Skip to content

Commit 75631a3

Browse files
dschogitster
authored andcommitted
Revert "core.hooksPath: add some protection while cloning"
This defense-in-depth was intended to protect the clone operation against future escalations where bugs in `git clone` would allow attackers to write arbitrary files in the `.git/` directory would allow for Remote Code Execution attacks via maliciously-placed hooks. However, it turns out that the `core.hooksPath` protection has unintentional side effects so severe that they do not justify the benefit of the protections. For example, it has been reported in https://lore.kernel.org/git/[email protected]/ that the following invocation, which is intended to make `git clone` safer, is itself broken by that protective measure: git clone --config core.hooksPath=/dev/null <url> Since it turns out that the benefit does not justify the cost, let's revert 20f3588 (core.hooksPath: add some protection while cloning, 2024-03-30). Signed-off-by: Johannes Schindelin <[email protected]> Signed-off-by: Junio C Hamano <[email protected]>
1 parent 197a772 commit 75631a3

File tree

2 files changed

+1
-27
lines changed

2 files changed

+1
-27
lines changed

config.c

Lines changed: 1 addition & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1525,19 +1525,8 @@ static int git_default_core_config(const char *var, const char *value, void *cb)
15251525
if (!strcmp(var, "core.attributesfile"))
15261526
return git_config_pathname(&git_attributes_file, var, value);
15271527

1528-
if (!strcmp(var, "core.hookspath")) {
1529-
if (current_config_scope() == CONFIG_SCOPE_LOCAL &&
1530-
git_env_bool("GIT_CLONE_PROTECTION_ACTIVE", 0))
1531-
die(_("active `core.hooksPath` found in the local "
1532-
"repository config:\n\t%s\nFor security "
1533-
"reasons, this is disallowed by default.\nIf "
1534-
"this is intentional and the hook should "
1535-
"actually be run, please\nrun the command "
1536-
"again with "
1537-
"`GIT_CLONE_PROTECTION_ACTIVE=false`"),
1538-
value);
1528+
if (!strcmp(var, "core.hookspath"))
15391529
return git_config_pathname(&git_hooks_path, var, value);
1540-
}
15411530

15421531
if (!strcmp(var, "core.bare")) {
15431532
is_bare_repository_cfg = git_config_bool(var, value);

t/t1800-hook.sh

Lines changed: 0 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -177,19 +177,4 @@ test_expect_success 'git hook run a hook with a bad shebang' '
177177
test_cmp expect actual
178178
'
179179

180-
test_expect_success 'clone protections' '
181-
test_config core.hooksPath "$(pwd)/my-hooks" &&
182-
mkdir -p my-hooks &&
183-
write_script my-hooks/test-hook <<-\EOF &&
184-
echo Hook ran $1
185-
EOF
186-
187-
git hook run test-hook 2>err &&
188-
grep "Hook ran" err &&
189-
test_must_fail env GIT_CLONE_PROTECTION_ACTIVE=true \
190-
git hook run test-hook 2>err &&
191-
grep "active .core.hooksPath" err &&
192-
! grep "Hook ran" err
193-
'
194-
195180
test_done

0 commit comments

Comments
 (0)