{"thread":{"id":"14226","subject":"[RFC] Single system account for multiple git users","startedAt":"2008-06-30T15:11:14Z","lastAt":"2008-07-02T14:45:36Z","messageCount":9,"participants":["Dmitry Potapov","Asheesh Laroia","Jakub Narebski","Jon Loeliger","Melchior FRANZ"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"81753","messageId":"20080630151113.GO5737@dpotapov.dyndns.org","threadId":"14226","inReplyTo":null,"subject":"[RFC] Single system account for multiple git users","fromName":"Dmitry Potapov","fromEmail":"dpotapov@gmail.com","sentAt":"2008-06-30T15:11:14Z","receivedAt":"2008-06-30T15:11:14Z","isPatch":false,"sender":{"key":"dpotapov@gmail.com","avatar":"https://avatars.githubusercontent.com/u/6568595?v=4"},"body":"Hi,\n\nUsing SSH access with restricted git-shell as login shell and using\nthe script from the update-hook-example.txt works fine, but it requres\nthat every Git user has a separate system account on the server, which\nis often frowned upon by system administrators, who would prefer to have\na single system account for access to Git repo.\n\nI have looked on gitosis, but it requires normal shell account for\nthe git user, which was vetoed by sysadmin. Also, I found its\nconfiguration more complex than necessary and not flexible enough\nto differentiate what branches can have non-fast-forward pushes on\nit and what cannot.\n\nIn fact, the simple solution for me would be to have authorized_key\nfor the git user being like this:\n\nenvironment=\"GIT_USER=user1\" ssh-rsa USER1-SSH-PUBLIC-KEY\nenvironment=\"GIT_USER=user2\" ssh-rsa USER2-SSH-PUBLIC-KEY\n...\n\nIn this case, with one line change to update-hook-example from\nusername=$(id -u -n)\nto\nusername=\"$GIT_USER\"\nI would get exactly what I want.\n\nHowever, the environment option in authorized_key works only if\nPermitUserEnvironment is set in sshd configuration, and this option\nwill allow _all_ users to overwrite their environment, which may be\nnot desirable in some settings for security reasons.\n\nSo, instead, I have to write a simple program, which is placed as\nthe login shell and interprets the given command as user name, sets\nGIT_USER to it, and invokes git-shell with SSH_ORIGINAL_COMMAND.\nThus authorized_key looks like that:\n\ncommand=\"git-su user1\" ssh-rsa USER1-SSH-PUBLIC-KEY\ncommand=\"git-su user2\" ssh-rsa USER2-SSH-PUBLIC-KEY\n...\n\nBut then I realized that it is simpler and more efficient to add\nsome built-in command to git-shell to do that.\n\nYou can see my patch below. I hope it will be useful for people\nwho wants to user git on server with a single system account for\nall git users.\n\nDmitry\n\n-- 8< --\nFrom: Dmitry Potapov <dpotapov@gmail.com>\nDate: Wed, 25 Jun 2008 08:14:22 +0400\nSubject: [PATCH] git-shell: add git-su command\n\ngit-su interprets the given command as a user name that must be set to the\nGIT_USER environment variable and then executing SSH_ORIGINAL_COMMAND as\nit were the command given to git-shell. This allows to have different\nvalues for GIT_USER variable for different ssh public keys, which is\nnecessary to have a single system for many Git users. With this command\nthe typical authorized_key will for git user will be look like this:\n\ncommand=\"git-su user1\" ssh-rsa USER1-SSH-PUBLIC-KEY\ncommand=\"git-su user2\" ssh-rsa USER2-SSH-PUBLIC-KEY\n...\n\nThe alternative of using the \"environment\" option in authorized_key may be\nproblematic as it requires that the PermitUserEnvironment option was set\nin sshd_config and by default this option is not enabled, because it may\nallow some users to bypass access restrictions.\n\nSigned-off-by: Dmitry Potapov <dpotapov@gmail.com>\n---\n\nI moved command parsing logic from main() to a separate function,\n(which makes the patch a bit bigger than it actually is) and then\nadded do_su_cmd(), which reuses this functionality.