git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v4 5/5] builtin/upload-pack: don't disable lazy fetching on trusted repo

From
Junio C Hamano <gitster@pobox.com>
Date
Sep 29, 2026, 17:47 UTC
Message-ID
<xmqqse2sgda6.fsf@gitster.g>
In-Reply-To
<20260928133846.2094261-6-christian.couder@gmail.com>
Christian Couder <christian.couder@gmail.com> writes:
Show 6 quoted lines
>  Documentation/config/uploadpack.adoc  |  49 +++++++++
>  Documentation/git-upload-pack.adoc    |   5 +
>  Documentation/git.adoc                |   4 +-
>  builtin/upload-pack.c                 |  19 +++-
>  t/t5710-promisor-remote-capability.sh | 142 ++++++++++++++++++++++++++
>  5 files changed, 217 insertions(+), 2 deletions(-)

The diffstat above is pleasing to see, with ample documentation to help users, tests with (hopefully) reasonable coverage, and a minimal amount of actual code changes to enable the feature, thanks to the preparatory work done in earlier steps.

> +uploadpack.lazyFetchTrusted::
> +	A multi-valued configuration variable, each of which contains the
> +	absolute local path of a repository that `upload-pack` is allowed to
> +	lazily fetch missing objects for.
"each of which" lacks a plural noun to modify.  Perhaps
	each value of which specifies the absolute local path of a
	repository from which upload-pack is allowed to lazily fetch
	missing objects.
> ++
> +A repository is identified by its git directory, i.e. the `.git`
"i.e." -> "i.e.," (similarly "e.g." -> "e.g.," below).
Show 34 quoted lines
> diff --git a/builtin/upload-pack.c b/builtin/upload-pack.c
> index 32831fb879..53e76deb23 100644
> --- a/builtin/upload-pack.c
> +++ b/builtin/upload-pack.c
> @@ -46,7 +46,6 @@ int cmd_upload_pack(int argc,
>  	packet_trace_identity("upload-pack");
>  	disable_replace_refs();
>  	save_commit_buffer = 0;
> -	xsetenv(NO_LAZY_FETCH_ENVIRONMENT, "1", 0);
>  
>  	argc = parse_options(argc, argv, prefix, options, upload_pack_usage, 0);
>  
> @@ -62,6 +61,24 @@ int cmd_upload_pack(int argc,
>  	if (!enter_repo(the_repository, dir, enter_repo_flags))
>  		die("'%s' does not appear to be a git repository", dir);
>  
> +	/*
> +	 * Lazily fetching while serving a client would run `git fetch`,
> +	 * which may execute arbitrary commands from the configuration
> +	 * and hooks of the served repo, so we disable it by default as
> +	 * we trust nobody. There are two ways for a server operator to
> +	 * allow it though:
> +	 *
> +	 *   - if GIT_NO_LAZY_FETCH is already set, we leave it alone and
> +	 *     honor whatever the operator put there,
> +	 *
> +	 *   - otherwise, if the served repo is in the
> +	 *     "uploadpack.lazyFetchTrusted" protected allowlist, we
> +	 *     don't disable lazy fetching.
> +	 */
> +	if (!getenv(NO_LAZY_FETCH_ENVIRONMENT) &&
> +	    !upload_pack_lazy_fetch_trusted(the_repository))
> +		xsetenv(NO_LAZY_FETCH_ENVIRONMENT, "1", 1);
> +

OK, the logic is so trivially obvious and clear that it wouldn't even need the above comment. Very nice.

