refs: refuse to write pseudorefs
Pseudorefs are not stored in the ref database as by definition, they carry additional metadata that essentially makes them not a ref. As such, writing pseudorefs via the ref backend does not make any sense whatsoever as the ref backend wouldn't know how exactly to store the data. Restrict writing pseudorefs via the ref backend. Signed-off-by: Patrick Steinhardt <ps@pks.im> Signed-off-by: Junio C Hamano <gitster@pobox.com>
Patrick Steinhardt committed
May 15, 2024 at 08:51 UTC
8e4f5c2dc26e8e88c8c4784f133d2b35a771d2ac
2 files changed
+10
-3
refs.c
+7
@@ -1263,6 +1263,13 @@ int ref_transaction_update(struct ref_transaction *transaction,
1263
return -1;
1264
}
1265
1266
+ if (!(flags & REF_SKIP_REFNAME_VERIFICATION) &&
1267
+ is_pseudo_ref(refname)) {
1268
+ strbuf_addf(err, _("refusing to update pseudoref '%s'"),
1269
+ refname);
1270
+ return -1;
1271
+ }
1272
+
1273
if (flags & ~REF_TRANSACTION_UPDATE_ALLOWED_FLAGS)
1274
BUG("illegal flags 0x%x passed to ref_transaction_update()", flags);
1275
t/t5510-fetch.sh
+3
-3
@@ -518,7 +518,7 @@ test_expect_success 'fetch with a non-applying branch.<name>.merge' '
518
test_expect_success 'fetch from GIT URL with a non-applying branch.<name>.merge [1]' '
519
one_head=$(cd one && git rev-parse HEAD) &&
520
this_head=$(git rev-parse HEAD) &&
521
- git update-ref -d FETCH_HEAD &&
521
+ rm .git/FETCH_HEAD &&
522
git fetch one &&
523
test $one_head = "$(git rev-parse --verify FETCH_HEAD)" &&
524
test $this_head = "$(git rev-parse --verify HEAD)"
@@ -530,7 +530,7 @@ test_expect_success 'fetch from GIT URL with a non-applying branch.<name>.merge
530
one_ref=$(cd one && git symbolic-ref HEAD) &&
531
git config branch.main.remote blub &&
532
git config branch.main.merge "$one_ref" &&
533
- git update-ref -d FETCH_HEAD &&
533
+ rm .git/FETCH_HEAD &&
534
git fetch one &&
535
test $one_head = "$(git rev-parse --verify FETCH_HEAD)" &&
536
test $this_head = "$(git rev-parse --verify HEAD)"
@@ -540,7 +540,7 @@ test_expect_success 'fetch from GIT URL with a non-applying branch.<name>.merge
540
# the merge spec does not match the branch the remote HEAD points to
541
test_expect_success 'fetch from GIT URL with a non-applying branch.<name>.merge [3]' '
542
git config branch.main.merge "${one_ref}_not" &&
543
- git update-ref -d FETCH_HEAD &&
543
+ rm .git/FETCH_HEAD &&
544
git fetch one &&
545
test $one_head = "$(git rev-parse --verify FETCH_HEAD)" &&
546
test $this_head = "$(git rev-parse --verify HEAD)"