git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git bundle format

From
Junio C Hamano <gitster@pobox.com>
Date
Nov 26, 2012, 20:38 UTC
Message-ID
<7vvccsqeva.fsf@alter.siamese.dyndns.org>
In-Reply-To
<871B6C10EBEFE342A772D1159D13208537ABF5AB@umechphj.easf.csd.disa.mil>
"Pyeron, Jason J CTR (US)" <jason.j.pyeron.ctr@mail.mil> writes:
Show 9 quoted lines
> In this situation we should assume that the bundle does not have
> any content which is already in the public repository, that is it
> has the minimum data to make it pass a git bundle verify from the
> public repositories point of view. We would then take the bundle
> and pipe it though the "git-bundle2text" program which would
> result in a "human" inspectable format as opposed to the packed
> format[2]. The security reviewer would then see all the
> information being released and with the help of the public
> repository see how the data changes the repository.

The bundle file is a thinly wrapped packfile, with extra information that tells what objects in the bundle are the tips of histories and what objects the repository the bundle gets unbundled has to have. So your "git-bundle2text" would likely to involve fetching from the bundle and inspecting the resulting history and the working tree files.

Previous: Felipe ContrerasNext: Pyeron, Jason J CTR (US)
Message 6 of 11 in “git bundle format”
  1. Pyeron, Jason J CTR (US)Nov 26, 2012
  2. Pyeron, Jason J CTR (US)Nov 26, 2012
  3. Felipe ContrerasNov 26, 2012
  4. Pyeron, Jason J CTR (US)Nov 26, 2012
  5. Felipe ContrerasNov 26, 2012
  6. Junio C HamanoNov 26, 2012
  7. Pyeron, Jason J CTR (US)Nov 26, 2012
  8. Stephen BashNov 26, 2012
  9. Pyeron, Jason J CTR (US)Nov 26, 2012
  10. Stephen BashNov 26, 2012
  11. Andrew ArdillNov 26, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.