git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git-clone causes out of memory

From
Jeff King <peff@peff.net>
Date
Oct 13, 2017, 12:44 UTC
Message-ID
<20171013124456.qsbaol7txdgdb6wq@sigill.intra.peff.net>
In-Reply-To
<2f9b8856-dacc-768d-32c2-985f5f145ba7@yandex.ru>
On Fri, Oct 13, 2017 at 03:12:43PM +0300, Constantine wrote:
Show 13 quoted lines
> On 13.10.2017 15:04, Junio C Hamano wrote:
> > Christian Couder <christian.couder@gmail.com> writes:
> > 
> > > Yeah, but perhaps Git could be smarter when rev-listing too and avoid
> > > processing files or directories it has already seen?
> > 
> > Aren't you suggesting to optimize for a wrong case?
> > 
> 
> Anything that is possible with a software should be considered as a possible
> usecase. It's in fact a DoS attack. Imagine there's a server that using git
> to process something, and now there's a way to knock down this server. It's
> also bad from a promotional stand point.

But the point is that you'd have the same problem with any repository that had 10^7 files in it. Yes, it's convenient for the attacker that there are only 9 objects, but fundamentally it's pretty easy for an attacker to construct repositories that have large trees (or very deep trees -- that's what causes stack exhaustion in some cases).

Note too that this attack almost always comes down to the diff code (which is why it kicks in for pathspec limiting) which has to actually expand the tree. Most "normal" server-side operations (like accepting pushes or serving fetches) operate only on the object graph and _do_ avoid processing already-seen objects.

As soon as servers start trying to checkout or diff, though, the attack surface gets quite large. And you really need to start thinking about having resource limits and quotas for CPU and memory use of each process (and group by requesting user, IP, repo, etc).

I think the main thing Git could be doing here is to limit the size of the tree (both width and depth). But arbitrary limits like that have a way of being annoying, and I think it just pushes resource-exhaustion attacks off a little (e.g., can you construct a blob that behaves badly with the "--patch"?).

-Peff
Previous: ConstantineNext: Derrick Stolee
Message 8 of 23 in “git-clone causes out of memory”
  1. ConstantineOct 13, 2017
  2. Mike HommeyOct 13, 2017
  3. Christian CouderOct 13, 2017
  4. Mike HommeyOct 13, 2017
  5. Christian CouderOct 13, 2017
  6. Junio C HamanoOct 13, 2017
  7. ConstantineOct 13, 2017
  8. Jeff KingOct 13, 2017
  9. Derrick StoleeOct 13, 2017
  10. Derrick StoleeOct 13, 2017
  11. Jeff KingOct 13, 2017
  12. Derrick StoleeOct 13, 2017
  13. Jeff KingOct 13, 2017
  14. Jeff KingOct 13, 2017
  15. Jeff KingOct 13, 2017
  16. Derrick StoleeOct 13, 2017
  17. Jeff KingOct 13, 2017
  18. Derrick StoleeOct 13, 2017
  19. revision: quit pruning diff more quickly when possibleJeff King, Oct 13, 2017
  20. Derrick StoleeOct 13, 2017
  21. Jeff KingOct 13, 2017
  22. Junio C HamanoOct 14, 2017
  23. Jeff KingOct 13, 2017

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.