public inbox for overseers@sourceware.org
 help / color / mirror / Atom feed
* Re: https access to git repo?
       [not found] ` <6b35da7f-91bc-92d2-6ea3-71cbe5d3d768@gmail.com>
@ 2018-11-02 14:37   ` Eric Blake
  0 siblings, 0 replies; only message in thread
From: Eric Blake @ 2018-11-02 14:37 UTC (permalink / raw)
  To: overseers

Forwarding a message from cygwin-developers:

On 11/2/18 9:32 AM, cyg Simple wrote:
> On 11/2/2018 9:20 AM, Eric Blake wrote:
>> https://cygwin.com/git.html recommends the use of git:// for accessing
>> the cygwin git repo.  However, git:// suffers from man-in-the-middle
>> attacks, in comparison to https://.  On the other hand, performance of
>> https:// is much worse than git:// UNLESS the git server is running a
>> new enough version of git, such that it advertises
>> application/x-git-upload-pack-advertisement support.
>>
>> Alas, the current sourceware server is running an old version of git:
>>
>> $ wget -S
>> 'http://sourceware.org/git/newlib-cygwin.git/info/refs?service=git-upload-pack'
>> 2>&1 | grep Content-Type
>>    Content-Type: text/plain; charset=UTF-8
>>
>> Contrast that with other git repos:
>>
>> $ wget -S
>> 'https://repo.or.cz/qemu.git/info/refs?service=git-upload-pack' 2>&1 |
>> grep Content-Type
>>    Content-Type: application/x-git-upload-pack-advertisement
>>
>> Is there a chance we can get sourceware to upgrade to a newer git
>> server, and then update our recommendations to point people to https://
>> clones instead of insecure git://, and without the current speed penalty
>> that current https:// access through our non-upgraded server provides?
> 
> You'll need to ask overseerers@sourceware.org.  They may have it on
> there radar already but it doesn't hurt to ask.
> 

-- 
Eric Blake, Principal Software Engineer
Red Hat, Inc.           +1-919-301-3266
Virtualization:  qemu.org | libvirt.org

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2018-11-02 14:37 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
     [not found] <09575e79-a64c-6227-34e3-3bc10290e7a5@redhat.com>
     [not found] ` <6b35da7f-91bc-92d2-6ea3-71cbe5d3d768@gmail.com>
2018-11-02 14:37   ` https access to git repo? Eric Blake

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).