git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v2] setup: notice more types of implicit bare repositories

From
Kyle Lippincott <spectral@google.com>
Date
Mar 11, 2024, 19:23 UTC
Message-ID
<CAO_smVhAp4V1pb7LQV7yvhs98JVrtDgW5LzjzyJHupGuGSA+sg@mail.gmail.com>
In-Reply-To
<xmqq5xxv0ywi.fsf_-_@gitster.g>
On Sat, Mar 9, 2024 at 3:27 PM Junio C Hamano <gitster@pobox.com> wrote:
Show 22 quoted lines
>
> Builds directly on top of 45bb9162 (setup: allow cwd=.git w/
> bareRepository=explicit, 2024-01-20).
>
> Instead of saying "primary worktree's $GIT_DIR is OK", "secondary
> worktree's $GIT_DIR is OK", and "submodule's $GIT_DIR is OK"
> separately, let's give them a name to call them collectively,
> "implicit bare repository" (for now, to reuse what an earlier commit
> used, which may not be an optimum name), as these share the same
> security guarantee and convenience benefit.
>
> The code got significantly simpler, and test moderately more
> complex, having to set up submodule tests.
>
> ------- >8 ------------- >8 ------------- >8 -------
> Setting the safe.bareRepository configuration variable to explicit
> stops git from using a bare repository, unless the repository is
> explicitly specified, either by the "--git-dir=<path>" command line
> option, or by exporting $GIT_DIR environment variable.  This may be
> a reasonable measure to safeguard users from accidentally straying
> into a bare repository in unexpected places, but often gets in the
> way of users who need valid accesses too the repository.
nit: 'to', not 'too'
Show 24 quoted lines
>
> Earlier, 45bb9162 (setup: allow cwd=.git w/ bareRepository=explicit,
> 2024-01-20) loosened the rule such that being inside the ".git"
> directory of a non-bare repository does not really count as
> accessing a "bare" repository.  The reason why such a loosening is
> needed is because often hooks and third-party tools run from within
> $GIT_DIR while working with a non-bare repository.
>
> More importantly, the reason why this is safe is because a directory
> whose contents look like that of a "bare" repository cannot be a
> bare repository that came embedded within a checkout of a malicious
> project, as long as its directory name is ".git", because ".git" is
> not a name allowed for a directory in payload.
>
> There are at least two other cases where tools have to work in a
> bare-repository looking directory that is not an embedded bare
> repository, and accesses to them are still not allowed by the recent
> change.
>
>  - A secondary worktree (whose name is $name) has its $GIT_DIR
>    inside "worktrees/$name/" subdirectory of the $GIT_DIR of the
>    primary worktree of the same repository.
>
>  - A submodule worktree (whose name is $hame) has its $GIT_DIR
nit: '$name', not '$hame'
Show 24 quoted lines
>    inside "modules/$name/" subdirectory of the $GIT_DIR of its
>    superproject.
>
> As long as the primary worktree or the superproject in these cases
> are not bare, the pathname of these "looks like bare but not really"
> directories will have "/.git/worktrees/" and "/.git/modules/" as a
> substring in its leading part, and we can take advantage of the same
> security guarantee allow git to work from these places.
>
> Extend the earlier "in a directory called '.git' we are OK" logic
> used for the primary worktree to also cover the secondary worktree's
> and non-embedded submodule's $GIT_DIR, by moving the logic to a
> helper function "is_implicit_bare_repo()".  We deliberately exclude
> secondary worktrees and submodules of a bare repository, as these
> are exactly what safe.bareRepository=explicit setting is designed to
> forbid accesses to without an explicit GIT_DIR/--git-dir=<path>
>
> Helped-by: Kyle Lippincott <spectral@google.com>
> Helped-by: Kyle Meyer <kyle@kyleam.com>
> Signed-off-by: Junio C Hamano <gitster@pobox.com>
> ---
>  setup.c                         | 28 +++++++++++++++++++++++++++-
>  t/t0035-safe-bare-repository.sh | 26 ++++++++++++++++++++++----
>  2 files changed, 49 insertions(+), 5 deletions(-)
Looks good, thanks!
Previous: Junio C HamanoNext: Junio C Hamano
Message 16 of 17 in “setup: allow cwd=.git w/ bareRepository=explicit”
  1. setup: allow cwd=.git w/ bareRepository=explicitKyle Lippincott via GitGitGadget, Jan 20, 2024
  2. Junio C HamanoJan 20, 2024
  3. Kyle LippincottJan 22, 2024
  4. Junio C HamanoMar 6, 2024
  5. 0/2 Loosening safe.bareRepository=explicit even furtherJunio C Hamano, Mar 8, 2024
  6. 2/2 setup: make bareRepository=explicit work in GIT_DIR of a secondary worktreeJunio C Hamano, Mar 8, 2024
  7. Junio C HamanoMar 8, 2024
  8. Kyle LippincottMar 8, 2024
  9. Junio C HamanoMar 8, 2024
  10. Kyle LippincottMar 9, 2024
  11. Junio C HamanoMar 9, 2024
  12. Kyle MeyerMar 9, 2024
  13. Junio C HamanoMar 9, 2024
  14. 1/2 setup: detect to be in $GIT_DIR with a new helperJunio C Hamano, Mar 8, 2024
  15. setup: notice more types of implicit bare repositoriesJunio C Hamano, Mar 9, 2024
  16. Kyle LippincottMar 11, 2024
  17. Junio C HamanoMar 11, 2024

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.