{"thread":{"id":"15193","subject":"[PATCH] \"git shell\" won't work, need \"git-shell\"","startedAt":"2008-08-24T20:23:25Z","lastAt":"2008-10-28T11:11:57Z","messageCount":28,"participants":["Tommi Virtanen","Junio C Hamano","Johannes Schindelin","Paolo Bonzini","Petr Baudis","Dmitry Potapov","Mikael Magnusson","Mike Hommey","Matthieu Moy","Mike Ralphson","Dmitry V. Levin"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"88394","messageId":"20080824202325.GA14930@eagain.net","threadId":"15193","inReplyTo":null,"subject":"[PATCH] \"git shell\" won't work, need \"git-shell\"","fromName":"Tommi Virtanen","fromEmail":"tv@eagain.net","sentAt":"2008-08-24T20:23:25Z","receivedAt":"2008-08-24T20:23:25Z","isPatch":true,"sender":{"key":"tv@debian.org","avatar":null},"body":">From 8e7935231e8a91d470b3a4a2310803031ef49fc4 Mon Sep 17 00:00:00 2001\nFrom: Tommi Virtanen <tv@eagain.net>\nDate: Sun, 24 Aug 2008 23:20:33 +0300\nSubject: [PATCH] Install git-shell in bindir, again.\n\n/etc/passwd shell field must be something execable, you can't enter\n\"/usr/bin/git shell\" there. git-shell must be present as a separate\nexecutable, or it is useless.\n\nSigned-off-by: Tommi Virtanen <tv@eagain.net>\n---\n\nHi. Recent changes moved away from \"git-foo\" to \"git foo\", except for\nsome commands that needed backwards compatibility. However, git-shell\nas a separate binary was removed. I hope you will reinstante git-shell\nas a publicly visible binary in bin. Here's why:\n\nThe shell field in /etc/passwd is *exec*ed, not interpreted via sh -c\nor some such. For example, source of Debian's shadow, containing\n/bin/login:\n\nlibmisc/shell.c:80:\texecle (file, arg, (char *) 0, envp);\n\nI also tested this for real, and having a\n\ntest:x:1001:1001:,,,:/home/test:/usr/bin/git-shell\n\nline works, and\n\ntest:x:1001:1001:,,,:/home/test:/usr/bin/git shell\n\njust makes ssh loop asking for a password, logging\n\n\"User test not allowed because shell /usr/bin/git shell does not exist\"\n\nSo, as far as I understand, as it currently is, \"git shell\" is utterly\nuseless for what it was meant to do. Restoring \"git-shell\" will fix\nit.\n\n Makefile |    2 +-\n 1 files changed, 1 insertions(+), 1 deletions(-)\n\ndiff --git a/Makefile b/Makefile\nindex 53ab4b5..24d5809 100644\n--- a/Makefile\n+++ b/Makefile\n@@ -1351,7 +1351,7 @@ install: all\n \t$(INSTALL) -d -m 755 '$(DESTDIR_SQ)$(bindir_SQ)'\n \t$(INSTALL) -d -m 755 '$(DESTDIR_SQ)$(gitexec_instdir_SQ)'\n \t$(INSTALL) $(ALL_PROGRAMS) '$(DESTDIR_SQ)$(gitexec_instdir_SQ)'\n-\t$(INSTALL) git$X git-upload-pack$X git-receive-pack$X git-upload-archive$X '$(DESTDIR_SQ)$(bindir_SQ)'\n+\t$(INSTALL) git$X git-upload-pack$X git-receive-pack$X git-upload-archive$X git-shell$X '$(DESTDIR_SQ)$(bindir_SQ)'\n \t$(MAKE) -C templates DESTDIR='$(DESTDIR_SQ)' install\n \t$(MAKE) -C perl prefix='$(prefix_SQ)' DESTDIR='$(DESTDIR_SQ)' install\n ifndef NO_TCLTK\n-- \n1.6.0.2.g2ebc0.dirty\n\n-- \n:(){ :|:&};:\n"},{"id":"88395","messageId":"7vfxoukv56.fsf@gitster.siamese.dyndns.org","threadId":"15193","inReplyTo":"20080824202325.GA14930@eagain.net","subject":"Re: [PATCH] \"git shell\" won't work, need \"git-shell\"","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2008-08-24T20:36:37Z","receivedAt":"2008-08-24T20:36:37Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Tommi Virtanen <tv@eagain.net> writes:\n\n> test:x:1001:1001:,,,:/home/test:/usr/bin/git-shell\n>\n> line works, and\n>\n> test:x:1001:1001:,,,:/home/test:/usr/bin/git shell\n>\n> just makes ssh loop asking for a password, logging\n\nOf course it would.  Does using /usr/libexec/git-core/git-shell work?\n"},{"id":"88397","messageId":"20080824203825.GB14930@eagain.net","threadId":"15193","inReplyTo":"7vfxoukv56.fsf@gitster.siamese.dyndns.org","subject":"Re: [PATCH] \"git shell\" won't work, need \"git-shell\"","fromName":"Tommi Virtanen","fromEmail":"tv@eagain.net","sentAt":"2008-08-24T20:38:25Z","receivedAt":"2008-08-24T20:38:25Z","isPatch":true,"sender":{"key":"tv@debian.org","avatar":null},"body":"On Sun, Aug 24, 2008 at 01:36:37PM -0700, Junio C Hamano wrote:\n> Of course it would.  Does using /usr/libexec/git-core/git-shell work?\n\nIt would, but do you really want people using that?\n\n-- \n:(){ :|:&};:\n"},{"id":"88398","messageId":"7vbpzikt4b.fsf@gitster.siamese.dyndns.org","threadId":"15193","inReplyTo":"20080824203825.GB14930@eagain.net","subject":"Re: [PATCH] \"git shell\" won't work, need \"git-shell\"","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2008-08-24T21:20:20Z","receivedAt":"2008-08-24T21:20:20Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Tommi Virtanen <tv@eagain.net> writes:\n\n> On Sun, Aug 24, 2008 at 01:36:37PM -0700, Junio C Hamano wrote:\n>> Of course it would.  Does using /usr/libexec/git-core/git-shell work?\n>\n> It would, but do you really want people using that?\n\nI do not have particular preference either way.  What people wanted was to\nhave smaller number of git-foo on $PATH, and especially as \"git-shell\" is\nnot something people would be typing from their command line, so I dunno.