git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] archive: re-allow HEAD:Documentation on a remote invocation

From
Jeff King <peff@peff.net>
Date
Jan 12, 2012, 02:54 UTC
Message-ID
<20120112025445.GB25365@sigill.intra.peff.net>
In-Reply-To
<7vipkh4oyn.fsf@alter.siamese.dyndns.org>
On Wed, Jan 11, 2012 at 06:46:56PM -0800, Junio C Hamano wrote:
Show 10 quoted lines
> Carlos Martín Nieto <cmn@elego.de> writes:
> 
> > The tightening done in (ee27ca4a: archive: don't let remote clients
> > get unreachable commits, 2011-11-17) went too far and disallowed
> > HEAD:Documentation as it would try to find "HEAD:Documentation" as a
> > ref.
> 
> I do not think it went too far. Actually we discussed this exact issue
> when the topic was cooking, and saw no objections. The commit in question
> itself advertises this restriction.

I think you and I discussed it off list (I originally took this off-list because the original issue did have some security implications). So I don't think people necessarily had a chance to object.

> Why are we loosening it now? I do not see a compelling reason to do so.

I see it the opposite way. People are clearly using the "$ref:$path" syntax. So why would we restrict them from doing so? There are no security implications (i.e., they could always just grab $ref and extract $path themselves). In my view, ee27ca4a was over-eager in its restrictions because I wanted it to be simple and close the hole. Now we can take our time adding more code to loosen it.

-Peff
Previous: Junio C HamanoNext: Jeff King
Message 24 of 30 in “[BUG] git archive broken in 1.7.8.1”
  1. Albert Astals CidJan 10, 2012
  2. Carlos Martín NietoJan 10, 2012
  3. Albert Astals CidJan 10, 2012
  4. Carlos Martín NietoJan 10, 2012
  5. Jeff KingJan 10, 2012
  6. archive: re-allow HEAD:Documentation on a remote invocationCarlos Martín Nieto, Jan 11, 2012
  7. Jeff KingJan 11, 2012
  8. 1/2 get_sha1_with_context: report features used in resolutionJeff King, Jan 11, 2012
  9. Junio C HamanoJan 12, 2012
  10. Jeff KingJan 12, 2012
  11. 2/2 archive: loosen restrictions on remote object lookupJeff King, Jan 11, 2012
  12. Ian HarveyMay 29, 2013
  13. Jeff KingJun 5, 2013
  14. 0/4 real reachability checks for upload-archiveJeff King, Jun 5, 2013
  15. 1/4 clear parsed flag when we free tree buffersJeff King, Jun 5, 2013
  16. Junio C HamanoJun 6, 2013
  17. 2/4 upload-archive: restrict remote objects with reachability checkJeff King, Jun 5, 2013
  18. 3/4 list-objects: optimize "revs->blob_objects = 0" caseJeff King, Jun 5, 2013
  19. 4/4 archive: ignore blob objects when checking reachabilityJeff King, Jun 5, 2013
  20. Michael HaggertyJun 6, 2013
  21. Eric SunshineJun 7, 2013
  22. Junio C HamanoJun 6, 2013
  23. Junio C HamanoJan 12, 2012
  24. Jeff KingJan 12, 2012
  25. Jeff KingJan 12, 2012
  26. Junio C HamanoJan 12, 2012
  27. Jeff KingJan 12, 2012
  28. Junio C HamanoJan 12, 2012
  29. Allan WindJan 10, 2012
  30. Carlos Martín NietoJan 11, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.