{"thread":{"id":"22027","subject":"Does smart-http need git-daemon-export-ok?","startedAt":"2009-12-26T16:21:23Z","lastAt":"2009-12-29T15:00:16Z","messageCount":14,"participants":["Tarmigan","Junio C Hamano","Tarmigan Casebolt","Shawn O. Pearce"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"130347","messageId":"905315640912260821k2fb149b3je69dbea5463afaa3@mail.gmail.com","threadId":"22027","inReplyTo":null,"subject":"Does smart-http need git-daemon-export-ok?","fromName":"Tarmigan","fromEmail":"tarmigan+git@gmail.com","sentAt":"2009-12-26T16:21:23Z","receivedAt":"2009-12-26T16:21:23Z","isPatch":false,"sender":{"key":"tarmigan+git@gmail.com","avatar":null},"body":"Hi all,\n\nShould the git-http-backend check something like git-daemon-export-ok\nbefore serving a repository?  It would have been better to discuss\nthis a month or two ago, but it's probably not too late since\nsmart-http is still so new in released versions.\n\nI think it's very similar to git-daemon which requires that to be set,\nand I think the same arguments could be made for the same kind of\ncheck.  There are already parallels for the upload-pack and\nreceive-pack services between the two.\n\nJust as git-daemon may be invoked with --export-all, for\ngit-http-backend we could have an environmental variable to export all\nrepositories.\n\nThoughts?\n\nThanks,\nTarmigan\n"},{"id":"130350","messageId":"7vk4w963np.fsf@alter.siamese.dyndns.org","threadId":"22027","inReplyTo":"905315640912260821k2fb149b3je69dbea5463afaa3@mail.gmail.com","subject":"Re: Does smart-http need git-daemon-export-ok?","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2009-12-26T17:33:46Z","receivedAt":"2009-12-26T17:33:46Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Tarmigan <tarmigan+git@gmail.com> writes:\n\n> Should the git-http-backend check something like git-daemon-export-ok\n> before serving a repository?\n\nI'd agree that it would make sense to have a way to mark individual\nrepository for (or not for) export.\n\nIn \"native\" case, the chain of events are: client talks to the daemon, the\ndaemon checks and decides to (or not to) export, and it runs upload-pack.\n\nIn \"smart http\" case, http-backend is one half of what corresponds to the\ndaemon (the other half being your http server configuration), and it is\nmore flexible and git specific half, so I'd say it would make sense to\nimplement the check that honors the same git-daemon-export-ok flag file in\nit.\n"},{"id":"130354","messageId":"1261870153-57572-1-git-send-email-tarmigan+git@gmail.com","threadId":"22027","inReplyTo":"7vk4w963np.fsf@alter.siamese.dyndns.org","subject":"[PATCH 1/2] Smart-http: Add tests and documentation for export-ok","fromName":"Tarmigan Casebolt","fromEmail":"tarmigan+git@gmail.com","sentAt":"2009-12-26T23:29:12Z","receivedAt":"2009-12-26T23:29:12Z","isPatch":true,"sender":{"key":"tarmigan+git@gmail.com","avatar":null},"body":"Add some tests for having smart-http check whether a repository is ok\nto export.  Add tests for the GIT_HTTP_EXPORT_ALL environmental\nvariable and checking the git-daemon-export-ok file, while leaving\nexisting tests still functional.\n\nSigned-off-by: Tarmigan Casebolt <tarmigan+git@gmail.com>\n---\n Documentation/git-http-backend.txt |   10 +++++++++\n t/lib-httpd/apache.conf            |    5 ++++\n t/t5560-http-backend.sh            |   39 ++++++++++++++++++++++++++++++++++-\n 3 files changed, 52 insertions(+), 2 deletions(-)\n\ndiff --git a/Documentation/git-http-backend.txt b/Documentation/git-http-backend.txt\nindex 67aec06..c8fe08a 100644\n--- a/Documentation/git-http-backend.txt\n+++ b/Documentation/git-http-backend.txt\n@@ -18,6 +18,11 @@ The program supports clients fetching using both the smart HTTP protcol\n and the backwards-compatible dumb HTTP protocol, as well as clients\n pushing using the smart HTTP protocol.