\n"},{"id":"88403","messageId":"20080824222534.GC14930@eagain.net","threadId":"15193","inReplyTo":"7vbpzikt4b.fsf@gitster.siamese.dyndns.org","subject":"Re: [PATCH] \"git shell\" won't work, need \"git-shell\"","fromName":"Tommi Virtanen","fromEmail":"tv@eagain.net","sentAt":"2008-08-24T22:25:34Z","receivedAt":"2008-08-24T22:25:34Z","isPatch":true,"sender":{"key":"tv@debian.org","avatar":null},"body":"On Sun, Aug 24, 2008 at 02:20:20PM -0700, Junio C Hamano wrote:\n> I do not have particular preference either way.  What people wanted was to\n> have smaller number of git-foo on $PATH, and especially as \"git-shell\" is\n> not something people would be typing from their command line, so I dunno.\n\nThat's true, but I kinda think libexec is something only used\n*internally*, and you can't claim /etc/passwd to be internal to git..\n\nAt the minimum, git-shell(1) should explain that one needs to use the\nlibexec path.\n\n-- \n:(){ :|:&};:\n"},{"id":"88441","messageId":"alpine.DEB.1.00.0808251235430.24820@pacific.mpi-cbg.de.mpi-cbg.de","threadId":"15193","inReplyTo":"20080824222534.GC14930@eagain.net","subject":"Re: [PATCH] \"git shell\" won't work, need \"git-shell\"","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2008-08-25T10:37:12Z","receivedAt":"2008-08-25T10:37:12Z","isPatch":true,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi,\n\nOn Mon, 25 Aug 2008, Tommi Virtanen wrote:\n\n> On Sun, Aug 24, 2008 at 02:20:20PM -0700, Junio C Hamano wrote:\n> > I do not have particular preference either way.  What people wanted was to\n> > have smaller number of git-foo on $PATH, and especially as \"git-shell\" is\n> > not something people would be typing from their command line, so I dunno.\n> \n> That's true, but I kinda think libexec is something only used\n> *internally*, and you can't claim /etc/passwd to be internal to git..\n> \n> At the minimum, git-shell(1) should explain that one needs to use the\n> libexec path.\n\nOr maybe the real issue can be fixed?  Namely that your configuration does \nnot work?  That would involve you actually finding out what's happening, \nthough.\n\nCiao,\nDscho\n"},{"id":"88443","messageId":"48B29B2A.6000802@gnu.org","threadId":"15193","inReplyTo":"alpine.DEB.1.00.0808251235430.24820@pacific.mpi-cbg.de.mpi-cbg.de","subject":"Re: [PATCH] \"git shell\" won't work, need \"git-shell\"","fromName":"Paolo Bonzini","fromEmail":"bonzini@gnu.org","sentAt":"2008-08-25T11:44:42Z","receivedAt":"2008-08-25T11:44:42Z","isPatch":true,"sender":{"key":"bonzini@gnu.org","avatar":"https://avatars.githubusercontent.com/u/42082?v=4"},"body":"\n>> At the minimum, git-shell(1) should explain that one needs to use the\n>> libexec path.\n> \n> Or maybe the real issue can be fixed?  Namely that your configuration does \n> not work?  That would involve you actually finding out what's happening, \n> though.\n\nHe said so:\n\n> The shell field in /etc/passwd is *exec*ed, not interpreted via sh -c\n> or some such. For example, source of Debian's shadow, containing\n> /bin/login:\n> \n> libmisc/shell.c:80:\texecle (file, arg, (char *) 0, envp);\n> \n> I also tested this for real, and having a\n> \n> test:x:1001:1001:,,,:/home/test:/usr/bin/git-shell\n> \n> line works, and\n> \n> test:x:1001:1001:,,,:/home/test:/usr/bin/git shell\n> \n> just makes ssh loop asking for a password, logging\n> \n> \"User test not allowed because shell /usr/bin/git shell does not exist\"\n> \n> So, as far as I understand, as it currently is, \"git shell\" is utterly\n> useless for what it was meant to do. Restoring \"git-shell\" will fix\n> it.\n\nRephrasing your question, do you (Dscho) actually know *anyone* who has\na working setup with \"/usr/bin/git shell\" in /etc/passwd?\n\nPaolo\n"},{"id":"88475","messageId":"20080825170816.GQ10544@machine.or.cz","threadId":"15193","inReplyTo":"7vbpzikt4b.fsf@gitster.siamese.dyndns.org","subject":"Re: [PATCH] \"git shell\" won't work, need \"git-shell\"","fromName":"Petr Baudis","fromEmail":"pasky@suse.cz","sentAt":"2008-08-25T17:08:16Z","receivedAt":"2008-08-25T17:08:16Z","isPatch":true,"sender":{"key":"pasky@ucw.cz","avatar":"https://avatars.githubusercontent.com/u/18439?v=4"},"body":"On Sun, Aug 24, 2008 at 02:20:20PM -0700, Junio C Hamano wrote:\n> Tommi Virtanen <tv@eagain.net> writes:\n> \n> > On Sun, Aug 24, 2008 at 01:36:37PM -0700, Junio C Hamano wrote:\n> >> Of course it would.  Does using /usr/libexec/git-core/git-shell work?\n> >\n> > It would, but do you really want people using that?\n> \n> I do not have particular preference either way.  What people wanted was to\n> have smaller number of git-foo on $PATH, and especially as \"git-shell\" is\n> not something people would be typing from their command line, so I dunno.\n\nCan we agree that direct calls of libexec stuff should never be part of\nthe \"official\" interface (i.e. not workarounds for deprecated usage)?\nConsidering that calling the git-shell executable directly is the _only_\nsensible way of using this interface, it should follow that it has to be\nin /usr/bin, no matter if users type this command or not.\n\n(I'm actually a little confused that you bring up the \"typing from their\ncommand line\" aspect at all, since that never seemed to be relevant\ncriterium. People type the commit command all the time, yet we do not\ninstall git-commit. Typing the three git-* commands we do install -\ngit-receive-pack, git-upload-pack and git-upload-archive - should be on\nthe other hand pretty rare occasion. About gitk, well, 'git k' would\njust look silly, I guess. ;-)\n\n-- \n\t\t\t\tPetr \"Pasky\" Baudis\nThe next generation of interesting software will be done\non the Macintosh, not the IBM PC.  -- Bill Gates\n"},{"id":"88477","messageId":"37fcd2780808251020j1ef51b38h7c6d6e8f050a92ce@mail.gmail.com","threadId":"15193","inReplyTo":"20080825170816.GQ10544@machine.or.cz","subject":"Re: [PATCH] \"git shell\" won't work, need \"git-shell\"","fromName":"Dmitry Potapov","fromEmail":"dpotapov@gmail.com","sentAt":"2008-08-25T17:20:38Z","receivedAt":"2008-08-25T17:20:38Z","isPatch":true,"sender":{"key":"dpotapov@gmail.com","avatar":"https://avatars.githubusercontent.com/u/6568595?v=4"},"body":"On Mon, Aug 25, 2008 at 9:08 PM, Petr Baudis <pasky@suse.cz> wrote:\n>\n> Can we agree that direct calls of libexec stuff should never be part of\n> the \"official\" interface (i.e. not workarounds for deprecated usage)?\n\nAgreed. It looks somewhat strange to type the libexec path in /etc/passwd.\n\n> Considering that calling the git-shell executable directly is the _only_\n> sensible way of using this interface, it should follow that it has to be\n> in /usr/bin, no matter if users type this command or not.\n\nPerhaps, /usr/sbin would be a better place, as it is intended only for\nsystem administration binaries.\n\nDmitry\n"},{"id":"88478","messageId":"20080825172630.GH23582@eagain.net","threadId":"15193","inReplyTo":"37fcd2780808251020j1ef51b38h7c6d6e8f050a92ce@mail.gmail.com","subject":"Re: [PATCH] \"git shell\" won't work, need \"git-shell\"","fromName":"Tommi Virtanen","fromEmail":"tv@eagain.net","sentAt":"2008-08-25T17:26:30Z","receivedAt":"2008-08-25T17:26:30Z","isPatch":true,"sender":{"key":"tv@debian.org","avatar":null},"body":"On Mon, Aug 25, 2008 at 09:20:38PM +0400, Dmitry Potapov wrote:\n> Perhaps, /usr/sbin would be a better place, as it is intended only for\n> system administration binaries.\n\nI'd argue that git-shell isn't *exclusively* for root, which is the\ncriteria for sbin. It's pretty easy to imagine a user setting up their\nown ~/.ssh/authorized_keys with a special passphraseless key that\ncan only do git operations.\n\n-- \n:(){ :|:&};:\n"},{"id":"88480","messageId":"37fcd2780808251053j5e8ced77ye633e05837cccd6@mail.gmail.com","threadId":"15193","inReplyTo":"20080825172630.GH23582@eagain.net","subject":"Re: [PATCH] \"git shell\" won't work, need \"git-shell\"","fromName":"Dmitry Potapov","fromEmail":"dpotapov@gmail.com","sentAt":"2008-08-25T17:53:06Z","receivedAt":"2008-08-25T17:53:06Z","isPatch":true,"sender":{"key":"dpotapov@gmail.com","avatar":"https://avatars.githubusercontent.com/u/6568595?v=4"},"body":"On Mon, Aug 25, 2008 at 9:26 PM, Tommi Virtanen <tv@eagain.net> wrote:\n> On Mon, Aug 25, 2008 at 09:20:38PM +0400, Dmitry Potapov wrote:\n>> Perhaps, /usr/sbin would be a better place, as it is intended only for\n>> system administration binaries.\n>\n> I'd argue that git-shell isn't *exclusively* for root, which is the\n> criteria for sbin.\n\nI don't think that your criteria is correct. mysqld is also not exclusively\nfor root as you can run it on a non-privilege port, yet, it is placed in\n/usr/sbin. Placing in /usr/sbin does not mean that users do not have access\nto it, but that those binaries are not run by users from their command line.\n\nDmitry\n"},{"id":"88481","messageId":"alpine.DEB.1.00.0808251955490.24820@pacific.mpi-cbg.de.mpi-cbg.de","threadId":"15193","inReplyTo":"48B29B2A.6000802@gnu.org","subject":"Re: [PATCH] \"git shell\" won't work, need \"git-shell\"","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2008-08-25T17:58:14Z","receivedAt":"2008-08-25T17:58:14Z","isPatch":true,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi,\n\nOn Mon, 25 Aug 2008, Paolo Bonzini wrote:\n\n> > That would involve you actually finding out what's happening, though.\n> \n> He said so:\n> \n> > test:x:1001:1001:,,,:/home/test:/usr/bin/git shell\n> > \n> > just makes ssh loop asking for a password, logging\n> > \n> > \"User test not allowed because shell /usr/bin/git shell does not exist\"\n\nOkay, so this means that you cannot pass arguments to the login shell.  \nMakes me wonder... I had the impression that bash was called with --login.\n\nCiao,\nDscho\n"},{"id":"88482","messageId":"alpine.DEB.1.00.0808252015080.24820@pacific.mpi-cbg.de.mpi-cbg.de","threadId":"15193","inReplyTo":"37fcd2780808251020j1ef51b38h7c6d6e8f050a92ce@mail.gmail.com","subject":"Re: [PATCH] \"git shell\" won't work, need \"git-shell\"","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2008-08-25T18:17:12Z","receivedAt":"2008-08-25T18:17:12Z","isPatch":true,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi,\n\nOn Mon, 25 Aug 2008, Dmitry Potapov wrote:\n\n> On Mon, Aug 25, 2008 at 9:08 PM, Petr Baudis <pasky@suse.cz> wrote:\n> >\n> > Can we agree that direct calls of libexec stuff should never be part \n> > of the \"official\" interface (i.e. not workarounds for deprecated \n> > usage)?\n> \n> Agreed. It looks somewhat strange to type the libexec path in \n> /etc/passwd.\n\nFWIW I do not agree.  IMNHO libexec/ is just a way to organize executable \nparts of any software package that are usually not called from the command \nline.  And a login shell qualifies for that.\n\n> > Considering that calling the git-shell executable directly is the \n> > _only_ sensible way of using this interface, it should follow that it \n> > has to be in /usr/bin, no matter if users type this command or not.\n> \n> Perhaps, /usr/sbin would be a better place, as it is intended only for \n> system administration binaries.\n\nDoes it not strike you as odd, then, that \"sh\" -- by far the most common \nlogin shell -- does not live in /usr/sbin/?\n\nCiao,\nDscho\n"},{"id":"88484","messageId":"237967ef0808251125q3e50fa04wf0e97ff29298bef2@mail.gmail.com","threadId":"15193","inReplyTo":"alpine.DEB.1.00.0808251955490.24820@pacific.mpi-cbg.de.mpi-cbg.de","subject":"Re: [PATCH] \"git shell\" won't work, need \"git-shell\"","fromName":"Mikael Magnusson","fromEmail":"mikachu@gmail.com","sentAt":"2008-08-25T18:25:38Z","receivedAt":"2008-08-25T18:25:38Z","isPatch":true,"sender":{"key":"mikachu@gmail.com","avatar":null},"body":"2008/8/25 Johannes Schindelin <Johannes.Schindelin@gmx.de>:\n> Hi,\n>\n> On Mon, 25 Aug 2008, Paolo Bonzini wrote:\n>\n>> > That would involve you actually finding out what's happening, though.\n>>\n>> He said so:\n>>\n>> > test:x:1001:1001:,,,:/home/test:/usr/bin/git shell\n>> >\n>> > just makes ssh loop asking for a password, logging\n>> >\n>> > \"User test not allowed because shell /usr/bin/git shell does not exist\"\n>\n> Okay, so this means that you cannot pass arguments to the login shell.\n> Makes me wonder... I had the impression that bash was called with --login.\n\nWhen you login, a '-' is prepended in argv[0], ie, bash checks if it's called\n\"-bash\". This is documented in man bash, but I couldn't find it in man login\nor man agetty, not sure where else it might be written down.\n\n-- \nMikael Magnusson\n"},{"id":"88496","messageId":"alpine.DEB.1.00.0808252206150.24820@pacific.mpi-cbg.de.mpi-cbg.de","threadId":"15193","inReplyTo":"237967ef0808251125q3e50fa04wf0e97ff29298bef2@mail.gmail.com","subject":"Re: [PATCH] \"git shell\" won't work, need \"git-shell\"","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2008-08-25T20:08:20Z","receivedAt":"2008-08-25T20:08:20Z","isPatch":true,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi,\n\nOn Mon, 25 Aug 2008, Mikael Magnusson wrote:\n\n> 2008/8/25 Johannes Schindelin <Johannes.Schindelin@gmx.de>:\n>\n> > On Mon, 25 Aug 2008, Paolo Bonzini wrote:\n> >\n> >> > That would involve you actually finding out what's happening, \n> >> > though.\n> >>\n> >> He said so:\n> >>\n> >> > test:x:1001:1001:,,,:/home/test:/usr/bin/git shell\n> >> >\n> >> > just makes ssh loop asking for a password, logging\n> >> >\n> >> > \"User test not allowed because shell /usr/bin/git shell does not \n> >> > exist\"\n> >\n> > Okay, so this means that you cannot pass arguments to the login shell. \n> > Makes me wonder... I had the impression that bash was called with \n> > --login.\n> \n> When you login, a '-' is prepended in argv[0], ie, bash checks if it's \n> called \"-bash\". This is documented in man bash, but I couldn't find it \n> in man login or man agetty, not sure where else it might be written \n> down.\n\nThanks!\n\nSo does this mean that we could check in git.c if there is a leading \"-\" \nin argv[0]?  If so, then the builtin git-shell should be called by \ndefault.\n\nAt least I do not expect many instances of git being called with argv[0] \nstarting with a \"-\"... :-)\n\nCiao,\nDscho\n"},{"id":"88500","messageId":"20080825202628.GA8072@dpotapov.dyndns.org","threadId":"15193","inReplyTo":"alpine.DEB.1.00.0808252015080.24820@pacific.mpi-cbg.de.mpi-cbg.de","subject":"Re: [PATCH] \"git shell\" won't work, need \"git-shell\"","fromName":"Dmitry Potapov","fromEmail":"dpotapov@gmail.com","sentAt":"2008-08-25T20:26:28Z","receivedAt":"2008-08-25T20:26:28Z","isPatch":true,"sender":{"key":"dpotapov@gmail.com","avatar":"https://avatars.githubusercontent.com/u/6568595?v=4"},"body":"On Mon, Aug 25, 2008 at 08:17:12PM +0200, Johannes Schindelin wrote:\n> \n> Does it not strike you as odd, then, that \"sh\" -- by far the most common \n> login shell -- does not live in /usr/sbin/?\n\nNot at all. \"sh\" is *often* run directly from the command line. Without\nit being in PATH, system(3) and many other things would not work, but\nno one tuns git-shell as the real shell to do some job.\n\nDmitry\n"},{"id":"88499","messageId":"alpine.DEB.1.00.0808252225520.24820@pacific.mpi-cbg.de.mpi-cbg.de","threadId":"15193","inReplyTo":"alpine.DEB.1.00.0808252206150.24820@pacific.mpi-cbg.de.mpi-cbg.de","subject":"Re: [PATCH] \"git shell\" won't work, need \"git-shell\"","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2008-08-25T20:28:55Z","receivedAt":"2008-08-25T20:28:55Z","isPatch":true,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi,\n\nOn Mon, 25 Aug 2008, Johannes Schindelin wrote:\n\n> On Mon, 25 Aug 2008, Mikael Magnusson wrote:\n> \n> > 2008/8/25 Johannes Schindelin <Johannes.Schindelin@gmx.de>:\n> >\n> > > On Mon, 25 Aug 2008, Paolo Bonzini wrote:\n> > >\n> > >> > That would involve you actually finding out what's happening, \n> > >> > though.\n> > >>\n> > >> He said so:\n> > >>\n> > >> > test:x:1001:1001:,,,:/home/test:/usr/bin/git shell\n> > >> >\n> > >> > just makes ssh loop asking for a password, logging\n> > >> >\n> > >> > \"User test not allowed because shell /usr/bin/git shell does not \n> > >> > exist\"\n> > >\n> > > Okay, so this means that you cannot pass arguments to the login shell. \n> > > Makes me wonder... I had the impression that bash was called with \n> > > --login.\n> > \n> > When you login, a '-' is prepended in argv[0], ie, bash checks if it's \n> > called \"-bash\". This is documented in man bash, but I couldn't find it \n> > in man login or man agetty, not sure where else it might be written \n> > down.\n> \n> Thanks!\n> \n> So does this mean that we could check in git.c if there is a leading \"-\" \n> in argv[0]?  If so, then the builtin git-shell should be called by \n> default.\n> \n> At least I do not expect many instances of git being called with argv[0] \n> starting with a \"-\"... :-)\n\nOh, well.  I just tested again, and slapped my head when it did not work, \nremembering that we do _not_ call Git as a login shell.  Instead, we call \nssh with the \"-c\" option, which just passes it to the shell.  \nConsequently, argv[0] does not get a \"-\" prepended.\n\nI seem to remember that Hannes had some code to support \"-c\" as an \nindicator that Git should execute git-shell, but I just might have dreamt \nthat, too.\n\nCiao,\nDscho\n"},{"id":"88503","messageId":"20080825204023.GA10280@glandium.org","threadId":"15193","inReplyTo":"alpine.DEB.1.00.0808252015080.24820@pacific.mpi-cbg.de.mpi-cbg.de","subject":"Re: [PATCH] \"git shell\" won't work, need \"git-shell\"","fromName":"Mike Hommey","fromEmail":"mh@glandium.org","sentAt":"2008-08-25T20:40:23Z","receivedAt":"2008-08-25T20:40:23Z","isPatch":true,"sender":{"key":"mh@glandium.org","avatar":"https://avatars.githubusercontent.com/u/1038527?v=4"},"body":"On Mon, Aug 25, 2008 at 08:17:12PM +0200, Johannes Schindelin wrote:\n> Hi,\n> \n> On Mon, 25 Aug 2008, Dmitry Potapov wrote:\n> \n> > On Mon, Aug 25, 2008 at 9:08 PM, Petr Baudis <pasky@suse.cz> wrote:\n> > >\n> > > Can we agree that direct calls of libexec stuff should never be part \n> > > of the \"official\" interface (i.e. not workarounds for deprecated \n> > > usage)?\n> > \n> > Agreed. It looks somewhat strange to type the libexec path in \n> > /etc/passwd.\n> \n> FWIW I do not agree.  IMNHO libexec/ is just a way to organize executable \n> parts of any software package that are usually not called from the command \n> line.  And a login shell qualifies for that.\n> \n> > > Considering that calling the git-shell executable directly is the \n> > > _only_ sensible way of using this interface, it should follow that it \n> > > has to be in /usr/bin, no matter if users type this command or not.\n> > \n> > Perhaps, /usr/sbin would be a better place, as it is intended only for \n> > system administration binaries.\n> \n> Does it not strike you as odd, then, that \"sh\" -- by far the most common \n> login shell -- does not live in /usr/sbin/?\n\nBut nologin is in /usr/sbin.\n\nMike\n"},{"id":"88505","messageId":"alpine.DEB.1.00.0808252248150.24820@pacific.mpi-cbg.de.mpi-cbg.de","threadId":"15193","inReplyTo":"alpine.DEB.1.00.0808252225520.24820@pacific.mpi-cbg.de.mpi-cbg.de","subject":"[PATCH 1/2] git wrapper: Make while loop more reader-friendly","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2008-08-25T20:51:25Z","receivedAt":"2008-08-25T20:51:25Z","isPatch":true,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"\nIt is not a good practice to prefer performance over readability in\nsomething as performance uncritical as finding the trailing slash\nof argv[0].\n\nSo avoid head-scratching by making the loop user-readable, and not\nhyper-performance-optimized.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n\n\tThe original version threatened to cause eye-cancer with this\n\tdeveloper, so that I had to run to the physician real quick.\n\tThat was quite hard, as no ophtalmologist seemed to be in\n\toffice at 10:30pm.  But I found a real good witch, and she\n\tdiagnozed me as healthy.\n\n git.c |    5 ++---\n 1 files changed, 2 insertions(+), 3 deletions(-)\n\ndiff --git a/git.c b/git.c\nindex a647741..2fd74c4 100644\n--- a/git.c\n+++ b/git.c\n@@ -427,9 +427,8 @@ int main(int argc, const char **argv)\n \t * name, and the dirname as the default exec_path\n \t * if we don't have anything better.\n \t */\n-\tdo\n-\t\t--slash;\n-\twhile (cmd <= slash && !is_dir_sep(*slash));\n+\twhile (cmd <= slash && !is_dir_sep(*slash))\n+\t\tslash--;\n \tif (slash < cmd) {\n \t\tcmd = lookup_program_in_path(cmd);\n \t\tfor (slash = (char *)cmd + strlen(cmd) - 1;\n-- \n1.6.0.211.ga840e.dirty\n"},{"id":"88506","messageId":"alpine.DEB.1.00.0808252251450.24820@pacific.mpi-cbg.de.mpi-cbg.de","threadId":"15193","inReplyTo":"alpine.DEB.1.00.0808252248150.24820@pacific.mpi-cbg.de.mpi-cbg.de","subject":"[PATCH 2/2] git wrapper: execute git-shell when argv[1] is '-c'","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2008-08-25T20:52:46Z","receivedAt":"2008-08-25T20:52:46Z","isPatch":true,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"\nWhen a program is called via ssh's '-c' option, the login shell is called \non the remote computer, with the given arguments.  In the case that Git \nwas specified as login shell in /etc/passwd, Git used to complain that it \ndoes not know the '-c' option and die.\n\nThis commit assumes that '-c' indicates that Git was specified as\na login shell, and hands off to git-shell.\n\nNoticed by Tommi Virtanen.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n\n\tThis should be pretty uncontroversial, as it turns a former\n\terror into something useful.\n\n\tHowever, I would not know where in the documentation (in addition\n\tto git-shell.txt, I guess), this change should be described.\n\n git.c |   11 ++++++++++-\n 1 files changed, 10 insertions(+), 1 deletions(-)\n\ndiff --git a/git.c b/git.c\nindex 2fd74c4..b16736a 100644\n--- a/git.c\n+++ b/git.c\n@@ -419,14 +419,23 @@ static void execv_dashed_external(const char **argv)\n int main(int argc, const char **argv)\n {\n \tconst char *cmd = argv[0] && *argv[0] ? argv[0] : \"git-help\";\n-\tchar *slash = (char *)cmd + strlen(cmd);\n+\tchar *slash;\n \tint done_alias = 0;\n \n \t/*\n+\t * When Git is called with \"-c\", it is either an error, or Git\n+\t * was specified as a login shell in /etc/passwd.  Assuming the\n+\t * latter, we continue with git-shell.\n+\t */\n+\tif (argc > 2 && !strcmp(argv[1], \"-c\"))\n+\t\tcmd = \"git-shell\";\n+\n+\t/*\n \t * Take the basename of argv[0] as the command\n \t * name, and the dirname as the default exec_path\n \t * if we don't have anything better.\n \t */\n+\tslash = (char *)cmd + strlen(cmd);\n \twhile (cmd <= slash && !is_dir_sep(*slash))\n \t\tslash--;\n \tif (slash < cmd) {\n-- \n1.6.0.211.ga840e.dirty\n"},{"id":"88508","messageId":"20080825210345.GE14930@eagain.net","threadId":"15193","inReplyTo":"alpine.DEB.1.00.0808252251450.24820@pacific.mpi-cbg.de.mpi-cbg.de","subject":"Re: [PATCH 2/2] git wrapper: execute git-shell when argv[1] is '-c'","fromName":"Tommi Virtanen","fromEmail":"tv@eagain.net","sentAt":"2008-08-25T21:03:45Z","receivedAt":"2008-08-25T21:03:45Z","isPatch":true,"sender":{"key":"tv@debian.org","avatar":null},"body":"On Mon, Aug 25, 2008 at 10:52:46PM +0200, Johannes Schindelin wrote:\n> When a program is called via ssh's '-c' option, the login shell is called \n> on the remote computer, with the given arguments.  In the case that Git \n> was specified as login shell in /etc/passwd, Git used to complain that it \n> does not know the '-c' option and die.\n> \n> This commit assumes that '-c' indicates that Git was specified as\n> a login shell, and hands off to git-shell.\n> \n> Noticed by Tommi Virtanen.\n\nMy imagination is insufficient in coming up with an uglier kludge, and\nI sincerely hope my name isn't associated with this in any way.\n\n-- \n:(){ :|:&};:\n"},{"id":"88520","messageId":"alpine.DEB.1.00.0808260001390.24820@pacific.mpi-cbg.de.mpi-cbg.de","threadId":"15193","inReplyTo":"20080825210345.GE14930@eagain.net","subject":"Re: [PATCH 2/2] git wrapper: execute git-shell when argv[1] is '-c'","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2008-08-25T22:05:21Z","receivedAt":"2008-08-25T22:05:21Z","isPatch":true,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi,\n\nOn Tue, 26 Aug 2008, Tommi Virtanen wrote:\n\n> On Mon, Aug 25, 2008 at 10:52:46PM +0200, Johannes Schindelin wrote:\n> > When a program is called via ssh's '-c' option, the login shell is called \n> > on the remote computer, with the given arguments.  In the case that Git \n> > was specified as login shell in /etc/passwd, Git used to complain that it \n> > does not know the '-c' option and die.\n> > \n> > This commit assumes that '-c' indicates that Git was specified as\n> > a login shell, and hands off to git-shell.\n> > \n> > Noticed by Tommi Virtanen.\n> \n> My imagination is insufficient in coming up with an uglier kludge, and\n> I sincerely hope my name isn't associated with this in any way.\n\nI have no problems deleting your name from the commit message.  None at \nall.  Even if you actually did notice the issue.\n\nI do disagree with you that it is a kludge though.  I think it makes \ncomplete sense to add this to Documentation/git.txt in addition to other \ndocumentation that is lacking from my patch, though:\n\n-- snip --\n-c <command>::\n\texecute <command> in git-shell.\n-- snap --\n\nCiao,\nDscho\n"},{"id":"88524","messageId":"20080825222002.GF14930@eagain.net","threadId":"15193","inReplyTo":"alpine.DEB.1.00.0808260001390.24820@pacific.mpi-cbg.de.mpi-cbg.de","subject":"Re: [PATCH 2/2] git wrapper: execute git-shell when argv[1] is '-c'","fromName":"Tommi Virtanen","fromEmail":"tv@eagain.net","sentAt":"2008-08-25T22:20:02Z","receivedAt":"2008-08-25T22:20:02Z","isPatch":true,"sender":{"key":"tv@debian.org","avatar":null},"body":"On Tue, Aug 26, 2008 at 12:05:21AM +0200, Johannes Schindelin wrote:\n> I do disagree with you that it is a kludge though.  I think it makes \n> complete sense to add this to Documentation/git.txt in addition to other \n> documentation that is lacking from my patch, though:\n> \n> -- snip --\n> -c <command>::\n> \texecute <command> in git-shell.\n> -- snap --\n\nAll I'm going to say is that that's not the way you build trustable\nsoftware. You take a minimal interface and restrict untrusted users to\nthat, you don't add a feature to the widest possible interface..\n\n-- \n:(){ :|:&};:\n"},{"id":"88530","messageId":"alpine.DEB.1.00.0808260249090.24820@pacific.mpi-cbg.de.mpi-cbg.de","threadId":"15193","inReplyTo":"20080825222002.GF14930@eagain.net","subject":"Re: [PATCH 2/2] git wrapper: execute git-shell when argv[1] is '-c'","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2008-08-26T00:52:35Z","receivedAt":"2008-08-26T00:52:35Z","isPatch":true,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi,\n\nOn Tue, 26 Aug 2008, Tommi Virtanen wrote:\n\n> On Tue, Aug 26, 2008 at 12:05:21AM +0200, Johannes Schindelin wrote:\n> > I do disagree with you that it is a kludge though.  I think it makes \n> > complete sense to add this to Documentation/git.txt in addition to \n> > other documentation that is lacking from my patch, though:\n> > \n> > -- snip --\n> > -c <command>::\n> > \texecute <command> in git-shell.\n> > -- snap --\n> \n> All I'm going to say is that that's not the way you build trustable \n> software. You take a minimal interface and restrict untrusted users to \n> that, you don't add a feature to the widest possible interface..\n\nI do not get your point.\n\nBut then, I think I start not to care anymore, as I think your reasoning \nis bogus.  \"widest possible interface\", \"trustable software\", etc.  Sounds \npretty buzzy-wordy to me.\n\nYeah, you would need to audit it.  Maybe you would even have to check for \n\"*argv[0] == '-'\" and set argv[0] to \"git-shell\" if so.  But buzz-wording \njust makes me go away and not listen anymore.\n\nWhatever,\nDscho\n"},{"id":"88550","messageId":"vpqy72ktgg7.fsf@bauges.imag.fr","threadId":"15193","inReplyTo":"alpine.DEB.1.00.0808260249090.24820@pacific.mpi-cbg.de.mpi-cbg.de","subject":"Re: [PATCH 2/2] git wrapper: execute git-shell when argv[1] is '-c'","fromName":"Matthieu Moy","fromEmail":"matthieu.moy@imag.fr","sentAt":"2008-08-26T06:53:44Z","receivedAt":"2008-08-26T06:53:44Z","isPatch":true,"sender":{"key":"git@matthieu-moy.fr","avatar":"https://avatars.githubusercontent.com/u/14709?v=4"},"body":"Johannes Schindelin <Johannes.Schindelin@gmx.de> writes:\n\n> On Tue, 26 Aug 2008, Tommi Virtanen wrote:\n>\n>> All I'm going to say is that that's not the way you build trustable \n>> software. You take a minimal interface and restrict untrusted users to \n>> that, you don't add a feature to the widest possible interface..\n>\n> I do not get your point.\n\nWith your patch, AAUI, one would put /usr/bin/git as a shell in\npasswd. It's pretty clear that someone calling the shell with -c will\nget the restriction of git-shell, but I'd hardly guarantee that the\nshell in /etc/passwd will never be called without -c. At least, if the\nuser tries to login, he will execute git without argument (which\nfortunately isn't serious, he'll just get the help message for git,\nwhich is unhelpful but not dangerous). My knowledge in Unix isn't\nsufficient to be sure there's no way at all to call git in a dangerous\nway here. With git-shell, it's much simpler to understand: either you\ngive -c, and you get the restricted command set, or you don't, and you\nget nothing.\n\n-- \nMatthieu\n"},{"id":"88560","messageId":"e2b179460808260150p15b7da0ev913eced3709c2cd1@mail.gmail.com","threadId":"15193","inReplyTo":"alpine.DEB.1.00.0808252248150.24820@pacific.mpi-cbg.de.mpi-cbg.de","subject":"Re: [PATCH 1/2] git wrapper: Make while loop more reader-friendly","fromName":"Mike Ralphson","fromEmail":"mike.ralphson@gmail.com","sentAt":"2008-08-26T08:50:34Z","receivedAt":"2008-08-26T08:50:34Z","isPatch":true,"sender":{"key":"mike.ralphson@gmail.com","avatar":"https://avatars.githubusercontent.com/u/21603?v=4"},"body":"2008/8/25 Johannes Schindelin <Johannes.Schindelin@gmx.de>:\n>\n> It is not a good practice to prefer performance over readability in\n> something as performance uncritical as finding the trailing slash\n> of argv[0].\n>\n> So avoid head-scratching by making the loop user-readable, and not\n> hyper-performance-optimized.\n>\n> Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n> ---\n>\n>  git.c |    5 ++---\n>  1 files changed, 2 insertions(+), 3 deletions(-)\n>\n> diff --git a/git.c b/git.c\n> index a647741..2fd74c4 100644\n> --- a/git.c\n> +++ b/git.c\n> @@ -427,9 +427,8 @@ int main(int argc, const char **argv)\n>         * name, and the dirname as the default exec_path\n>         * if we don't have anything better.