git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 0/4] Redact unsafe URLs in the Trace2 output

From
Elijah Newren <newren@gmail.com>
Date
Nov 23, 2023, 19:08 UTC
Message-ID
<CABPp-BHsWRPPdHzvZO+Wp01fB6yqo2fnqYsrSvk6_m932YkoeA@mail.gmail.com>
In-Reply-To
<pull.1616.git.1700680717.gitgitgadget@gmail.com>

On Wed, Nov 22, 2023 at 11:18 AM Johannes Schindelin via GitGitGadget <gitgitgadget@gmail.com> wrote:

Show 13 quoted lines
>
> The Trace2 output can contain secrets when a user issues a Git command with
> sensitive information in the command-line. A typical (if highly discouraged)
> example is: git clone https://user:password@host.com/.
>
> With this PR, the Trace2 output redacts passwords in such URLs by default.
>
> This series also includes a commit to temporarily disable leak checking on
> t0210,t0211 because the tests uncover other unrelated bugs in Git.
>
> These patches were integrated into Microsoft's fork of Git, as
> https://github.com/microsoft/git/pull/616, and have been cooking there ever
> since.

Thanks for making these changes. Makes me wonder, back when we were logging trace2 data, if we had some of these leaks. Eek.

As I commented in patch 2, I think this is a good start, but I'm curious if others would be willing to turn clone/fetch of such bad URLs into warnings for now and errors later. The prevalence of AI-assist add-ons for various IDEs and the number of developers opting to use those IDEs and add-ons, and the fact that these tools sometimes include repository URLs in what they send off to third parties, makes me wonder if our recent infosec fire drill is soon going to be a widely shared experience by lots of other companies and individuals. Training users to not do bad things is hard, and it might be worth saving them from themselves. Thoughts?

Previous: Jeff Hostetler via GitGitGadget
Message 9 of 9 in “Redact unsafe URLs in the Trace2 output”
  1. 0/4 Redact unsafe URLs in the Trace2 outputJohannes Schindelin via GitGitGadget, Nov 22, 2023
  2. 1/4 trace2: fix signature of trace2_def_param() macroJeff Hostetler via GitGitGadget, Nov 22, 2023
  3. Junio C HamanoNov 23, 2023
  4. 2/4 trace2: redact passwords from https:// URLs by defaultJohannes Schindelin via GitGitGadget, Nov 22, 2023
  5. Elijah NewrenNov 23, 2023
  6. Jeff KingNov 27, 2023
  7. 3/4 t0211: test URL redacting in PERF formatJeff Hostetler via GitGitGadget, Nov 22, 2023
  8. 4/4 t0212: test URL redacting in EVENT formatJeff Hostetler via GitGitGadget, Nov 22, 2023
  9. Elijah NewrenNov 23, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.