Mirror sync connects only to an address checked at sync time.
- Each sync resolves the mirror's host, refuses private, loopback, link-local, shared (100.64.0.0/10) and multicast addresses with
webhook.CheckAddrs, and runs git pinned to the checked address (http.curloptResolve), withhttp.followRedirects=false. A failed check records the reason onrepo mirror list. - Sync runs git with
GIT_CONFIG_NOSYSTEM=1andGIT_CONFIG_GLOBAL=/dev/null, so operator gitconfig cannot proxy or rewrite around the pin. It needs git 2.37 or later; with an older git no mirror syncs and each records why. bay1 has git 2.47.3. - Webhooks refuse 100.64.0.0/10 and multicast targets too.
repo import --fromstill fetches without an address check; filed as #298 and listed in Known-Gaps and the SSRF controls row.- Admin, API, Threat-Model and Architecture pages; CHANGELOG.
Stacked on !491 (mail-require-tls).
Closes #279