go-git-packfile-ofs-delta-cycle-resolution
I've implemented, tested, and documented the complete solution.
Deliverables
- ~/packfile/packfile.go — the streaming Git packfile v2 reader (631 lines)
- ~/packfile/packfile_test.go — real-git + synthetic adversarial tests (581 lines)
- ~/SOLUTION.md — self-contained write-up with root-cause analysis, the exact code, usage, and verification (1,472 lines, code embeds verified byte-exact against the source)
Root causes addressed
| Trap | Fix |
|---|---|
| 2 GB pack loaded into RAM | os.File.ReadAt + per-object io.SectionReader; Open reads only headers/idx, payloads inflate lazily |
| Delta base is itself a delta | Recursive resolve(offset, depth) propagating the ultimate base's type; oid→offset and offset→entry maps |
| Declared base size lies | Reject when delta source-size varint ≠ len(materialized base) |
| OFS offset underflow | Reject distance > off-12 and verify the computed base offset is a real object |
| Chain deeper than 50 | depth > MaxDeltaDepth rejected before work |
| Truncated / self-referential copy operands | Every operand read is bounds-checked; copy checked via size <= len(base)-off (overflow-safe) |
| No integrity check | Every reconstructed object's SHA-1 compared to the .idx oid |
Objects stream in ascending pack order via ForEach; memory is bounded by the largest object plus its materialized base, never the pack.
Verification (all pass, including -race)
- Real packs: git repack → 24 OFS-deltas; git pack-objects → 24 REF-deltas; both SHA-1 verified end-to-end.
- Adversarial packs built byte-by-byte (OFS distance encoding + v2 idx writer): base-size mismatch, OFS underflow, 51-deep chain, truncated copy operand, out-of-range copy, corrupted index oid.
- A 30-level alternating OFS/REF chain resolves correctly, and the delta encoder round-trips.
The reproduction commands are in section 4 of SOLUTION.md (go vet ./..., go test -v -count=1 ./..., go test -race -count=1 ./...).
# Evidence - Problem class: go-git-packfile-ofs-delta-cycle-resolution - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-20T16:50:10.453Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Implement a reader for Git's v2 packfile format that fully resolves both REF_DELTA (object-id base) and OFS_DELTA (negative-offset base) chains, including bases that are themselves deltas, without ever loading a 2 GB pack into memory. Handle the adversarial cases: a delta whose declared base size disagrees with the materialized base; an OFS_DELTA whose raw offset underflows past the pack header; a delta chain deeper than 50; and copy instructions with truncated offset/size operands that make a delta self-referential. Verify every reconstructed object's SHA-1 against the pack index, keep resident memory proportional to the largest single object rather than the pack, and stream resolved objects to the caller in pack order.", "environment": "go1.26", "language": "go", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "go-git-packfile-ofs-delta-cycle-resolution", "provider": "openrouter", "solved_at": "2026-09-20T16:50:10.454Z", "version": "1.26"}I've implemented, tested, and documented the complete solution.
Deliverables
- ~/packfile/packfile.go — the streaming Git packfile v2 reader (631 lines)
- ~/packfile/packfile_test.go — real-git + synthetic adversarial tests (581 lines)
- ~/SOLUTION.md — self-contained write-up with root-cause analysis, the exact code, usage, and verification (1,472 lines, code embeds verified byte-exact against the source)
Root causes addressed
| Trap | Fix |
|---|---|
| 2 GB pack loaded into RAM | os.File.ReadAt + per-object io.SectionReader; Open reads only headers/idx, payloads inflate lazily |
| Delta base is itself a delta | Recursive resolve(offset, depth) propagating the ultimate base's type; oid→offset and offset→entry maps |
| Declared base size lies | Reject when delta source-size varint ≠ len(materialized base) |
| OFS offset underflow | Reject distance > off-12 and verify the computed base offset is a real object |
| Chain deeper than 50 | depth > MaxDeltaDepth rejected before work |
| Truncated / self-referential copy operands | Every operand read is bounds-checked; copy checked via size <= len(base)-off (overflow-safe) |
| No integrity check | Every reconstructed object's SHA-1 compared to the .idx oid |
Objects stream in ascending pack order via ForEach; memory is bounded by the largest object plus its materialized base, never the pack.
Verification (all pass, including -race)
- Real packs: git repack → 24 OFS-deltas; git pack-objects → 24 REF-deltas; both SHA-1 verified end-to-end.
- Adversarial packs built byte-by-byte (OFS distance encoding + v2 idx writer): base-size mismatch, OFS underflow, 51-deep chain, truncated copy operand, out-of-range copy, corrupted index oid.
- A 30-level alternating OFS/REF chain resolves correctly, and the delta encoder round-trips.
The reproduction commands are in section 4 of SOLUTION.md (go vet ./..., go test -v -count=1 ./..., go test -race -count=1 ./...).
# Evidence - Problem class: go-git-packfile-ofs-delta-cycle-resolution - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-20T16:50:10.453Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Implement a reader for Git's v2 packfile format that fully resolves both REF_DELTA (object-id base) and OFS_DELTA (negative-offset base) chains, including bases that are themselves deltas, without ever loading a 2 GB pack into memory. Handle the adversarial cases: a delta whose declared base size disagrees with the materialized base; an OFS_DELTA whose raw offset underflows past the pack header; a delta chain deeper than 50; and copy instructions with truncated offset/size operands that make a delta self-referential. Verify every reconstructed object's SHA-1 against the pack index, keep resident memory proportional to the largest single object rather than the pack, and stream resolved objects to the caller in pack order.", "environment": "go1.26", "language": "go", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "go-git-packfile-ofs-delta-cycle-resolution", "provider": "openrouter", "solved_at": "2026-09-20T16:50:10.454Z", "version": "1.26"}