sparse-index: avoid crash on intent-to-add entry outside the cone

When collapsing a full index to a sparse index, the recursive convert_to_sparse_rec() walks the cache tree to determine if any of the cache tree entries can be used to represent a sparse directory. As it goes, the method tracks how many cache entries are being represented by the cache tree entry. The cache tree node's 'entry_count' represents how many cache entries are covered by the node. However, this value can be negative, representing that a node is invalid, and is no longer reflecting the number of cache entries fit within. This can happen when the user uses 'git add --intent-to-add' to mark an untracked file with the intent-to-add bit to avoid committing without finishing the add. When such an intent-to-add file exists and the sparse-checkout changes to no longer contain its parent directory, this leads to a segfault. Two tests are added to demonstrate this fault: * One test is added to t3705-add-sparse-checkout.sh to demonstrate how 'git add' behaves with sparse-checkout. * One test is added to t1092-sparse-checkout-compatibility.sh to demonstrate the interaction with the sparse index and to compare it directly to how the commands behave with a full index or no sparse-checkout. The fix involves engaging with the loop that iterates over all cache entries within the parent cache tree node (from 'start' to 'end') and to set the 'span' variable slightly earlier. At this point, the cache entry is for a file that is at least one directory deeper than the current cache tree node. The path is also not in the sparse-checkout because of an earlier path_in_sparse_checkout() check above the loop. So we are trying to collapse this directory by recursively calling convert_to_sparse_rec() over that span of entries, but the negative value prevents us from predicting that number without scanning. Theoretically, we could scan to find the range of entries that match this directory and determine if they truly do have an intent-to-add bit and then collapse as many child trees as possible (the ones with valid cache tree nodes). That would be a non-trivial change for performance-only benefit. Since this combination of the intent-to-add and sparse index features has so far gone undetected by real users, this scenario is unlikely to be worth such a change. We settle for the simplest change that prevents a bug: don't try to collapse a node that is invalid for this reason. The tests that would demonstrate a segfault now pass. Further, they demonstrate that the intent-to-add bit persists in the index file after changing the sparse-checkout scope. The test in t1092 demonstrates how some sparse directories could be collapsed further with a more involved fix, if so desired in the future. Signed-off-by: Derrick Stolee <stolee@gmail.com> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Derrick Stolee committed Jul 6, 2026 at 13:50 UTC eede1e69fe4b852f14cade6c18abd156fbcc8cd1
3 files changed +82 -1
sparse-index.c
+8 -1
@@ -113,10 +113,17 @@ static int convert_to_sparse_rec(struct index_state *istate,
113 continue;
114 }
115
116 + span = ct->down[pos]->cache_tree->entry_count;
117 + if (span < 0) {
118 + /* cache-tree entry is invalidated, cannot collapse. */
119 + istate->cache[num_converted++] = ce;
120 + i++;
121 + continue;
122 + }
123 +
124 strbuf_setlen(&child_path, 0);
125 strbuf_add(&child_path, ce->name, slash - ce->name + 1);
126
119 - span = ct->down[pos]->cache_tree->entry_count;
127 count = convert_to_sparse_rec(istate,
128 num_converted, i, i + span,
129 child_path.buf, child_path.len,
t/t1092-sparse-checkout-compatibility.sh
+48
@@ -384,6 +384,54 @@ test_expect_success 'add, commit, checkout' '
384 test_all_match git checkout -
385 '
386
387 +test_expect_success 'intent-to-add entries outside sparse-checkout' '
388 + init_repos &&
389 +
390 + write_script edit-contents <<-\EOF &&
391 + echo text >>$1
392 + EOF
393 +
394 + test_sparse_match git sparse-checkout set deep folder1 &&
395 + run_on_sparse mkdir -p folder1 &&
396 + run_on_all ../edit-contents folder1/newita &&
397 + test_sparse_match git add -N folder1/newita &&
398 +
399 + test_sparse_match git sparse-checkout set deep &&
400 + test_sparse_match git status --porcelain=v2 &&
401 + test_sparse_match git ls-files --stage
402 +'
403 +
404 +test_expect_success 'intent-to-add with --sparse outside sparse-checkout' '
405 + init_repos &&
406 +
407 + write_script edit-contents <<-\EOF &&
408 + echo text >>$1
409 + EOF
410 +
411 + run_on_all mkdir -p folder1 &&
412 + run_on_all ../edit-contents folder1/newita &&
413 + test_all_match git add --sparse --intent-to-add folder1/newita &&
414 +
415 + test_all_match git status --porcelain=v2 &&
416 + test_all_match git ls-files --stage &&
417 + test_all_match git diff --cached --stat &&
418 +
419 + # Ensure sparse index stores correct sparse directories and
420 + # intent-to-add path.
421 + git -C sparse-index ls-files --format="%(path)" --sparse >out &&
422 +
423 + # These paths should be present in index as-is.
424 + test_grep "^before/\$" out &&
425 + test_grep "^folder1/newita\$" out &&
426 + test_grep "^folder2/\$" out &&
427 + test_grep "^x/\$" out &&
428 +
429 + # folder/0/ could theoretically be collapsed to a sparse
430 + # directory entry, but the current implementation avoids the
431 + # reduction because of folder1/newita
432 + test_grep "^folder1/0/0/0\$" out
433 +'
434 +
435 test_expect_success 'git add, checkout, and reset with -p' '
436 init_repos &&
437
t/t3705-add-sparse-checkout.sh
+26
@@ -233,4 +233,30 @@ test_expect_success 'refuse to add non-skip-worktree file from sparse dir' '
233 test_cmp expect stderr
234 '
235
236 +test_expect_success 'intent-to-add entry and sparse index' '
237 + test_when_finished "git sparse-checkout disable" &&
238 + test_when_finished "git reset --hard" &&
239 +
240 + git sparse-checkout disable &&
241 + mkdir -p in out &&
242 + echo base >in/file &&
243 + echo base >out/file &&
244 + git add in/file out/file &&
245 + git commit -m "in and out directories" &&
246 +
247 + # enable sparse-checkout, but with all child directories.
248 + git config index.sparse true &&
249 + git sparse-checkout set in out &&
250 +
251 + # create a new path and set intent-to-add bit
252 + echo new >out/newita &&
253 + git add -N out/newita &&
254 +
255 + # collapse sparse-checkout, and make sure that the sparse index
256 + # maintains the intent-to-add bit.
257 + git sparse-checkout set in &&
258 + git ls-files --error-unmatch out/newita &&
259 + git status --porcelain
260 +'
261 +
262 test_done