git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git submodule: update=!command

From
Jeff King <peff@peff.net>
Date
Mar 17, 2015, 19:50 UTC
Message-ID
<20150317195030.GA18725@peff.net>
In-Reply-To
<1426620537.1785877.241673949.72FB3B40@webmail.messagingengine.com>
On Tue, Mar 17, 2015 at 03:28:57PM -0400, Ryan Lortie wrote:
Show 5 quoted lines
> The first is a question about git's basic policy with respect to things
> like this.  I hope that it's safe to assume that running 'git' commands
> on repositories downloaded from potentially-hostile places will never
> result in the authors of those repositories being able to run code on my
> machine.

Definitely, our policy is that downloading a git repository should not result in arbitrary code being run. If there is a case of that, it would be a serious security bug.

I am not an expert on submodules, but I think the security module there is:

  1. You can do whatever you like in submodule.*.update entries in
     .git/config, including arbitrary code. Nobody but the user can
     write to it.
  2. The submodule code may migrate entries from .gitmodules into
     .git/config, but does so with an allow-known-good whitelist (see
     git-submodule.sh lines 622-637).

So AFAICT there's no bug here, and the system is working as designed. It might be worth mentioning that restriction in the submodule documentation, if only to prevent non-malicious people from wondering why adding "!foo" does not work in .gitmodules.

> If that is true then, the second request would be to spell this out more
> explicitly in the relevant documentation.  I'm happy to write a patch to
> do that, if it is deemed appropriate.

Yeah, spelling out the security model more explicitly would be good. There is also some subtlety around hooks. Doing:

  git clone user@host:/path/to/repo.git local

should never run code controlled by "repo.git" as "user@host". But doing:

  ssh user@host 'cd /path/to/repo.git && git log'

will respect the .git/config in repo.git, which may include arbitrary commands.

-Peff
Previous: Ryan LortieNext: Ryan Lortie
Message 2 of 10 in “git submodule: update=!command”
  1. Ryan LortieMar 17, 2015
  2. Jeff KingMar 17, 2015
  3. Ryan LortieMar 17, 2015
  4. Chris PackhamMar 18, 2015
  5. Junio C HamanoMar 17, 2015
  6. Ryan LortieMar 17, 2015
  7. Junio C HamanoMar 17, 2015
  8. Ryan LortieMar 17, 2015
  9. Chris PackhamMar 18, 2015
  10. Chris PackhamMar 18, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.