\n \n+It verifies that the directory has the magic file\n+\"git-daemon-export-ok\", and it will refuse to export any git directory\n+that hasn't explicitly been marked for export this way (unless the\n+GIT_HTTP_EXPORT_ALL environmental variable is set).\n+\n By default, only the `upload-pack` service is enabled, which serves\n 'git-fetch-pack' and 'git-ls-remote' clients, which are invoked from\n 'git-fetch', 'git-pull', and 'git-clone'.  If the client is authenticated,\n@@ -70,6 +75,7 @@ Apache 2.x::\n +\n ----------------------------------------------------------------\n SetEnv GIT_PROJECT_ROOT /var/www/git\n+SetEnv GIT_HTTP_EXPORT_ALL\n ScriptAlias /git/ /usr/libexec/git-core/git-http-backend/\n ----------------------------------------------------------------\n +\n@@ -157,6 +163,10 @@ by the invoking web server, including:\n * QUERY_STRING\n * REQUEST_METHOD\n \n+The GIT_HTTP_EXPORT_ALL environmental variable may be passed to\n+'git-http-backend' to bypass the check for the \"git-daemon-export-ok\"\n+file in each repository before allowing export of that repository.\n+\n The backend process sets GIT_COMMITTER_NAME to '$REMOTE_USER' and\n GIT_COMMITTER_EMAIL to '$\\{REMOTE_USER}@http.$\\{REMOTE_ADDR\\}',\n ensuring that any reflogs created by 'git-receive-pack' contain some\ndiff --git a/t/lib-httpd/apache.conf b/t/lib-httpd/apache.conf\nindex 0fe3fd0..4961505 100644\n--- a/t/lib-httpd/apache.conf\n+++ b/t/lib-httpd/apache.conf\n@@ -22,8 +22,13 @@ Alias /dumb/ www/\n \n <Location /smart/>\n \tSetEnv GIT_EXEC_PATH ${GIT_EXEC_PATH}\n+\tSetEnv GIT_HTTP_EXPORT_ALL\n+</Location>\n+<Location /smart_noexport/>\n+\tSetEnv GIT_EXEC_PATH ${GIT_EXEC_PATH}\n </Location>\n ScriptAlias /smart/ ${GIT_EXEC_PATH}/git-http-backend/\n+ScriptAlias /smart_noexport/ ${GIT_EXEC_PATH}/git-http-backend/\n <Directory ${GIT_EXEC_PATH}>\n \tOptions None\n </Directory>\ndiff --git a/t/t5560-http-backend.sh b/t/t5560-http-backend.sh\nindex ed034bc..f763880 100755\n--- a/t/t5560-http-backend.sh\n+++ b/t/t5560-http-backend.sh\n@@ -23,7 +23,7 @@ config() {\n }\n \n GET() {\n-\tcurl --include \"$HTTPD_URL/smart/repo.git/$1\" >out 2>/dev/null &&\n+\tcurl --include \"$HTTPD_URL/$SMART/repo.git/$1\" >out 2>/dev/null &&\n \ttr '\\015' Q <out |\n \tsed '\n \t\ts/Q$//\n@@ -91,6 +91,20 @@ get_static_files() {\n \tGET $IDX_URL \"$1\"\n }\n \n+SMART=smart_noexport\n+test_expect_success 'no export by default' '\n+\tlog_div \"no git-daemon-export-ok\"\n+\tget_static_files \"404 Not Found\"\n+'\n+test_expect_success 'export if git-daemon-export-ok' '\n+\tlog_div \"git-daemon-export-ok\"\n+        (cd \"$HTTPD_DOCUMENT_ROOT_PATH/repo.git\" &&\n+\t touch git-daemon-export-ok\n+\t) &&\n+        get_static_files \"200 OK\"\n+'\n+\n+SMART=smart\n test_expect_success 'direct refs/heads/master not found' '\n \tlog_div \"refs/heads/master\"\n \tGET refs/heads/master \"404 Not Found\"\n@@ -145,7 +159,6 @@ test_expect_success 'http.receivepack false' '\n \tGET info/refs?service=git-receive-pack \"403 Forbidden\" &&\n \tPOST git-receive-pack 0000 \"403 Forbidden\"\n '\n-\n run_backend() {\n \tREQUEST_METHOD=GET \\\n \tGIT_PROJECT_ROOT=\"$HTTPD_DOCUMENT_ROOT_PATH\" \\\n@@ -179,6 +192,28 @@ test_expect_success 'http-backend blocks bad PATH_INFO' '\n \n cat >exp <<EOF\n \n+###  no git-daemon-export-ok\n+###\n+GET  /smart_noexport/repo.git/HEAD HTTP/1.1 404 -\n+GET  /smart_noexport/repo.git/info/refs HTTP/1.1 404 -\n+GET  /smart_noexport/repo.git/objects/info/packs HTTP/1.1 404 -\n+GET  /smart_noexport/repo.git/objects/info/alternates HTTP/1.1 404 -\n+GET  /smart_noexport/repo.git/objects/info/http-alternates HTTP/1.1 404 -\n+GET  /smart_noexport/repo.git/$LOOSE_URL HTTP/1.1 404 -\n+GET  /smart_noexport/repo.git/$PACK_URL HTTP/1.1 404 -\n+GET  /smart_noexport/repo.git/$IDX_URL HTTP/1.1 404 -\n+\n+###  git-daemon-export-ok\n+###\n+GET  /smart_noexport/repo.git/HEAD HTTP/1.1 200\n+GET  /smart_noexport/repo.git/info/refs HTTP/1.1 200\n+GET  /smart_noexport/repo.git/objects/info/packs HTTP/1.1 200\n+GET  /smart_noexport/repo.git/objects/info/alternates HTTP/1.1 200 -\n+GET  /smart_noexport/repo.git/objects/info/http-alternates HTTP/1.1 200 -\n+GET  /smart_noexport/repo.git/$LOOSE_URL HTTP/1.1 200\n+GET  /smart_noexport/repo.git/$PACK_URL HTTP/1.1 200\n+GET  /smart_noexport/repo.git/$IDX_URL HTTP/1.1 200\n+\n ###  refs/heads/master\n ###\n GET  /smart/repo.git/refs/heads/master HTTP/1.1 404 -\n-- \n1.6.6.2.g5daf2\n"},{"id":"130353","messageId":"1261870153-57572-2-git-send-email-tarmigan+git@gmail.com","threadId":"22027","inReplyTo":"1261870153-57572-1-git-send-email-tarmigan+git@gmail.com","subject":"[PATCH 2/2] Smart-http: check if repository is OK to export before serving it","fromName":"Tarmigan Casebolt","fromEmail":"tarmigan+git@gmail.com","sentAt":"2009-12-26T23:29:13Z","receivedAt":"2009-12-26T23:29:13Z","isPatch":true,"sender":{"key":"tarmigan+git@gmail.com","avatar":null},"body":"Similar to how git-daemon checks whether a repository is OK to be\nexported, smart-http should also check.  This check can be satisfied\nin two different ways: the environmental variable GIT_HTTP_EXPORT_ALL\nmay be set to export all repositories, or the individual repository\nmay have the file git-daemon-export-ok.\n\nSigned-off-by: Tarmigan Casebolt <tarmigan+git@gmail.com>\n---\n http-backend.c |    3 +++\n 1 files changed, 3 insertions(+), 0 deletions(-)\n\ndiff --git a/http-backend.c b/http-backend.c\nindex f729488..345c12b 100644\n--- a/http-backend.c\n+++ b/http-backend.c\n@@ -648,6 +648,9 @@ int main(int argc, char **argv)\n \tsetup_path();\n \tif (!enter_repo(dir, 0))\n \t\tnot_found(\"Not a git repository: '%s'\", dir);\n+\tif (!getenv(\"GIT_HTTP_EXPORT_ALL\") &&\n+\t    access(\"git-daemon-export-ok\", F_OK) )\n+\t\tnot_found(\"Repository not exported: '%s'\", dir);\n \n \tgit_config(http_config, NULL);\n \tcmd->imp(cmd_arg);\n-- \n1.6.6.2.g5daf2\n"},{"id":"130371","messageId":"20091227210653.GA609@spearce.org","threadId":"22027","inReplyTo":"7vk4w963np.fsf@alter.siamese.dyndns.org","subject":"Re: Does smart-http need git-daemon-export-ok?","fromName":"Shawn O. Pearce","fromEmail":"spearce@spearce.org","sentAt":"2009-12-27T21:06:53Z","receivedAt":"2009-12-27T21:06:53Z","isPatch":false,"sender":{"key":"spearce@spearce.org","avatar":"https://avatars.githubusercontent.com/u/34844?v=4"},"body":"Junio C Hamano <gitster@pobox.com> wrote:\n> Tarmigan <tarmigan+git@gmail.com> writes:\n> > Should the git-http-backend check something like git-daemon-export-ok\n> > before serving a repository?\n> \n> I'd agree that it would make sense to have a way to mark individual\n> repository for (or not for) export.\n\nJust for some background... early drafts of git-http-backend actually\ndid check for, and require, this file before it exported a repository.\n\nI took the check out because I was relying on the HTTP server's\ndocument root translation to provide the mapping into the local\nfilesystem.  That meant the HTTP repository was already exported via\ndumb-http, and the git-daemon-export-ok flag wasn't being checked.\n\nLater in the series development we got the patch to allow a\ndifferent filesystem root via an environment variable, which means\nits possible to hide repositories and make them available only\nthrough git-http-backend.  In that configuration, checking the\ngit-daemon-export-ok flag makes sense again.\n \n> In \"native\" case, the chain of events are: client talks to the daemon, the\n> daemon checks and decides to (or not to) export, and it runs upload-pack.\n> \n> In \"smart http\" case, http-backend is one half of what corresponds to the\n> daemon (the other half being your http server configuration), and it is\n> more flexible and git specific half, so I'd say it would make sense to\n> implement the check that honors the same git-daemon-export-ok flag file in\n> it.\n\nYea, I'd agree.\n\n-- \nShawn.