\n\n shell.c |   51 ++++++++++++++++++++++++++++++++++-----------------\n 1 files changed, 34 insertions(+), 17 deletions(-)\n\ndiff --git a/shell.c b/shell.c\nindex 91ca7de..05bd3cc 100644\n--- a/shell.c\n+++ b/shell.c\n@@ -41,6 +41,19 @@ static int do_cvs_cmd(const char *me, char *arg)\n \treturn execv_git_cmd(cvsserver_argv);\n }\n \n+static int exec_cmd(char *prog);\n+\n+static int do_su_cmd(const char *me, char *arg)\n+{\n+\tchar *cmd = getenv(\"SSH_ORIGINAL_COMMAND\");\n+\tif (!cmd)\n+\t\tdie(\"SSH_ORIGINAL_COMMAND is not set\");\n+\tif (setenv(\"GIT_USER\", arg, 1))\n+\t\tdie (\"setenv failed: %s\", strerror(errno));\n+\tif (unsetenv(\"SSH_ORIGINAL_COMMAND\"))\n+\t\tdie (\"unsetenv failed: %s\", strerror(errno));\n+\treturn exec_cmd(cmd);\n+}\n \n static struct commands {\n \tconst char *name;\n@@ -49,28 +62,14 @@ static struct commands {\n \t{ \"git-receive-pack\", do_generic_cmd },\n \t{ \"git-upload-pack\", do_generic_cmd },\n \t{ \"cvs\", do_cvs_cmd },\n+\t{ \"git-su\", do_su_cmd },\n \t{ NULL },\n };\n \n-int main(int argc, char **argv)\n+static int exec_cmd(char *prog)\n {\n-\tchar *prog;\n \tstruct commands *cmd;\n \n-\t/*\n-\t * Special hack to pretend to be a CVS server\n-\t */\n-\tif (argc == 2 && !strcmp(argv[1], \"cvs server\"))\n-\t\targv--;\n-\n-\t/*\n-\t * We do not accept anything but \"-c\" followed by \"cmd arg\",\n-\t * where \"cmd\" is a very limited subset of git commands.\n-\t */\n-\telse if (argc != 3 || strcmp(argv[1], \"-c\"))\n-\t\tdie(\"What do you think I am? A shell?\");\n-\n-\tprog = argv[2];\n \tif (!strncmp(prog, \"git\", 3) && isspace(prog[3]))\n \t\t/* Accept \"git foo\" as if the caller said \"git-foo\". */\n \t\tprog[3] = '-';\n@@ -91,7 +90,25 @@ int main(int argc, char **argv)\n \t\tdefault:\n \t\t\tcontinue;\n \t\t}\n-\t\texit(cmd->exec(cmd->name, arg));\n+\t\treturn cmd->exec(cmd->name, arg);\n \t}\n \tdie(\"unrecognized command '%s'\", prog);\n }\n+\n+int main(int argc, char **argv)\n+{\n+\t/*\n+\t * Special hack to pretend to be a CVS server\n+\t */\n+\tif (argc == 2 && !strcmp(argv[1], \"cvs server\"))\n+\t\targv--;\n+\n+\t/*\n+\t * We do not accept anything but \"-c\" followed by \"cmd arg\",\n+\t * where \"cmd\" is a very limited subset of git commands.\n+\t */\n+\telse if (argc != 3 || strcmp(argv[1], \"-c\"))\n+\t\tdie(\"What do you think I am? A shell?\");\n+\n+\treturn exec_cmd(argv[2]);\n+}\n-- \n1.5.6.1\n"},{"id":"81755","messageId":"alpine.DEB.1.10.0806300858380.25384@alchemy.localdomain","threadId":"14226","inReplyTo":"20080630151113.GO5737@dpotapov.dyndns.org","subject":"Re: [RFC] Single system account for multiple git users","fromName":"Asheesh Laroia","fromEmail":"asheesh@asheesh.org","sentAt":"2008-06-30T15:59:56Z","receivedAt":"2008-06-30T15:59:56Z","isPatch":false,"sender":{"key":"asheesh@asheesh.org","avatar":"https://avatars.githubusercontent.com/u/25457?v=4"},"body":"On Mon, 30 Jun 2008, Dmitry Potapov wrote:\n\n> Hi,\n>\n> Using SSH access with restricted git-shell as login shell and using the \n> script from the update-hook-example.txt works fine, but it requres that \n> every Git user has a separate system account on the server, which is \n> often frowned upon by system administrators, who would prefer to have a \n> single system account for access to Git repo.\n>\n> I have looked on gitosis, but it requires normal shell account for the \n> git user, which was vetoed by sysadmin. Also, I found its configuration \n> more complex than necessary and not flexible enough to differentiate \n> what branches can have non-fast-forward pushes on it and what cannot.\n\nI seem to recall that gitosis works with git-shell.  Maybe I'm \nmis-remembering, though.\n\n-- Asheesh.\n\n-- \nQOTD:\n \tSome people have one of those days.  I've had one of those lives.