mirror: connect only to the address checked at sync time !493

merged merged by cmc on 2026-09-28 21:50 UTC · krz/gitbay:mirror-pin-address into main

Discussion

cmc

Mirror sync connects only to an address checked at sync time.

  • Each sync resolves the mirror's host, refuses private, loopback, link-local, shared (100.64.0.0/10) and multicast addresses with webhook.CheckAddrs, and runs git pinned to the checked address (http.curloptResolve), with http.followRedirects=false. A failed check records the reason on repo mirror list.
  • Sync runs git with GIT_CONFIG_NOSYSTEM=1 and GIT_CONFIG_GLOBAL=/dev/null, so operator gitconfig cannot proxy or rewrite around the pin. It needs git 2.37 or later; with an older git no mirror syncs and each records why. bay1 has git 2.47.3.
  • Webhooks refuse 100.64.0.0/10 and multicast targets too.
  • repo import --from still fetches without an address check; filed as #298 and listed in Known-Gaps and the SSRF controls row.
  • Admin, API, Threat-Model and Architecture pages; CHANGELOG.

Stacked on !491 (mail-require-tls).

Closes #279