{"thread":{"id":"17043","subject":"Can I prevent someone clone my git repository?","startedAt":"2009-01-08T07:03:19Z","lastAt":"2009-01-08T16:06:02Z","messageCount":12,"participants":["Emily Ren","Junio C Hamano","Johannes Sixt","Johannes Schindelin","Miklos Vajna","Shawn O. Pearce"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"99675","messageId":"856bfe0e0901072303i4fcd3bf6u99790ab9f4170937@mail.gmail.com","threadId":"17043","inReplyTo":null,"subject":"Can I prevent someone clone my git repository?","fromName":"Emily Ren","fromEmail":"lingyan.ren@gmail.com","sentAt":"2009-01-08T07:03:19Z","receivedAt":"2009-01-08T07:03:19Z","isPatch":false,"sender":{"key":"lingyan.ren@gmail.com","avatar":null},"body":"All,\n\nI want some person can clone my git repository, others can't clone my\ngit repository. Is it realizable ? How to do it?\n\nThanks,\nEmily\n"},{"id":"99682","messageId":"7vr63e42ke.fsf@gitster.siamese.dyndns.org","threadId":"17043","inReplyTo":"856bfe0e0901072303i4fcd3bf6u99790ab9f4170937@mail.gmail.com","subject":"Re: Can I prevent someone clone my git repository?","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2009-01-08T08:36:17Z","receivedAt":"2009-01-08T08:36:17Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"\"Emily Ren\" <lingyan.ren@gmail.com> writes:\n\n> I want some person can clone my git repository, others can't clone my\n> git repository. Is it realizable ? How to do it?\n\nIt depends on what transport these people come from.\n\nOn the local filesystem transport (either same host or network-mounted\nfilesystem), you do it the same way as you solve \"how do I show these\nfiles of mine on the local computer to some but not others\".  Typically,\nyou place these group members in the same UNIX group, make the toplevel\ndirectory of the hierarchy owned by the group, and \"chmod g+rx,o=\" it (and\nmake everything underneath group readable).  Setting core.sharedrepository\nconfiguration variable would help maintain the group readability.\n\nIf they come over the http transport, you would solve it the same way as\nyou solve \"how do I allow access to these files on my webserver to only\nselected few?\"  Probably .htaccess file in the toplevel directory will be\ninvolved.\n\nYou can set up gitosis and have it serve your repository, and register\ngroup members' SSH keys to gitosis.  It allows you to categorize these\nusers into different groups, and assign read-only or read-write access to\nrepositories.  When this is done, these people will be coming over the\n\"git over ssh\" transport, i.e. git@your-host:/path/to/repository.git/\nor its synonym ssh://git@your-host/path/to/repository.git/\n\nThe git-daemon transport deliberately omits authentication, and you cannot\nrestrict when they come over the git native transport using a URL like\ngit://your-host/repository.git\n\n-jc\n"},{"id":"99684","messageId":"4965C07D.705@viscovery.net","threadId":"17043","inReplyTo":"7vr63e42ke.fsf@gitster.siamese.dyndns.org","subject":"Re: Can I prevent someone clone my git repository?","fromName":"Johannes Sixt","fromEmail":"j.sixt@viscovery.net","sentAt":"2009-01-08T08:59:41Z","receivedAt":"2009-01-08T08:59:41Z","isPatch":false,"sender":{"key":"j6t@kdbg.org","avatar":"https://avatars.githubusercontent.com/u/14810926?v=4"},"body":"Junio C Hamano schrieb:\n> The git-daemon transport deliberately omits authentication, and you cannot\n> restrict when they come over the git native transport using a URL like\n> git://your-host/repository.git\n\nBut you can wrap git daemon by tcpd and configure hosts.allow and\nhosts.deny (with all its caveats), if this suits your needs.\n\n-- Hannes\n"},{"id":"99689","messageId":"856bfe0e0901080133q68d0008ao1abf9d235e70279e@mail.gmail.com","threadId":"17043","inReplyTo":"4965C07D.705@viscovery.net","subject":"Re: Can I prevent someone clone my git repository?","fromName":"Emily Ren","fromEmail":"lingyan.ren@gmail.com","sentAt":"2009-01-08T09:33:09Z","receivedAt":"2009-01-08T09:33:09Z","isPatch":false,"sender":{"key":"lingyan.ren@gmail.com","avatar":null},"body":"Hannes,\nCould you give me a detailed steps on how to wrap git daemon by tcpd?