Skip to content

gitoxide

vgix-pack-v0.72.0 scope: gix-pack Breaking

This release includes 1 breaking change for platform teams planning a safe upgrade.

Published 1mo Version Control
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

blazingly-fast built-with-rust cli git version-control

Summary

AI summary

Bug fixes, breaking removal of index::Version::hash(), commit statistics updates, and SHA-256 pack integration.

Full changelog

Bug Fixes

  • cap aggregate delta data allocation in gix-pack
    A ClusterFuzz data_file testcase could build a malformed delta chain whose
    individual entry sizes stayed below the configured fuzz allocation cap, but
    whose aggregate decompressed delta payload size reached multi-gigabyte scale.
    The fuzz harness then attempted to reserve that aggregate buffer and aborted
    with libFuzzer out-of-memory.

    Reject aggregate delta payload sizes once they exceed
    File::with_alloc_limit_bytes(), matching the existing protection for individual
    decoded object sizes. Add the minimized ClusterFuzz testcase to the data_file
    artefacts so the known input remains available to the fuzz target and artifact
    smoke test.

Bug Fixes (BREAKING)

  • remove unused index::Version::hash() method.
    It's not useful either as there is no relationship between the Version
    of the index file and the hash to use.

Commit Statistics

  • 10 commits contributed to the release over the course of 27 calendar days.
  • 27 days passed between releases.
  • 2 commits were understood as conventional.
  • 0 issues like '(#ID)' were seen in commit messages

Commit Details

view details
  • Uncategorized
    • Merge pull request #2657 from GitoxideLabs/dev/aratiu/sha256-pack (cdafa6a)
    • Review (14025af)
    • Cover multi-index write under SHA-256 (bbf6fe3)
    • Correct the index-verification progress label for non-SHA-1 hashes (aa319aa)
    • Merge pull request #2632 from GitoxideLabs/fix-fuzz-failure (70d38bf)
    • Cap aggregate delta data allocation in gix-pack (6de909b)
    • Merge pull request #2602 from cruessler/run-gix-pack-tests-with-sha-256 (4f862a5)
    • Remove unused index::Version::hash() method. (ee91e31)
    • Add generated archives for SHA-256 in gix-pack (4f1bb83)
    • Merge pull request #2618 from GitoxideLabs/report (f7d4f33)

Breaking Changes

  • Removed unused `index::Version::hash()` method.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track gitoxide

Get notified when new releases ship.

Sign up free

About gitoxide

An idiomatic, lean, fast & safe pure Rust implementation of Git

All releases →

Related context

Related tools

Earlier breaking changes

  • vgix-v0.84.0 Allow checkouts of empty repositories; `destination_must_be_empty` becomes `Option<bool>`
  • vgix-worktree-stream-v0.33.0 Changes API of `Stream::add_entry_from_path` to require `hash_kind` argument.
  • vgix-object-v0.61.0 Renames `Data::hash_kind` to `Data::object_hash` for consistency.

Beta — feedback welcome: [email protected]