Re: [PATCH] fetch/push: document that private data can be leaked
- From
Junio C Hamano <gitster@pobox.com>
- Date
- Nov 14, 2016, 02:57 UTC
- Message-ID
- <xmqq1syezs3g.fsf@gitster.mtv.corp.google.com>
- In-Reply-To
- <1479001205.3471.1.camel@mattmccutchen.net>
Matt McCutchen <matt@mattmccutchen.net> writes:
> Documentation/fetch-push-security.txt | 9 +++++++++
A new (consolidated) piece like this that can be included in multiple places is a good idea. I wonder if the original description in "namespaces" thing can be moved here and then "namespaces" page can be made to also borrow from this?
Show 20 quoted lines
> Documentation/git-fetch.txt | 2 ++ > Documentation/git-pull.txt | 2 ++ > Documentation/git-push.txt | 2 ++ > 4 files changed, 15 insertions(+) > create mode 100644 Documentation/fetch-push-security.txt > > diff --git a/Documentation/fetch-push-security.txt b/Documentation/fetch-push-security.txt > new file mode 100644 > index 0000000..00944ed > --- /dev/null > +++ b/Documentation/fetch-push-security.txt > @@ -0,0 +1,9 @@ > +SECURITY > +-------- > +The fetch and push protocols are not designed to prevent a malicious > +server from stealing data from your repository that you did not intend to > +share. The possible attacks are similar to the ones described in the > +"SECURITY" section of linkgit:gitnamespaces[7]. If you have private data > +that you need to protect from the server, keep it in a separate > +repository.
Yup, and then "do not push to untrustworthy place without checking what you are pushing", too?
> diff --git a/Documentation/git-fetch.txt b/Documentation/git-fetch.txt > diff --git a/Documentation/git-pull.txt b/Documentation/git-pull.txt > diff --git a/Documentation/git-push.txt b/Documentation/git-push.txt
These three look sensible.