git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 2/2] setup: make bareRepository=explicit work in GIT_DIR of a secondary worktree

From
Junio C Hamano <gitster@pobox.com>
Date
Mar 8, 2024, 22:30 UTC
Message-ID
<xmqqil1wfjbg.fsf@gitster.g>
In-Reply-To
<20240308211957.3758770-3-gitster@pobox.com>
Junio C Hamano <gitster@pobox.com> writes:
Show 28 quoted lines
> In the previous commit, we created a helper function to house the
> logic that checks if a directory that looks like a bare repository
> is actually a part of a non-bare repository.  Extend the helper
> function to also check if the apparent bare-repository is a $GIT_DIR
> of a secondary worktree, by checking three things:
>
>  * The path to the $GIT_DIR must be a subdirectory of
>    ".git/worktrees/", which is the primary worktree [*].
>
>  * Such $GIT_DIR must have file "gitdir", that records the path of
>    the ".git" file that is at the root level of the secondary
>    worktree.
>
>  * That ".git" file in turn points back at the $GIT_DIR we are
>    inspecting.
>
> The latter two points are merely for checking sanity.  The security
> lies in the first requirement.
>
> Remember that a tree object with an entry whose pathname component
> is ".git" is forbidden at various levels (fsck, object transfer and
> checkout), so malicious projects cannot cause users to clone and
> checkout a crafted ".git" directory in a shell directory that
> pretends to be a working tree with that ".git" thing at its root
> level.  That is where 45bb9162 (setup: allow cwd=.git w/
> bareRepository=explicit, 2024-01-20) draws its security guarantee
> from.  And the solution for secondary worktrees in this commit draws
> its security guarantee from the same place.

I wrote the "[*]" mark but forgot to add a footnote with an additional information for it. Something like this was what I had in mind to write there:

[Footnote]
 * This does not help folks who create a new worktree out of a bare
   repository, because in their set-up, there won't be "/.git/" in
   front of "worktrees" directory.  It is fundamentally impossible
   to lift this limitation, as long as safe.bareRepository is
   considered to be a meaningful security measure.  The security of
   both the loosening for a secondary worktree's GIT_DIR as well as
   the loosening for the GIT_DIR of the primary worktree, hinge on
   the fact that ".git/" directory is impossible to create as
   payload to be cloned.
Previous: Junio C HamanoNext: Kyle Lippincott
Message 7 of 17 in “setup: allow cwd=.git w/ bareRepository=explicit”
  1. setup: allow cwd=.git w/ bareRepository=explicitKyle Lippincott via GitGitGadget, Jan 20, 2024
  2. Junio C HamanoJan 20, 2024
  3. Kyle LippincottJan 22, 2024
  4. Junio C HamanoMar 6, 2024
  5. 0/2 Loosening safe.bareRepository=explicit even furtherJunio C Hamano, Mar 8, 2024
  6. 2/2 setup: make bareRepository=explicit work in GIT_DIR of a secondary worktreeJunio C Hamano, Mar 8, 2024
  7. Junio C HamanoMar 8, 2024
  8. Kyle LippincottMar 8, 2024
  9. Junio C HamanoMar 8, 2024
  10. Kyle LippincottMar 9, 2024
  11. Junio C HamanoMar 9, 2024
  12. Kyle MeyerMar 9, 2024
  13. Junio C HamanoMar 9, 2024
  14. 1/2 setup: detect to be in $GIT_DIR with a new helperJunio C Hamano, Mar 8, 2024
  15. setup: notice more types of implicit bare repositoriesJunio C Hamano, Mar 9, 2024
  16. Kyle LippincottMar 11, 2024
  17. Junio C HamanoMar 11, 2024

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.