git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: On undoing a forced push

From
Sitaram Chamarty <sitaramc@gmail.com>
Date
Jun 9, 2015, 14:50 UTC
Message-ID
<5576FD24.2040700@gmail.com>
In-Reply-To
<20150609142550.GB7894@peff.net>
On 06/09/2015 07:55 PM, Jeff King wrote:
Show 26 quoted lines
> On Tue, Jun 09, 2015 at 07:36:20PM +0530, Sitaram Chamarty wrote:
> 
>>> This patch prints the latest SHA-1 before the forced push in full. He
>>> then can do
>>>
>>>     git push <remote> +<old-sha1>:<ref>
>>>
>>> He does not even need to have the objects that <old-sha1> refers
>>> to. We could simply push an empty pack and the the remote will happily
>>> accept the force, assuming garbage collection has not happened. But
>>> that's another and a little more complex patch.
>>
>> If I am not mistaken, we actively prevent people from downloading an
>> unreferenced SHA (such as would happen if you overwrote refs that
>> contained sensitive information like passwords).
>>
>> Wouldn't allowing the kind of push you just described, require negating
>> that protection?
> 
> No, this has always worked. If you have write access to a repository,
> you can fetch anything from it with this trick. Even if we blocked this,
> there are other ways to leak information. For instance, I can push up
> objects that are "similar" to the target object, claim to have the
> target object, and then hope git will make a delta between my similar
> object and the target. Iterate on the "similar" object and you can
> eventually figure out what is in the target object.
aah ok; I must have mis-remembered something.  Thanks!
Previous: Jeff KingNext: Johannes Schindelin
Message 5 of 11 in “On undoing a forced push”
  1. Duy NguyenJun 9, 2015
  2. Matthieu MoyJun 9, 2015
  3. Sitaram ChamartyJun 9, 2015
  4. Jeff KingJun 9, 2015
  5. Sitaram ChamartyJun 9, 2015
  6. Johannes SchindelinJun 9, 2015
  7. Stefan BellerJun 9, 2015
  8. Duy NguyenJun 9, 2015
  9. brian m. carlsonJun 9, 2015
  10. Duy NguyenJun 10, 2015
  11. brian m. carlsonJun 10, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.