git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH 0/2] Revert defense-in-depth patches breaking Git LFS

From
brian m. carlson <sandals@crustytoothpaste.net>
Date
May 14, 2024, 18:16 UTC
Message-ID
<20240514181641.150112-1-sandals@crustytoothpaste.net>

The recent defense-in-depth patches to restrict hooks while cloning broke Git LFS because it installs necessary hooks when it is invoked by Git's smudge filter. This means that currently, anyone with Git LFS installed who attempts to clone a repository with at least one LFS file will see a message like the following (fictitious example):

----
$ git clone https://github.com/octocat/xyzzy.git
Cloning into 'pull-bug'...
remote: Enumerating objects: 1275, done.
remote: Counting objects: 100% (343/343), done.
remote: Compressing objects: 100% (136/136), done.
remote: Total 1275 (delta 221), reused 327 (delta 206), pack-reused 932
Receiving objects: 100% (1275/1275), 290.78 KiB | 2.88 MiB/s, done.
Resolving deltas: 100% (226/226), done.
Filtering content: 100% (504/504), 1.86 KiB | 0 bytes/s, done.
fatal: active `post-checkout` hook found during `git clone`:
        /home/octocat/xyzzy/.git/hooks/post-checkout
For security reasons, this is disallowed by default.
If this is intentional and the hook should actually be run, please
run the command again with `GIT_CLONE_PROTECTION_ACTIVE=false`
warning: Clone succeeded, but checkout failed.
You can inspect what was checked out with 'git status'
and retry with 'git restore --source=HEAD :/'
----

This causes most CI systems to be broken in such a case, as well as a confusing message for the user.

It's not really possible to avoid the need to install the hooks at this location because the post-checkout hook must be ready during the checkout that's part of the clone in order to properly adjust permissions on files. Thus, we'll need to revert the changes to restrict hooks while cloning, which this series does.

brian m. carlson (2):
  Revert "clone: prevent hooks from running during a clone"
  Revert "core.hooksPath: add some protection while cloning"
 builtin/clone.c  |  5 -----
 config.c         | 13 +-----------
 hook.c           | 32 ------------------------------
 t/t1800-hook.sh  | 15 --------------
 t/t5601-clone.sh | 51 ------------------------------------------------
 5 files changed, 1 insertion(+), 115 deletions(-)
Next: brian m. carlson
Message 1 of 14 in “Revert defense-in-depth patches breaking Git LFS”
  1. 0/2 Revert defense-in-depth patches breaking Git LFSbrian m. carlson, May 14, 2024
  2. 2/2 Revert "core.hooksPath: add some protection while cloning"brian m. carlson, May 14, 2024
  3. 1/2 Revert "clone: prevent hooks from running during a clone"brian m. carlson, May 14, 2024
  4. Johannes SchindelinMay 14, 2024
  5. brian m. carlsonMay 14, 2024
  6. Joey HessMay 22, 2024
  7. Johannes SchindelinMay 27, 2024
  8. Joey HessMay 28, 2024
  9. Jeff KingMay 29, 2024
  10. Johannes SchindelinMay 29, 2024
  11. Junio C HamanoMay 29, 2024
  12. Jeff KingMay 30, 2024
  13. Joey HessMay 24, 2024
  14. Junio C HamanoMay 28, 2024

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.