git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: ACLs for GIT

From
Sitaram Chamarty <sitaramc@gmail.com>
Date
May 17, 2011, 15:41 UTC
Message-ID
<BANLkTik6dP9su_K5WxUYkcGUL76J5ObvMg@mail.gmail.com>
In-Reply-To
<BANLkTi=W2CtA2YaV_spru1E9pTWgoge3Kw@mail.gmail.com>
On Tue, May 17, 2011 at 7:36 PM, Shawn Pearce <spearce@spearce.org> wrote:
> On Tue, May 17, 2011 at 05:08, Sitaram Chamarty <sitaramc@gmail.com> wrote:
> Yes. Or, he has a SHA-1 he suspects is a tree or blob and lists that
> in a tree he pushes to a branch he can write to. Now he can fetch that
> branch back, and obtain that object whose SHA-1 he has but whose
> contents he does not have.
Good point.  Not too hard too I guess, unlike this one:
> There is another attack that is incredibly improbable, but that JGit
[snipped lots of complicated stuff]
> assume this theoretical attack is too improbable to succeed. (And it
> is given what we know about SHA-1 today.)

IMO most of the theoretical attacks are just that. They advance the state of the art but I've not heard of any of them actually being used in a real life scenario. The sad fact is there are much weaker links to be found if you look around and you don't need all this.

>> Having two repos is still the best plan ;-)
>
> Yes, but tell that to Gerrit Code Review users. They really use the
> branch ACL features. :-)

Interesting. I do a fair amount of git consulting and training (inhouse) and this has only come up once so far. I haven't seen it as being that common at all.

Previous: Shawn PearceNext: Marc Weber
Message 14 of 15 in “ACLs for GIT”
  1. Martin L ResnickMay 15, 2011
  2. Magnus BäckMay 15, 2011
  3. Martin L ResnickMay 16, 2011
  4. Richard PetersonMay 16, 2011
  5. Phil HordMay 16, 2011
  6. Martin L ResnickMay 16, 2011
  7. Jakub NarebskiMay 16, 2011
  8. R. Tyler CroyMay 15, 2011
  9. Martin L ResnickMay 16, 2011
  10. Sitaram ChamartyMay 17, 2011
  11. Shawn PearceMay 17, 2011
  12. Sitaram ChamartyMay 17, 2011
  13. Shawn PearceMay 17, 2011
  14. Sitaram ChamartyMay 17, 2011
  15. Marc WeberMay 15, 2011

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.