]> git.ipfire.org Git - thirdparty/git.git/commit - list-objects-filter-options.c
list-objects-filter: disable 'sparse:path' filters
authorChristian Couder <christian.couder@gmail.com>
Wed, 29 May 2019 12:44:32 +0000 (14:44 +0200)
committerJunio C Hamano <gitster@pobox.com>
Wed, 29 May 2019 18:05:34 +0000 (11:05 -0700)
commite693237e2ba27b6129e8af7f6a794f5c2fbd26f3
tree2317223e6228a03a1b0b9fd4ecf5dc51a5eb5fbb
parentaa25c82427ae70aebf3b8f970f2afd54e9a2a8c6
list-objects-filter: disable 'sparse:path' filters

If someone wants to use as a filter a sparse file that is in the
repository, something like "--filter=sparse:oid=<ref>:<path>"
already works.

So 'sparse:path' is only interesting if the sparse file is not in
the repository. In this case though the current implementation has
a big security issue, as it makes it possible to ask the server to
read any file, like for example /etc/password, and to explore the
filesystem, as well as individual lines of files.

If someone is interested in using a sparse file that is not in the
repository as a filter, then at the minimum a config option, such
as "uploadpack.sparsePathFilter", should be implemented first to
restrict the directory from which the files specified by
'sparse:path' can be read.

For now though, let's just disable 'sparse:path' filters.

Helped-by: Matthew DeVore <matvore@google.com>
Helped-by: Jeff Hostetler <git@jeffhostetler.com>
Signed-off-by: Christian Couder <chriscool@tuxfamily.org>
Signed-off-by: Junio C Hamano <gitster@pobox.com>
Documentation/rev-list-options.txt
contrib/completion/git-completion.bash
list-objects-filter-options.c
list-objects-filter-options.h
list-objects-filter.c
t/t5317-pack-objects-filter-objects.sh
t/t6112-rev-list-filters-objects.sh