mirror of
https://github.com/go-gitea/gitea.git
synced 2026-10-01 20:59:45 +09:00
fix(git): reject fsck-invalid objects on push (#39472)
Set receive.fsckObjects=true in Gitea's internal global git config so the receiving git process rejects bad, malicious or duplicate objects at push time, before Gitea ever stores them. Assisted-by: Codet:claude-opus-4-8 --------- Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com> Co-authored-by: silverwind <me@silverwind.io>
This commit is contained in:
@@ -42,6 +42,25 @@ func syncGitConfig(ctx context.Context) (err error) {
|
||||
return err
|
||||
}
|
||||
|
||||
// reject malformed objects on push and fetch, e.g. duplicate tree entries
|
||||
// that the web UI and checkout can resolve differently
|
||||
if err := configSet(ctx, "transfer.fsckObjects", "true"); err != nil {
|
||||
return err
|
||||
}
|
||||
// ignore harmless issues found in real-world histories, same as Gitaly:
|
||||
// https://gitlab.com/gitlab-org/gitaly/-/blob/bd3bba454181f52331cca441b3417bbd2de4b1cb/internal/git/gitcmd/command_description.go#L506-547
|
||||
for _, prefix := range []string{"fsck", "fetch.fsck", "receive.fsck"} {
|
||||
for _, key := range []string{
|
||||
"badTimezone", // e.g. +051800 written by Grit 2.3.1 to 2.4
|
||||
"missingSpaceBeforeDate", // e.g. dateless tags from git-cvsimport before git 1.5.3
|
||||
"zeroPaddedFilemode", // e.g. 040000 written by Grit before 2.1
|
||||
} {
|
||||
if err := configSet(ctx, fmt.Sprintf("%s.%s", prefix, key), "ignore"); err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if err := configSet(ctx, "core.commitGraph", "true"); err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user