git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 0/1] files-backend: check symref name before update

From
Karthik Nayak <karthik.188@gmail.com>
Date
Oct 2, 2025, 09:34 UTC
Message-ID
<CAOLa=ZSboPeTNSSh1fsaKc+Ef5DhaKGX+mNiRzyYfvFERa=JLQ@mail.gmail.com>
In-Reply-To
<20251001150805.9652-1-hanyang.tony@bytedance.com>
Han Young <hanyang.tony@bytedance.com> writes:
Show 24 quoted lines
> From: Han Young <hanyoung@protonmail.com>
>
> In the ref files backend, the symbolic reference name is not checked
> before an update. This could cause reference and lock files to be created
> outside the refs/ directory.
>
> Below are the original bug report by Sigma:
>
>   $ echo ref: refs/../HEAD > .git/HEAD
>   $ git commit -m "test" --allow-empty
>   fatal: cannot lock ref 'HEAD': Unable to create '/home/sigma/headtest/.git/refs/../HEAD.lock': File exists.
>
>   Another git process seems to be running in this repository, e.g.
>   an editor opened by 'git commit'. Please make sure all processes
>   are terminated then try again. If it still fails, a git process
>   may have crashed in this repository earlier:
>   remove the file manually to continue.
>
> In this case, while trying to update the symbolic reference refs/../HEAD,
> the lock file conflicts with the ./git/HEAD.lock.
>
> If the HEAD points to refs/../foo, a reference file named foo will be
> created under ./git directory.
>

I quickly checked if this can also be done by using 'git-update-ref(1)'. But the command calls on 'check_refname_format()' to check the new ref for the symref update and fails:

  $ git update-ref --stdin
  symref-update HEAD refs/../HEAD
  fatal: invalid ref format: refs/../HEAD
So this is only possible by manually editing the .git/HEAD file, right?
In that case, isn't the repository already broken?

In other words, the fix seem to only stop us from creating files outside the $GIT_DIR, but this seems like something that the user would have to orchestrate intentionally.

The bigger question for me is if there is an instance that you'd want to modify the HEAD file manually. Or is there a way this can be done via any of the existing Git commands. Otherwise, I'm not sure I would call this a bug.

Show 8 quoted lines
> Han Young (1):
>   files-backend: check symref name before update
>
>  refs/files-backend.c | 10 ++++++++++
>  1 file changed, 10 insertions(+)
>
> --
> 2.51.0.373.gaf4ee0e35.dirty
Previous: shejialuoNext: Junio C Hamano
Message 10 of 11 in “files-backend: check symref name before update”
  1. 0/1 files-backend: check symref name before updateHan Young, Oct 1, 2025
  2. 1/1 files-backend: check symref name before updateHan Young, Oct 1, 2025
  3. Junio C HamanoOct 1, 2025
  4. Karthik NayakOct 2, 2025
  5. Patrick SteinhardtOct 2, 2025
  6. Junio C HamanoOct 2, 2025
  7. Patrick SteinhardtOct 2, 2025
  8. Junio C HamanoOct 2, 2025
  9. shejialuoOct 5, 2025
  10. Karthik NayakOct 2, 2025
  11. Junio C HamanoOct 2, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.