\n"},{"id":"130372","messageId":"20091227211033.GB609@spearce.org","threadId":"22027","inReplyTo":"1261870153-57572-2-git-send-email-tarmigan+git@gmail.com","subject":"Re: [PATCH 2/2] Smart-http: check if repository is OK to export before serving it","fromName":"Shawn O. Pearce","fromEmail":"spearce@spearce.org","sentAt":"2009-12-27T21:10:33Z","receivedAt":"2009-12-27T21:10:33Z","isPatch":true,"sender":{"key":"spearce@spearce.org","avatar":"https://avatars.githubusercontent.com/u/34844?v=4"},"body":"Tarmigan Casebolt <tarmigan+git@gmail.com> wrote:\n> Similar to how git-daemon checks whether a repository is OK to be\n> exported, smart-http should also check.  This check can be satisfied\n> in two different ways: the environmental variable GIT_HTTP_EXPORT_ALL\n> may be set to export all repositories, or the individual repository\n> may have the file git-daemon-export-ok.\n> \n> Signed-off-by: Tarmigan Casebolt <tarmigan+git@gmail.com>\n\nAcked-by: Shawn O. Pearce <spearce@spearce.org>\n\nI really think this and 1/2 should be squashed together, in which\ncase you can apply my ACK to the entire thing.\n\n-- \nShawn.\n"},{"id":"130381","messageId":"905315640912272007i8b4904dv2b93879789b453fb@mail.gmail.com","threadId":"22027","inReplyTo":"20091227211033.GB609@spearce.org","subject":"Re: [PATCH 2/2] Smart-http: check if repository is OK to export before serving it","fromName":"Tarmigan","fromEmail":"tarmigan+git@gmail.com","sentAt":"2009-12-28T04:07:26Z","receivedAt":"2009-12-28T04:07:26Z","isPatch":true,"sender":{"key":"tarmigan+git@gmail.com","avatar":null},"body":"On Sun, Dec 27, 2009 at 4:10 PM, Shawn O. Pearce <spearce@spearce.org> wrote:\n> Tarmigan Casebolt <tarmigan+git@gmail.com> wrote:\n>> Similar to how git-daemon checks whether a repository is OK to be\n>> exported, smart-http should also check.  This check can be satisfied\n>> in two different ways: the environmental variable GIT_HTTP_EXPORT_ALL\n>> may be set to export all repositories, or the individual repository\n>> may have the file git-daemon-export-ok.\n>>\n>> Signed-off-by: Tarmigan Casebolt <tarmigan+git@gmail.com>\n>\n> Acked-by: Shawn O. Pearce <spearce@spearce.org>\n>\n> I really think this and 1/2 should be squashed together, in which\n> case you can apply my ACK to the entire thing.\n\nGreat, thanks for the ACK.\n\nSquashing sounds good to me, I just split it so someone could verify\nthat the tests fail first if they want.\n\nI've been thinking that the not_found() to a forbidden() instead.\nThoughts?  I'll send out a unified patch with that change in a reply.\n\nThanks,\nTarmigan\n"},{"id":"130384","messageId":"1261974166-66866-1-git-send-email-tarmigan+git@gmail.com","threadId":"22027","inReplyTo":"905315640912272007i8b4904dv2b93879789b453fb@mail.gmail.com","subject":"[PATCH] Smart-http: check if repository is OK to export before serving it","fromName":"Tarmigan Casebolt","fromEmail":"tarmigan+git@gmail.com","sentAt":"2009-12-28T04:22:46Z","receivedAt":"2009-12-28T04:22:46Z","isPatch":true,"sender":{"key":"tarmigan+git@gmail.com","avatar":null},"body":"Similar to how git-daemon checks whether a repository is OK to be\nexported, smart-http should also check.  This check can be satisfied\nin two different ways: the environmental variable GIT_HTTP_EXPORT_ALL\nmay be set to export all repositories, or the individual repository\nmay have the file git-daemon-export-ok.\n\nAcked-by: Shawn O. Pearce <spearce@spearce.org>\nSigned-off-by: Tarmigan Casebolt <tarmigan+git@gmail.com>\n---\n Documentation/git-http-backend.txt |   10 +++++++++\n http-backend.c                     |    3 ++\n t/lib-httpd/apache.conf            |    5 ++++\n t/t5560-http-backend.sh            |   39 ++++++++++++++++++++++++++++++++++-\n 4 files changed, 55 insertions(+), 2 deletions(-)\n\ndiff --git a/Documentation/git-http-backend.txt b/Documentation/git-http-backend.txt\nindex 67aec06..c8fe08a 100644\n--- a/Documentation/git-http-backend.txt\n+++ b/Documentation/git-http-backend.txt\n@@ -18,6 +18,11 @@ The program supports clients fetching using both the smart HTTP protcol\n and the backwards-compatible dumb HTTP protocol, as well as clients\n pushing using the smart HTTP protocol.