status on security of embedded repos?
- From
Christoph Anton Mitterer <calestyo@scientia.org>
- Date
- Sep 3, 2022, 18:48 UTC
- Message-ID
- <4e9ad5486e8a887f1e92cc4e401ca61be5f2bb9a.camel@scientia.org>
Hey.
A while ago there was this discussion about security issues with respect to bare repos embedded in another repo[0][1].
I just wondered what's the status on this? Was that fixed in a way that one can clone untrusted repos and navigate / use git commands within them, without any risk… or is it still open?
Saw proposed patches like: https://lore.kernel.org/git/pull.1261.git.git.1651861810633.gitgitgadget@gmail.com/#r
But it seems at least as of git 2.37.2, ther's no safe.barerepository option, yet.
Also, couldn't the same happen for non-bare repos, too, or how is that prevented for such?
Thanks, Chris.
[0] https://lwn.net/ml/git/kl6lsfqpygsj.fsf@chooglen-macbookpro.roam.corp.google.com/ [1] https://lwn.net/Articles/892755/