git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 0/6] Improved infrastructure for refname normalization

From
A Large Angry SCM <gitzilla@gmail.com>
Date
Sep 9, 2011, 14:06 UTC
Message-ID
<4E6A1D7D.6050602@gmail.com>
In-Reply-To
<1315568778-3592-1-git-send-email-mhagger@alum.mit.edu>
On 09/09/2011 07:46 AM, Michael Haggerty wrote:
Show 14 quoted lines
> As a prerequisite to storing references caches hierarchically (itself
> needed for performance reasons), here is a patch series to help us get
> refname normalization under control.
>
> The problem is that some UI accepts unnormalized reference names (like
> "/foo/bar" or "foo///bar" instead of "foo/bar") and passes them on to
> library routines without normalizing them.  The library, on the other
> hand, assumes that the refnames are normalized.  Sometimes (mostly in
> the case of loose references) unnormalized refnames happen to work,
> but in other cases (like packed references or when looking up refnames
> in the cache) they silently fail.  Given that refnames are sometimes
> treated as path names, there is a chance that some security-relevant
> bugs are lurking in this area, if not in git proper then in scripts
> that interact with git.

Why can't the library do the normalization instead of expecting every other component that deals with reference names having to do it for the library?

[...]
>
> * Forbid ".lock" at the end of any refname component, as directories
>    with such names can conflict with attempts to create lock files for
>    other refnames.

I find this overly restrictive. If you need to create a lock based on a reference name or component, use a name for the lock object that starts with one of the characters that reference names or components are already forbidden from starting with.

Gitzilla
Previous: Michael HaggertyNext: Michael Haggerty
Message 10 of 13 in “Improved infrastructure for refname normalization”
  1. 0/6 Improved infrastructure for refname normalizationMichael Haggerty, Sep 9, 2011
  2. 1/6 Change bad_ref_char() to return a boolean valueMichael Haggerty, Sep 9, 2011
  3. 2/6 git check-ref-format: add options --onelevel-ok and --refname-patternMichael Haggerty, Sep 9, 2011
  4. 3/6 Change check_ref_format() to take a flags argumentMichael Haggerty, Sep 9, 2011
  5. 4/6 Add a library function normalize_refname()Michael Haggerty, Sep 9, 2011
  6. 5/6 Do not allow ".lock" at the end of any refname componentMichael Haggerty, Sep 9, 2011
  7. 6/6 Add a REFNAME_ALLOW_UNNORMALIZED flag to check_ref_format()Michael Haggerty, Sep 9, 2011
  8. Junio C HamanoSep 9, 2011
  9. Michael HaggertySep 10, 2011
  10. A Large Angry SCMSep 9, 2011
  11. Michael HaggertySep 9, 2011
  12. Junio C HamanoSep 9, 2011
  13. Michael HaggertySep 10, 2011

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.