git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[RFC][PATCH] Allow transfer of any valid sha1

From
Eric W. Biederman <ebiederm@xmission.com>
Date
May 24, 2006, 07:51 UTC
Message-ID
<m164jvj1x3.fsf@ebiederm.dsl.xmission.com>

While working on git-quiltimport I decided to see if I could transform Andrews patches where he imports git tress into git-pull commands, which should result in better history and better attribution.

To be accurate of his source Andrew records the sha1 of the commit and the git tree he pulled from. Which looks like:

GIT b307e8548921c686d2eb948ca418ab2941876daa \
 git+ssh://master.kernel.org/pub/scm/linux/kernel/git/torvalds/linux-2.6.git

So I figured I would transform the above line into the obvious git-pull command:

 git-pull \
  git+ssh://master.kernel.org/pub/scm/linux/kernel/git/torvalds/linux-2.6.git \
  b307e8548921c686d2eb948ca418ab2941876daa

To my surprise that didn't work. There were a couple of little places in the scripts where git-fetch and git-fetch-pack never expected to be given a sha1 but that was easy to fix up, and had no real repercussions.

More problematic was the little bit in git-upload pack that only allows you to a sha1 if it was on the list of sha1 generated from looking at the heads. I'm not at all certain of the sense of that check as you can get everything by just cloning the repository.

Can we fix the check in upload-pack.c something like my patch below does? Are there any security implications for doing that?

Could we just make the final check before dying if (!o) ?
		/* We have sent all our refs already, and the other end
		 * should have chosen out of them; otherwise they are
		 * asking for nonsense.
		 *
		 * Hmph.  We may later want to allow "want" line that
		 * asks for something like "master~10" (symbolic)...
		 * would it make sense?  I don't know.
		 */
diff --git a/upload-pack.c b/upload-pack.c
index 47560c9..0f2e544 100644
--- a/upload-pack.c
+++ b/upload-pack.c
@@ -207,7 +207,9 @@ static int receive_needs(void)
 		 * would it make sense?  I don't know.
 		 */
 		o = lookup_object(sha1_buf);
-		if (!o || !(o->flags & OUR_REF))
+		if (!o)
+			o = parse_object(sha1_buf);
+		if (!o || ((o->type != commit_type) && (o->type != tag_type)))
 			die("git-upload-pack: not our ref %s", line+5);
 		if (!(o->flags & WANTED)) {
 			o->flags |= WANTED;
Next: Junio C Hamano
Message 1 of 18 in “Allow transfer of any valid sha1”
  1. Eric W. BiedermanMay 24, 2006
  2. Junio C HamanoMay 24, 2006
  3. Eric W. BiedermanMay 25, 2006
  4. Junio C HamanoMay 25, 2006
  5. Eric W. BiedermanMay 25, 2006
  6. Linus TorvaldsMay 25, 2006
  7. Eric W. BiedermanMay 25, 2006
  8. Junio C HamanoMay 25, 2006
  9. Linus TorvaldsMay 25, 2006
  10. Eric W. BiedermanMay 25, 2006
  11. Junio C HamanoMay 25, 2006
  12. Eric W. BiedermanMay 26, 2006
  13. Junio C HamanoMay 26, 2006
  14. Eric W. BiedermanMay 26, 2006
  15. Eric W. BiedermanMay 25, 2006
  16. Junio C HamanoMay 25, 2006
  17. Eric W. BiedermanMay 26, 2006
  18. Eric W. BiedermanJun 8, 2006

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.