git/Documentation/config
Taylor Blau 8c735b11de upload-pack: disallow object-info capability by default
We added an "object-info" capability to the v2 upload-pack protocol in
a2ba162cda (object-info: support for retrieving object info,
2021-04-20). In the almost 3 years since, we have not added any
client-side support, and it does not appear to exist in other
implementations either (JGit understands the verb on the server side,
but not on the client side).

Since this largely unused code is accessible over the network by
default, it increases the attack surface of upload-pack. I don't know of
any particularly severe problem, but one issue is that because of the
request/response nature of the v2 protocol, it will happily read an
unbounded number of packets, adding each one to a string list (without
regard to whether they are objects we know about, duplicates, etc).

This may be something we want to improve in the long run, but in the
short term it makes sense to disable the feature entirely. We'll add a
config option as an escape hatch for anybody who wants to develop the
feature further.

A more gentle option would be to add the config option to let people
disable it manually, but leave it enabled by default. But given that
there's no client side support, that seems like the wrong balance with
security.

Disabling by default will slow adoption a bit once client-side support
does become available (there were some patches[1] in 2022, but nothing
got merged and there's been nothing since). But clients have to deal
with older servers that do not understand the option anyway (and the
capability system handles that), so it will just be a matter of servers
flipping their config at that point (and hopefully once any unbounded
allocations have been addressed).

[jk: this is a patch that GitHub has been running for several years, but
     rebased forward and with a new commit message for upstream]