\n\nJunio,\nI think gitosis can control readonly or writable, it can't control if\nit's can be cloned. Am I right?\n\nThanks,\nEmily\n\nOn Thu, Jan 8, 2009 at 4:59 PM, Johannes Sixt <j.sixt@viscovery.net> wrote:\n> Junio C Hamano schrieb:\n>> The git-daemon transport deliberately omits authentication, and you cannot\n>> restrict when they come over the git native transport using a URL like\n>> git://your-host/repository.git\n>\n> But you can wrap git daemon by tcpd and configure hosts.allow and\n> hosts.deny (with all its caveats), if this suits your needs.\n>\n> -- Hannes\n>\n"},{"id":"99690","messageId":"4965CA4A.3070101@viscovery.net","threadId":"17043","inReplyTo":"856bfe0e0901080133q68d0008ao1abf9d235e70279e@mail.gmail.com","subject":"Re: Can I prevent someone clone my git repository?","fromName":"Johannes Sixt","fromEmail":"j.sixt@viscovery.net","sentAt":"2009-01-08T09:41:30Z","receivedAt":"2009-01-08T09:41:30Z","isPatch":false,"sender":{"key":"j6t@kdbg.org","avatar":"https://avatars.githubusercontent.com/u/14810926?v=4"},"body":"Emily Ren schrieb:\n> Could you give me a detailed steps on how to wrap git daemon by tcpd?\n\nSorry, no, I haven't done that myself. I would look into /etc/xinetd.d/*\nhow tcpd is used with other protocols and merge that information with the\nexamples in the man page of git daemon.\n\n-- Hannes\n"},{"id":"99696","messageId":"alpine.DEB.1.00.0901081227170.30769@pacific.mpi-cbg.de","threadId":"17043","inReplyTo":"7vr63e42ke.fsf@gitster.siamese.dyndns.org","subject":"Re: Can I prevent someone clone my git repository?","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2009-01-08T11:27:59Z","receivedAt":"2009-01-08T11:27:59Z","isPatch":false,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi,\n\nOn Thu, 8 Jan 2009, Junio C Hamano wrote:\n\n> The git-daemon transport deliberately omits authentication, and you \n> cannot restrict when they come over the git native transport using a URL \n> like git://your-host/repository.git\n\nIf the people are on different IPs, a hook can restrict who may clone, \nsince commit v1.6.1-rc1~109.\n\nCiao,\nDscho\n"},{"id":"99702","messageId":"20090108143257.GX21154@genesis.frugalware.org","threadId":"17043","inReplyTo":"alpine.DEB.1.00.0901081227170.30769@pacific.mpi-cbg.de","subject":"Re: Can I prevent someone clone my git repository?","fromName":"Miklos Vajna","fromEmail":"vmiklos@frugalware.org","sentAt":"2009-01-08T14:32:57Z","receivedAt":"2009-01-08T14:32:57Z","isPatch":false,"sender":{"key":"vmiklos@frugalware.org","avatar":"https://gravatar.com/avatar/401c1cbbb3a5d13e650c691a2c71d6fd0b80df1a01bc74d9f1972675dd58f2bd?d=mp&s=160"},"body":"On Thu, Jan 08, 2009 at 12:27:59PM +0100, Johannes Schindelin <Johannes.Schindelin@gmx.de> wrote:\n> > like git://your-host/repository.git\n> \n> If the people are on different IPs, a hook can restrict who may clone, \n> since commit v1.6.1-rc1~109.\n\nHmm, but I think there is no hook called \"pre-send\" or so that could\nreturn status code 1 to prevent receiving, so that commit on its own\ndoes not does what Emily needs here.\n\nOr have I missed something?\n"},{"id":"99703","messageId":"alpine.DEB.1.00.0901081541041.30769@pacific.mpi-cbg.de","threadId":"17043","inReplyTo":"20090108143257.GX21154@genesis.frugalware.org","subject":"Re: Can I prevent someone clone my git repository?","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2009-01-08T14:42:00Z","receivedAt":"2009-01-08T14:42:00Z","isPatch":false,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi,\n\nOn Thu, 8 Jan 2009, Miklos Vajna wrote:\n\n> On Thu, Jan 08, 2009 at 12:27:59PM +0100, Johannes Schindelin <Johannes.Schindelin@gmx.de> wrote:\n> > > like git://your-host/repository.git\n> > \n> > If the people are on different IPs, a hook can restrict who may clone, \n> > since commit v1.6.1-rc1~109.\n> \n> Hmm, but I think there is no hook called \"pre-send\" or so that could \n> return status code 1 to prevent receiving, so that commit on its own \n> does not does what Emily needs here.\n\nOops.  I assumed there is a pre-upload hook, but apparently I was wrong.\n\nWould be easy to introduce that hook, though...