\n"},{"id":"81756","messageId":"m3iqvqhptu.fsf@localhost.localdomain","threadId":"14226","inReplyTo":"20080630151113.GO5737@dpotapov.dyndns.org","subject":"Re: [RFC] Single system account for multiple git users","fromName":"Jakub Narebski","fromEmail":"jnareb@gmail.com","sentAt":"2008-06-30T16:04:15Z","receivedAt":"2008-06-30T16:04:15Z","isPatch":false,"sender":{"key":"jnareb@gmail.com","avatar":"https://avatars.githubusercontent.com/u/2706?v=4"},"body":"Dmitry Potapov <dpotapov@gmail.com> writes:\n\n> Using SSH access with restricted git-shell as login shell and using\n> the script from the update-hook-example.txt works fine, but it requres\n> that every Git user has a separate system account on the server, which\n> is often frowned upon by system administrators, who would prefer to have\n> a single system account for access to Git repo.\n> \n> I have looked on gitosis, but it requires normal shell account for\n> the git user, which was vetoed by sysadmin. [...]\n\nHave you took a look at ssh_acl from InterfacesFrontendsAndTools\nfrom Git Wiki?\n\n-- \nJakub Narebski\nPoland\nShadeHawk on #git\n"},{"id":"81759","messageId":"37fcd2780806300951sd164870ib09bfc5e47dcaa57@mail.gmail.com","threadId":"14226","inReplyTo":"alpine.DEB.1.10.0806300858380.25384@alchemy.localdomain","subject":"Re: [RFC] Single system account for multiple git users","fromName":"Dmitry Potapov","fromEmail":"dpotapov@gmail.com","sentAt":"2008-06-30T16:51:39Z","receivedAt":"2008-06-30T16:51:39Z","isPatch":false,"sender":{"key":"dpotapov@gmail.com","avatar":"https://avatars.githubusercontent.com/u/6568595?v=4"},"body":"On Mon, Jun 30, 2008 at 7:59 PM, Asheesh Laroia <asheesh@asheesh.org> wrote:\n>\n> I seem to recall that gitosis works with git-shell.  Maybe I'm\n> mis-remembering, though.\n\nI don't see how it is possible for gitosis to work with git-shell.\nBesides, in the article (which also is mentioned in Gitosis FAQ in the\nsection:  Creating new repositories and adding users\") clearly state:\n\n\"The next thing to do is to create a user that will own the repositories\nyou want to manage. This user is usually called git, but any name will\nwork, and you can have more than one per system if you really want to.\nThe user does not need a password, but does need a valid shell\n(otherwise, SSH will refuse to work).\"\n\nSource: http://scie.nti.st/2007/11/14/hosting-git-repositories-the-easy-and-secure-way\n\nSo, I think you misread something.\n\nDmitry\n"},{"id":"81760","messageId":"48691059.4060604@freescale.com","threadId":"14226","inReplyTo":"37fcd2780806300951sd164870ib09bfc5e47dcaa57@mail.gmail.com","subject":"Re: [RFC] Single system account for multiple git users","fromName":"Jon Loeliger","fromEmail":"jdl@freescale.com","sentAt":"2008-06-30T16:56:57Z","receivedAt":"2008-06-30T16:56:57Z","isPatch":false,"sender":{"key":"jdl@jdl.com","avatar":"https://gravatar.com/avatar/75ce9a10b151acd2c28ec4ab2136dba7b2ff1634530bd04b155981a749d08a64?d=mp&s=160"},"body":"Dmitry Potapov wrote:\n\n> \"The next thing to do is to create a user that will own the repositories\n> you want to manage. This user is usually called git, but any name will\n> work, and you can have more than one per system if you really want to.\n> The user does not need a password, but does need a valid shell\n> (otherwise, SSH will refuse to work).\"\n\nDoes that just mean that the git-shell program\nhas to be listed in /etc/shells?\n\njdl\n"},{"id":"81761","messageId":"37fcd2780806301005w66500825n79719ce9950d807d@mail.gmail.com","threadId":"14226","inReplyTo":"m3iqvqhptu.fsf@localhost.localdomain","subject":"Re: [RFC] Single system account for multiple git users","fromName":"Dmitry Potapov","fromEmail":"dpotapov@gmail.com","sentAt":"2008-06-30T17:05:02Z","receivedAt":"2008-06-30T17:05:02Z","isPatch":false,"sender":{"key":"dpotapov@gmail.com","avatar":"https://avatars.githubusercontent.com/u/6568595?v=4"},"body":"On Mon, Jun 30, 2008 at 8:04 PM, Jakub Narebski <jnareb@gmail.com> wrote:\n>\n> Have you took a look at ssh_acl from InterfacesFrontendsAndTools\n> from Git Wiki?\n\nI have looked at it and if I am not mistaken it requires the normal\nshell as login shell.