git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] git-daemon extra paranoia

From
HAH. Peter Anvin <hpa@zytor.com>
Date
Oct 18, 2005, 22:08 UTC
Message-ID
<43557254.3010807@zytor.com>
In-Reply-To
<4355691D.2010200@zytor.com>
H. Peter Anvin wrote:
Show 9 quoted lines
> 
> For security, avoiding aliases is highly desirable, and if they're 
> useless the easiest way to do that is to reject.  If aliases are 
> required, which it sounds like it might be, then canonicalization needs 
> to be applied.
> 
> This may sound redundant, but a lot of avoiding security holes involves 
> applying good practices up front, instead of reactively.
> 

I thought I might want to add a bit of an explanation, just for the purpose of illustration.

Right now, we use a whitelist for access control. Aliases are not a problem, because they fail shut.

A year from now, someone decides that they want a "all but" feature, and thus adds a blacklist on top of the whitelist. If aliases are permitted, unless the blacklist logic is written very carefully, one would then be able to get around the blacklist by using one of the aliased paths.

Improper handling of aliases is probably second only to buffer overflows and large-string DoS attacks when it comes to security vulnerabilities.

	-hpa
Previous: H. Peter AnvinNext: H. Peter Anvin
Message 4 of 12 in “git-daemon extra paranoia”
  1. git-daemon extra paranoiaH. Peter Anvin, Oct 18, 2005
  2. Junio C HamanoOct 18, 2005
  3. H. Peter AnvinOct 18, 2005
  4. H. Peter AnvinOct 18, 2005
  5. Revised - git-daemon extra paranoiaH. Peter Anvin, Oct 18, 2005
  6. Linus TorvaldsOct 18, 2005
  7. Junio C HamanoOct 18, 2005
  8. Linus TorvaldsOct 18, 2005
  9. H. Peter AnvinOct 19, 2005
  10. Linus TorvaldsOct 19, 2005
  11. H. Peter AnvinOct 19, 2005
  12. Junio C HamanoOct 19, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.