git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 0/3] refs-advertise: add hook to filter advertised refs

From
孙超 <16657101987@163.com>
Date
Aug 4, 2022, 08:27 UTC
Message-ID
<FEAF81E9-61C7-4A41-9882-D05895340003@163.com>
In-Reply-To
<xmqq35ed9iof.fsf@gitster.g>
Show 18 quoted lines
> On Aug 4, 2022, at 04:27, Junio C Hamano <gitster@pobox.com> wrote:
> 
> "Sun Chao via GitGitGadget" <gitgitgadget@gmail.com> writes:
> 
>> Gerrit is implemented by JGit and is known as a centralized workflow system
>> which supports reference-level access control for repository. If we choose
>> to work in centralized workflow like what Gerrit provided, reference-level
>> access control is needed and is possible if we add a reference advertise
>> filter hook just like what Gerrit did.
> 
> It may be one starting point, but is it sufficient to call it
> "possible"?  The server side needs to tighten "fetch by object name"
> to refuse to serve objects that are not reachable from any of the
> refs advertised to the client requesting them.  IIRC, fetch protocol
> v2 is wide open and does not limit the requests to those that are
> only reachable from the advertised refs.
> 
> 
Hi Junio, thanks for you reply.

I agree with you that the server need to refuse the fetch requests that want to steal objects not reachable from the advertised refs. So I have tried to understand the source codes of of `ls-refs.c` and `upload-pack.c` (maybe I lost some important files), and I put a new function `filter_advertise_object` to call `refs-advertise` hook checks the `want` objects.

```diff
@@ -1118,7 +1119,7 @@ static void receive_needs(struct upload_pack_data *data,
               }

               o = parse_object(the_repository, &oid_buf);
-               if (!o) {
+               if ((!o) || (filter_advertise_object(&oid_buf))) {
                       packet_writer_error(&data->writer,
                                           "upload-pack: not our ref %s",
                                           oid_to_hex(&oid_buf));

...

@@ -1421,7 +1445,7 @@ static int parse_want(struct packet_writer *writer, const char *line,
               else
                       o = parse_object(the_repository, &oid);

-               if (!o) {
+               if ((!o) || (filter_advertise_object(&oid))) {
                       packet_writer_error(writer,
                                           "upload-pack: not our ref %s",
                                           oid_to_hex(&oid));
```

The `filter_advertise_object` will exchange messages with the hook by pkt-line
messages, eg:

       # Send commit filter request to hook
       G: PKT-LINE(obj <oid>)
       G: flush-pkt

       # Receive result from the hook.
       # Case 1: this object is valid
       H: PKT-LINE(ok obj <oid>)
       H: flush-pkt
       # Case 2: this object is filtered out
       H: PKT-LINE(ng obj <oid>)
       H: flush-pkt

the hook can check if the `oid` is valid for the client and returns `ng` message if not,
so git server will hide the objects to the client. And I added some test cases for
upload-pack V1 and V2 and looks like it works, but maybe I lost some important points and
I'm still trying to understand other codes for upload-pack and receive-pack because
currently I only implements the filter process for upload-pack and receive-pack.

Thanks for your reply again.
Previous: Junio C HamanoNext: Jiang Xin
Message 6 of 42 in “refs-advertise: add hook to filter advertised refs”
  1. 0/3 refs-advertise: add hook to filter advertised refsSun Chao via GitGitGadget, Aug 3, 2022
  2. 1/3 refs-advertise: add hook to filter advertised refsSun Chao via GitGitGadget, Aug 3, 2022
  3. 3/3 doc: add documentation for the refs-advertise hookSun Chao via GitGitGadget, Aug 3, 2022
  4. 2/3 t1419: add test cases for refs-advertise hookSun Chao via GitGitGadget, Aug 3, 2022
  5. Junio C HamanoAug 3, 2022
  6. 孙超Aug 4, 2022
  7. Jiang XinAug 10, 2022
  8. 孙超Aug 10, 2022
  9. 0/3 hide-refs: add hook to force hide refsSun Chao via GitGitGadget, Aug 15, 2022
  10. 1/3 hide-refs: add hook to force hide refsSun Chao via GitGitGadget, Aug 15, 2022
  11. 2/3 t1419: add test cases for hide-refs hookSun Chao via GitGitGadget, Aug 15, 2022
  12. 3/3 doc: add documentation for the hide-refs hookSun Chao via GitGitGadget, Aug 15, 2022
  13. Eric SunshineAug 15, 2022
  14. 孙超Aug 15, 2022
  15. Junio C HamanoAug 15, 2022
  16. 0/3 hide-refs: add hook to force hide refsSun Chao via GitGitGadget, Aug 15, 2022
  17. 1/3 hide-refs: add hook to force hide refsSun Chao via GitGitGadget, Aug 15, 2022
  18. 3/3 doc: add documentation for the hide-refs hookSun Chao via GitGitGadget, Aug 15, 2022
  19. 2/3 t1419: add test cases for hide-refs hookSun Chao via GitGitGadget, Aug 15, 2022
  20. 0/3 hide-refs: add hook to force hide refsSun Chao via GitGitGadget, Aug 15, 2022
  21. 3/3 doc: add documentation for the hide-refs hookSun Chao via GitGitGadget, Aug 15, 2022
  22. 1/3 hide-refs: add hook to force hide refsSun Chao via GitGitGadget, Aug 15, 2022
  23. Junio C HamanoAug 15, 2022
  24. 孙超Aug 16, 2022
  25. Calvin WanAug 18, 2022
  26. 孙超Aug 19, 2022
  27. 2/3 t1419: add test cases for hide-refs hookSun Chao via GitGitGadget, Aug 15, 2022
  28. 0/5 hiderefs: add hide-refs hook to hide refs dynamicallySun Chao via GitGitGadget, Sep 9, 2022
  29. 1/5 hiderefs: add hide-refs hook to hide refs dynamicallySun Chao via GitGitGadget, Sep 9, 2022
  30. Junio C HamanoSep 13, 2022
  31. Junio C HamanoSep 16, 2022
  32. 孙超Sep 17, 2022
  33. 2/5 hiderefs: use new flag to mark force hidden refsSun Chao via GitGitGadget, Sep 9, 2022
  34. 3/5 hiderefs: hornor hide flags in wire protocol V2Sun Chao via GitGitGadget, Sep 9, 2022
  35. 4/5 test: add test cases for hide-refs hookSun Chao via GitGitGadget, Sep 9, 2022
  36. 5/5 doc: add documentation for the hide-refs hookSun Chao via GitGitGadget, Sep 9, 2022
  37. 0/5 hiderefs: add hide-refs hook to hide refs dynamicallySun Chao via GitGitGadget, Sep 20, 2022
  38. 1/5 hiderefs: add hide-refs hook to hide refs dynamicallySun Chao via GitGitGadget, Sep 20, 2022
  39. 3/5 hiderefs: hornor hide flags in wire protocol V2Sun Chao via GitGitGadget, Sep 20, 2022
  40. 2/5 hiderefs: use a new flag to mark force hidden refsSun Chao via GitGitGadget, Sep 20, 2022
  41. 5/5 doc: add documentation for the hide-refs hookSun Chao via GitGitGadget, Sep 20, 2022
  42. 4/5 test: add test cases for hide-refs hookSun Chao via GitGitGadget, Sep 20, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.