git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 0/3] refs-advertise: add hook to filter advertised refs

From
孙超 <16657101987@163.com>
Date
Aug 10, 2022, 13:09 UTC
Message-ID
<1E392965-45B2-4CD8-942C-24E3CA045ABD@163.com>
In-Reply-To
<CANYiYbFc6xywoCPgge+RMb6Scr8JwS2f=n65XG2jupHS-w2jLw@mail.gmail.com>
Show 34 quoted lines
> On Aug 10, 2022, at 09:06, Jiang Xin <worldhello.net@gmail.com> wrote:
> 
> On Thu, Aug 4, 2022 at 12:31 AM Sun Chao via GitGitGadget
> <gitgitgadget@gmail.com> wrote:
>> 
>> Gerrit is implemented by JGit and is known as a centralized workflow system
>> which supports reference-level access control for repository. If we choose
>> to work in centralized workflow like what Gerrit provided, reference-level
>> access control is needed and is possible if we add a reference advertise
>> filter hook just like what Gerrit did.
>> 
>> This hook would be invoked by 'git-receive-pack' and 'git-upload-pack'
>> during the reference discovery phase and the commit fetching phase, each
>> reference and will be filtered by this hook. Git server can put
>> reference-level control process to this hook and the git client does not
>> need to change or known about that.
> 
> From the document you provided in patch 3/3, the hook returns not only
> names of the references, but also OIDs. Since the oid of reference
> should be provided as-is during the advertising phase, it is
> sufficient for the hook to just return the visible reference names.
> 
> How about:
> 1. Implement a batch version of "ref_is_hidden()", such as
>    "refs_batch_hidden()", to turn on or turn off the hidden bit
>    for all references.
> 
> 2. If there is an external hook, such as "hide-refs", call it instead
>    of the config variables such as "transfer.hideRefs" to filter refs
>    based on ACL and operations (read and write).
> 
> --
> Jiang Xin
> 
Thanks a lot, Jiang Xin.

Your suggestion is right, for protocol V1 we do not need to filter the OIDs, and there should be a configuration to turn on/off the hidden bit, I will try to add such kind of configuration, maybe "transfer.hideRefs" is a good choice.

And after received Junio's reply I also did tests for V2, I find that even I hide all the refs (by "git config transfer.hiderefs refs/" in upstream) the client can still fetch specific object by it’s object id, here is the trace log:

```
.............................           trace: built-in: git fetch origin 5585e358b2a240ca8ed65a00008dbc865a1381c1
.............................           packet:        fetch< version 2
.............................           packet:        fetch< agent=git/2.37.1.288.gef002b009d
.............................           packet:        fetch> command=ls-refs
# the server does not advertise any refs
.............................           packet:        fetch< 0000
.............................           packet:        fetch> command=fetch
# the client send the want command with object oid
.............................           packet:        fetch> want 5585e358b2a240ca8ed65a00008dbc865a1381c1
.............................           packet:        fetch> done
.............................           packet:        fetch> 0000
.............................           packet:        fetch< packfile
# the client received the packfile contains the objects
.............................
From file:///local/upstream.git
 * branch                5585e358b2a240ca8ed65a00008dbc865a1381c1 -> FETCH_HEAD
```

Protocol V2 does not limit the request to the advertised refs, and if we want to hide some refs, we need to hide the objects only reachable from them (for V2), but it truly has performance issue for some huge repository.

Previous: Jiang XinNext: Sun Chao via GitGitGadget
Message 8 of 42 in “refs-advertise: add hook to filter advertised refs”
  1. 0/3 refs-advertise: add hook to filter advertised refsSun Chao via GitGitGadget, Aug 3, 2022
  2. 1/3 refs-advertise: add hook to filter advertised refsSun Chao via GitGitGadget, Aug 3, 2022
  3. 3/3 doc: add documentation for the refs-advertise hookSun Chao via GitGitGadget, Aug 3, 2022
  4. 2/3 t1419: add test cases for refs-advertise hookSun Chao via GitGitGadget, Aug 3, 2022
  5. Junio C HamanoAug 3, 2022
  6. 孙超Aug 4, 2022
  7. Jiang XinAug 10, 2022
  8. 孙超Aug 10, 2022
  9. 0/3 hide-refs: add hook to force hide refsSun Chao via GitGitGadget, Aug 15, 2022
  10. 1/3 hide-refs: add hook to force hide refsSun Chao via GitGitGadget, Aug 15, 2022
  11. 2/3 t1419: add test cases for hide-refs hookSun Chao via GitGitGadget, Aug 15, 2022
  12. 3/3 doc: add documentation for the hide-refs hookSun Chao via GitGitGadget, Aug 15, 2022
  13. Eric SunshineAug 15, 2022
  14. 孙超Aug 15, 2022
  15. Junio C HamanoAug 15, 2022
  16. 0/3 hide-refs: add hook to force hide refsSun Chao via GitGitGadget, Aug 15, 2022
  17. 1/3 hide-refs: add hook to force hide refsSun Chao via GitGitGadget, Aug 15, 2022
  18. 3/3 doc: add documentation for the hide-refs hookSun Chao via GitGitGadget, Aug 15, 2022
  19. 2/3 t1419: add test cases for hide-refs hookSun Chao via GitGitGadget, Aug 15, 2022
  20. 0/3 hide-refs: add hook to force hide refsSun Chao via GitGitGadget, Aug 15, 2022
  21. 3/3 doc: add documentation for the hide-refs hookSun Chao via GitGitGadget, Aug 15, 2022
  22. 1/3 hide-refs: add hook to force hide refsSun Chao via GitGitGadget, Aug 15, 2022
  23. Junio C HamanoAug 15, 2022
  24. 孙超Aug 16, 2022
  25. Calvin WanAug 18, 2022
  26. 孙超Aug 19, 2022
  27. 2/3 t1419: add test cases for hide-refs hookSun Chao via GitGitGadget, Aug 15, 2022
  28. 0/5 hiderefs: add hide-refs hook to hide refs dynamicallySun Chao via GitGitGadget, Sep 9, 2022
  29. 1/5 hiderefs: add hide-refs hook to hide refs dynamicallySun Chao via GitGitGadget, Sep 9, 2022
  30. Junio C HamanoSep 13, 2022
  31. Junio C HamanoSep 16, 2022
  32. 孙超Sep 17, 2022
  33. 2/5 hiderefs: use new flag to mark force hidden refsSun Chao via GitGitGadget, Sep 9, 2022
  34. 3/5 hiderefs: hornor hide flags in wire protocol V2Sun Chao via GitGitGadget, Sep 9, 2022
  35. 4/5 test: add test cases for hide-refs hookSun Chao via GitGitGadget, Sep 9, 2022
  36. 5/5 doc: add documentation for the hide-refs hookSun Chao via GitGitGadget, Sep 9, 2022
  37. 0/5 hiderefs: add hide-refs hook to hide refs dynamicallySun Chao via GitGitGadget, Sep 20, 2022
  38. 1/5 hiderefs: add hide-refs hook to hide refs dynamicallySun Chao via GitGitGadget, Sep 20, 2022
  39. 3/5 hiderefs: hornor hide flags in wire protocol V2Sun Chao via GitGitGadget, Sep 20, 2022
  40. 2/5 hiderefs: use a new flag to mark force hidden refsSun Chao via GitGitGadget, Sep 20, 2022
  41. 5/5 doc: add documentation for the hide-refs hookSun Chao via GitGitGadget, Sep 20, 2022
  42. 4/5 test: add test cases for hide-refs hookSun Chao via GitGitGadget, Sep 20, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.