\n\nBTW, the link to GitWiki is outdated, the new link is\nhttp://www.inf.ufpr.br/ribas/ssh_acl.html\nbut it practically lacks of all documentation, and at the top\nof that page, you can see:\n===================\nWARNING\n\nThese explanation are outdated!\n\nI already wrote a new version and I'm using\n\nSoon I will update here\n===================\n\nMy goal was to have something small and simple. I really like git-shell\nplus the update hook from the documentation, but that does not allow\nto have multiple Git users with a single system account.\n\nDmitry\n"},{"id":"81762","messageId":"37fcd2780806301007p6c1717bcue325bd5bca96ffe4@mail.gmail.com","threadId":"14226","inReplyTo":"48691059.4060604@freescale.com","subject":"Re: [RFC] Single system account for multiple git users","fromName":"Dmitry Potapov","fromEmail":"dpotapov@gmail.com","sentAt":"2008-06-30T17:07:53Z","receivedAt":"2008-06-30T17:07:53Z","isPatch":false,"sender":{"key":"dpotapov@gmail.com","avatar":"https://avatars.githubusercontent.com/u/6568595?v=4"},"body":"On Mon, Jun 30, 2008 at 8:56 PM, Jon Loeliger <jdl@freescale.com> wrote:\n>\n> Does that just mean that the git-shell program\n> has to be listed in /etc/shells?\n\nWhether git-shell should be listed in etc/shells depends on your\ndistributive, but it is irrelevant in this case. git-shell will not interpret\nthe given command. So, it won't work.\n\nDmitry\n"},{"id":"81849","messageId":"200807011055.51738@rk-nord.at","threadId":"14226","inReplyTo":"20080630151113.GO5737@dpotapov.dyndns.org","subject":"Re: [RFC] Single system account for multiple git users","fromName":"Melchior FRANZ","fromEmail":"melchior.franz@gmail.com","sentAt":"2008-07-01T08:55:50Z","receivedAt":"2008-07-01T08:55:50Z","isPatch":false,"sender":{"key":"melchior.franz@gmail.com","avatar":null},"body":"* Dmitry Potapov -- Monday 30 June 2008:\n> [...] but it requres that every Git user has a separate system\n> account on the server, which is often frowned upon by system\n> administrators, who would prefer to have a single system account\n> for access to Git repo. \n\nIndeed. This is AFAIK the main reason why git might not be used\nby a project where I'm contributor. gitosis could help here, but\nI guess that a built-in solution would be preferred. An external\naddon looks a bit like band-aid.  ;-)\n\nm.\n"},{"id":"81984","messageId":"20080702144536.GA1721@dpotapov.dyndns.org","threadId":"14226","inReplyTo":"200807011055.51738@rk-nord.at","subject":"Re: [RFC] Single system account for multiple git users","fromName":"Dmitry Potapov","fromEmail":"dpotapov@gmail.com","sentAt":"2008-07-02T14:45:36Z","receivedAt":"2008-07-02T14:45:36Z","isPatch":false,"sender":{"key":"dpotapov@gmail.com","avatar":"https://avatars.githubusercontent.com/u/6568595?v=4"},"body":"On Tue, Jul 01, 2008 at 10:55:50AM +0200, Melchior FRANZ wrote:\n> \n> Indeed. This is AFAIK the main reason why git might not be used\n> by a project where I'm contributor. gitosis could help here, but\n> I guess that a built-in solution would be preferred. An external\n> addon looks a bit like band-aid.  ;-)\n\nYes, and they impose some its own access control model, which is\ndifferent to what you normally have using git-shell. So, the purpose\nof my patch was to provide the absolutely minimal change to git-shell\nwhich allows to have a central Git server with multiple Git users under\none system account. I guess that most Git developers do not use Git in\nthis configuration, so they are not very interested in this patch. But\nthere are projects where having a central repo is strict requirement\n(usually justified by having centralized place to backup all sources,\ndifficult exchanging patches by email especially in great volume, and\nimpossibility direct connection due to firewalls, etc...).\n\nSo, I believe that my patch (or something simple like that) could help\nGit with wider adaptation.\n\nThanks,\nDmitry\n"}]}