{"thread":{"id":"20592","subject":"[PATCH v2] git-cvsimport: add support for cvs pserver password scrambling.","startedAt":"2009-08-14T06:58:31Z","lastAt":"2009-08-14T09:46:19Z","messageCount":3,"participants":["Dirk Hoerner","Junio C Hamano","Dirk Hörner"],"isPatch":true,"patchVersion":2,"patchTotal":null},"messages":[{"id":"120614","messageId":"1250233111-19188-1-git-send-email-dirker@gmail.com","threadId":"20592","inReplyTo":null,"subject":"[PATCH v2] git-cvsimport: add support for cvs pserver password scrambling.","fromName":"Dirk Hoerner","fromEmail":"dirker@gmail.com","sentAt":"2009-08-14T06:58:31Z","receivedAt":"2009-08-14T06:58:31Z","isPatch":true,"sender":{"key":"dirker@gmail.com","avatar":null},"body":"Instead of a cleartext password, the CVS pserver expects a scrambled one\nin the authentication request. With this patch it is possible to import\nCVS repositories only accessible via pserver and user/password.\n\nSigned-off-by: Dirk Hoerner <dirker@gmail.com>\n---\n git-cvsimport.perl   |   39 ++++++++++++++++++++++++++++++++++++++-\n t/t9600-cvsimport.sh |   41 +++++++++++++++++++++++++++++++++++++++++\n 2 files changed, 79 insertions(+), 1 deletions(-)\n\ndiff --git a/git-cvsimport.perl b/git-cvsimport.perl\nindex e439202..593832d 100755\n--- a/git-cvsimport.perl\n+++ b/git-cvsimport.perl\n@@ -252,7 +252,8 @@ sub conn {\n \t\t\t\t}\n \t\t\t};\n \t\t}\n-\t\t$pass=\"A\" unless $pass;\n+\n+\t\t$pass = $self->_scramble($pass);\n \n \t\tmy ($s, $rep);\n \t\tif ($proxyhost) {\n@@ -484,6 +485,42 @@ sub _fetchfile {\n \treturn $res;\n }\n \n+sub _scramble {\n+\tmy ($self, $pass) = @_;\n+\tmy $scrambled = \"A\";\n+\n+\treturn $scrambled unless $pass;\n+\n+\tmy $pass_len = length($pass);\n+\tmy @pass_arr = split(\"\", $pass);\n+\tmy $i;\n+\n+\t# from cvs/src/scramble.c\n+\tmy @shifts = (\n+\t\t  0,  1,  2,  3,  4,  5,  6,  7,  8,  9, 10, 11, 12, 13, 14, 15,\n+\t\t 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31,\n+\t\t114,120, 53, 79, 96,109, 72,108, 70, 64, 76, 67,116, 74, 68, 87,\n+\t\t111, 52, 75,119, 49, 34, 82, 81, 95, 65,112, 86,118,110,122,105,\n+\t\t 41, 57, 83, 43, 46,102, 40, 89, 38,103, 45, 50, 42,123, 91, 35,\n+\t\t125, 55, 54, 66,124,126, 59, 47, 92, 71,115, 78, 88,107,106, 56,\n+\t\t 36,121,117,104,101,100, 69, 73, 99, 63, 94, 93, 39, 37, 61, 48,\n+\t\t 58,113, 32, 90, 44, 98, 60, 51, 33, 97, 62, 77, 84, 80, 85,223,\n+\t\t225,216,187,166,229,189,222,188,141,249,148,200,184,136,248,190,\n+\t\t199,170,181,204,138,232,218,183,255,234,220,247,213,203,226,193,\n+\t\t174,172,228,252,217,201,131,230,197,211,145,238,161,179,160,212,\n+\t\t207,221,254,173,202,146,224,151,140,196,205,130,135,133,143,246,\n+\t\t192,159,244,239,185,168,215,144,139,165,180,157,147,186,214,176,\n+\t\t227,231,219,169,175,156,206,198,129,164,150,210,154,177,134,127,\n+\t\t182,128,158,208,162,132,167,209,149,241,153,251,237,236,171,195,\n+\t\t243,233,253,240,194,250,191,155,142,137,245,235,163,242,178,152\n+\t);\n+\n+\tfor ($i = 0; $i < $pass_len; $i++) {\n+\t\t$scrambled .= pack(\"C\", $shifts[ord($pass_arr[$i])]);\n+\t}\n+\n+\treturn $scrambled;\n+}\n \n package main;\n \ndiff --git a/t/t9600-cvsimport.sh b/t/t9600-cvsimport.sh\nindex 363345f..57c0eac 100755\n--- a/t/t9600-cvsimport.sh\n+++ b/t/t9600-cvsimport.sh\n@@ -128,4 +128,45 @@ test_expect_success 'import from a CVS working tree' '\n \n test_expect_success 'test entire HEAD' 'test_cmp_branch_tree master'\n \n+if ! type nc >/dev/null 2>&1\n+then\n+\tsay 'skipping cvsimport pserver test, nc not found'\n+\ttest_done\n+\texit\n+fi\n+\n+cat << EOF >expected\n+BEGIN AUTH REQUEST\n+/cvs\n+me\n+AyuhedEIc?