repo import --from fetches any address #298

closed cmc opened this on 2026-09-28 21:20 UTC

Discussion

cmc 2026-09-28 21:20 UTC

repo import --from fetches from a user-supplied URL with no address check.

internal/control/import.go (~79-90) allows http, https and git:// and calls gitutil.FetchMirror, which runs git with the daemon's full environment and follows redirects. Nothing resolves or checks the host, so any user can make the server fetch from loopback or private addresses. Mirrors and webhooks resolve, check (webhook.CheckAddrs) and pin since #279; import does not.

  • Give import the same resolve, check and pin as mirror sync (http.curloptResolve, http.followRedirects=false, a clean environment); decide whether git:// stays (it cannot be pinned the same way).
  • Update Threat-Model and Architecture/09-Controls (SSRF row) when it lands.

referenced in commit 539835bd23 by cmc: wiki: Known-Gaps keeps the open #298 row

2026-09-28 23:13 UTC

referenced in commit fb6e9dcfa4 by cmc: plans: #287, #284, #298, #285, #297

2026-09-29 00:09 UTC

closed by cmc in commit 592e7bcb92: import: document the address check; e2e imports with allow_local

2026-09-29 02:21 UTC

referenced in commit ecfc702093 by cmc: import: refuse a query or fragment, ls-remote in the new repository

2026-09-29 02:21 UTC

referenced in commit c32afe91e2 by cmc: gitpin: refuse odd numeric hosts, pin every name on the port

2026-09-29 02:21 UTC

referenced in commit 1c6440454b by cmc: import: http(s) only, address checked and pinned like a mirror sync

2026-09-29 02:21 UTC

referenced in commit ae2edb026f by cmc: mirror: sync through gitpin

2026-09-29 02:21 UTC

referenced in commit 7e3afe5f90 by cmc: gitpin: resolve, check and pin a git remote

2026-09-29 02:21 UTC

referenced in commit 0c7b382159 by cmc: control: mirror add refuses a numerically written host

2026-09-29 02:39 UTC

referenced in commit fad7a633f4 by cmc: changelog: one #297 entry, upgrade notes after the list, #298 note corrected

2026-09-29 02:39 UTC