{"thread":{"id":"16515","subject":"[PATCH] git-cvsimport: add support for cvs pserver password scrambling.","startedAt":"2008-11-28T18:06:40Z","lastAt":"2009-08-14T06:17:17Z","messageCount":8,"participants":["Dirk Hörner","Johannes Schindelin","Nanako Shiraishi","Junio C Hamano","Sverre Rabbelier"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"96690","messageId":"5794AED2-43FF-4441-8292-0C9BFB3139A2@gmail.com","threadId":"16515","inReplyTo":null,"subject":"[PATCH] git-cvsimport: add support for cvs pserver password scrambling.","fromName":"Dirk Hörner","fromEmail":"dirker@gmail.com","sentAt":"2008-11-28T18:06:40Z","receivedAt":"2008-11-28T18:06:40Z","isPatch":true,"sender":{"key":"dirker@gmail.com","avatar":null},"body":"Instead of a cleartext password, the CVS pserver expects a scrambled one\nin the authentication request. With this patch it is possible to import\nCVS repositories only accessible via pserver and user/password.\n\nSigned-off-by: Dirk Hoerner <dirker@gmail.com>\n---\n  git-cvsimport.perl |   39 ++++++++++++++++++++++++++++++++++++++-\n  1 files changed, 38 insertions(+), 1 deletions(-)\n\ndiff --git a/git-cvsimport.perl b/git-cvsimport.perl\nindex e439202..593832d 100755\n--- a/git-cvsimport.perl\n+++ b/git-cvsimport.perl\n@@ -252,7 +252,8 @@ sub conn {\n  \t\t\t\t}\n  \t\t\t};\n  \t\t}\n-\t\t$pass=\"A\" unless $pass;\n+\n+\t\t$pass = $self->_scramble($pass);\n\n  \t\tmy ($s, $rep);\n  \t\tif ($proxyhost) {\n@@ -484,6 +485,42 @@ sub _fetchfile {\n  \treturn $res;\n  }\n\n+sub _scramble {\n+\tmy ($self, $pass) = @_;\n+\tmy $scrambled = \"A\";\n+\n+\treturn $scrambled unless $pass;\n+\n+\tmy $pass_len = length($pass);\n+\tmy @pass_arr = split(\"\", $pass);\n+\tmy $i;\n+\n+\t# from cvs/src/scramble.c\n+\tmy @shifts = (\n+\t\t  0,  1,  2,  3,  4,  5,  6,  7,  8,  9, 10, 11, 12, 13, 14, 15,\n+\t\t 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31,\n+\t\t114,120, 53, 79, 96,109, 72,108, 70, 64, 76, 67,116, 74, 68, 87,\n+\t\t111, 52, 75,119, 49, 34, 82, 81, 95, 65,112, 86,118,110,122,105,\n+\t\t 41, 57, 83, 43, 46,102, 40, 89, 38,103, 45, 50, 42,123, 91, 35,\n+\t\t125, 55, 54, 66,124,126, 59, 47, 92, 71,115, 78, 88,107,106, 56,\n+\t\t 36,121,117,104,101,100, 69, 73, 99, 63, 94, 93, 39, 37, 61, 48,\n+\t\t 58,113, 32, 90, 44, 98, 60, 51, 33, 97, 62, 77, 84, 80, 85,223,\n+\t\t225,216,187,166,229,189,222,188,141,249,148,200,184,136,248,190,\n+\t\t199,170,181,204,138,232,218,183,255,234,220,247,213,203,226,193,\n+\t\t174,172,228,252,217,201,131,230,197,211,145,238,161,179,160,212,\n+\t\t207,221,254,173,202,146,224,151,140,196,205,130,135,133,143,246,\n+\t\t192,159,244,239,185,168,215,144,139,165,180,157,147,186,214,176,\n+\t\t227,231,219,169,175,156,206,198,129,164,150,210,154,177,134,127,\n+\t\t182,128,158,208,162,132,167,209,149,241,153,251,237,236,171,195,\n+\t\t243,233,253,240,194,250,191,155,142,137,245,235,163,242,178,152\n+\t);\n+\n+\tfor ($i = 0; $i < $pass_len; $i++) {\n+\t\t$scrambled .= pack(\"C\", $shifts[ord($pass_arr[$i])]);\n+\t}\n+\n+\treturn $scrambled;\n+}\n\n  package main;\n\n-- \n1.6.0.4.837.gae258\n"},{"id":"96840","messageId":"alpine.DEB.1.00.0812011442530.30769@pacific.mpi-cbg.de","threadId":"16515","inReplyTo":"5794AED2-43FF-4441-8292-0C9BFB3139A2@gmail.com","subject":"Re: [PATCH] git-cvsimport: add support for cvs pserver password scrambling.","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2008-12-01T13:43:16Z","receivedAt":"2008-12-01T13:43:16Z","isPatch":true,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi,\n\nOn Fri, 28 Nov 2008, Dirk Hörner wrote:\n\n> Instead of a cleartext password, the CVS pserver expects a scrambled one \n> in the authentication request. With this patch it is possible to import \n> CVS repositories only accessible via pserver and user/password.