git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Commit ID in exported Tar Ball

From
Petr Baudis <pasky@suse.cz>
Date
May 21, 2007, 12:09 UTC
Message-ID
<20070521120920.GF4489@pasky.or.cz>
In-Reply-To
<20070521060231.GI3141@spearce.org>
On Mon, May 21, 2007 at 08:02:32AM CEST, Shawn O. Pearce wrote:
Show 18 quoted lines
> Ren?? Scharfe <rene.scharfe@lsrfire.ath.cx> wrote:
> > Shawn O. Pearce schrieb:
> > > 
> > > git-describe is more human-friendly than a SHA-1...
> > 
> > Yes, and the Makefile does even more than that: it adds a version file,
> > a spec file and another version file for git-gui.
> > 
> > The first two are probably useful for most projects that actually do
> > versioned releases.  We could have a simple parser that reads a
> > template, replaces @@VERSION@@ with a git-describe output string and
> > adds the result as a synthetic file to the archive.  It's not exactly
> > trivial -- e.g., how to specify git-describe options, template file and
> > synthetic name, all in one command line parameter? -- but it's doable.
> 
> Maybe something just as simple as allowing the user to specify a
> shell script in-tree that we unpack and run for them?  That script
> prints to stdout the content of the file to include.

Specify how? At the point of git-archive execution? At that point you usually can append the file to the archive as well.

And if you make it somehow a "project default", that becomes a huge security risk, since anyone who clones the project and runs git-archive will execute aribtrary code on his account.

Besides, the original motivation for this were snapshots from gitweb. Gitweb frequently does not run with the uid of the project owner, so this becomes a security problem as well.

Maybe some kind of format-string in .git/config...
-- 
				Petr "Pasky" Baudis
Stuff: http://pasky.or.cz/
Ever try. Ever fail. No matter. // Try again. Fail again. Fail better.
		-- Samuel Beckett
Previous: Shawn O. PearceNext: René Scharfe
Message 17 of 38 in “Commit ID in exported Tar Ball”
  1. Thomas GlanzmannMay 17, 2007
  2. Johan HerlandMay 17, 2007
  3. Frank LichtenheldMay 17, 2007
  4. Thomas GlanzmannMay 17, 2007
  5. Johan HerlandMay 17, 2007
  6. git-archive: convert archive entries like checkouts doRené Scharfe, May 18, 2007
  7. Daniel BarkalowMay 18, 2007
  8. René ScharfeMay 18, 2007
  9. René ScharfeMay 19, 2007
  10. Junio C HamanoMay 19, 2007
  11. A Large Angry SCMMay 19, 2007
  12. René ScharfeMay 20, 2007
  13. René ScharfeMay 20, 2007
  14. Shawn O. PearceMay 20, 2007
  15. René ScharfeMay 20, 2007
  16. Shawn O. PearceMay 21, 2007
  17. Petr BaudisMay 21, 2007
  18. René ScharfeMay 21, 2007
  19. René ScharfeMay 22, 2007
  20. Junio C HamanoMay 22, 2007
  21. René ScharfeMay 22, 2007
  22. Shawn O. PearceMay 23, 2007
  23. René ScharfeMay 20, 2007
  24. Thomas GlanzmannMay 20, 2007
  25. Brian GernhardtMay 20, 2007
  26. Thomas GlanzmannMay 20, 2007
  27. Peter BaumannMay 21, 2007
  28. Thomas GlanzmannMay 21, 2007
  29. Shawn O. PearceMay 21, 2007
  30. Thomas GlanzmannMay 21, 2007
  31. Shawn O. PearceMay 21, 2007
  32. Thomas GlanzmannMay 21, 2007
  33. Brian GernhardtMay 21, 2007
  34. Thomas GlanzmannMay 21, 2007
  35. Frank LichtenheldMay 17, 2007
  36. Johan HerlandMay 17, 2007
  37. Kristian HøgsbergMay 17, 2007
  38. Thomas GlanzmannMay 17, 2007

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.