-
Notifications
You must be signed in to change notification settings - Fork 44
pin_git_object records a fabricated CID when /api/v0/add returns no Hash #452
Copy link
Copy link
Open
Labels
crate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIkind:bugDefect fix — wrong or unsafe behaviorDefect fix — wrong or unsafe behaviorsev:highMajor break or real security/trust risk, no easy workaroundMajor break or real security/trust risk, no easy workaroundsubsystem:encryptionEncrypted subtrees, recipient blinding, key zeroizationEncrypted subtrees, recipient blinding, key zeroizationsubsystem:storageBlob/object store, Arweave, IPFS, archivesBlob/object store, Arweave, IPFS, archives
Description
Activity
Metadata
Metadata
Assignees
Labels
crate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIkind:bugDefect fix — wrong or unsafe behaviorDefect fix — wrong or unsafe behaviorsev:highMajor break or real security/trust risk, no easy workaroundMajor break or real security/trust risk, no easy workaroundsubsystem:encryptionEncrypted subtrees, recipient blinding, key zeroizationEncrypted subtrees, recipient blinding, key zeroizationsubsystem:storageBlob/object store, Arweave, IPFS, archivesBlob/object store, Arweave, IPFS, archives
pin_git_object(crates/gitlawb-node/src/ipfs_pin.rs) parses the NDJSON response fromPOST /api/v0/addand takes the last line carrying aHash. When no line yields one (empty body, malformed NDJSON, a backend with a different response schema), it falls back toCid::from_git_object_bytes(data), the CID it computed locally.That records an address the backend never confirmed stored. Above the backend's chunk threshold (262144 bytes on Kubo) it is guaranteed wrong: the add goes out with
raw-leaves=true, so large payloads land as chunked leaves under a dag-pb root, and the whole-object raw CID is not a stored block. Every later/api/v0/caton it 500s. Since the result lands inencrypted_blobs.cid,get_encrypted_blobfails on every fetch of an affected envelope and mirrors retry it on each sync.Reproduced against Kubo v0.43.0: a 200 add response of
{"Name":"object","Size":"19"}returnsOk(<locally computed raw CID>)instead of an error.Expected: a 200 without a usable
Hashis an add failure. The returned hash stays authoritative; above-threshold adds legitimately return the dag-pb root CID, so the fix should not require the returnedHashto equal the locally computed raw CID.