Re: [PATCH v2 4/5] upload-pack: read uploadpack.lazyFetchTrusted

Junio C Hamano <[email protected]>
Newsgroups org.kernel.vger.git
Message-ID <[email protected]>
Christian Couder <[email protected]> writes:

> Previous commits created and prepared the path_allowlist_apply()
> function.
>
> Let's reuse this function for a new "uploadpack.lazyFetchTrusted"
> configuration variable.
>
> It allows us to:
>
>   - read an allowlist from that config variable,
>   - check if the current repo is in that list, and
>   - return the result from a new upload_pack_lazy_fetch_trusted()
>     function.
>
> The new function will be used in a following commit.
>
> Note that the new config variable should be read only from protected
> configuration files.
>
> Signed-off-by: Christian Couder <[email protected]>
> ---

OK.

I am not sure if the idea of configuration variable is truly sound,
but if it were, I agree that this is a reasonable implementation for
it.

Thanks.

>  upload-pack.c | 37 +++++++++++++++++++++++++++++++++++++
>  upload-pack.h |  3 +++
>  2 files changed, 40 insertions(+)
>
> diff --git a/upload-pack.c b/upload-pack.c
> index a52856d869..29e700e43b 100644
> --- a/upload-pack.c
> +++ b/upload-pack.c
> @@ -34,6 +34,8 @@
>  #include "json-writer.h"
>  #include "strmap.h"
>  #include "promisor-remote.h"
> +#include "setup.h"
> +#include "abspath.h"
>  
>  /* Remember to update object flag allocation in object.h */
>  #define THEY_HAVE	(1u << 11)
> @@ -1378,6 +1380,41 @@ static int upload_pack_config(const char *var, const char *value,
>  	return parse_hide_refs_config(var, value, "uploadpack", &data->hidden_refs);
>  }
>  
> +struct lazy_fetch_trusted {
> +	int trusted;
> +	char *repo_path;
> +};
> +
> +static int upload_pack_protected_lazy_fetch_config(const char *var, const char *value,
> +						   const struct config_context *ctx UNUSED,
> +						   void *cb_data)
> +{
> +	struct lazy_fetch_trusted *data = cb_data;
> +
> +	if (!strcmp("uploadpack.lazyfetchtrusted", var)) {
> +		path_allowlist_apply(var, value, data->repo_path,
> +				     &data->trusted, false);
> +		return 0;
> +	}
> +
> +	return 0;
> +}
> +
> +bool upload_pack_lazy_fetch_trusted(struct repository *r)
> +{
> +	struct lazy_fetch_trusted data = { 0 };
> +
> +	data.repo_path = real_pathdup(r->worktree ? r->worktree : r->gitdir, 0);
> +	if (!data.repo_path)
> +		return false;
> +
> +	git_protected_config(upload_pack_protected_lazy_fetch_config, &data);
> +
> +	free(data.repo_path);
> +
> +	return !!data.trusted;
> +}
> +
>  static int upload_pack_protected_config(const char *var, const char *value,
>  					const struct config_context *ctx UNUSED,
>  					void *cb_data)
> diff --git a/upload-pack.h b/upload-pack.h
> index d6ee25ea98..b2212992c3 100644
> --- a/upload-pack.h
> +++ b/upload-pack.h
> @@ -12,4 +12,7 @@ struct strbuf;
>  int upload_pack_advertise(struct repository *r,
>  			  struct strbuf *value);
>  
> +/* Is this repo trusted for lazy fetching? */
> +bool upload_pack_lazy_fetch_trusted(struct repository *r);
> +
>  #endif /* UPLOAD_PACK_H */
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.