git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: "git symbolic-ref" doesn't do a very good job

From
Linus Torvalds <torvalds@linux-foundation.org>
Date
Aug 1, 2022, 17:49 UTC
Message-ID
<CAHk-=wg8EaHnM_OcHrw=+sT3VPAkTUpzeaQ8EjTDLUENK58HSw@mail.gmail.com>
In-Reply-To
<YugPER9UsH1z6MZo@coredump.intra.peff.net>
)(
On Mon, Aug 1, 2022 at 10:36 AM Jeff King <peff@peff.net> wrote:
Show 5 quoted lines
>
> No, sadly, that isn't the rule. See afe5d3d516 (symbolic ref: refuse
> non-ref targets in HEAD, 2009-01-29) which tightened it to "refs/heads"
> and then e9cc02f0e4 (symbolic-ref: allow refs/<whatever> in HEAD,
> 2009-02-13) which had to loosen it.
But it seems that at least this issue won't affect check_refname_format().

Hmm. Looking at that again - even without ALLOW_ONELEVEL I don't actually think check_refname_format() requires "refs/" per se. So the HEAD check isn't actually made redundant.

I wonder what the intended semantic meaning of ALLOW_ONELEVEL really is supposed to be. It seems to really only require *one* slash - but it doesn't really end up checking that it's in the "refs/" hierarchy, it can be anywhere.

I guess the only thing it disallows is literally HEAD and MERGE_HEAD and the like. But it's a bit odd, because it would seem to possibly allow you to use "refs" that point to the objects/ directory or similar.

Maybe the refs/ protection comes in somewhere later, I didn't really go around to check.

                Linus
Previous: Jeff KingNext: Jeff King
Message 16 of 17 in “"git symbolic-ref" doesn't do a very good job”
  1. Linus TorvaldsJul 30, 2022
  2. Linus TorvaldsJul 30, 2022
  3. Junio C HamanoJul 30, 2022
  4. Jeff KingJul 31, 2022
  5. Jeff KingJul 31, 2022
  6. Linus TorvaldsJul 31, 2022
  7. Jeff KingAug 1, 2022
  8. Jeff KingAug 1, 2022
  9. Jeff KingAug 1, 2022
  10. Junio C HamanoAug 1, 2022
  11. Jeff KingAug 2, 2022
  12. Junio C HamanoAug 2, 2022
  13. Linus TorvaldsAug 1, 2022
  14. Junio C HamanoJul 31, 2022
  15. Jeff KingAug 1, 2022
  16. Linus TorvaldsAug 1, 2022
  17. Jeff KingAug 1, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.