[1] https://lore.kernel.org/git/20220208231911.725273-1-calvinwan@google.com/

Signed-off-by: Taylor Blau <me@ttaylorr.com>
Signed-off-by: Jeff King <peff@peff.net>
Signed-off-by: Junio C Hamano <gitster@pobox.com>
2024-02-28 14:42:01 -08:00
..
add.txt add: remove "add.interactive.useBuiltin" & Perl "git add--interactive" 2023-02-06 15:03:34 -08:00
advice.txt advice: allow disabling the automatic hint in advise_if_enabled() 2024-01-16 13:07:00 -08:00
alias.txt documentation: fix subject/verb agreement 2023-10-09 12:06:29 -07:00
am.txt
apply.txt documentation: whitespace is already generally plural 2023-10-09 12:06:29 -07:00
attr.txt attr: add attr.tree for setting the treeish to read attributes from 2023-10-13 11:43:29 -07:00
blame.txt
branch.txt documentation: use clearer prepositions 2023-10-09 12:06:29 -07:00
browser.txt
bundle.txt bundle-uri: parse bundle.heuristic=creationToken 2023-01-31 08:57:48 -08:00
checkout.txt documentation: fix capitalization 2023-10-09 12:06:29 -07:00
clean.txt documentation: add some commas where they are helpful 2023-10-09 12:06:44 -07:00
clone.txt documentation: fix verb tense 2023-10-09 12:06:29 -07:00
color.txt documentation: add some commas where they are helpful 2023-10-09 12:06:44 -07:00
column.txt documentation: fix singular vs. plural 2023-10-09 12:06:29 -07:00
commit.txt documentation: add missing article 2023-10-09 12:06:29 -07:00
commitgraph.txt
completion.txt
core.txt add core.maxTreeDepth config 2023-08-31 15:51:07 -07:00
credential.txt documentation: add some commas where they are helpful 2023-10-09 12:06:44 -07:00
diff.txt documentation: fix singular vs. plural 2023-10-09 12:06:29 -07:00
difftool.txt mergetool: new config guiDefault supports auto-toggling gui by DISPLAY 2023-04-05 21:03:29 -07:00
extensions.txt setup: introduce "extensions.refStorage" extension 2024-01-02 09:24:48 -08:00
fastimport.txt documentation: add some commas where they are helpful 2023-10-09 12:06:44 -07:00
feature.txt pack-objects: enable multi-pack reuse via `feature.experimental` 2024-02-05 15:27:01 -08:00
fetch.txt fetch: add new config option fetch.all 2024-01-08 13:36:23 -08:00
filter.txt
fmt-merge-msg.txt
format.txt Merge branch 'jc/doc-misspelt-refs-fix' 2023-12-27 14:52:26 -08:00
fsck.txt documentation: add some commas where they are helpful 2023-10-09 12:06:44 -07:00
fsmonitor--daemon.txt documentation: wording improvements 2023-10-09 12:04:21 -07:00
gc.txt Merge branch 'en/docfixes' 2023-10-23 13:56:37 -07:00
gitcvs.txt
gitweb.txt
gpg.txt documentation: fix subject/verb agreement 2023-10-09 12:06:29 -07:00
grep.txt grep docs: de-duplicate configuration sections 2022-09-07 09:46:05 -07:00
gui.txt documentation: add missing article 2023-10-09 12:06:29 -07:00
guitool.txt
help.txt
http.txt documentation: add missing words 2023-10-09 12:06:29 -07:00
i18n.txt documentation: use clearer prepositions 2023-10-09 12:06:29 -07:00
imap.txt documentation: fix verb vs. noun 2023-10-09 12:06:29 -07:00
includeif.txt config.txt: document include, includeIf 2022-07-17 14:23:42 -07:00
index.txt documentation: fix apostrophe usage 2023-10-09 12:06:29 -07:00
init.txt
instaweb.txt
interactive.txt
log.txt documentation: add some commas where they are helpful 2023-10-09 12:06:44 -07:00
lsrefs.txt docs: move protocol-related docs to man section 5 2022-08-04 14:12:23 -07:00
mailinfo.txt documentation: fix singular vs. plural 2023-10-09 12:06:29 -07:00
mailmap.txt
maintenance.txt documentation: fix subject/verb agreement 2023-10-09 12:06:29 -07:00
man.txt documentation: add missing article 2023-10-09 12:06:29 -07:00
merge.txt documentation: add some commas where they are helpful 2023-10-09 12:06:44 -07:00
mergetool.txt documentation: add some commas where they are helpful 2023-10-09 12:06:44 -07:00
notes.txt documentation: add missing article 2023-10-09 12:06:29 -07:00
pack.txt pack-bitmap: enable reuse from all bitmapped packs 2023-12-14 14:38:09 -08:00
pager.txt
pretty.txt
protocol.txt Sync with 2.37.4 2022-10-06 20:00:04 -04:00
pull.txt
push.txt documentation: add some commas where they are helpful 2023-10-09 12:06:44 -07:00
rebase.txt Merge branch 'ms/rebase-insnformat-doc-fix' 2024-01-12 16:09:57 -08:00
receive.txt documentation: employ consistent verb tense for a list 2023-10-09 12:06:29 -07:00
remote.txt
remotes.txt
repack.txt builtin/repack.c: allow configuring cruft pack generation 2022-05-26 15:48:26 -07:00
rerere.txt documentation: fix singular vs. plural 2023-10-09 12:06:29 -07:00
revert.txt revert: config documentation fixes 2022-06-27 08:37:36 -07:00
safe.txt documentation: wording improvements 2023-10-09 12:04:21 -07:00
sendemail.txt documentation: add missing article 2023-10-09 12:06:29 -07:00
sequencer.txt documentation: add some commas where they are helpful 2023-10-09 12:06:44 -07:00
showbranch.txt
sparse.txt
splitindex.txt documentation: add some commas where they are helpful 2023-10-09 12:06:44 -07:00
ssh.txt
stash.txt documentation: add missing article 2023-10-09 12:06:29 -07:00
status.txt documentation: add missing hyphens 2023-10-09 12:06:29 -07:00
submodule.txt documentation: fix apostrophe usage 2023-10-09 12:06:29 -07:00
tag.txt
tar.txt
trace2.txt documentation: wording improvements 2023-10-09 12:04:21 -07:00
transfer.txt upload-pack: disallow object-info capability by default 2024-02-28 14:42:01 -08:00
uploadarchive.txt
uploadpack.txt Documentation: define protected configuration 2022-07-14 15:08:29 -07:00
url.txt
user.txt documentation: add some commas where they are helpful 2023-10-09 12:06:44 -07:00
versionsort.txt documentation: add some commas where they are helpful 2023-10-09 12:06:44 -07:00
web.txt
worktree.txt