git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Git Merge contributor summit notes

From
BWBrandon Williams <bmwill@google.com>
Date
Mar 13, 2018, 00:49 UTC
Message-ID
<20180313004940.GG61720@google.com>
In-Reply-To
<20180312234037.GE1968@sigill.intra.peff.net>
On 03/12, Jeff King wrote:
Show 23 quoted lines
> On Sat, Mar 10, 2018 at 02:01:14PM +0100, Ævar Arnfjörð Bjarmason wrote:
> 
> > >  - (peff) Time to deprecate the git anonymous protocol?
> > [...]
> > 
> > I think the conclusion was that nobody cares about the git:// protocol,
> > but people do care about it being super easy to spin up a server, and
> > currently it's easiest to spin up git://, but we could also ship with
> > some git-daemon mode that had a stand-alone webserver (or ssh server) to
> > get around that.
> 
> I don't think keeping support for git:// is too onerous at this point
> (especially because it should make the jump to protocol v2 with the
> rest). But it really is a pretty dated protocol, lacking any kind of
> useful security properties (yes, I know, if we're all verifying signed
> tags it's great, but realistically people are fetching the tip of master
> over a hijack-able TCP connection and running arbitrary code on the
> result). It might be nice if it went away completely so we don't have to
> warn people off of it.
> 
> The only thing git:// really has going over git-over-http right now is
> that it doesn't suffer from the stateless-rpc overhead. But if we unify
> that behavior in v2, then any advantage goes away.

It's still my intention to unify this behavior in v2 but then begin working on improving negotiation as a whole (once v2 is in) so that we can hopefully get rid of the nasty corner cases that exist in http://. Since v2 will be hidden behind a config anyway, it may be prudent to wait until negotiation gets better before we entertain making v2 default (well there's also needing to wait for hosting providers to begin supporting it).

Show 8 quoted lines
> 
> I do agree we should have _something_ that is easy to spin up. But it
> would be wonderful if git-over-http could become that, and we could just
> deprecate git://. I suppose it's possible people build clients without
> curl, but I suspect that's an extreme minority these days (most third
> party hosters don't seem to offer git:// at all).
> 
> -Peff
-- 
Brandon Williams
Previous: Jeff KingNext: Jeff King
Message 5 of 17 in “Git Merge contributor summit notes”
  1. Alex VandiverMar 10, 2018
  2. Ævar Arnfjörð BjarmasonMar 10, 2018
  3. Junio C HamanoMar 11, 2018
  4. Jeff KingMar 12, 2018
  5. Brandon WilliamsMar 13, 2018
  6. Jeff KingMar 12, 2018
  7. Ævar Arnfjörð BjarmasonMar 25, 2018
  8. Jeff HostetlerMar 26, 2018
  9. Stefan BellerMar 26, 2018
  10. Jeff HostetlerMar 26, 2018
  11. Brandon WilliamsMar 26, 2018
  12. Jakub NarebskiApr 7, 2018
  13. Including object type and size in object id (Re: Git Merge contributor summit notes)Jonathan Nieder, Mar 26, 2018
  14. Jeff HostetlerMar 26, 2018
  15. Junio C HamanoMar 26, 2018
  16. Per-object encryption (Re: Git Merge contributor summit notes)Jonathan Nieder, Mar 26, 2018
  17. Ævar Arnfjörð BjarmasonMar 26, 2018

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.