Re: git-index-pack really does suck..
- From
- David Lang <david.lang@digitalinsight.com>
- Date
- Apr 6, 2007, 21:56 UTC
- Message-ID
- <Pine.LNX.4.63.0704061455380.24050@qynat.qvtvafvgr.pbz>
- In-Reply-To
- <81b0412b0704040251j34b0bc5eh1518eadcfa2ed299@mail.gmail.com>
On Wed, 4 Apr 2007, Alex Riesen wrote:
Show 20 quoted lines
> On 4/4/07, David Lang <david.lang@digitalinsight.com> wrote: >> >> > The keeping of fetched packs broke that presumption of trust towards >> > local objects and it opened a real path for potential future attacks. >> > Those attacks are still fairly theoretical of course. But for how >> > _long_? Do we want GIT to be considered backdoor prone in a couple >> > years from now just because we were obsessed by a 7% CPU overhead? >> > >> > I think we have much more to gain by playing it safe and being more >> > secure and paranoid than trying to squeeze some CPU cycles out of an >> > operation that is likely to ever be bounded by network speed for most >> > people. >> >> this is why -paranoid should be left on for network pulls, but having it on >> for >> the local uses means that the cost isn't hidden in the network limits isn't >> good. > > You never know what pull is networked (or should I say: remote enough > to cause a collision).
so leave it on for all pulls, but for other commands don't turn it on.
remember that the command that linus ran into at the start of the thread wasn't a pull.
David Lang