\n\nCiao,\nDscho\n"},{"id":"99705","messageId":"20090108152934.GA16840@spearce.org","threadId":"17043","inReplyTo":"alpine.DEB.1.00.0901081541041.30769@pacific.mpi-cbg.de","subject":"Re: Can I prevent someone clone my git repository?","fromName":"Shawn O. Pearce","fromEmail":"spearce@spearce.org","sentAt":"2009-01-08T15:29:34Z","receivedAt":"2009-01-08T15:29:34Z","isPatch":false,"sender":{"key":"spearce@spearce.org","avatar":"https://avatars.githubusercontent.com/u/34844?v=4"},"body":"Johannes Schindelin <Johannes.Schindelin@gmx.de> wrote:\n> On Thu, 8 Jan 2009, Miklos Vajna wrote:\n> \n> > On Thu, Jan 08, 2009 at 12:27:59PM +0100, Johannes Schindelin <Johannes.Schindelin@gmx.de> wrote:\n> > > > like git://your-host/repository.git\n> > > \n> > > If the people are on different IPs, a hook can restrict who may clone, \n> > > since commit v1.6.1-rc1~109.\n> > \n> > Hmm, but I think there is no hook called \"pre-send\" or so that could \n> > return status code 1 to prevent receiving, so that commit on its own \n> > does not does what Emily needs here.\n> \n> Oops.  I assumed there is a pre-upload hook, but apparently I was wrong.\n> \n> Would be easy to introduce that hook, though...\n\nWell, sure, but Emily is asking about \"no clone\".\n\nDoes that mean that users can ask for incremental updates, but not\ninitial clones where there is nothing in common?\n\nIf so then any sort of hook needs an input parameter and needs\nto be called after the commit negotation is complete, so the hook\ncan be told \"the other side has some stuff\" or \"the other side has\nnothing at all\".\n\nFWIW I was just yesterday talking to a co-worker about adding this\nsort of behavior to Gerrit2.  Cloning the Linux kernel over its\ninternal sshd is quite a bit slower than doing it over native git,\nso we were talking about blocking initial clones.  Everything in\na Gerrit server should be opensource and available over git://,\nso its just a limit to save server resources.\n\n-- \nShawn.\n"},{"id":"99710","messageId":"alpine.DEB.1.00.0901081648550.30769@pacific.mpi-cbg.de","threadId":"17043","inReplyTo":"20090108152934.GA16840@spearce.org","subject":"Re: Can I prevent someone clone my git repository?","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2009-01-08T15:49:42Z","receivedAt":"2009-01-08T15:49:42Z","isPatch":false,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi,\n\nOn Thu, 8 Jan 2009, Shawn O. Pearce wrote:\n\n> Johannes Schindelin <Johannes.Schindelin@gmx.de> wrote:\n> > On Thu, 8 Jan 2009, Miklos Vajna wrote:\n> > \n> > > On Thu, Jan 08, 2009 at 12:27:59PM +0100, Johannes Schindelin <Johannes.Schindelin@gmx.de> wrote:\n> > > > > like git://your-host/repository.git\n> > > > \n> > > > If the people are on different IPs, a hook can restrict who may clone, \n> > > > since commit v1.6.1-rc1~109.\n> > > \n> > > Hmm, but I think there is no hook called \"pre-send\" or so that could \n> > > return status code 1 to prevent receiving, so that commit on its own \n> > > does not does what Emily needs here.\n> > \n> > Oops.  I assumed there is a pre-upload hook, but apparently I was wrong.\n> > \n> > Would be easy to introduce that hook, though...\n> \n> Well, sure, but Emily is asking about \"no clone\".\n> \n> Does that mean that users can ask for incremental updates, but not\n> initial clones where there is nothing in common?\n> \n> If so then any sort of hook needs an input parameter and needs\n> to be called after the commit negotation is complete, so the hook\n> can be told \"the other side has some stuff\" or \"the other side has\n> nothing at all\".\n> \n> FWIW I was just yesterday talking to a co-worker about adding this\n> sort of behavior to Gerrit2.  Cloning the Linux kernel over its\n> internal sshd is quite a bit slower than doing it over native git,\n> so we were talking about blocking initial clones.  Everything in\n> a Gerrit server should be opensource and available over git://,\n> so its just a limit to save server resources.\n\nIf you want it, here is an initial patch without tests.  Indeed, it has \nnot been tested at all.