\n\nThe patch looks obvious enough; care to add a testcase?\n\nCiao,\nDscho"},{"id":"110973","messageId":"20090410093434.6117@nanako3.lavabit.com","threadId":"16515","inReplyTo":"5794AED2-43FF-4441-8292-0C9BFB3139A2@gmail.com","subject":"Re: [PATCH] git-cvsimport: add support for cvs pserver password scrambling.","fromName":"Nanako Shiraishi","fromEmail":"nanako3@lavabit.com","sentAt":"2009-04-10T00:34:34Z","receivedAt":"2009-04-10T00:34:34Z","isPatch":true,"sender":{"key":"nanako3@lavabit.com","avatar":"https://gravatar.com/avatar/3777b9e201c5883a62b1a6fdf7c53f2d712d1d80989146063ea861e33aad72a8?d=mp&s=160"},"body":"Quoting Dirk Hörner:\n\n> Instead of a cleartext password, the CVS pserver expects a scrambled one\n> in the authentication request. With this patch it is possible to import\n> CVS repositories only accessible via pserver and user/password.\n> \n> Signed-off-by: Dirk Hoerner <dirker@gmail.com>\n\nJunio, may I ask what happened to this patch?\n\n-- \nNanako Shiraishi\nhttp://ivory.ap.teacup.com/nanako3/\n"},{"id":"111097","messageId":"7vhc0udiac.fsf@gitster.siamese.dyndns.org","threadId":"16515","inReplyTo":"20090410093434.6117@nanako3.lavabit.com","subject":"Re: [PATCH] git-cvsimport: add support for cvs pserver password scrambling.","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2009-04-11T20:52:59Z","receivedAt":"2009-04-11T20:52:59Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Nanako Shiraishi <nanako3@lavabit.com> writes:\n\n> Quoting Dirk Hörner:\n>\n>> Instead of a cleartext password, the CVS pserver expects a scrambled one\n>> in the authentication request. With this patch it is possible to import\n>> CVS repositories only accessible via pserver and user/password.\n>> \n>> Signed-off-by: Dirk Hoerner <dirker@gmail.com>\n>\n> Junio, may I ask what happened to this patch?\n\nI do not use cvs emulation myself, nor pserver access, and I actually have\nbeen waiting for people who do use pserver access to report breakages and\npeople pointing this patch out.\n"},{"id":"120539","messageId":"alpine.DEB.1.00.0908131837110.7429@intel-tinevez-2-302","threadId":"16515","inReplyTo":"7vhc0udiac.fsf@gitster.siamese.dyndns.org","subject":"Re: [PATCH] git-cvsimport: add support for cvs pserver password scrambling.","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2009-08-13T16:43:55Z","receivedAt":"2009-08-13T16:43:55Z","isPatch":true,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi,\n\nOn Sat, 11 Apr 2009, Junio C Hamano wrote:\n\n> Nanako Shiraishi <nanako3@lavabit.com> writes:\n> \n> > Quoting Dirk Hörner:\n> >\n> >> Instead of a cleartext password, the CVS pserver expects a scrambled one\n> >> in the authentication request. With this patch it is possible to import\n> >> CVS repositories only accessible via pserver and user/password.\n> >> \n> >> Signed-off-by: Dirk Hoerner <dirker@gmail.com>\n> >\n> > Junio, may I ask what happened to this patch?\n> \n> I do not use cvs emulation myself, nor pserver access, and I actually have\n> been waiting for people who do use pserver access to report breakages and\n> people pointing this patch out.\n\nI really think it would be good if this patch was amended with a simple \nand quick test. Using the stdin/stdout server method, it should not be \nhard.