git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Fetch/push lets a malicious server steal the targets of "have" lines

From
Jeff King <peff@peff.net>
Date
Oct 29, 2016, 19:10 UTC
Message-ID
<20161029191023.ztrfe76u4gi4l3ci@sigill.intra.peff.net>
In-Reply-To
<1477757311.1524.21.camel@mattmccutchen.net>
On Sat, Oct 29, 2016 at 12:08:31PM -0400, Matt McCutchen wrote:
Show 7 quoted lines
> Let's focus on the first scenario.  There the user is just pulling and
> pushing a master branch.  Are you saying that each time the user pulls,
> they need to look over all the commits they pulled before pushing them
> back?  I think that's unrealistic, for example, on a busy project with
> centralized code review or if the user is publishing a project-specific 
> modified version of an upstream library.  The natural user expectation
> is that anything pulled from a public repository is public.

No, I'm saying if you are running "git push foo master", then you should expect the contents of "master" to go to "foo". That _could_ have security implications if you come up with a sequence of events where secret things made it to "master". But it seems to me that "foo previously lied to you about what it has" is not the weak link in that chain. It is not thinking about what secret things are hitting the master that you are pushing, no matter how they got there.

I agree there is a potential workflow (that you have laid out) where such lying can cause an innocent-looking sequence of events to disclose the secret commits. And again, I don't mind a note in the documentation mentioning that. I just have trouble believing it's a common one in practice.

The reason I brought up the delta thing, even though it's a much harder attack to execute, is that it comes up in much more common workflows, like simply fetching from a private security-sensitive repo into your "main" public repo (which is an example you brought up, and something I know that I have personally done in the past for git.git).

-Peff
Previous: Matt McCutchenNext: Junio C Hamano
Message 8 of 24 in “Fetch/push lets a malicious server steal the targets of "have" lines”
  1. Matt McCutchenOct 28, 2016
  2. Junio C HamanoOct 28, 2016
  3. Matt McCutchenOct 28, 2016
  4. Junio C HamanoOct 29, 2016
  5. Matt McCutchenOct 29, 2016
  6. Jeff KingOct 29, 2016
  7. Matt McCutchenOct 29, 2016
  8. Jeff KingOct 29, 2016
  9. Junio C HamanoOct 30, 2016
  10. fetch/push: document that private data can be leakedMatt McCutchen, Nov 13, 2016
  11. Junio C HamanoNov 14, 2016
  12. Matt McCutchenNov 14, 2016
  13. doc: mention transfer data leaks in more placesMatt McCutchen, Nov 14, 2016
  14. Junio C HamanoNov 14, 2016
  15. Junio C HamanoNov 14, 2016
  16. Jeff KingNov 14, 2016
  17. Junio C HamanoNov 14, 2016
  18. Matt McCutchenNov 14, 2016
  19. Jon LoeligerOct 29, 2016
  20. Junio C HamanoOct 30, 2016
  21. Matt McCutchenNov 13, 2016
  22. Matt McCutchenOct 29, 2016
  23. Junio C HamanoOct 30, 2016
  24. Matt McCutchenNov 13, 2016

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.