Previous: Christian CouderNext: Christian Couder
Message 45 of 70 in “Introduce a 'fromAccepted' option to GIT_NO_LAZY_FETCH”
  1. 0/3 Introduce a 'fromAccepted' option to GIT_NO_LAZY_FETCHChristian Couder, Jul 10, 2026
  2. 1/3 promisor-remote: factor out lazy_fetch_objects()Christian Couder, Jul 10, 2026
  3. 2/3 promisor-remote: introduce enum allow_lazy_fetchChristian Couder, Jul 10, 2026
  4. 3/3 promisor-remote: teach 'fromAccepted' to GIT_NO_LAZY_FETCHChristian Couder, Jul 10, 2026
  5. brian m. carlsonJul 10, 2026
  6. Christian CouderJul 12, 2026
  7. 0/5 Introduce 'uploadpack.lazyFetchTrusted'Christian Couder, Aug 7, 2026
  8. 1/5 promisor-remote: factor out lazy_fetch_objects()Christian Couder, Aug 7, 2026
  9. Christian CouderAug 7, 2026
  10. 2/5 setup: extract path_allowlist_apply()Christian Couder, Aug 7, 2026
  11. 4/5 upload-pack: read uploadpack.lazyFetchTrustedChristian Couder, Aug 7, 2026
  12. 5/5 builtin/upload-pack: set GIT_NO_LAZY_FETCH to 0 on trusted repoChristian Couder, Aug 7, 2026
  13. 3/5 setup: add 'allow_dot' arg to path_allowlist_apply()Christian Couder, Aug 7, 2026
  14. Junio C HamanoAug 7, 2026
  15. Christian CouderAug 10, 2026
  16. Junio C HamanoAug 11, 2026
  17. 0/5 Introduce 'uploadpack.lazyFetchTrusted'Christian Couder, Aug 13, 2026
  18. Junio C HamanoAug 13, 2026
  19. Christian CouderAug 14, 2026
  20. Junio C HamanoAug 14, 2026
  21. 0/5 Introduce 'uploadpack.lazyFetchTrusted'Christian Couder, Sep 8, 2026
  22. 1/5 promisor-remote: factor out lazy_fetch_objects()Christian Couder, Sep 8, 2026
  23. Junio C HamanoSep 8, 2026
  24. Christian CouderSep 28, 2026
  25. 2/5 setup: extract path_allowlist_apply()Christian Couder, Sep 8, 2026
  26. Junio C HamanoSep 8, 2026
  27. Christian CouderSep 28, 2026
  28. 3/5 upload-pack: read uploadpack.lazyFetchTrustedChristian Couder, Sep 8, 2026
  29. 4/5 promisor-remote: prevent infinite recursion when lazy fetchingChristian Couder, Sep 8, 2026
  30. Junio C HamanoSep 8, 2026
  31. Christian CouderSep 9, 2026
  32. Junio C HamanoSep 9, 2026
  33. Christian CouderSep 28, 2026
  34. 5/5 builtin/upload-pack: set GIT_NO_LAZY_FETCH to 0 on trusted repoChristian Couder, Sep 8, 2026
  35. Junio C HamanoSep 8, 2026
  36. Christian CouderSep 28, 2026
  37. 0/5 Introduce 'uploadpack.lazyFetchTrusted'Christian Couder, Sep 28, 2026
  38. 1/5 promisor-remote: factor out lazy_fetch_objects()Christian Couder, Sep 28, 2026
  39. 2/5 setup: extract path_allowlist_apply()Christian Couder, Sep 28, 2026
  40. Junio C HamanoSep 29, 2026
  41. Christian CouderOct 2, 2026
  42. 3/5 upload-pack: read uploadpack.lazyFetchTrustedChristian Couder, Sep 28, 2026
  43. 4/5 promisor-remote: prevent infinite recursion when lazy fetchingChristian Couder, Sep 28, 2026
  44. 5/5 builtin/upload-pack: don't disable lazy fetching on trusted repoChristian Couder, Sep 28, 2026
  45. Junio C HamanoSep 29, 2026
  46. Christian CouderOct 2, 2026
  47. Christian CouderOct 2, 2026
  48. 0/5 Introduce 'uploadpack.lazyFetchTrusted'Christian Couder, Oct 2, 2026
  49. 1/5 promisor-remote: factor out lazy_fetch_objects()Christian Couder, Oct 2, 2026
  50. 2/5 setup: extract path_allowlist_apply()Christian Couder, Oct 2, 2026
  51. 3/5 upload-pack: read uploadpack.lazyFetchTrustedChristian Couder, Oct 2, 2026
  52. 4/5 promisor-remote: prevent infinite recursion when lazy fetchingChristian Couder, Oct 2, 2026
  53. 5/5 builtin/upload-pack: don't disable lazy fetching on trusted repoChristian Couder, Oct 2, 2026
  54. Junio C HamanoOct 5, 2026
  55. Christian CouderOct 6, 2026
  56. 1/5 promisor-remote: factor out lazy_fetch_objects()Christian Couder, Aug 13, 2026
  57. Junio C HamanoAug 14, 2026
  58. Christian CouderSep 8, 2026
  59. 2/5 setup: extract path_allowlist_apply()Christian Couder, Aug 13, 2026
  60. Junio C HamanoAug 14, 2026
  61. Christian CouderSep 8, 2026
  62. Junio C HamanoSep 8, 2026
  63. 3/5 setup: add 'allow_dot' arg to path_allowlist_apply()Christian Couder, Aug 13, 2026
  64. Junio C HamanoAug 14, 2026
  65. Christian CouderSep 8, 2026
  66. 4/5 upload-pack: read uploadpack.lazyFetchTrustedChristian Couder, Aug 13, 2026
  67. Junio C HamanoAug 14, 2026
  68. 5/5 builtin/upload-pack: set GIT_NO_LAZY_FETCH to 0 on trusted repoChristian Couder, Aug 13, 2026
  69. Junio C HamanoAug 14, 2026
  70. Christian CouderSep 8, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.