\n\nCiao,\nDscho\n"},{"id":"120561","messageId":"4da546dc0908131219q149844abi453d8429847af1cf@mail.gmail.com","threadId":"16515","inReplyTo":"alpine.DEB.1.00.0908131837110.7429@intel-tinevez-2-302","subject":"Re: [PATCH] git-cvsimport: add support for cvs pserver password scrambling.","fromName":"Dirk Hörner","fromEmail":"dirker@gmail.com","sentAt":"2009-08-13T19:19:57Z","receivedAt":"2009-08-13T19:19:57Z","isPatch":true,"sender":{"key":"dirker@gmail.com","avatar":null},"body":"Hi all,\n\nsorry for the long delay, but I finally sat down, hacked two testcases\nand amended the patch after rebasing to the most recent HEAD. Find it\nattached to this mail.\n\nCiao,\nDirk\n\nOn Thu, Aug 13, 2009 at 6:43 PM, Johannes Schindelin\n<Johannes.Schindelin@gmx.de> wrote:\n>\n> Hi,\n>\n> On Sat, 11 Apr 2009, Junio C Hamano wrote:\n>\n> > Nanako Shiraishi <nanako3@lavabit.com> writes:\n> >\n> > > Quoting Dirk Hörner:\n> > >\n> > >> Instead of a cleartext password, the CVS pserver expects a scrambled one\n> > >> in the authentication request. With this patch it is possible to import\n> > >> CVS repositories only accessible via pserver and user/password.\n> > >>\n> > >> Signed-off-by: Dirk Hoerner <dirker@gmail.com>\n> > >\n> > > Junio, may I ask what happened to this patch?\n> >\n> > I do not use cvs emulation myself, nor pserver access, and I actually have\n> > been waiting for people who do use pserver access to report breakages and\n> > people pointing this patch out.\n>\n> I really think it would be good if this patch was amended with a simple\n> and quick test. Using the stdin/stdout server method, it should not be\n> hard.\n>\n> Ciao,\n> Dscho\n\n\nFrom 2f3deea40def04286f0483bd33a5756ac233838a Mon Sep 17 00:00:00 2001\nFrom: Dirk Hoerner <dirker@gmail.com>\nDate: Fri, 28 Nov 2008 19:11:38 +0200\nSubject: [PATCH] git-cvsimport: add support for cvs pserver password scrambling.\n\nInstead of a cleartext password, the CVS pserver expects a scrambled one\nin the authentication request. With this patch it is possible to import\nCVS repositories only accessible via pserver and user/password.\n\nSigned-off-by: Dirk Hoerner <dirker@gmail.com>\n---\n git-cvsimport.perl   |   39 ++++++++++++++++++++++++++++++++++++++-\n t/t9600-cvsimport.sh |   41 +++++++++++++++++++++++++++++++++++++++++\n 2 files changed, 79 insertions(+), 1 deletions(-)\n\ndiff --git a/git-cvsimport.perl b/git-cvsimport.perl\nindex e439202..593832d 100755\n--- a/git-cvsimport.perl\n+++ b/git-cvsimport.perl\n@@ -252,7 +252,8 @@ sub conn {\n \t\t\t\t}\n \t\t\t};\n \t\t}\n-\t\t$pass=\"A\" unless $pass;\n+\n+\t\t$pass = $self->_scramble($pass);\n \n \t\tmy ($s, $rep);\n \t\tif ($proxyhost) {\n@@ -484,6 +485,42 @@ sub _fetchfile {\n \treturn $res;\n }\n \n+sub _scramble {\n+\tmy ($self, $pass) = @_;\n+\tmy $scrambled = \"A\";\n+\n+\treturn $scrambled unless $pass;\n+\n+\tmy $pass_len = length($pass);\n+\tmy @pass_arr = split(\"\", $pass);\n+\tmy $i;\n+\n+\t# from cvs/src/scramble.c\n+\tmy @shifts = (\n+\t\t  0,  1,  2,  3,  4,  5,  6,  7,  8,  9, 10, 11, 12, 13, 14, 15,\n+\t\t 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31,\n+\t\t114,120, 53, 79, 96,109, 72,108, 70, 64, 76, 67,116, 74, 68, 87,\n+\t\t111, 52, 75,119, 49, 34, 82, 81, 95, 65,112, 86,118,110,122,105,\n+\t\t 41, 57, 83, 43, 46,102, 40, 89, 38,103, 45, 50, 42,123, 91, 35,\n+\t\t125, 55, 54, 66,124,126, 59, 47, 92, 71,115, 78, 88,107,106, 56,\n+\t\t 36,121,117,104,101,100, 69, 73, 99, 63, 94, 93, 39, 37, 61, 48,\n+\t\t 58,113, 32, 90, 44, 98, 60, 51, 33, 97, 62, 77, 84, 80, 85,223,\n+\t\t225,216,187,166,229,189,222,188,141,249,148,200,184,136,248,190,\n+\t\t199,170,181,204,138,232,218,183,255,234,220,247,213,203,226,193,\n+\t\t174,172,228,252,217,201,131,230,197,211,145,238,161,179,160,212,\n+\t\t207,221,254,173,202,146,224,151,140,196,205,130,135,133,143,246,\n+\t\t192,159,244,239,185,168,215,144,139,165,180,157,147,186,214,176,\n+\t\t227,231,219,169,175,156,206,198,129,164,150,210,154,177,134,127,\n+\t\t182,128,158,208,162,132,167,209,149,241,153,251,237,236,171,195,\n+\t\t243,233,253,240,194,250,191,155,142,137,245,235,163,242,178,152\n+\t);\n+\n+\tfor ($i = 0; $i < $pass_len; $i++) {\n+\t\t$scrambled .