git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Fetch/push lets a malicious server steal the targets of "have" lines

From
Junio C Hamano <gitster@pobox.com>
Date
Oct 30, 2016, 08:16 UTC
Message-ID
<xmqqpomiuu8q.fsf@gitster.mtv.corp.google.com>
In-Reply-To
<E1c0XaZ-0007Ab-QI@mylo.jdl.com>
Jon Loeliger <jdl@jdl.com> writes:
> Is there an existing protocol provision, or an extension to
> the protocol that would allow a distrustful client to say to
> the server, "Really, you have Y2?  Prove it."
There is not, but I do not think it would be an effective solution.

The issue is not the lack of protocol support, but how to determine that the other side needs such a proof for Y2 but not for other commits. How does your side know what makes Y2 special and why does yout side think they should not have Y2?

Once you know how to determine Y2 is special, that knowledge can be used to abort the "push" before even starting. When you are pushing back the 'master' and that 'master' reaches Y2, which must be kept secret, you shouldn't be pushing that 'master' to them, whether they claim to have Y2 or not.

I think the above is just a different way to say what Peff just said (paraphrasing, do not push what is secret).

Previous: Jon LoeligerNext: Matt McCutchen
Message 20 of 24 in “Fetch/push lets a malicious server steal the targets of "have" lines”
  1. Matt McCutchenOct 28, 2016
  2. Junio C HamanoOct 28, 2016
  3. Matt McCutchenOct 28, 2016
  4. Junio C HamanoOct 29, 2016
  5. Matt McCutchenOct 29, 2016
  6. Jeff KingOct 29, 2016
  7. Matt McCutchenOct 29, 2016
  8. Jeff KingOct 29, 2016
  9. Junio C HamanoOct 30, 2016
  10. fetch/push: document that private data can be leakedMatt McCutchen, Nov 13, 2016
  11. Junio C HamanoNov 14, 2016
  12. Matt McCutchenNov 14, 2016
  13. doc: mention transfer data leaks in more placesMatt McCutchen, Nov 14, 2016
  14. Junio C HamanoNov 14, 2016
  15. Junio C HamanoNov 14, 2016
  16. Jeff KingNov 14, 2016
  17. Junio C HamanoNov 14, 2016
  18. Matt McCutchenNov 14, 2016
  19. Jon LoeligerOct 29, 2016
  20. Junio C HamanoOct 30, 2016
  21. Matt McCutchenNov 13, 2016
  22. Matt McCutchenOct 29, 2016
  23. Junio C HamanoOct 30, 2016
  24. Matt McCutchenNov 13, 2016

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.