git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] archive: re-allow HEAD:Documentation on a remote invocation

From
Jeff King <peff@peff.net>
Date
Jan 12, 2012, 02:59 UTC
Message-ID
<20120112025910.GA26038@sigill.intra.peff.net>
In-Reply-To
<20120112025445.GB25365@sigill.intra.peff.net>
On Wed, Jan 11, 2012 at 09:54:45PM -0500, Jeff King wrote:
Show 16 quoted lines
> On Wed, Jan 11, 2012 at 06:46:56PM -0800, Junio C Hamano wrote:
> 
> > Carlos Martín Nieto <cmn@elego.de> writes:
> > 
> > > The tightening done in (ee27ca4a: archive: don't let remote clients
> > > get unreachable commits, 2011-11-17) went too far and disallowed
> > > HEAD:Documentation as it would try to find "HEAD:Documentation" as a
> > > ref.
> > 
> > I do not think it went too far. Actually we discussed this exact issue
> > when the topic was cooking, and saw no objections. The commit in question
> > itself advertises this restriction.
> 
> I think you and I discussed it off list (I originally took this off-list
> because the original issue did have some security implications). So I
> don't think people necessarily had a chance to object.
Here is the only on-list discussion:
  http://article.gmane.org/gmane.comp.version-control.git/186366
Quoted below:
  >> * jk/maint-1.6.2-upload-archive (2011-11-21) 1 commit
  >>  - archive: don't let remote clients get unreachable commits
  >>  (this branch is used by jk/maint-upload-archive.)
  >>
  >> * jk/maint-upload-archive (2011-11-21) 1 commit
  >>  - Merge branch 'jk/maint-1.6.2-upload-archive' into
  >>  jk/maint-upload-archive
  >>  (this branch uses jk/maint-1.6.2-upload-archive.)
  >>
  >> Will merge to 'next' after taking another look.
  >
  > Thanks. I also have some followup patches to re-loosen to at least
  > trees reachable from refs. Do you want to leave the tightening to
  > the maint track, and then consider the re-loosening for master?
  I was planning to first have the really tight version graduate to
  'master' and ship it in 1.7.9, while possibly merging that to 1.7.8.X
  series.  If we hear complaints from real users in the meantime before
  or after such releases, we could apply loosening patch on top of these
  topics and call them "regression fix", but I have been assuming that
  nobody would have been using this backdoor for anything that really
  matters.
So now we have heard a complaint. :)
-Peff
Previous: Jeff KingNext: Junio C Hamano
Message 25 of 30 in “[BUG] git archive broken in 1.7.8.1”
  1. Albert Astals CidJan 10, 2012
  2. Carlos Martín NietoJan 10, 2012
  3. Albert Astals CidJan 10, 2012
  4. Carlos Martín NietoJan 10, 2012
  5. Jeff KingJan 10, 2012
  6. archive: re-allow HEAD:Documentation on a remote invocationCarlos Martín Nieto, Jan 11, 2012
  7. Jeff KingJan 11, 2012
  8. 1/2 get_sha1_with_context: report features used in resolutionJeff King, Jan 11, 2012
  9. Junio C HamanoJan 12, 2012
  10. Jeff KingJan 12, 2012
  11. 2/2 archive: loosen restrictions on remote object lookupJeff King, Jan 11, 2012
  12. Ian HarveyMay 29, 2013
  13. Jeff KingJun 5, 2013
  14. 0/4 real reachability checks for upload-archiveJeff King, Jun 5, 2013
  15. 1/4 clear parsed flag when we free tree buffersJeff King, Jun 5, 2013
  16. Junio C HamanoJun 6, 2013
  17. 2/4 upload-archive: restrict remote objects with reachability checkJeff King, Jun 5, 2013
  18. 3/4 list-objects: optimize "revs->blob_objects = 0" caseJeff King, Jun 5, 2013
  19. 4/4 archive: ignore blob objects when checking reachabilityJeff King, Jun 5, 2013
  20. Michael HaggertyJun 6, 2013
  21. Eric SunshineJun 7, 2013
  22. Junio C HamanoJun 6, 2013
  23. Junio C HamanoJan 12, 2012
  24. Jeff KingJan 12, 2012
  25. Jeff KingJan 12, 2012
  26. Junio C HamanoJan 12, 2012
  27. Jeff KingJan 12, 2012
  28. Junio C HamanoJan 12, 2012
  29. Allan WindJan 10, 2012
  30. Carlos Martín NietoJan 11, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.