\n \n+It verifies that the directory has the magic file\n+\"git-daemon-export-ok\", and it will refuse to export any git directory\n+that hasn't explicitly been marked for export this way (unless the\n+GIT_HTTP_EXPORT_ALL environmental variable is set).\n+\n By default, only the `upload-pack` service is enabled, which serves\n 'git-fetch-pack' and 'git-ls-remote' clients, which are invoked from\n 'git-fetch', 'git-pull', and 'git-clone'.  If the client is authenticated,\n@@ -70,6 +75,7 @@ Apache 2.x::\n +\n ----------------------------------------------------------------\n SetEnv GIT_PROJECT_ROOT /var/www/git\n+SetEnv GIT_HTTP_EXPORT_ALL\n ScriptAlias /git/ /usr/libexec/git-core/git-http-backend/\n ----------------------------------------------------------------\n +\n@@ -157,6 +163,10 @@ by the invoking web server, including:\n * QUERY_STRING\n * REQUEST_METHOD\n \n+The GIT_HTTP_EXPORT_ALL environmental variable may be passed to\n+'git-http-backend' to bypass the check for the \"git-daemon-export-ok\"\n+file in each repository before allowing export of that repository.\n+\n The backend process sets GIT_COMMITTER_NAME to '$REMOTE_USER' and\n GIT_COMMITTER_EMAIL to '$\\{REMOTE_USER}@http.$\\{REMOTE_ADDR\\}',\n ensuring that any reflogs created by 'git-receive-pack' contain some\ndiff --git a/http-backend.c b/http-backend.c\nindex f729488..9de85cb 100644\n--- a/http-backend.c\n+++ b/http-backend.c\n@@ -648,6 +648,9 @@ int main(int argc, char **argv)\n \tsetup_path();\n \tif (!enter_repo(dir, 0))\n \t\tnot_found(\"Not a git repository: '%s'\", dir);\n+\tif (!getenv(\"GIT_HTTP_EXPORT_ALL\") &&\n+\t    access(\"git-daemon-export-ok\", F_OK) )\n+\t\tforbidden(\"Repository not exported: '%s'\", dir);\n \n \tgit_config(http_config, NULL);\n \tcmd->imp(cmd_arg);\ndiff --git a/t/lib-httpd/apache.conf b/t/lib-httpd/apache.conf\nindex 0fe3fd0..4961505 100644\n--- a/t/lib-httpd/apache.conf\n+++ b/t/lib-httpd/apache.conf\n@@ -22,8 +22,13 @@ Alias /dumb/ www/\n \n <Location /smart/>\n \tSetEnv GIT_EXEC_PATH ${GIT_EXEC_PATH}\n+\tSetEnv GIT_HTTP_EXPORT_ALL\n+</Location>\n+<Location /smart_noexport/>\n+\tSetEnv GIT_EXEC_PATH ${GIT_EXEC_PATH}\n </Location>\n ScriptAlias /smart/ ${GIT_EXEC_PATH}/git-http-backend/\n+ScriptAlias /smart_noexport/ ${GIT_EXEC_PATH}/git-http-backend/\n <Directory ${GIT_EXEC_PATH}>\n \tOptions None\n </Directory>\ndiff --git a/t/t5560-http-backend.sh b/t/t5560-http-backend.sh\nindex ed034bc..126f6d5 100755\n--- a/t/t5560-http-backend.sh\n+++ b/t/t5560-http-backend.sh\n@@ -23,7 +23,7 @@ config() {\n }\n \n GET() {\n-\tcurl --include \"$HTTPD_URL/smart/repo.git/$1\" >out 2>/dev/null &&\n+\tcurl --include \"$HTTPD_URL/$SMART/repo.git/$1\" >out 2>/dev/null &&\n \ttr '\\015' Q <out |\n \tsed '\n \t\ts/Q$//\n@@ -91,6 +91,20 @@ get_static_files() {\n \tGET $IDX_URL \"$1\"\n }\n \n+SMART=smart_noexport\n+test_expect_success 'no export by default' '\n+\tlog_div \"no git-daemon-export-ok\"\n+\tget_static_files \"403 Forbidden\"\n+'\n+test_expect_success 'export if git-daemon-export-ok' '\n+\tlog_div \"git-daemon-export-ok\"\n+        (cd \"$HTTPD_DOCUMENT_ROOT_PATH/repo.git\" &&\n+\t touch git-daemon-export-ok\n+\t) &&\n+        get_static_files \"200 OK\"\n+'\n+\n+SMART=smart\n test_expect_success 'direct refs/heads/master not found' '\n \tlog_div \"refs/heads/master\"\n \tGET refs/heads/master \"404 Not Found\"\n@@ -145,7 +159,6 @@ test_expect_success 'http.receivepack false' '\n \tGET info/refs?service=git-receive-pack \"403 Forbidden\" &&\n \tPOST git-receive-pack 0000 \"403 Forbidden\"\n '\n-\n run_backend() {\n \tREQUEST_METHOD=GET \\\n \tGIT_PROJECT_ROOT=\"$HTTPD_DOCUMENT_ROOT_PATH\" \\\n@@ -179,6 +192,28 @@ test_expect_success 'http-backend blocks bad PATH_INFO' '\n \n cat >exp <<EOF\n \n+###  no git-daemon-export-ok\n+###\n+GET  /smart_noexport/repo.git/HEAD HTTP/1.1 403 -\n+GET  /smart_noexport/repo.git/info/refs HTTP/1.1 403 -\n+GET  /smart_noexport/repo.git/objects/info/packs HTTP/1.1 403 -\n+GET  /smart_noexport/repo.git/objects/info/alternates HTTP/1.1 403 -\n+GET  /smart_noexport/repo.git/objects/info/http-alternates HTTP/1.1 403 -\n+GET  /smart_noexport/repo.git/$LOOSE_URL HTTP/1.1 403 -\n+GET  /smart_noexport/repo.git/$PACK_URL HTTP/1.1 403 -\n+GET  /smart_noexport/repo.git/$IDX_URL HTTP/1.1 403 -\n+\n+###  git-daemon-export-ok\n+###\n+GET  /smart_noexport/repo.git/HEAD HTTP/1.1 200\n+GET  /smart_noexport/repo.git/info/refs HTTP/1.1 200\n+GET  /smart_noexport/repo.git/objects/info/packs HTTP/1.1 200\n+GET  /smart_noexport/repo.git/objects/info/alternates HTTP/1.1 200 -\n+GET  /smart_noexport/repo.git/objects/info/http-alternates HTTP/1.1 200 -\n+GET  /smart_noexport/repo.git/$LOOSE_URL HTTP/1.1 200\n+GET  /smart_noexport/repo.git/$PACK_URL HTTP/1.1 200\n+GET  /smart_noexport/repo.git/$IDX_URL HTTP/1.1 200\n+\n ###  refs/heads/master\n ###\n GET  /smart/repo.git/refs/heads/master HTTP/1.1 404 -\n-- \n1.6.6.1.g8eede.dirty\n"},{"id":"130401","messageId":"20091228155931.GC2252@spearce.org","threadId":"22027","inReplyTo":"905315640912272007i8b4904dv2b93879789b453fb@mail.gmail.com","subject":"Re: [PATCH 2/2] Smart-http: check if repository is OK to export before serving it","fromName":"Shawn O. Pearce","fromEmail":"spearce@spearce.org","sentAt":"2009-12-28T15:59:31Z","receivedAt":"2009-12-28T15:59:31Z","isPatch":true,"sender":{"key":"spearce@spearce.org","avatar":"https://avatars.githubusercontent.com/u/34844?v=4"},"body":"Tarmigan <tarmigan+git@gmail.com> wrote:\n> On Sun, Dec 27, 2009 at 4:10 PM, Shawn O. Pearce <spearce@spearce.org> wrote:\n> > Tarmigan Casebolt <tarmigan+git@gmail.com> wrote:\n> >> Similar to how git-daemon checks whether a repository is OK to be\n> >> exported, smart-http should also check. ?This check can be satisfied\n> >> in two different ways: the environmental variable GIT_HTTP_EXPORT_ALL\n> >> may be set to export all repositories, or the individual repository\n> >> may have the file git-daemon-export-ok.\n...\n> I've been thinking that the not_found() to a forbidden() instead.\n\nOh.  Interesting question.\n\nBecause you can't resolve the access error by authenticating to\nthe server, we may actually want to just return not_found() here\nwith a message in the log of \"Repository not exported: '%s'\".\n\nThat would mirror the behavior of git-daemon.\n\n-- \nShawn.\n"},{"id":"130404","messageId":"905315640912280857g710b45fcne21a21d53ff0fedf@mail.gmail.com","threadId":"22027","inReplyTo":"20091228155931.GC2252@spearce.org","subject":"Re: [PATCH 2/2] Smart-http: check if repository is OK to export before serving it","fromName":"Tarmigan","fromEmail":"tarmigan+git@gmail.com","sentAt":"2009-12-28T16:57:18Z","receivedAt":"2009-12-28T16:57:18Z","isPatch":true,"sender":{"key":"tarmigan+git@gmail.com","avatar":null},"body":"On Mon, Dec 28, 2009 at 10:59 AM, Shawn O. Pearce <spearce@spearce.org> wrote:\n> Tarmigan <tarmigan+git@gmail.com> wrote:\n>> I've been thinking that the not_found() to a forbidden() instead.\n>\n> Oh.  Interesting question.\n>\n> Because you can't resolve the access error by authenticating to\n> the server, we may actually want to just return not_found() here\n> with a message in the log of \"Repository not exported: '%s'\".\n\nI'm no http expert, but isn't that what 401 would be?  From\nhttp://tools.ietf.org/html/rfc2616#section-10.4.4\n403 Forbidden\n   The server understood the request, but is refusing to fulfill it.\n   Authorization will not help and the request SHOULD NOT be repeated.\n   If the request method was not HEAD and the server wishes to make\n   public why the request has not been fulfilled, it SHOULD describe the\n   reason for the refusal in the entity.  