Excessive git server operations for hostap.git

Jouni Malinen j at w1.fi
Tue Oct 31 01:48:23 PDT 2023


It looks like there is a large number of organizations that have started
automatically cloning the hostap.git repository way too frequently. At
times, this shows up as a practical DoS attack against the server. This
is unacceptable and needs to stop. There cannot be an acceptable use
case that ends up having ten servers doing a full git clone of the
repository in parallel and multiple times per minute (or per second as
has been the case in some more extreme sequences).

Unfortunately, I have no way of identifying the exact source of an issue
in a manner that would make it convenient to ask things to be fixed in
more individual and friendly manner. As such, I will have to start
blocking access to the server based on IP address to stop the most
egregious cases. In other words, if you notice that your automated build
(or whatever) setup stops getting updates from hostap.git, it may be
because of this. Please feel free to contact me privately if you want to
get such blocking removed after you have confirmed that there won't be
more than ten git operations per hour from the IP network to my git
server, and ideally, not really more than once an hour update for any
particular automated task, or be prepared to explain why your use cases
needs more frequent operations.

-- 
Jouni Malinen                                            PGP id EFC895FA



More information about the Hostap mailing list