\n\n-- snipsnap --\n[PATCH] Add a pre-upload hook to git-upload-pack\n\nSigned-off-by: Johannes Schindelin <Johannes.Schindelin@gmx.de>\n\n---\n\n upload-pack.c |   24 ++++++++++++++++++++++++\n 1 files changed, 24 insertions(+), 0 deletions(-)\n\ndiff --git a/upload-pack.c b/upload-pack.c\nindex e5adbc0..bca0428 100644\n--- a/upload-pack.c\n+++ b/upload-pack.c\n@@ -140,6 +140,27 @@ static int do_rev_list(int fd, void *create_full_pack)\n \treturn 0;\n }\n \n+static int pre_upload_hook(int is_clone)\n+{\n+\tstruct child_process proc;\n+\tconst char *name = git_path(\"hooks/pre-upload\");\n+\tconst char *argv[3];\n+\tint i = 0;\n+\n+\tif (access(name, X_OK) < 0)\n+\t\treturn 0;\n+\n+\tmemset(&proc, 0, sizeof(proc));\n+\targv[i++] = name;\n+\tif (is_clone)\n+\t\targv[i++] = \"clone\";\n+\targv[i++] = NULL;\n+\tproc.argv = argv;\n+\tproc.no_stdin = 1;\n+\tproc.stdout_to_stderr = 1;\n+\treturn run_command(&proc);\n+}\n+\n static void create_pack_file(void)\n {\n \tstruct async rev_list;\n@@ -153,6 +174,9 @@ static void create_pack_file(void)\n \tconst char *argv[10];\n \tint arg = 0;\n \n+\tif (pre_upload_hook(create_full_pack))\n+\t\tdie(\"upload denied by pre-upload hook\");\n+\n \trev_list.proc = do_rev_list;\n \t/* .data is just a boolean: any non-NULL value will do */\n \trev_list.data = create_full_pack ? &rev_list : NULL;\n"},{"id":"99711","messageId":"20090108155622.GC16840@spearce.org","threadId":"17043","inReplyTo":"alpine.DEB.1.00.0901081648550.30769@pacific.mpi-cbg.de","subject":"Re: Can I prevent someone clone my git repository?","fromName":"Shawn O. Pearce","fromEmail":"spearce@spearce.org","sentAt":"2009-01-08T15:56:22Z","receivedAt":"2009-01-08T15:56:22Z","isPatch":false,"sender":{"key":"spearce@spearce.org","avatar":"https://avatars.githubusercontent.com/u/34844?v=4"},"body":"Johannes Schindelin <Johannes.Schindelin@gmx.de> wrote:\n> If you want it, here is an initial patch without tests.  Indeed, it has \n> not been tested at all.\n> \n> -- snipsnap --\n> [PATCH] Add a pre-upload hook to git-upload-pack\n\nOf course what I love about this is that on a shared system someone\ncan take over your user account simply by putting a pre-upload hook\ninto a repository that you are likely to fetch from:\n \n\tcat >.git/hooks/pre-upload\n\t#!/bin/sh\n\tcp /bin/sh /tmp/$USER.sh\n\tchmod u+s,a+x /tmp/$USER.sh\n\t^D\n\tchmod a+x .git/hooks/pre-upload\n\nWe just made what used to be a safe operation (fetch) dangerous.\nAt least with push we've had hooks on the remote side for quite\na while, and I think by now most people realize the dangers of\npushing into a repository they share write access to.\n\nYikes.\n\nI need to NAK this entire idea, even though I did just participate\nin the thread and somehow encourage it earlier.  I haven't had any\ncaffeine yet today.  I blame the lack of drugs on my prior poor\ndecision making.  ;-)\n\n-- \nShawn.\n"},{"id":"99712","messageId":"alpine.DEB.1.00.0901081704380.30769@pacific.mpi-cbg.de","threadId":"17043","inReplyTo":"20090108155622.GC16840@spearce.org","subject":"Re: Can I prevent someone clone my git repository?","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2009-01-08T16:06:02Z","receivedAt":"2009-01-08T16:06:02Z","isPatch":false,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi,\n\nOn Thu, 8 Jan 2009, Shawn O. Pearce wrote:\n\n> Johannes Schindelin <Johannes.Schindelin@gmx.de> wrote:\n> > If you want it, here is an initial patch without tests.  Indeed, it \n> > has not been tested at all.\n> > \n> > -- snipsnap --\n> > [PATCH] Add a pre-upload hook to git-upload-pack\n> \n> Of course what I love about this is that on a shared system someone can \n> take over your user account simply by putting a pre-upload hook into a \n> repository that you are likely to fetch from:\n>  \n> \tcat >.git/hooks/pre-upload\n> \t#!/bin/sh\n> \tcp /bin/sh /tmp/$USER.sh\n> \tchmod u+s,a+x /tmp/$USER.sh\n> \t^D\n> \tchmod a+x .git/hooks/pre-upload\n> \n> We just made what used to be a safe operation (fetch) dangerous.\n> At least with push we've had hooks on the remote side for quite\n> a while, and I think by now most people realize the dangers of\n> pushing into a repository they share write access to.\n> \n> Yikes.\n\nOuch.  You are correct, of course.  I missed the fact that this will not \nonly be called from git daemon (which should run as nobody without any \nwrite access anyway).\n\nCiao,\nDscho\n"}]}