feat: fsck incoming objects (#12695)

Weirdly, git doesn't verify the consistency of objects when receiving
new objects. Enable that git verifies this, so we don't allow a
repository to get in a weird or even corrupt state.

We've already dealt with a few cases of inconsistent objects, the most
notable one being mode of objects (forgejo/forgejo!9161). This can be
risky, as such ignore 3 consistency checks that are not harmful to
ignore and is battle tested by Gitlab.

bad timezone:
https://gitlab.com/gitlab-org/gitaly/-/commit/692a0d3476a5fe5832ec78df5a6d9d5e1d780364

missing space:
https://gitlab.com/gitlab-org/gitaly/-/commit/2da0b393998d394b743c70e7cf9cd0757a8f2733

non-zero padded filemode:
https://gitlab.com/gitlab-org/gitaly/-/commit/db8f2e8da5e7ff9cf84a99195481303016cd2138

Typically we set these settings in `modules/git/git.go`, but that means
a instance administrator wouldn't be able to override it. Given we don't
strictly require these settings to be set. A instance admin could
choose to disable the consistency checks or override our set of ignores
this would allow them to do so via the `[git.config]` section.

Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12695
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>
Reviewed-by: elle <0xllx0@noreply.codeberg.org>
This commit is contained in:
Gusted
2026-05-25 14:51:04 +02:00
committed by Gusted
parent ed30c7de45
commit 385c0db94f
38 changed files with 121 additions and 60 deletions
+11
View File
@@ -95,6 +95,17 @@ func loadGitFrom(rootCfg ConfigProvider) {
GitConfig.SetOption("core.logAllRefUpdates", "true")
GitConfig.SetOption("gc.reflogExpire", "90")
GitConfig.SetOption("transfer.fsckObjects", "true")
// To ignore specific warnings they have to be set for all of the three
// scenarios. Per git-config(1): "To uniformly configure the same fsck
// settings in different circumstances, all three of them must be set to the
// same values."
for _, prefix := range []string{"fsck.", "fetch.fsck.", "receive.fsck."} {
GitConfig.SetOption(prefix+"badTimezone", "ignore")
GitConfig.SetOption(prefix+"missingSpaceBeforeDate", "ignore")
GitConfig.SetOption(prefix+"zeroPaddedFilemode", "ignore")
}
for _, key := range secGitConfig.Keys() {
GitConfig.SetOption(key.Name(), key.String())
}
+26
View File
@@ -32,6 +32,32 @@ diff.algorithm = other
require.NoError(t, err)
loadGitFrom(cfg)
assert.Equal(t, "other", GitConfig.Options["diff.algorithm"])
t.Run("Fsck options", func(t *testing.T) {
cfg, err := NewConfigProviderFromData(`
[git.config]
receive.fsckObjects = false
fetch.fsck.zeroPaddedFilemode = warn
fsck.missingSpaceBeforeDate = error
`)
require.NoError(t, err)
loadGitFrom(cfg)
assert.Equal(t, "false", GitConfig.Options["receive.fsckobjects"])
assert.Equal(t, "true", GitConfig.Options["transfer.fsckobjects"])
assert.NotContains(t, GitConfig.Options, "fetch.fsckobjects")
assert.Equal(t, "ignore", GitConfig.Options["fsck.badtimezone"])
assert.Equal(t, "error", GitConfig.Options["fsck.missingspacebeforedate"])
assert.Equal(t, "ignore", GitConfig.Options["fsck.zeropaddedfilemode"])
assert.Equal(t, "ignore", GitConfig.Options["receive.fsck.badtimezone"])
assert.Equal(t, "ignore", GitConfig.Options["receive.fsck.missingspacebeforedate"])
assert.Equal(t, "ignore", GitConfig.Options["receive.fsck.zeropaddedfilemode"])
assert.Equal(t, "ignore", GitConfig.Options["fetch.fsck.badtimezone"])
assert.Equal(t, "ignore", GitConfig.Options["fetch.fsck.missingspacebeforedate"])
assert.Equal(t, "warn", GitConfig.Options["fetch.fsck.zeropaddedfilemode"])
})
}
func TestGitReflog(t *testing.T) {