^]'%=0:q Z,b<3!a>\n+END AUTH REQUEST\n+EOF\n+\n+test_expect_success 'connect to pserver with password' '\n+\n+\techo \"I HATE YOU\" | nc -l 2401 >actual &\n+\ttest_must_fail git cvsimport -d \\\n+\t\t:pserver:me:abcdefghijklmnopqrstuvwxyz@localhost:/cvs foo \\\n+\t\t>/dev/null 2>&1 &&\n+\ttest_cmp expected actual\n+'\n+\n+cat << EOF >expected\n+BEGIN AUTH REQUEST\n+/cvs\n+anonymous\n+A\n+END AUTH REQUEST\n+EOF\n+\n+test_expect_success 'connect to pserver without password' '\n+\n+\techo \"I HATE YOU\" | nc -l 2401 >actual &\n+\ttest_must_fail git cvsimport -d \\\n+\t\t:pserver:anonymous@localhost:/cvs foo \\\n+\t\t>/dev/null 2>&1 &&\n+\ttest_cmp expected actual\n+'\n+\n test_done\n-- \n1.6.4\n"},{"id":"120619","messageId":"7vskfusvpq.fsf@alter.siamese.dyndns.org","threadId":"20592","inReplyTo":"1250233111-19188-1-git-send-email-dirker@gmail.com","subject":"Re: [PATCH v2] git-cvsimport: add support for cvs pserver password scrambling.","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2009-08-14T07:25:37Z","receivedAt":"2009-08-14T07:25:37Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Dirk Hoerner <dirker@gmail.com> writes:\n\n> Instead of a cleartext password, the CVS pserver expects a scrambled one\n> in the authentication request. With this patch it is possible to import\n> CVS repositories only accessible via pserver and user/password.\n>\n> Signed-off-by: Dirk Hoerner <dirker@gmail.com>\n\nThanks.\n\nWhile I appreciate your effort to add a test, I'd rather not apply the\ntest part of your patch for two reasons:\n\n - It is not a test against a real cvs pserver but is a whitebox test to\n   verify that the program says what the program is supposed to spit out\n   to the network; and\n\n - It still is a network test that will fail if the TCP port is occupied\n   for whatever reason when the test is run, which will make automated\n   build and test cycle unreliable.\n\nUnfortunately, I do not see an easy way to run a real cvs pserver\nlistening to a local unix domain socket under $TRASH_DIRECTORY, which\nwould solve both of the above issues.\n"},{"id":"120629","messageId":"4da546dc0908140246i35b28052wd7b7790d191a9984@mail.gmail.com","threadId":"20592","inReplyTo":"7vskfusvpq.fsf@alter.siamese.dyndns.org","subject":"Re: [PATCH v2] git-cvsimport: add support for cvs pserver password scrambling.","fromName":"Dirk Hörner","fromEmail":"dirker@gmail.com","sentAt":"2009-08-14T09:46:19Z","receivedAt":"2009-08-14T09:46:19Z","isPatch":true,"sender":{"key":"dirker@gmail.com","avatar":null},"body":"Hi Junio,\n\nOn Fri, Aug 14, 2009 at 9:25 AM, Junio C Hamano<gitster@pobox.com> wrote:\n> Thanks.\n>\n> While I appreciate your effort to add a test, I'd rather not apply the\n> test part of your patch for two reasons:\n>\n>  - It is not a test against a real cvs pserver but is a whitebox test to\n>   verify that the program says what the program is supposed to spit out\n>   to the network; and\n>\n>  - It still is a network test that will fail if the TCP port is occupied\n>   for whatever reason when the test is run, which will make automated\n>   build and test cycle unreliable.\n>\n> Unfortunately, I do not see an easy way to run a real cvs pserver\n> listening to a local unix domain socket under $TRASH_DIRECTORY, which\n> would solve both of the above issues.\n>\n\nI agree with you, the tests are not the best. As Dscho stated in one\nof the replies to the last version of this patch, the cvs pserver is\nquite good to test with because it uses stdin/stdout for\ncommunication. The main problem is git-cvsimport, which right now only\nsupports tcp sockets.\n\nCiao,\nDirk\n"}]}