Git development
 help / color / mirror / Atom feed
From: Christian Couder <christian.couder@gmail.com>
To: git@vger.kernel.org
Cc: Junio C Hamano <gitster@pobox.com>,
	"brian m . carlson" <sandals@crustytoothpaste.net>,
	Patrick Steinhardt <ps@pks.im>,
	Karthik Nayak <karthik.188@gmail.com>, Jeff King <peff@peff.net>,
	Elijah Newren <newren@gmail.com>,
	Christian Couder <christian.couder@gmail.com>
Subject: [PATCH v4 3/5] upload-pack: read uploadpack.lazyFetchTrusted
Date: Mon, 28 Sep 2026 15:38:44 +0200	[thread overview]
Message-ID: <20260928133846.2094261-4-christian.couder@gmail.com> (raw)
In-Reply-To: <20260928133846.2094261-1-christian.couder@gmail.com>

Previous commits created and prepared the path_allowlist_apply()
and path_allowlist_config_apply() functions, but used them only for the
"safe.directory" configuration variable.

Let's reuse these functions for a new "uploadpack.lazyFetchTrusted"
configuration variable.

It allows us to:

  - read an allowlist from that config variable,
  - check if the current repo is in that list, and
  - return the result from a new upload_pack_lazy_fetch_trusted()
    function.

As path_allowlist_config_apply() lets each caller decide which paths
it is willing to accept using a callback, let's pass it a new
allow_trusted_path() callback. Unlike the "safe.directory" callback, it
accepts only absolute paths, and not ".", as `upload-pack` always
serves a repository given by an absolute path, so there is no "current
repository" for "." to refer to.

Note that a served repository is identified by its git directory, and
not by its worktree. This is because `upload-pack` uses enter_repo()
instead of the usual repository discovery, so it never learns about a
worktree and `r->worktree` is always NULL there. In practice this
means that a non-bare repository served as "/srv/repo" has to be
allowlisted as "/srv/repo/.git".

The new upload_pack_lazy_fetch_trusted() function will be used in a
following commit.

Note that the new config variable should be read only from protected
configuration files.

Signed-off-by: Christian Couder <christian.couder@gmail.com>
---
 upload-pack.c | 59 +++++++++++++++++++++++++++++++++++++++++++++++++++
 upload-pack.h |  3 +++
 2 files changed, 62 insertions(+)

diff --git a/upload-pack.c b/upload-pack.c
index 22573ad365..a300870fa9 100644
--- a/upload-pack.c
+++ b/upload-pack.c
@@ -34,6 +34,8 @@
 #include "json-writer.h"
 #include "strmap.h"
 #include "promisor-remote.h"
+#include "setup.h"
+#include "abspath.h"
 
 /* Remember to update object flag allocation in object.h */
 #define THEY_HAVE	(1u << 11)
@@ -1343,6 +1345,63 @@ static int upload_pack_config(const char *var, const char *value,
 	return parse_hide_refs_config(var, value, "uploadpack", &data->hidden_refs);
 }
 
+/*
+ * Only absolute paths make sense here. Unlike 'safe.directory', "."
+ * is not accepted, as the served repository is always identified by
+ * an absolute path.
+ */
+static bool allow_trusted_path(const char *path, void *cbdata_)
+{
+	struct path_allowlist_cb_data *cbdata = cbdata_;
+
+	if (is_absolute_path(path))
+		return true;
+
+	warning(_("%s '%s' not absolute"), cbdata->key, path);
+	return false;
+}
+
+struct lazy_fetch_trusted {
+	char *repo_path;
+	bool trusted;
+};
+
+static int upload_pack_protected_lazy_fetch_config(const char *var, const char *value,
+						   const struct config_context *ctx UNUSED,
+						   void *cb_data)
+{
+	struct lazy_fetch_trusted *data = cb_data;
+	struct path_allowlist_cb_data cbdata = { .key = var };
+
+	if (strcmp("uploadpack.lazyfetchtrusted", var))
+		return 0;
+
+	path_allowlist_config_apply(var, value, data->repo_path, &data->trusted,
+				    allow_trusted_path, &cbdata);
+
+	return 0;
+}
+
+bool upload_pack_lazy_fetch_trusted(struct repository *r)
+{
+	struct lazy_fetch_trusted data = { 0 };
+
+	/*
+	 * A served repository is identified by its git directory, as
+	 * `upload-pack` uses enter_repo() instead of the usual repository
+	 * discovery, so its worktree, if any, is never known here.
+	 */
+	data.repo_path = real_pathdup(r->gitdir, 0);
+	if (!data.repo_path)
+		return false;
+
+	git_protected_config(upload_pack_protected_lazy_fetch_config, &data);
+
+	free(data.repo_path);
+
+	return !!data.trusted;
+}
+
 static int upload_pack_protected_config(const char *var, const char *value,
 					const struct config_context *ctx UNUSED,
 					void *cb_data)
diff --git a/upload-pack.h b/upload-pack.h
index d6ee25ea98..b2212992c3 100644
--- a/upload-pack.h
+++ b/upload-pack.h
@@ -12,4 +12,7 @@ struct strbuf;
 int upload_pack_advertise(struct repository *r,
 			  struct strbuf *value);
 
