git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 0/3] protocol v2 and hidden refs

From
Ævar Arnfjörð Bjarmason <avarab@gmail.com>
Date
Dec 11, 2018, 11:45 UTC
Message-ID
<875zw0nv77.fsf@evledraar.gmail.com>
In-Reply-To
<20181211104236.GA6899@sigill.intra.peff.net>
On Tue, Dec 11 2018, Jeff King wrote:
Show 25 quoted lines
> When using the v2 protocol, hidden-ref config is not respected at all:
>
>   $ git config transfer.hiderefs refs/tags/
>   $ git -c protocol.version=0 ls-remote . | grep -c refs/tags
>   0
>   $ git -c protocol.version=2 ls-remote . | grep -c refs/tags
>   1424
>
> The fix in patch 3 is pretty straightforward, but note:
>
>   - I'm a little worried this may happen again with future features. The
>     root cause is that "ls-refs" follows a different code path than the
>     ref advertisement for "upload-pack". So if we add any new config,
>     it needs to go both places (non ref-advertisement config is OK, as
>     the v2 "fetch" command is a lot closer to a v0 upload-pack).
>
>     I think this is just an issue for any future features. I looked for
>     other existing features which might be missing in v2, but couldn't
>     find any.
>
>     I don't know if there's a good solution. I tried running the whole
>     test suite with v2 as the default. It does find this bug, but it has
>     a bunch of other problems (notably fetch-pack won't run as v2, but
>     some other tests I think also depend on v0's reachability rules,
>     which v2 is documented not to enforce).
I think a global test mode for it would be a very good idea.
Show 21 quoted lines
>   - The "serve" command is funky, because it has no concept of whether
>     the "ls-refs" is for fetching or pushing. Is git-serve even a thing
>     that we want to support going forward?  I know part of the original
>     v2 conception was that one would be able to just connect to
>     "git-serve" and do a number of operations. But in practice the v2
>     probing requires saying "I'd like to git-upload-pack, and v2 if you
>     please". So no client ever calls git-serve.
>
>     Is this something we plan to eventually move to? Or can it be
>     considered a funny vestige of the development? In the latter case, I
>     think we should consider removing it.
>
>     I've worked around it here with patch 2, but note that "git serve"
>     would not ever respect uploadpack.hiderefs nor receive.hiderefs
>     (since it has no idea which operation it's doing).
>
> The patches are:
>
>   [1/3]: serve: pass "config context" through to individual commands
>   [2/3]: parse_hide_refs_config: handle NULL section
>   [3/3]: upload-pack: support hidden refs with protocol v2

Does this issue rise to the level of needing a security point-release (which I'm discussing here as the details are already public). The transfer.hideRefs docs have said:

    Even if you hide refs, a client may still be able to steal the
    target objects via the techniques described in the "SECURITY"
    section of the gitnamespaces(7) man page; it’s best to keep private
    data in a separate repository.

So we never promised to hide the objects, but definitely promised to hide the ref names. I don't know if anyone uses this in practice for secret ref names, but if they do they have a data leak if they enable protocol v2.

More importantly, the docs for receive.hideRefs say. "An attempt to update or delete a hidden ref by git push is rejected.". It seems this bit was enforced, i.e. this passes before and after your 3/3, but I have not dug enough to be 100% satisfied with that.

    diff --git a/t/t5512-ls-remote.sh b/t/t5512-ls-remote.sh
    index ca69636fd5..20059c3308 100755
    --- a/t/t5512-ls-remote.sh
    +++ b/t/t5512-ls-remote.sh
    @@ -210,6 +210,13 @@ test_expect_success 'protocol v2 supports hiderefs' '
     	! grep refs/tags actual
     '
    +test_expect_success 'protocol v2 respects hiderefs when pushing' '
    +	git init --bare server.git &&
    +	git -C server.git config transfer.hideRefs refs/tags &&
    +	test_must_fail git -c protocol.version=0 push "file://$PWD/server.git" mark &&
    +	test_must_fail git -c protocol.version=2 push "file://$PWD/server.git" mark
    +'
    +
     test_expect_success 'ls-remote --symref' '
     	git fetch origin &&
     	cat >expect <<-EOF &&

If there's some bug where you can bypass this push protection that would be much worse. E.g. GitLab uses "keep-around" refs to track its own internal state, and it would be bad if users could manipulate it.

