mirror: re-check the address at sync time #279

closed cmc opened this on 2026-09-28 04:33 UTC · ops security

Discussion

cmc 2026-09-28 04:33 UTC

Mirror URLs are checked against private, loopback and link-local addresses when saved (internal/control/mirrorcmd.go, via webhook.ValidateURL), but git makes the connection later with no re-check. A hostname that resolves publicly when saved and privately when the mirror runs reaches internal addresses. Webhooks re-check at connect time; mirrors do not.

  • Resolve and check the host immediately before each sync and pass git a pinned address, or run mirror git through a proxy that enforces the same rule.

referenced in commit 4e0958a163 by cmc: plans: open issues from the architecture and UX reviews

2026-09-28 05:43 UTC

referenced in commit 298ac0b456 by cmc: mirror: ignore operator gitconfig, require git 2.37; import SSRF gap documented

2026-09-28 21:50 UTC

closed by cmc in commit 869d5659fb: mirror: check the address before each sync and pin git to it

2026-09-28 21:50 UTC

referenced in commit 0babae2db0 by cmc: webhook: refuse shared (100.64.0.0/10) and multicast addresses

2026-09-28 21:50 UTC

referenced in commit 7673081613 by cmc: webhook: CheckAddrs for callers that resolve before connecting

2026-09-28 21:50 UTC