git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v4 1/2] fetch-pack: redact packfile urls in traces

From
Ivan Frade <ifrade@google.com>
Date
Oct 28, 2021, 22:15 UTC
Message-ID
<CANQMx9WFKJAGF+7zti8+-b2je9sFuNxwOx-LCPtEoGCea54Mdw@mail.gmail.com>
In-Reply-To
<xmqq35omt11f.fsf@gitster.g>
On Wed, Oct 27, 2021 at 6:01 PM Junio C Hamano <gitster@pobox.com> wrote:
Show 5 quoted lines
>
> "Ivan Frade via GitGitGadget" <gitgitgadget@gmail.com> writes:
>
> > From: Ivan Frade <ifrade@google.com>
> >
> Just a curiosity.  Do we call these packfile URI, or packfile URL?

The feature is "packfile URI" (and the section is called so in the protocol). I changed all "url" to "uri".

Show 17 quoted lines
> > diff --git a/pkt-line.c b/pkt-line.c
> > index 2dc8ac274bd..ba0a2d65f0c 100644
> > --- a/pkt-line.c
> > +++ b/pkt-line.c
> > @@ -370,6 +370,31 @@ int packet_length(const char lenbuf_hex[4])
> >       return (val < 0) ? val : (val << 8) | hex2chr(lenbuf_hex + 2);
> >  }
> >
> > +static char *find_url_path(const char* buffer, int *path_len)
> > +{
> > +     const char *URL_MARK = "://";
> > +     char *path = strstr(buffer, URL_MARK);
> > +     if (!path)
> > +             return NULL;
>
> Hmph, the format we expect is "<hash> <uri>"; don't we need to
> validate the leading <hash> followed by SP?

I was trying to find a uri in a packet in general, not counting on the packfile-uri line format. That is probably an overgeneralization.

Next patch version follows these suggestions to look for a packfile-uri line.
Show 7 quoted lines
> > +     if (path_len) {
> > +             char *url_end = strchrnul(path, ' ');
>
> Is this because SP is not a valid character in packfile URI, or at
> this point in the callchain it would be encoded or something?  The
> format we expect is "<hash> <uri>", so we shouldn't even have to
> look for SP but just redact everything to the end, no?

Yes, now that we count on the packfile-uri line format, we can redact everything to the end and there is no need to return the length.

Show 16 quoted lines
> > -     packet_trace(buffer, len, 0);
> > +     if (options & PACKET_READ_REDACT_URL_PATH &&
> > +         (url_path_start = find_url_path(buffer, &url_path_len))) {
> > +             const char *redacted = "<redacted>";
> > +             struct strbuf tracebuf = STRBUF_INIT;
> > +             strbuf_insert(&tracebuf, 0, buffer, len);
> > +             strbuf_splice(&tracebuf, url_path_start - buffer,
> > +                           url_path_len, redacted, strlen(redacted));
> > +             packet_trace(tracebuf.buf, tracebuf.len, 0);
> > +             strbuf_release(&tracebuf);
>
> I briefly wondered if the repeated allocation (and more
> fundamentally, preparing the redacted copy of packet whether we are
> actually tracing the packet in the first place) is blindly wasting
> the resources too much, but this only happens in the protocol header
> part, so it might be OK.

We only allocate and redact if it looks like a packfile-uri line, so it shouldn't happen too frequently.

Show 5 quoted lines
> Even if that is not the case, we should be able to update
> fetch_pack.c::do_fetch_pack_v2() so that the REDACT_URL_PATH bit is
> turned on in a much narrower region of code, right?  Enable when we
> enter the GET_PACK state and drop the bit when we are done with the
> packfile URI packets, or something?

I move the set/unset of the redacting flag to the FETCH_GET_PACK around the "packfile-uris" section. There is no need to check every incoming packet for a packfile-uri line, we know when they should come.

Thanks,
Ivan
Previous: Junio C HamanoNext: Junio C Hamano
Message 15 of 43 in “fetch-pack: redact packfile urls in traces”
  1. 0/2 fetch-pack: redact packfile urls in tracesIvan Frade via GitGitGadget, Oct 8, 2021
  2. 1/2 fetch-pack: redact packfile urls in tracesIvan Frade via GitGitGadget, Oct 8, 2021
  3. Ævar Arnfjörð BjarmasonOct 8, 2021
  4. Ivan FradeOct 8, 2021
  5. 2/2 Documentation: packfile-uri hash can be longer than 40 hex charsIvan Frade via GitGitGadget, Oct 8, 2021
  6. Ævar Arnfjörð BjarmasonOct 8, 2021
  7. fetch-pack: redact packfile urls in tracesIvan Frade via GitGitGadget, Oct 9, 2021
  8. Junio C HamanoOct 11, 2021
  9. Ivan FradeOct 26, 2021
  10. fetch-pack: redact packfile urls in tracesIvan Frade via GitGitGadget, Oct 19, 2021
  11. Ævar Arnfjörð BjarmasonOct 20, 2021
  12. 0/2 fetch-pack: redact packfile urls in tracesIvan Frade via GitGitGadget, Oct 26, 2021
  13. 1/2 fetch-pack: redact packfile urls in tracesIvan Frade via GitGitGadget, Oct 26, 2021
  14. Junio C HamanoOct 28, 2021
  15. Ivan FradeOct 28, 2021
  16. Junio C HamanoOct 28, 2021
  17. 2/2 http-fetch: redact url on die() messageIvan Frade via GitGitGadget, Oct 26, 2021
  18. Ævar Arnfjörð BjarmasonOct 28, 2021
  19. Eric SunshineOct 28, 2021
  20. Ivan FradeOct 28, 2021
  21. Ivan FradeOct 28, 2021
  22. Junio C HamanoOct 29, 2021
  23. Ævar Arnfjörð BjarmasonNov 9, 2021
  24. 0/2 fetch-pack: redact packfile urls in tracesIvan Frade via GitGitGadget, Oct 28, 2021
  25. 1/2 fetch-pack: redact packfile urls in tracesIvan Frade via GitGitGadget, Oct 28, 2021
  26. Junio C HamanoOct 28, 2021
  27. Ivan FradeOct 29, 2021
  28. Junio C HamanoOct 29, 2021
  29. Jonathan TanNov 8, 2021
  30. 2/2 http-fetch: redact url on die() messageIvan Frade via GitGitGadget, Oct 28, 2021
  31. 0/2 fetch-pack: redact packfile urls in tracesIvan Frade via GitGitGadget, Oct 29, 2021
  32. 1/2 fetch-pack: redact packfile urls in tracesIvan Frade via GitGitGadget, Oct 29, 2021
  33. Jonathan TanNov 8, 2021
  34. Ævar Arnfjörð BjarmasonNov 9, 2021
  35. Ivan FradeNov 10, 2021
  36. Ævar Arnfjörð BjarmasonNov 11, 2021
  37. Ivan FradeNov 10, 2021
  38. 2/2 http-fetch: redact url on die() messageIvan Frade via GitGitGadget, Oct 29, 2021
  39. Jonathan TanNov 8, 2021
  40. 0/2 fetch-pack: redact packfile urls in tracesIvan Frade via GitGitGadget, Nov 10, 2021
  41. 1/2 fetch-pack: redact packfile urls in tracesIvan Frade via GitGitGadget, Nov 10, 2021
  42. 2/2 http-fetch: redact url on die() messageIvan Frade via GitGitGadget, Nov 10, 2021
  43. Junio C HamanoNov 12, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.