Pre-receive with require_signed_commits forks one process per commit #100

closed cmc opened this on 2026-09-03 05:13 UTC · ops security · milestone v1.12.0

Discussion

cmc 2026-09-03 05:13 UTC

cmd/gitbayd/hook.go:29 runs rev-list --not --all then one cat-file process per new commit and ships every raw commit as one JSON message over the hook socket (internal/hookd/hookd.go:297). A 50k-commit initial push to a protected branch forks 50k processes and builds the payload in memory.

Remedy: cat-file --batch and stream verification per commit.

closed by commit 6ab65cbbaf by cmc: hook: one cat-file for the whole push, verified as it streams

2026-09-04 15:58 UTC