+/* Is this repo trusted for lazy fetching? */
+bool upload_pack_lazy_fetch_trusted(struct repository *r);
+
 #endif /* UPLOAD_PACK_H */
-- 
2.56.0.rc2.20.g34f06850c1


  parent reply	other threads:[~2026-09-28 13:39 UTC|newest]

Thread overview: 70+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-10  8:51 [PATCH 0/3] Introduce a 'fromAccepted' option to GIT_NO_LAZY_FETCH Christian Couder
2026-07-10  8:51 ` [PATCH 1/3] promisor-remote: factor out lazy_fetch_objects() Christian Couder
2026-07-10  8:51 ` [PATCH 2/3] promisor-remote: introduce enum allow_lazy_fetch Christian Couder
2026-07-10  8:51 ` [PATCH 3/3] promisor-remote: teach 'fromAccepted' to GIT_NO_LAZY_FETCH Christian Couder
2026-07-10 19:50 ` [PATCH 0/3] Introduce a 'fromAccepted' option " brian m. carlson
2026-07-12  9:06   ` Christian Couder
2026-08-07 13:55 ` [PATCH 0/5] Introduce 'uploadpack.lazyFetchTrusted' Christian Couder
2026-08-07 13:55   ` [PATCH 1/5] promisor-remote: factor out lazy_fetch_objects() Christian Couder
2026-08-07 13:58     ` Christian Couder
2026-08-07 13:55   ` [PATCH 2/5] setup: extract path_allowlist_apply() Christian Couder
2026-08-07 13:55   ` [PATCH 3/5] setup: add 'allow_dot' arg to path_allowlist_apply() Christian Couder
2026-08-07 13:55   ` [PATCH 4/5] upload-pack: read uploadpack.lazyFetchTrusted Christian Couder
2026-08-07 13:55   ` [PATCH 5/5] builtin/upload-pack: set GIT_NO_LAZY_FETCH to 0 on trusted repo Christian Couder
2026-08-07 18:31   ` [PATCH 0/5] Introduce 'uploadpack.lazyFetchTrusted' Junio C Hamano
2026-08-10  8:06     ` Christian Couder
2026-08-11  5:55       ` Junio C Hamano
2026-08-13 15:47   ` [PATCH v2 " Christian Couder
2026-08-13 20:31     ` Junio C Hamano
2026-08-14 16:31       ` Christian Couder
2026-08-14 16:40         ` Junio C Hamano
2026-09-08 16:41     ` [PATCH v3 " Christian Couder
2026-09-08 16:41       ` [PATCH v3 1/5] promisor-remote: factor out lazy_fetch_objects() Christian Couder
2026-09-08 17:39         ` Junio C Hamano
2026-09-28 13:39           ` Christian Couder
2026-09-08 16:41       ` [PATCH v3 2/5] setup: extract path_allowlist_apply() Christian Couder
2026-09-08 17:48         ` Junio C Hamano
2026-09-28 13:40           ` Christian Couder
2026-09-08 16:41       ` [PATCH v3 3/5] upload-pack: read uploadpack.lazyFetchTrusted Christian Couder
2026-09-08 16:41       ` [PATCH v3 4/5] promisor-remote: prevent infinite recursion when lazy fetching Christian Couder
2026-09-08 18:12         ` Junio C Hamano
2026-09-09 10:00           ` Christian Couder
2026-09-09 21:39             ` Junio C Hamano
2026-09-28 13:41               ` Christian Couder
2026-09-08 16:41       ` [PATCH v3 5/5] builtin/upload-pack: set GIT_NO_LAZY_FETCH to 0 on trusted repo Christian Couder
2026-09-08 18:34         ` Junio C Hamano
2026-09-28 13:42           ` Christian Couder
2026-09-28 13:38       ` [PATCH v4 0/5] Introduce 'uploadpack.lazyFetchTrusted' Christian Couder
