoted
On Wed, Jul 31, 2013 at 9:51 PM, Brandon Casey [off-list ref] wrote:
quoted
-----------------------------------------------------------------------------------
This email message is for the sole use of the intended recipient(s) and may contain
confidential information. Any unauthorized review, use, disclosure or distribution
is prohibited. If you are not the intended recipient, please contact the sender by
reply email and destroy all copies of the original message.
-----------------------------------------------------------------------------------
I'm certainly not a lawyer, and I'm sorry for not reviewing the
content of the patch instead, but is that not a problem from a legal
point of view ?
Talking about legal, is it a problem if a commit isn't signed-off by
it's committer or author e-mail? Like in this case where the sign-off is
from gmail.com and the committer from nvidia.com?
It never has been. My commits should have the author and committer
set to my gmail address actually.
Others have sometimes used the two fields to distinguish between a
corporate identity (i.e. me@somecompany.com) that represents the
funder of the work and a canonical identity (me@personalemail.com)
that identifies the person that performed the work.
-Brandon
From: Fredrik Gustafsson <hidden> Date: 2016-06-15 22:58:17
On Wed, Jul 31, 2013 at 02:31:34PM -0700, Brandon Casey wrote:
On Wed, Jul 31, 2013 at 2:21 PM, Fredrik Gustafsson [off-list ref] wrote:
quoted
On Wed, Jul 31, 2013 at 11:08:21PM +0200, Antoine Pelisse wrote:
quoted
On Wed, Jul 31, 2013 at 9:51 PM, Brandon Casey [off-list ref] wrote:
quoted
-----------------------------------------------------------------------------------
This email message is for the sole use of the intended recipient(s) and may contain
confidential information. Any unauthorized review, use, disclosure or distribution
is prohibited. If you are not the intended recipient, please contact the sender by
reply email and destroy all copies of the original message.
-----------------------------------------------------------------------------------
I'm certainly not a lawyer, and I'm sorry for not reviewing the
content of the patch instead, but is that not a problem from a legal
point of view ?
Talking about legal, is it a problem if a commit isn't signed-off by
it's committer or author e-mail? Like in this case where the sign-off is
from gmail.com and the committer from nvidia.com?
It never has been. My commits should have the author and committer
set to my gmail address actually.
Oh, that's why the extra "From: " - field below the header is for.
Others have sometimes used the two fields to distinguish between a
corporate identity (i.e. me@somecompany.com) that represents the
funder of the work and a canonical identity (me@personalemail.com)
that identifies the person that performed the work.
In some contries your work when you're employed does not belong
to you but to your employer and when you're acting for your employer
you're representing the corporate legal person. Therefore two different
e-mails can be seen as two different (legal not physical) persons.
At least that's how I understand those "legal tips for developers" I've
got.
--
Med vänliga hälsningar
Fredrik Gustafsson
tel: 0733-608274
e-post: iveqy@iveqy.com