git/list[1] front-page[2] threads[3] people[4] search[5] about
wed 2026-10-07 18:09 UTC

[PATCH v5 3/5] upload-pack: read uploadpack.lazyFetchTrusted

From
Christian Couder <christian.couder@gmail.com>
Date
Oct 2, 2026, 08:23 UTC
Message-ID
<20261002082322.2682869-4-christian.couder@gmail.com>
In-Reply-To
<20261002082322.2682869-1-christian.couder@gmail.com>

Previous commits created and prepared the path_allowlist_apply() and path_allowlist_config_apply() functions, but used them only for the "safe.directory" configuration variable.

Let's reuse these functions for a new "uploadpack.lazyFetchTrusted" configuration variable.

It allows us to:
  - read an allowlist from that config variable,
  - check if the current repo is in that list, and
  - return the result from a new upload_pack_lazy_fetch_trusted()
    function.

As path_allowlist_config_apply() lets each caller decide which paths it is willing to accept using a callback, let's pass it a new allow_trusted_path() callback. Unlike the "safe.directory" callback, it accepts only absolute paths, and not ".", as `upload-pack` always serves a repository given by an absolute path, so there is no "current repository" for "." to refer to.

Note that a served repository is identified by its git directory, and not by its worktree. This is because `upload-pack` uses enter_repo() instead of the usual repository discovery, so it never learns about a worktree and `r->worktree` is always NULL there. In practice this means that a non-bare repository served as "/srv/repo" has to be allowlisted as "/srv/repo/.git" (or as the directory its ".git" file points to, if it has a ".git" file instead of a ".git" directory).

The new upload_pack_lazy_fetch_trusted() function will be used in a following commit.

Note that the new config variable should be read only from protected configuration files.

Signed-off-by: Christian Couder <christian.couder@gmail.com>
---
 upload-pack.c | 59 +++++++++++++++++++++++++++++++++++++++++++++++++++
 upload-pack.h |  3 +++
 2 files changed, 62 insertions(+)
diff --git a/upload-pack.c b/upload-pack.c
index 22573ad365..a300870fa9 100644
--- a/upload-pack.c
+++ b/upload-pack.c
@@ -34,6 +34,8 @@
 #include "json-writer.h"
 #include "strmap.h"
 #include "promisor-remote.h"
+#include "setup.h"
+#include "abspath.h"
 
 /* Remember to update object flag allocation in object.h */
 #define THEY_HAVE	(1u << 11)
@@ -1343,6 +1345,63 @@ static int upload_pack_config(const char *var, const char *value,
 	return parse_hide_refs_config(var, value, "uploadpack", &data->hidden_refs);
 }
 
+/*
+ * Only absolute paths make sense here. Unlike 'safe.directory', "."
+ * is not accepted, as the served repository is always identified by
+ * an absolute path.
+ */
+static bool allow_trusted_path(const char *path, void *cbdata_)
+{
+	struct path_allowlist_cb_data *cbdata = cbdata_;
+
+	if (is_absolute_path(path))
+		return true;
+
+	warning(_("%s '%s' not absolute"), cbdata->key, path);
+	return false;
+}
+
+struct lazy_fetch_trusted {
+	char *repo_path;
+	bool trusted;
+};
+
+static int upload_pack_protected_lazy_fetch_config(const char *var, const char *value,
+						   const struct config_context *ctx UNUSED,
+						   void *cb_data)
+{
+	struct lazy_fetch_trusted *data = cb_data;
+	struct path_allowlist_cb_data cbdata = { .key = var };
+
+	if (strcmp("uploadpack.lazyfetchtrusted", var))
+		return 0;
+
+	path_allowlist_config_apply(var, value, data->repo_path, &data->trusted,
+				    allow_trusted_path, &cbdata);
+
+	return 0;
+}
+
+bool upload_pack_lazy_fetch_trusted(struct repository *r)
+{
+	struct lazy_fetch_trusted data = { 0 };
+
+	/*
+	 * A served repository is identified by its git directory, as
+	 * `upload-pack` uses enter_repo() instead of the usual repository
+	 * discovery, so its worktree, if any, is never known here.
+	 */
+	data.repo_path = real_pathdup(r->gitdir, 0);
+	if (!data.repo_path)
+		return false;
+
+	git_protected_config(upload_pack_protected_lazy_fetch_config, &data);
+
+	free(data.repo_path);
+
+	return !!data.trusted;
+}
+
 static int upload_pack_protected_config(const char *var, const char *value,
 					const struct config_context *ctx UNUSED,
 					void *cb_data)
diff --git a/upload-pack.h b/upload-pack.h
index d6ee25ea98..b2212992c3 100644
--- a/upload-pack.h
+++ b/upload-pack.h
@@ -12,4 +12,7 @@ struct strbuf;
 int upload_pack_advertise(struct repository *r,
 			  struct strbuf *value);
 
