Path: csiph.com!news.samoylyk.net!gothmog.csi.it!bofh.it!news.nic.it!robomod From: Sean Whitton Newsgroups: linux.debian.bugs.dist Subject: Bug#1109423: want dgit push-source --facilitate-xz-attack Date: Fri, 18 Jul 2025 11:10:01 +0200 Message-ID: References: X-Mailbox-Line: From debian-bugs-dist-request@lists.debian.org Fri Jul 18 09:07:10 2025 Old-Return-Path: X-Spam-Flag: NO X-Spam-Score: -3.999 Reply-To: Sean Whitton , 1109423@bugs.debian.org Resent-To: debian-bugs-dist@lists.debian.org Resent-Cc: Debian tag2upload Delegates X-Debian-Pr-Message: followup 1109423 X-Debian-Pr-Package: dgit X-Debian-Pr-Source: dgit Feedback-ID: 20115:3760:null:purelymail X-Pm-Original-To: 1109423@bugs.debian.org User-Agent: Gnus/5.13 (Gnus v5.13) MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" X-Debian-Message: from BTS X-Mailing-List: archive/latest/1914191 List-ID: List-URL: Approved: robomod@news.nic.it Lines: 62 Organization: linux.* mail to news gateway Sender: robomod@news.nic.it X-Original-Cc: 1109423@bugs.debian.org X-Original-Date: Fri, 18 Jul 2025 10:05:46 +0100 X-Original-Message-ID: <878qkl27it.fsf@zephyr.silentflame.com> X-Original-References: <26744.61801.529730.455509@chiark.greenend.org.uk> <26744.61801.529730.455509@chiark.greenend.org.uk> Xref: csiph.com linux.debian.bugs.dist:1253127 --=-=-= Content-Type: text/plain Content-Transfer-Encoding: quoted-printable Hello, On Thu 17 Jul 2025 at 01:49pm +01, Ian Jackson wrote: > Package: dgit > Version: 13.5 > > It has become clear to me in many corridor conversations that, > workflows involving pristine-tar and upstream origs are really very > common. Where upstream origs are not treesame to git (which is > basically, whenever they were not made by git-archive): > > 1. Existing non-git-first workflows (git-buildpackage) do not report > the discrepancy. They treat the tarball as more authoritative. > > 2. dgit push-source will fail. tag2upload will fail, even if > we implement pristine-tar support. > > Of course no-one should be using these workflows, but we need to think > whether we would rather somehow dismantle this barrier to dgit/t2u > adoption. In practice I think the folks with the vulnerable workflow > are going to keep with their vulnerable workflow anyway. > > The obvious way would be to reify the xz attack diff as an extra patch > in d/patches, during git canonicalisation (as we do for .gitignore). Interesting. Doing it as an extra patch sounds good; it's easy to inspect what was done. The UI for turning this on for tag2upload seems tricky unless we only add one additional quilt mode which is like --gbp plus this. Otherwise we need another [dgit ...] element. Could it be on by default if the user is already using the foreseen pristine-tar support? I.e. we defer to their pristine-tar data. =2D-=20 Sean Whitton --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQJNBAEBCgA3FiEEm5FwB64DDjbk/CSLaVt65L8GYkAFAmh6DmoZHHNwd2hpdHRv bkBzcHdoaXR0b24ubmFtZQAKCRBpW3rkvwZiQP2oD/9l3TwWt7YXMtyxFZzGLMRT dc/hCPmRr/Wo/aGN66qYLi9LiNNAv7RhG0WwRwlgwUFugAc23lX32n8Mw0DSSiYs dhRUfrYHmMkSCoKWhOrMdTzuE90NZvF4+Zeno3cf0eRAU4NfxLAZzwDfgA8pZhao G6NZAw+0/4N+w2+3lWTYLlbHh7Ui1gtCRj2VjyNMjZNhjGfxg9uxazAzovgcROIj nApCL6KxjYQNj0yt7lvA4+f1l7nob6bM7Yfk0dumqS8AFFy9Kkoy6nf23r0W/mNh 48MRyab2EOlg5k08q3sIqu/OQ86ASh31AEoeGF8iFijIKaufkjCygLtlPQSiIsdF K/GdfYa5f9LI0feyC5ktoCEe9xYexlMkRkbGN0LnNBAsicWaPj9AzsZFYa5eM63n zx3fL81ftShSQWTGtBSj690qk9eUMMUWtR6UZx2IHbu+SDpyw3qR66BN7enr7gUJ /iZDOqlJKKxlT92oF+7bf1qVdtdPDH+CIsGnV8oKHn0cKiL8rrdmG/P9n+iA2vau q/W2AronvYmldsBEEFZzN7sNhqU+LlTjtje14trwWGB+gVBcTF6alh7bWPDLmvFJ wlBA1tuiEPyrLDBSIl8gt0ZEL+s0LV6ulPlQVAusxY/DRoK55amGCBir6raKB7om tN4p6MOB/UXyP74y8NvK7g== =xxar -----END PGP SIGNATURE----- --=-=-=--