If the server does not wish to\n   make this information available to the client, the status code 404\n   (Not Found) can be used instead.\nwhich to me points to 403 instead of 404.\n\nI don't have a strong preference, and will resend with those changes\nif you'd prefer 404.\n\nThanks,\nTarmigan\n"},{"id":"130405","messageId":"20091228170811.GE2252@spearce.org","threadId":"22027","inReplyTo":"905315640912280857g710b45fcne21a21d53ff0fedf@mail.gmail.com","subject":"Re: [PATCH 2/2] Smart-http: check if repository is OK to export before serving it","fromName":"Shawn O. Pearce","fromEmail":"spearce@spearce.org","sentAt":"2009-12-28T17:08:11Z","receivedAt":"2009-12-28T17:08:11Z","isPatch":true,"sender":{"key":"spearce@spearce.org","avatar":"https://avatars.githubusercontent.com/u/34844?v=4"},"body":"Tarmigan <tarmigan+git@gmail.com> wrote:\n> On Mon, Dec 28, 2009 at 10:59 AM, Shawn O. Pearce <spearce@spearce.org> wrote:\n> > Tarmigan <tarmigan+git@gmail.com> wrote:\n> >> I've been thinking that the not_found() to a forbidden() instead.\n> >\n> > Because you can't resolve the access error by authenticating to\n> > the server, we may actually want to just return not_found() here\n> > with a message in the log of \"Repository not exported: '%s'\".\n> \n> I'm no http expert, but isn't that what 401 would be?  From\n> http://tools.ietf.org/html/rfc2616#section-10.4.4\n> 403 Forbidden\n>    The server understood the request, but is refusing to fulfill it.\n>    Authorization will not help and the request SHOULD NOT be repeated.\n>    If the request method was not HEAD and the server wishes to make\n>    public why the request has not been fulfilled, it SHOULD describe the\n>    reason for the refusal in the entity.  If the server does not wish to\n>    make this information available to the client, the status code 404\n>    (Not Found) can be used instead.\n> which to me points to 403 instead of 404.\n\nGood point, that is 403.  But the last sentance leads me to believe\n404 might be a better use here.  Under git-daemon we don't tell\nthe client the difference between \"Not Found\" and \"Not Exported\",\nso I think we should be doing the same thing here under HTTP.\n \n-- \nShawn.\n"},{"id":"130422","messageId":"1262036940-9678-1-git-send-email-tarmigan+git@gmail.com","threadId":"22027","inReplyTo":"20091228170811.GE2252@spearce.org","subject":"[PATCH] Smart-http: check if repository is OK to export before serving it","fromName":"Tarmigan Casebolt","fromEmail":"tarmigan+git@gmail.com","sentAt":"2009-12-28T21:49:00Z","receivedAt":"2009-12-28T21:49:00Z","isPatch":true,"sender":{"key":"tarmigan+git@gmail.com","avatar":null},"body":"Similar to how git-daemon checks whether a repository is OK to be\nexported, smart-http should also check.  This check can be satisfied\nin two different ways: the environmental variable GIT_HTTP_EXPORT_ALL\nmay be set to export all repositories, or the individual repository\nmay have the file git-daemon-export-ok.\n\nAcked-by: Shawn O. Pearce <spearce@spearce.org>\nSigned-off-by: Tarmigan Casebolt <tarmigan+git@gmail.com>\n---\nOK, I see what you're saying Shawn.  I've changed it back to \"404 \nNot Found\" again.\n\nI've also reordered the new tests since the last time I sent it out.\nThe new tests use the same test as in\n\"static file is ok\"\nso put the new tests after that test in case that test breaks.\n\n Documentation/git-http-backend.txt |   10 +++++++++\n http-backend.c                     |    3 ++\n t/lib-httpd/apache.conf            |    5 ++++\n t/t5560-http-backend.sh            |   39 ++++++++++++++++++++++++++++++++++-\n 4 files changed, 55 insertions(+), 2 deletions(-)\n\ndiff --git a/Documentation/git-http-backend.txt b/Documentation/git-http-backend.txt\nindex 67aec06..c8fe08a 100644\n--- a/Documentation/git-http-backend.txt\n+++ b/Documentation/git-http-backend.txt\n@@ -18,6 +18,11 @@ The program supports clients fetching using both the smart HTTP protcol\n and the backwards-compatible dumb HTTP protocol, as well as clients\n pushing using the smart HTTP protocol.