git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: persistent-https, url insteadof, and `git submodule`

From
Jeff King <peff@peff.net>
Date
May 31, 2017, 21:22 UTC
Message-ID
<20170531212224.bhn36sa4g5ns54aj@sigill.intra.peff.net>
In-Reply-To
<CACBZZX6LQRW=78R-rkeUKmDCRUmN52SjkShSjDC5AgV5o7T6iQ@mail.gmail.com>
On Wed, May 31, 2017 at 04:23:49PM +0200, Ævar Arnfjörð Bjarmason wrote:
Show 14 quoted lines
> > It really is an issue of the user knowing about the problem (and how to
> > solve it), and I don't think we can get around that securely. So better
> > documentation probably is the right solution.
> >
> > I'll see if I can cook something up.
> 
> I was going to say: A way to have our cake & eat it too here would be
> to just support *.insteadOfRegex, i.e.
> "url.persistent-https://.insteadOfRegex="^https://".
> 
> But in this case, even if we can just do un-anchored string
> replacement, isn't a way around this just to do
> "url.persistent-https://.insteadOf=https://" & untaint & document that
> you should do that?

I think we already do the second form, and that's what Elliott ran into. The problem is that it is not clear if "persistent-https" is safe to use for submodules. _We_ know that it is because we know what that remote does, but Git doesn't know that. You would not necessarily want:

  [url "ext::ssh-wrapper "]
  insteadOf  = "ssh://"

to kick in for a submodule. That's a fairly insane thing to be doing, but the point is that we don't know if the rewritten protocol is ready to handle "tainted" URLs that come from an untrusted submodule file.

-Peff
Previous: Ævar Arnfjörð BjarmasonNext: Jeff King
Message 8 of 10 in “persistent-https, url insteadof, and `git submodule`”
  1. Elliott CableMay 19, 2017
  2. Dennis KaarsemakerMay 19, 2017
  3. Dennis KaarsemakerMay 19, 2017
  4. Jeff KingMay 20, 2017
  5. Elliott CableMay 26, 2017
  6. Jeff KingMay 31, 2017
  7. Ævar Arnfjörð BjarmasonMay 31, 2017
  8. Jeff KingMay 31, 2017
  9. docs/config: mention protocol implications of url.insteadOfJeff King, May 31, 2017
  10. Brandon WilliamsJun 1, 2017

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.