= pack(\"C\", $shifts[ord($pass_arr[$i])]);\n+\t}\n+\n+\treturn $scrambled;\n+}\n \n package main;\n \ndiff --git a/t/t9600-cvsimport.sh b/t/t9600-cvsimport.sh\nindex 363345f..57c0eac 100755\n--- a/t/t9600-cvsimport.sh\n+++ b/t/t9600-cvsimport.sh\n@@ -128,4 +128,45 @@ test_expect_success 'import from a CVS working tree' '\n \n test_expect_success 'test entire HEAD' 'test_cmp_branch_tree master'\n \n+if ! type nc >/dev/null 2>&1\n+then\n+\tsay 'skipping cvsimport pserver test, nc not found'\n+\ttest_done\n+\texit\n+fi\n+\n+cat << EOF >expected\n+BEGIN AUTH REQUEST\n+/cvs\n+me\n+AyuhedEIc?^]'%=0:q Z,b<3!a>\n+END AUTH REQUEST\n+EOF\n+\n+test_expect_success 'connect to pserver with password' '\n+\n+\techo \"I HATE YOU\" | nc -l 2401 >actual &\n+\ttest_must_fail git cvsimport -d \\\n+\t\t:pserver:me:abcdefghijklmnopqrstuvwxyz@localhost:/cvs foo \\\n+\t\t>/dev/null 2>&1 &&\n+\ttest_cmp expected actual\n+'\n+\n+cat << EOF >expected\n+BEGIN AUTH REQUEST\n+/cvs\n+anonymous\n+A\n+END AUTH REQUEST\n+EOF\n+\n+test_expect_success 'connect to pserver without password' '\n+\n+\techo \"I HATE YOU\" | nc -l 2401 >actual &\n+\ttest_must_fail git cvsimport -d \\\n+\t\t:pserver:anonymous@localhost:/cvs foo \\\n+\t\t>/dev/null 2>&1 &&\n+\ttest_cmp expected actual\n+'\n+\n test_done\n-- \n1.6.4\n\n"},{"id":"120571","messageId":"fabb9a1e0908131304m53ab2a68p9faade35969add5@mail.gmail.com","threadId":"16515","inReplyTo":"4da546dc0908131219q149844abi453d8429847af1cf@mail.gmail.com","subject":"Re: [PATCH] git-cvsimport: add support for cvs pserver password scrambling.","fromName":"Sverre Rabbelier","fromEmail":"srabbelier@gmail.com","sentAt":"2009-08-13T20:04:58Z","receivedAt":"2009-08-13T20:04:58Z","isPatch":true,"sender":{"key":"srabbelier@gmail.com","avatar":"https://avatars.githubusercontent.com/u/3098?v=4"},"body":"Heya,\n\n2009/8/13 Dirk Hörner <dirker@gmail.com>:\n> sorry for the long delay, but I finally sat down, hacked two testcases\n> and amended the patch after rebasing to the most recent HEAD. Find it\n> attached to this mail.\n\nI think we'd rather find it inlined, as per SubmittingPatches ;).\n\n-- \nCheers,\n\nSverre Rabbelier\n"},{"id":"120606","messageId":"4da546dc0908132317t656f503ah5adc6e0cd09f0288@mail.gmail.com","threadId":"16515","inReplyTo":"fabb9a1e0908131304m53ab2a68p9faade35969add5@mail.gmail.com","subject":"Re: [PATCH] git-cvsimport: add support for cvs pserver password scrambling.","fromName":"Dirk Hörner","fromEmail":"dirker@gmail.com","sentAt":"2009-08-14T06:17:17Z","receivedAt":"2009-08-14T06:17:17Z","isPatch":true,"sender":{"key":"dirker@gmail.com","avatar":null},"body":"Hi Sverre,\n\nthanks for the heads up, I will resend it in a minute.\n\nCiao,\nDirk\n\n2009/8/13 Sverre Rabbelier <srabbelier@gmail.com>:\n> Heya,\n>\n> 2009/8/13 Dirk Hörner <dirker@gmail.com>:\n>> sorry for the long delay, but I finally sat down, hacked two testcases\n>> and amended the patch after rebasing to the most recent HEAD. Find it\n>> attached to this mail.\n>\n> I think we'd rather find it inlined, as per SubmittingPatches ;).\n>\n> --\n> Cheers,\n>\n> Sverre Rabbelier\n>\n"}]}