Show 12 quoted lines
>  builtin/upload-pack.c |  1 +
>  ls-refs.c             | 16 +++++++++++++++-
>  ls-refs.h             |  3 ++-
>  refs.c                |  3 ++-
>  serve.c               |  9 +++++----
>  serve.h               |  7 +++++++
>  t/t5512-ls-remote.sh  |  6 ++++++
>  upload-pack.c         |  4 ++--
>  upload-pack.h         |  4 ++--
>  9 files changed, 42 insertions(+), 11 deletions(-)
>
> -Peff
Previous: Jeff KingNext: Jeff King
Message 16 of 73 in “protocol v2 and hidden refs”
  1. 0/3 protocol v2 and hidden refsJeff King, Dec 11, 2018
  2. 1/3 serve: pass "config context" through to individual commandsJeff King, Dec 11, 2018
  3. Junio C HamanoDec 14, 2018
  4. Jeff KingDec 14, 2018
  5. Junio C HamanoDec 15, 2018
  6. Jeff KingDec 16, 2018
  7. Junio C HamanoDec 16, 2018
  8. Jeff KingDec 18, 2018
  9. Jonathan NiederDec 14, 2018
  10. Jeff KingDec 14, 2018
  11. Jonathan NiederDec 14, 2018
  12. Jeff KingDec 14, 2018
  13. 2/3 parse_hide_refs_config: handle NULL sectionJeff King, Dec 11, 2018
  14. Junio C HamanoDec 14, 2018
  15. 3/3 upload-pack: support hidden refs with protocol v2Jeff King, Dec 11, 2018
  16. Ævar Arnfjörð BjarmasonDec 11, 2018
  17. Jeff KingDec 11, 2018
  18. 0/3 Add a GIT_TEST_PROTOCOL_VERSION=X test modeÆvar Arnfjörð Bjarmason, Dec 11, 2018
  19. Ævar Arnfjörð BjarmasonDec 11, 2018
  20. 1/3 tests: add a special setup where for protocol.versionÆvar Arnfjörð Bjarmason, Dec 11, 2018
  21. 0/3 Some fixes and improvementsJonathan Tan, Dec 12, 2018
  22. 1/3 squash this into your patchJonathan Tan, Dec 12, 2018
  23. 3/3 also squash this into your patchJonathan Tan, Dec 12, 2018
  24. 2/3 builtin/fetch-pack: support protocol version 2Jonathan Tan, Dec 12, 2018
  25. Junio C HamanoDec 13, 2018
  26. 0/8 protocol v2 fixesÆvar Arnfjörð Bjarmason, Dec 13, 2018
  27. 0/4 protocol v2 fixesÆvar Arnfjörð Bjarmason, Dec 17, 2018
  28. Jeff KingDec 18, 2018
  29. 1/4 serve: pass "config context" through to individual commandsÆvar Arnfjörð Bjarmason, Dec 17, 2018
  30. 3/4 upload-pack: support hidden refs with protocol v2Ævar Arnfjörð Bjarmason, Dec 17, 2018
  31. 2/4 parse_hide_refs_config: handle NULL sectionÆvar Arnfjörð Bjarmason, Dec 17, 2018
  32. 4/4 fetch-pack: support protocol version 2Ævar Arnfjörð Bjarmason, Dec 17, 2018
  33. Junio C HamanoJan 8, 2019
  34. Jonathan TanJan 8, 2019
  35. Jeff KingJan 8, 2019
  36. 1/8 serve: pass "config context" through to individual commandsÆvar Arnfjörð Bjarmason, Dec 13, 2018
  37. 2/8 parse_hide_refs_config: handle NULL sectionÆvar Arnfjörð Bjarmason, Dec 13, 2018
  38. 3/8 upload-pack: support hidden refs with protocol v2Ævar Arnfjörð Bjarmason, Dec 13, 2018
  39. 4/8 tests: add a check for unportable env --unsetÆvar Arnfjörð Bjarmason, Dec 13, 2018
  40. 5/8 tests: add a special setup where for protocol.versionÆvar Arnfjörð Bjarmason, Dec 13, 2018
  41. Jonathan TanDec 13, 2018
  42. 6/8 tests: mark & fix tests broken under GIT_TEST_PROTOCOL_VERSION=1Ævar Arnfjörð Bjarmason, Dec 13, 2018
  43. 7/8 builtin/fetch-pack: support protocol version 2Ævar Arnfjörð Bjarmason, Dec 13, 2018
  44. Jeff KingDec 14, 2018
  45. 8/8 tests: mark tests broken under GIT_TEST_PROTOCOL_VERSION=2Ævar Arnfjörð Bjarmason, Dec 13, 2018
  46. Ævar Arnfjörð BjarmasonDec 13, 2018
  47. Junio C HamanoDec 14, 2018
  48. Jeff KingDec 14, 2018
  49. Ævar Arnfjörð BjarmasonDec 14, 2018
  50. Ævar Arnfjörð BjarmasonDec 14, 2018
  51. Jeff KingDec 17, 2018
  52. Jeff KingDec 17, 2018
  53. upload-pack: turn on uploadpack.allowAnySHA1InWant=trueÆvar Arnfjörð Bjarmason, Dec 17, 2018
  54. David TurnerDec 17, 2018
  55. Ævar Arnfjörð BjarmasonDec 17, 2018
  56. David TurnerDec 17, 2018
  57. Jonathan NiederDec 17, 2018
  58. Ævar Arnfjörð BjarmasonDec 17, 2018
  59. Jonathan NiederDec 18, 2018
  60. Ævar Arnfjörð BjarmasonDec 18, 2018
  61. Jeff KingDec 18, 2018
  62. Jeff KingDec 18, 2018
  63. Ævar Arnfjörð BjarmasonDec 18, 2018
  64. Junio C HamanoDec 26, 2018
  65. Ævar Arnfjörð BjarmasonDec 27, 2018
  66. Jonathan NiederDec 27, 2018
  67. 2/3 tests: mark tests broken under GIT_TEST_PROTOCOL_VERSION=1Ævar Arnfjörð Bjarmason, Dec 11, 2018
  68. 3/3 tests: mark tests broken under GIT_TEST_PROTOCOL_VERSION=2Ævar Arnfjörð Bjarmason, Dec 11, 2018
  69. Jonathan TanDec 13, 2018
  70. Jeff KingDec 14, 2018
  71. Ævar Arnfjörð BjarmasonDec 15, 2018
  72. Jeff KingDec 16, 2018
  73. Ævar Arnfjörð BjarmasonDec 16, 2018

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.