{"thread":{"id":"57061","subject":"Issue with git clone via http/https and alternates","startedAt":"2021-12-09T19:59:19Z","lastAt":"2021-12-10T04:08:19Z","messageCount":2,"participants":["Ralf Baechle","Jeff King"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"443686","messageId":"YbJgEnvuKm+GGXkd@linux-mips.org","threadId":"57061","inReplyTo":null,"subject":"Issue with git clone via http/https and alternates","fromName":"Ralf Baechle","fromEmail":"ralf@linux-mips.org","sentAt":"2021-12-09T19:59:14Z","receivedAt":"2021-12-09T19:59:19Z","isPatch":false,"sender":{"key":"ralf@linux-mips.org","avatar":null},"body":"I'm hosting a number of largish repositories which being very similar\nare using git's alternates feature to save disk and memory.  Cloning via\ngit:// or ssh for users with accounts on the server works as expected but\ncloning via http or https results fails as follows:\n\n$ git clone http://git.linux-mips.org/pub/scm/linux-mti.git\nCloning into 'linux-mti'...\nwarning: alternate disabled by http.followRedirects: http://git.linux-mips.org/pub/scm/ralf/linux.git/\nerror: Unable to find e4add961d4aaeb19f607f6d7bea8d59e1bd39ff0 under http://git.linux-mips.org/pub/scm/linux-mti.git\nFetching objects: 11, done.\nCannot obtain needed object e4add961d4aaeb19f607f6d7bea8d59e1bd39ff0\nwhile processing commit 9e2bf7cf7d9003c0f06736be5218ed79234f254c.\nerror: fetch failed.\n\nAdding -c http.followRedirects=true will make the clone succeed. Question,\nshouldn't the default of http.followRedirects=initial already suffice?\n\nAnyway, what I'm looking for is something I can do serverside so users\ncloning the repository are not bothered with this http.followRedirects\nbusiness.  Is there anything I can do?\n\nThanks,\n\n  Ralf\n"},{"id":"443743","messageId":"YbLSsbBOtcFb0hIy@coredump.intra.peff.net","threadId":"57061","inReplyTo":"YbJgEnvuKm+GGXkd@linux-mips.org","subject":"Re: Issue with git clone via http/https and alternates","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2021-12-10T04:08:17Z","receivedAt":"2021-12-10T04:08:19Z","isPatch":false,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Thu, Dec 09, 2021 at 08:59:14PM +0100, Ralf Baechle wrote:\n\n> I'm hosting a number of largish repositories which being very similar\n> are using git's alternates feature to save disk and memory.  Cloning via\n> git:// or ssh for users with accounts on the server works as expected but\n> cloning via http or https results fails as follows:\n> \n> $ git clone http://git.linux-mips.org/pub/scm/linux-mti.git\n> Cloning into 'linux-mti'...\n> warning: alternate disabled by http.followRedirects: http://git.linux-mips.org/pub/scm/ralf/linux.git/\n> error: Unable to find e4add961d4aaeb19f607f6d7bea8d59e1bd39ff0 under http://git.linux-mips.org/pub/scm/linux-mti.git\n> Fetching objects: 11, done.\n> Cannot obtain needed object e4add961d4aaeb19f607f6d7bea8d59e1bd39ff0\n> while processing commit 9e2bf7cf7d9003c0f06736be5218ed79234f254c.\n> error: fetch failed.\n> \n> Adding -c http.followRedirects=true will make the clone succeed. Question,\n> shouldn't the default of http.followRedirects=initial already suffice?\n\nThere are security implications to allowing more redirects. See\ncb4d2d35c4 (http: treat http-alternates like redirects, 2016-12-06).\nThat commit message does mention that we could be more lenient for\nsame-server redirects here, but AFAIK this is the first time anybody\ncared enough to even bring it up the list.\n\nThat said...\n\n> Anyway, what I'm looking for is something I can do serverside so users\n> cloning the repository are not bothered with this http.followRedirects\n> business.  Is there anything I can do?\n\nTurn on smart-http support for your server. The dumb-http protocol is\nrather inefficient, and is what requires the client to even know about\nyour server-side alternates in the first place. And personally, I have a\nlot less trust in it in general, compared to smart-http. There have been\ntons of fixes and improvements in the smart-http code in the past 10\nyears, and I don't think anybody is really paying much attention to\ndumb-http.\n\n-Peff\n"}]}