Jeff King ee27ca4a78 archive: don't let remote clients get unreachable commits
Usually git is careful not to allow clients to fetch
arbitrary objects from the database; for example, objects
received via upload-pack must be reachable from a ref.
Upload-archive breaks this by feeding the client's tree-ish
directly to get_sha1, which will accept arbitrary hex sha1s,
reflogs, etc.

This is not a problem if all of your objects are publicly
reachable anyway (or at least public to anybody who can run
upload-archive). Or if you are making the repo available by
dumb protocols like http or rsync (in which case the client
can read your whole object db directly).

But for sites which allow access only through smart
protocols, clients may be able to fetch trees from commits
that exist in the server's object database but are not
referenced (e.g., because history was rewound).

This patch tightens upload-archive's lookup to use dwim_ref
rather than get_sha1. This means a remote client can only
fetch the tip of a named ref, not an arbitrary sha1 or
reflog entry.

This also restricts some legitimate requests, too:

  1. Reachable non-tip commits, like:

        git archive --remote=$url v1.0~5

  2. Sub-trees of reachable commits, like:

        git archive --remote=$url v1.7.7:Documentation

Local requests continue to use get_sha1, and are not
restricted at all.

Signed-off-by: Jeff King <peff@peff.net>
Signed-off-by: Junio C Hamano <gitster@pobox.com>
2011-11-21 14:42:25 -08:00
2009-03-02 18:28:06 -08:00
2008-12-17 21:56:48 -08:00
2009-02-10 21:32:10 -08:00
2008-09-10 15:00:17 -07:00
2009-01-28 11:33:51 -08:00
2008-09-15 23:11:35 -07:00
2009-02-19 23:44:07 -08:00
2008-09-25 09:39:24 -07:00
2009-01-25 17:13:29 -08:00
2009-01-25 17:13:29 -08:00
2009-02-10 21:32:10 -08:00
2009-01-28 11:33:03 -08:00
2009-05-05 22:49:43 -07:00
2009-01-05 13:01:01 -08:00
2008-10-10 08:39:20 -07:00
2008-10-10 08:39:20 -07:00
2009-01-17 18:30:41 -08:00
2008-11-02 16:36:40 -08:00
2009-01-25 17:13:34 -08:00
2009-02-10 21:32:10 -08:00
2008-11-11 14:49:50 -08:00
2009-02-26 23:06:38 -08:00
2009-02-05 19:40:35 -08:00
2009-04-05 01:16:31 -07:00
2009-05-03 16:54:14 -07:00
2008-09-25 08:00:28 -07:00
2009-04-28 00:46:25 -07:00
2008-09-07 23:52:16 -07:00
2008-12-07 15:13:02 -08:00
2008-11-23 19:23:34 -08:00
2008-10-25 12:09:31 -07:00
2009-03-07 11:22:42 -08:00
2009-02-10 22:26:20 -08:00
2009-02-10 22:26:20 -08:00
2009-05-03 16:54:14 -07:00
2009-02-10 22:26:37 -08:00
2009-01-17 18:30:41 -08:00
2008-10-09 11:26:17 -07:00
2009-04-20 13:44:14 -07:00
2009-01-21 23:52:16 -08:00
2009-02-04 16:30:43 -08:00
2009-02-04 16:30:43 -08:00
2009-02-10 22:26:37 -08:00

////////////////////////////////////////////////////////////////

	GIT - the stupid content tracker

////////////////////////////////////////////////////////////////

"git" can mean anything, depending on your mood.

 - random three-letter combination that is pronounceable, and not
   actually used by any common UNIX command.  The fact that it is a
   mispronunciation of "get" may or may not be relevant.
 - stupid. contemptible and despicable. simple. Take your pick from the
   dictionary of slang.
 - "global information tracker": you're in a good mood, and it actually
   works for you. Angels sing, and a light suddenly fills the room.
 - "goddamn idiotic truckload of sh*t": when it breaks

Git is a fast, scalable, distributed revision control system with an
unusually rich command set that provides both high-level operations
and full access to internals.

Git is an Open Source project covered by the GNU General Public License.
It was originally written by Linus Torvalds with help of a group of
hackers around the net. It is currently maintained by Junio C Hamano.

Please read the file INSTALL for installation instructions.

See Documentation/gittutorial.txt to get started, then see
Documentation/everyday.txt for a useful minimum set of commands, and
Documentation/git-commandname.txt for documentation of each command.
If git has been correctly installed, then the tutorial can also be
read with "man gittutorial" or "git help tutorial", and the
documentation of each command with "man git-commandname" or "git help
commandname".

CVS users may also want to read Documentation/gitcvs-migration.txt
("man gitcvs-migration" or "git help cvs-migration" if git is
installed).

Many Git online resources are accessible from http://git.or.cz/
including full documentation and Git related tools.

The user discussion and development of Git take place on the Git
mailing list -- everyone is welcome to post bug reports, feature
requests, comments and patches to git@vger.kernel.org. To subscribe
to the list, send an email with just "subscribe git" in the body to
majordomo@vger.kernel.org. The mailing list archives are available at
http://marc.theaimsgroup.com/?l=git and other archival sites.

The messages titled "A note from the maintainer", "What's in
git.git (stable)" and "What's cooking in git.git (topics)" and
the discussion following them on the mailing list give a good
reference for project status, development direction and
remaining tasks.
Description
No description provided
Readme 235 MiB
Languages
C 50.1%
Shell 38.4%
Perl 5.1%
Tcl 3.3%
Python 0.8%
Other 2%