+/* Is this repo trusted for lazy fetching? */
+bool upload_pack_lazy_fetch_trusted(struct repository *r);
+
 #endif /* UPLOAD_PACK_H */
-- 
2.56.0.rc2.20.g34f06850c1
Previous: Christian CouderNext: Christian Couder
Message 63 of 70 in “Introduce a 'fromAccepted' option to GIT_NO_LAZY_FETCH”
  1. 0/3 Introduce a 'fromAccepted' option to GIT_NO_LAZY_FETCHChristian Couder, Jul 10, 2026
  2. 1/3 promisor-remote: factor out lazy_fetch_objects()Christian Couder, Jul 10, 2026
  3. 2/3 promisor-remote: introduce enum allow_lazy_fetchChristian Couder, Jul 10, 2026
  4. 3/3 promisor-remote: teach 'fromAccepted' to GIT_NO_LAZY_FETCHChristian Couder, Jul 10, 2026
  5. brian m. carlsonJul 10, 2026
  6. Christian CouderJul 12, 2026
  7. 0/5 Introduce 'uploadpack.lazyFetchTrusted'Christian Couder, Aug 7, 2026
  8. 1/5 promisor-remote: factor out lazy_fetch_objects()Christian Couder, Aug 7, 2026
  9. 2/5 setup: extract path_allowlist_apply()Christian Couder, Aug 7, 2026
  10. 4/5 upload-pack: read uploadpack.lazyFetchTrustedChristian Couder, Aug 7, 2026
  11. 5/5 builtin/upload-pack: set GIT_NO_LAZY_FETCH to 0 on trusted repoChristian Couder, Aug 7, 2026
  12. 3/5 setup: add 'allow_dot' arg to path_allowlist_apply()Christian Couder, Aug 7, 2026
  13. Christian CouderAug 7, 2026
  14. Junio C HamanoAug 7, 2026
  15. Christian CouderAug 10, 2026
  16. Junio C HamanoAug 11, 2026
  17. 0/5 Introduce 'uploadpack.lazyFetchTrusted'Christian Couder, Aug 13, 2026
  18. 1/5 promisor-remote: factor out lazy_fetch_objects()Christian Couder, Aug 13, 2026
  19. 2/5 setup: extract path_allowlist_apply()Christian Couder, Aug 13, 2026
  20. 3/5 setup: add 'allow_dot' arg to path_allowlist_apply()Christian Couder, Aug 13, 2026
  21. 4/5 upload-pack: read uploadpack.lazyFetchTrustedChristian Couder, Aug 13, 2026
  22. 5/5 builtin/upload-pack: set GIT_NO_LAZY_FETCH to 0 on trusted repoChristian Couder, Aug 13, 2026
  23. Junio C HamanoAug 13, 2026
  24. Christian CouderAug 14, 2026
  25. Junio C HamanoAug 14, 2026
  26. Junio C HamanoAug 14, 2026
  27. Junio C HamanoAug 14, 2026
  28. Junio C HamanoAug 14, 2026
  29. Junio C HamanoAug 14, 2026
  30. Junio C HamanoAug 14, 2026
  31. 0/5 Introduce 'uploadpack.lazyFetchTrusted'Christian Couder, Sep 8, 2026
  32. 1/5 promisor-remote: factor out lazy_fetch_objects()Christian Couder, Sep 8, 2026
  33. 2/5 setup: extract path_allowlist_apply()Christian Couder, Sep 8, 2026
  34. 3/5 upload-pack: read uploadpack.lazyFetchTrustedChristian Couder, Sep 8, 2026
  35. 4/5 promisor-remote: prevent infinite recursion when lazy fetchingChristian Couder, Sep 8, 2026
  36. 5/5 builtin/upload-pack: set GIT_NO_LAZY_FETCH to 0 on trusted repoChristian Couder, Sep 8, 2026
  37. Christian CouderSep 8, 2026
  38. Christian CouderSep 8, 2026
  39. Christian CouderSep 8, 2026
  40. Christian CouderSep 8, 2026
  41. Junio C HamanoSep 8, 2026
  42. Junio C HamanoSep 8, 2026
  43. Junio C HamanoSep 8, 2026
  44. Junio C HamanoSep 8, 2026
  45. Junio C HamanoSep 8, 2026
  46. Christian CouderSep 9, 2026
  47. Junio C HamanoSep 9, 2026
  48. 0/5 Introduce 'uploadpack.lazyFetchTrusted'Christian Couder, Sep 28, 2026
  49. 1/5 promisor-remote: factor out lazy_fetch_objects()Christian Couder, Sep 28, 2026
  50. 2/5 setup: extract path_allowlist_apply()Christian Couder, Sep 28, 2026
  51. 3/5 upload-pack: read uploadpack.lazyFetchTrustedChristian Couder, Sep 28, 2026
  52. 4/5 promisor-remote: prevent infinite recursion when lazy fetchingChristian Couder, Sep 28, 2026
  53. 5/5 builtin/upload-pack: don't disable lazy fetching on trusted repoChristian Couder, Sep 28, 2026
  54. Christian CouderSep 28, 2026
  55. Christian CouderSep 28, 2026
  56. Christian CouderSep 28, 2026
  57. Christian CouderSep 28, 2026
  58. Junio C HamanoSep 29, 2026
  59. Junio C HamanoSep 29, 2026
  60. 0/5 Introduce 'uploadpack.lazyFetchTrusted'Christian Couder, Oct 2, 2026
  61. 1/5 promisor-remote: factor out lazy_fetch_objects()Christian Couder, Oct 2, 2026
  62. 2/5 setup: extract path_allowlist_apply()Christian Couder, Oct 2, 2026
  63. 3/5 upload-pack: read uploadpack.lazyFetchTrustedChristian Couder, Oct 2, 2026
  64. 4/5 promisor-remote: prevent infinite recursion when lazy fetchingChristian Couder, Oct 2, 2026
  65. 5/5 builtin/upload-pack: don't disable lazy fetching on trusted repoChristian Couder, Oct 2, 2026
  66. Christian CouderOct 2, 2026
  67. Christian CouderOct 2, 2026
  68. Christian CouderOct 2, 2026
  69. Junio C HamanoOct 5, 2026
  70. Christian CouderOct 6, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.