diff options
author | Christian Couder <christian.couder@gmail.com> | 2019-05-29 12:44:32 (GMT) |
---|---|---|
committer | Junio C Hamano <gitster@pobox.com> | 2019-05-29 18:05:34 (GMT) |
commit | e693237e2ba27b6129e8af7f6a794f5c2fbd26f3 (patch) | |
tree | 2317223e6228a03a1b0b9fd4ecf5dc51a5eb5fbb /list-objects-filter-options.h | |
parent | aa25c82427ae70aebf3b8f970f2afd54e9a2a8c6 (diff) | |
download | git-e693237e2ba27b6129e8af7f6a794f5c2fbd26f3.zip git-e693237e2ba27b6129e8af7f6a794f5c2fbd26f3.tar.gz git-e693237e2ba27b6129e8af7f6a794f5c2fbd26f3.tar.bz2 |
list-objects-filter: disable 'sparse:path' filters
If someone wants to use as a filter a sparse file that is in the
repository, something like "--filter=sparse:oid=<ref>:<path>"
already works.
So 'sparse:path' is only interesting if the sparse file is not in
the repository. In this case though the current implementation has
a big security issue, as it makes it possible to ask the server to
read any file, like for example /etc/password, and to explore the
filesystem, as well as individual lines of files.
If someone is interested in using a sparse file that is not in the
repository as a filter, then at the minimum a config option, such
as "uploadpack.sparsePathFilter", should be implemented first to
restrict the directory from which the files specified by
'sparse:path' can be read.
For now though, let's just disable 'sparse:path' filters.
Helped-by: Matthew DeVore <matvore@google.com>
Helped-by: Jeff Hostetler <git@jeffhostetler.com>
Signed-off-by: Christian Couder <chriscool@tuxfamily.org>
Signed-off-by: Junio C Hamano <gitster@pobox.com>
Diffstat (limited to 'list-objects-filter-options.h')
-rw-r--r-- | list-objects-filter-options.h | 2 |
1 files changed, 0 insertions, 2 deletions
diff --git a/list-objects-filter-options.h b/list-objects-filter-options.h index e3adc78..c54f000 100644 --- a/list-objects-filter-options.h +++ b/list-objects-filter-options.h @@ -13,7 +13,6 @@ enum list_objects_filter_choice { LOFC_BLOB_LIMIT, LOFC_TREE_DEPTH, LOFC_SPARSE_OID, - LOFC_SPARSE_PATH, LOFC__COUNT /* must be last */ }; @@ -44,7 +43,6 @@ struct list_objects_filter_options { * choice. */ struct object_id *sparse_oid_value; - char *sparse_path_value; unsigned long blob_limit_value; unsigned long tree_exclude_depth; }; |