git/list[1] front-page[2] threads[3] people[4] search[5] about
 

status on security of embedded repos?

From
Christoph Anton Mitterer <calestyo@scientia.org>
Date
Sep 3, 2022, 18:48 UTC
Message-ID
<4e9ad5486e8a887f1e92cc4e401ca61be5f2bb9a.camel@scientia.org>
Hey.

A while ago there was this discussion about security issues with respect to bare repos embedded in another repo[0][1].

I just wondered what's the status on this? Was that fixed in a way that one can clone untrusted repos and navigate / use git commands within them, without any risk… or is it still open?

Saw proposed patches like: https://lore.kernel.org/git/pull.1261.git.git.1651861810633.gitgitgadget@gmail.com/#r

But it seems at least as of git 2.37.2, ther's no safe.barerepository option, yet.

Also, couldn't the same happen for non-bare repos, too, or how is that prevented for such?

Thanks, Chris.

[0] https://lwn.net/ml/git/kl6lsfqpygsj.fsf@chooglen-macbookpro.roam.corp.google.com/ [1] https://lwn.net/Articles/892755/

Next: Johannes Schindelin
Message 1 of 8 in “status on security of embedded repos?”
  1. Christoph Anton MittererSep 3, 2022
  2. Johannes SchindelinSep 5, 2022
  3. Christoph Anton MittererSep 5, 2022
  4. Johannes SchindelinSep 6, 2022
  5. Christoph Anton MittererSep 7, 2022
  6. Glen ChooSep 8, 2022
  7. Christoph Anton MittererSep 9, 2022
  8. Christoph Anton MittererSep 9, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.