2026-09-28 13:38         ` [PATCH v4 1/5] promisor-remote: factor out lazy_fetch_objects() Christian Couder
2026-09-28 13:38         ` [PATCH v4 2/5] setup: extract path_allowlist_apply() Christian Couder
2026-09-29 17:26           ` Junio C Hamano
2026-10-02  9:00             ` Christian Couder
2026-09-28 13:38         ` Christian Couder [this message]
2026-09-28 13:38         ` [PATCH v4 4/5] promisor-remote: prevent infinite recursion when lazy fetching Christian Couder
2026-09-28 13:38         ` [PATCH v4 5/5] builtin/upload-pack: don't disable lazy fetching on trusted repo Christian Couder
2026-09-29 17:47           ` Junio C Hamano
2026-10-02  8:57             ` Christian Couder
2026-10-02  9:18               ` Christian Couder
2026-10-02  8:23         ` [PATCH v5 0/5] Introduce 'uploadpack.lazyFetchTrusted' Christian Couder
2026-10-02  8:23           ` [PATCH v5 1/5] promisor-remote: factor out lazy_fetch_objects() Christian Couder
2026-10-02  8:23           ` [PATCH v5 2/5] setup: extract path_allowlist_apply() Christian Couder
2026-10-02  8:23           ` [PATCH v5 3/5] upload-pack: read uploadpack.lazyFetchTrusted Christian Couder
2026-10-02  8:23           ` [PATCH v5 4/5] promisor-remote: prevent infinite recursion when lazy fetching Christian Couder
2026-10-02  8:23           ` [PATCH v5 5/5] builtin/upload-pack: don't disable lazy fetching on trusted repo Christian Couder
2026-10-05 15:37           ` [PATCH v5 0/5] Introduce 'uploadpack.lazyFetchTrusted' Junio C Hamano
2026-10-06 14:54             ` Christian Couder
2026-08-13 15:47   ` [PATCH v2 1/5] promisor-remote: factor out lazy_fetch_objects() Christian Couder
2026-08-14 17:49     ` Junio C Hamano
2026-09-08 17:11       ` Christian Couder
2026-08-13 15:47   ` [PATCH v2 2/5] setup: extract path_allowlist_apply() Christian Couder
2026-08-14 17:56     ` Junio C Hamano
2026-09-08 16:46       ` Christian Couder
2026-09-08 17:49         ` Junio C Hamano
2026-08-13 15:47   ` [PATCH v2 3/5] setup: add 'allow_dot' arg to path_allowlist_apply() Christian Couder
2026-08-14 18:12     ` Junio C Hamano
2026-09-08 16:55       ` Christian Couder
2026-08-13 15:47   ` [PATCH v2 4/5] upload-pack: read uploadpack.lazyFetchTrusted Christian Couder
2026-08-14 18:56     ` Junio C Hamano
2026-08-13 15:47   ` [PATCH v2 5/5] builtin/upload-pack: set GIT_NO_LAZY_FETCH to 0 on trusted repo Christian Couder
2026-08-14 19:35     ` Junio C Hamano
2026-09-08 17:02       ` Christian Couder

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260928133846.2094261-4-christian.couder@gmail.com \
    --to=christian.couder@gmail.com \
    --cc=git@vger.kernel.org \
    --cc=gitster@pobox.com \
    --cc=karthik.188@gmail.com \
    --cc=newren@gmail.com \
    --cc=peff@peff.net \
    --cc=ps@pks.im \
    --cc=sandals@crustytoothpaste.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox