{"thread":{"id":"16033","subject":"[PATCH] git-daemon: set REMOTE_ADDR to client address","startedAt":"2008-10-24T05:48:50Z","lastAt":"2008-10-24T05:48:50Z","messageCount":1,"participants":["Joey Hess"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"93826","messageId":"20081024054849.GA29048@kodama.kitenet.net","threadId":"16033","inReplyTo":null,"subject":"[PATCH] git-daemon: set REMOTE_ADDR to client address","fromName":"Joey Hess","fromEmail":"joey@kitenet.net","sentAt":"2008-10-24T05:48:50Z","receivedAt":"2008-10-24T05:48:50Z","isPatch":true,"sender":{"key":"joey@kitenet.net","avatar":"https://avatars.githubusercontent.com/u/16392?v=4"},"body":"This allows hooks like pre-receive to look at the client's IP\naddress.\n\nOf course the IP address can't be used to get strong security;\ngit-daemon isn't the right thing to use if you need that. However,\nbasic IP address checking can be good enough in some situations.\n\nREMOTE_ADDR is the same environment variable used to communicate the\nclient's address to CGI scripts.\n\nSigned-off-by: Joey Hess <joey@kitenet.net>\n---\n\nReal world example: ikiwiki can use pre-receive to check that the pushed\nchanges are ones that anyone could make to the wiki's source via the web\ninterface, and thus safe to accept. It's useful to be able to ban IP\naddresses from editing a wiki on the web, as a first line of defence to\nguard against spammers etc. With this patch the same IP guards can be\napplied to changes pushed in via git-daemon.\n\n Documentation/git-daemon.txt |    9 +++++++++\n daemon.c                     |    4 ++++\n 2 files changed, 13 insertions(+), 0 deletions(-)\n\ndiff --git a/Documentation/git-daemon.txt b/Documentation/git-daemon.txt\nindex b08a08c..f1a570a 100644\n--- a/Documentation/git-daemon.txt\n+++ b/Documentation/git-daemon.txt\n@@ -270,6 +270,15 @@ selectively enable/disable services per repository::\n ----------------------------------------------------------------\n \n \n+ENVIRONMENT\n+-----------\n+'git-daemon' will set REMOTE_ADDR to the IP address of the client\n+that connected to it, if the IP address is available. REMOTE_ADDR will\n+be available in the environment of hooks called when\n+services are performed.\n+\n+\n+\n Author\n ------\n Written by Linus Torvalds <torvalds@osdl.org>, YOSHIFUJI Hideaki\ndiff --git a/daemon.c b/daemon.c\nindex 3e5582d..b9ba44c 100644\n--- a/daemon.c\n+++ b/daemon.c\n@@ -537,6 +537,10 @@ static int execute(struct sockaddr *addr)\n #endif\n \t\t}\n \t\tloginfo(\"Connection from %s:%d\", addrbuf, port);\n+\t\tsetenv(\"REMOTE_ADDR\", addrbuf, 1);\n+\t}\n+\telse {\n+\t\tunsetenv(\"REMOTE_ADDR\");\n \t}\n \n \talarm(init_timeout ? init_timeout : timeout);\n\n-- \n1.5.6.5\n"}]}