\n>         */\n> -       do\n> -               --slash;\n> -       while (cmd <= slash && !is_dir_sep(*slash));\n> +       while (cmd <= slash && !is_dir_sep(*slash))\n> +               slash--;\n>        if (slash < cmd) {\n>                cmd = lookup_program_in_path(cmd);\n>                for (slash = (char *)cmd + strlen(cmd) - 1;\n> --\n> 1.6.0.211.ga840e.dirty\n\nIsn't it more likely that this form was chosen to indicate that the\nloop body was expected to execute at least once, rather than zero or\nmore times?\n\nMike\n"},{"id":"88616","messageId":"7vod3facz7.fsf@gitster.siamese.dyndns.org","threadId":"15193","inReplyTo":"vpqy72ktgg7.fsf@bauges.imag.fr","subject":"Re: [PATCH 2/2] git wrapper: execute git-shell when argv[1] is '-c'","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2008-08-26T17:43:40Z","receivedAt":"2008-08-26T17:43:40Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Matthieu Moy <Matthieu.Moy@imag.fr> writes:\n\n> Johannes Schindelin <Johannes.Schindelin@gmx.de> writes:\n>\n>> On Tue, 26 Aug 2008, Tommi Virtanen wrote:\n>>\n>>> All I'm going to say is that that's not the way you build trustable \n>>> software. You take a minimal interface and restrict untrusted users to \n>>> that, you don't add a feature to the widest possible interface..\n>>\n>> I do not get your point.\n>\n> With your patch, AAUI, one would put /usr/bin/git as a shell in\n> passwd....\n\nWell, it was sheer stupidity of mine.\n\nLet's stop this and apply this patch instead.  The patch text is obvious\nso I won't quote.\n\n-- * --\nFrom: Junio C Hamano <gitster@pobox.com>\nDate: Mon, 25 Aug 2008 22:39:17 -0700\nSubject: [PATCH] Revert \"Build-in \"git-shell\"\"\n\nThis reverts commit daa0cc9a92c9c2c714aa5f7da6d0ff65b93e0698.\nIt was a stupid idea to do this; when run as a log-in shell,\nit is spawned with argv[0] set to \"-git-shell\", so the usual\nname-based dispatch would not work to begin with.\n\nSigned-off-by: Junio C Hamano <gitster@pobox.com>\n\n Makefile        |    2 +-\n builtin-shell.c |   90 -------------------------------------------------------\n builtin.h       |    1 -\n git.c           |    1 -\n shell.c         |   89 ++++++++++++++++++++++++++++++++++++++++++++++++++++++\n 5 files changed, 90 insertions(+), 93 deletions(-)\n-- \n1.6.0.1.113.g0a79b\n"},{"id":"94098","messageId":"20081028111157.GD1682@wo.int.altlinux.org","threadId":"15193","inReplyTo":"20080824202325.GA14930@eagain.net","subject":"Re: [PATCH] \"git shell\" won't work, need \"git-shell\"","fromName":"Dmitry V. Levin","fromEmail":"ldv@altlinux.org","sentAt":"2008-10-28T11:11:57Z","receivedAt":"2008-10-28T11:11:57Z","isPatch":true,"sender":{"key":"ldv@altlinux.org","avatar":"https://avatars.githubusercontent.com/u/5281408?v=4"},"body":"Hi,\n\nPlease apply this compatibility fix (commit v1.6.0.1-90-g27a6ed4)\nto maint as well.\n\nOn Sun, Aug 24, 2008 at 11:23:25PM +0300, Tommi Virtanen wrote:\n> >From 8e7935231e8a91d470b3a4a2310803031ef49fc4 Mon Sep 17 00:00:00 2001\n> From: Tommi Virtanen <tv@eagain.net>\n> Date: Sun, 24 Aug 2008 23:20:33 +0300\n> Subject: [PATCH] Install git-shell in bindir, again.\n> \n> /etc/passwd shell field must be something execable, you can't enter\n> \"/usr/bin/git shell\" there. git-shell must be present as a separate\n> executable, or it is useless.\n> \n> Signed-off-by: Tommi Virtanen <tv@eagain.net>\n> ---\n> \n> Hi. Recent changes moved away from \"git-foo\" to \"git foo\", except for\n> some commands that needed backwards compatibility. However, git-shell\n> as a separate binary was removed. I hope you will reinstante git-shell\n> as a publicly visible binary in bin. Here's why:\n> \n> The shell field in /etc/passwd is *exec*ed, not interpreted via sh -c\n> or some such. For example, source of Debian's shadow, containing\n> /bin/login:\n> \n> libmisc/shell.c:80:\texecle (file, arg, (char *) 0, envp);\n> \n> I also tested this for real, and having a\n> \n> test:x:1001:1001:,,,:/home/test:/usr/bin/git-shell\n> \n> line works, and\n> \n> test:x:1001:1001:,,,:/home/test:/usr/bin/git shell\n> \n> just makes ssh loop asking for a password, logging\n> \n> \"User test not allowed because shell /usr/bin/git shell does not exist\"\n> \n> So, as far as I understand, as it currently is, \"git shell\" is utterly\n> useless for what it was meant to do. Restoring \"git-shell\" will fix\n> it.\n> \n>  Makefile |    2 +-\n>  1 files changed, 1 insertions(+), 1 deletions(-)\n> \n> diff --git a/Makefile b/Makefile\n> index 53ab4b5..24d5809 100644\n> --- a/Makefile\n> +++ b/Makefile\n> @@ -1351,7 +1351,7 @@ install: all\n>  \t$(INSTALL) -d -m 755 '$(DESTDIR_SQ)$(bindir_SQ)'\n>  \t$(INSTALL) -d -m 755 '$(DESTDIR_SQ)$(gitexec_instdir_SQ)'\n>  \t$(INSTALL) $(ALL_PROGRAMS) '$(DESTDIR_SQ)$(gitexec_instdir_SQ)'\n> -\t$(INSTALL) git$X git-upload-pack$X git-receive-pack$X git-upload-archive$X '$(DESTDIR_SQ)$(bindir_SQ)'\n> +\t$(INSTALL) git$X git-upload-pack$X git-receive-pack$X git-upload-archive$X git-shell$X '$(DESTDIR_SQ)$(bindir_SQ)'\n>  \t$(MAKE) -C templates DESTDIR='$(DESTDIR_SQ)' install\n>  \t$(MAKE) -C perl prefix='$(prefix_SQ)' DESTDIR='$(DESTDIR_SQ)' install\n>  ifndef NO_TCLTK\n> -- \n> 1.6.0.2.g2ebc0.dirty\n\n\n-- \nldv\n"}]}