\n \n+It verifies that the directory has the magic file\n+\"git-daemon-export-ok\", and it will refuse to export any git directory\n+that hasn't explicitly been marked for export this way (unless the\n+GIT_HTTP_EXPORT_ALL environmental variable is set).\n+\n By default, only the `upload-pack` service is enabled, which serves\n 'git-fetch-pack' and 'git-ls-remote' clients, which are invoked from\n 'git-fetch', 'git-pull', and 'git-clone'.  If the client is authenticated,\n@@ -70,6 +75,7 @@ Apache 2.x::\n +\n ----------------------------------------------------------------\n SetEnv GIT_PROJECT_ROOT /var/www/git\n+SetEnv GIT_HTTP_EXPORT_ALL\n ScriptAlias /git/ /usr/libexec/git-core/git-http-backend/\n ----------------------------------------------------------------\n +\n@@ -157,6 +163,10 @@ by the invoking web server, including:\n * QUERY_STRING\n * REQUEST_METHOD\n \n+The GIT_HTTP_EXPORT_ALL environmental variable may be passed to\n+'git-http-backend' to bypass the check for the \"git-daemon-export-ok\"\n+file in each repository before allowing export of that repository.\n+\n The backend process sets GIT_COMMITTER_NAME to '$REMOTE_USER' and\n GIT_COMMITTER_EMAIL to '$\\{REMOTE_USER}@http.$\\{REMOTE_ADDR\\}',\n ensuring that any reflogs created by 'git-receive-pack' contain some\ndiff --git a/http-backend.c b/http-backend.c\nindex f729488..345c12b 100644\n--- a/http-backend.c\n+++ b/http-backend.c\n@@ -648,6 +648,9 @@ int main(int argc, char **argv)\n \tsetup_path();\n \tif (!enter_repo(dir, 0))\n \t\tnot_found(\"Not a git repository: '%s'\", dir);\n+\tif (!getenv(\"GIT_HTTP_EXPORT_ALL\") &&\n+\t    access(\"git-daemon-export-ok\", F_OK) )\n+\t\tnot_found(\"Repository not exported: '%s'\", dir);\n \n \tgit_config(http_config, NULL);\n \tcmd->imp(cmd_arg);\ndiff --git a/t/lib-httpd/apache.conf b/t/lib-httpd/apache.conf\nindex 0fe3fd0..4961505 100644\n--- a/t/lib-httpd/apache.conf\n+++ b/t/lib-httpd/apache.conf\n@@ -22,8 +22,13 @@ Alias /dumb/ www/\n \n <Location /smart/>\n \tSetEnv GIT_EXEC_PATH ${GIT_EXEC_PATH}\n+\tSetEnv GIT_HTTP_EXPORT_ALL\n+</Location>\n+<Location /smart_noexport/>\n+\tSetEnv GIT_EXEC_PATH ${GIT_EXEC_PATH}\n </Location>\n ScriptAlias /smart/ ${GIT_EXEC_PATH}/git-http-backend/\n+ScriptAlias /smart_noexport/ ${GIT_EXEC_PATH}/git-http-backend/\n <Directory ${GIT_EXEC_PATH}>\n \tOptions None\n </Directory>\ndiff --git a/t/t5560-http-backend.sh b/t/t5560-http-backend.sh\nindex ed034bc..04a9896 100755\n--- a/t/t5560-http-backend.sh\n+++ b/t/t5560-http-backend.sh\n@@ -23,7 +23,7 @@ config() {\n }\n \n GET() {\n-\tcurl --include \"$HTTPD_URL/smart/repo.git/$1\" >out 2>/dev/null &&\n+\tcurl --include \"$HTTPD_URL/$SMART/repo.git/$1\" >out 2>/dev/null &&\n \ttr '\\015' Q <out |\n \tsed '\n \t\ts/Q$//\n@@ -91,6 +91,7 @@ get_static_files() {\n \tGET $IDX_URL \"$1\"\n }\n \n+SMART=smart\n test_expect_success 'direct refs/heads/master not found' '\n \tlog_div \"refs/heads/master\"\n \tGET refs/heads/master \"404 Not Found\"\n@@ -99,6 +100,19 @@ test_expect_success 'static file is ok' '\n \tlog_div \"getanyfile default\"\n \tget_static_files \"200 OK\"\n '\n+SMART=smart_noexport\n+test_expect_success 'no export by default' '\n+\tlog_div \"no git-daemon-export-ok\"\n+\tget_static_files \"404 Not Found\"\n+'\n+test_expect_success 'export if git-daemon-export-ok' '\n+\tlog_div \"git-daemon-export-ok\"\n+        (cd \"$HTTPD_DOCUMENT_ROOT_PATH/repo.git\" &&\n+\t touch git-daemon-export-ok\n+\t) &&\n+        get_static_files \"200 OK\"\n+'\n+SMART=smart\n test_expect_success 'static file if http.getanyfile true is ok' '\n \tlog_div \"getanyfile true\"\n \tconfig http.getanyfile true &&\n@@ -145,7 +159,6 @@ test_expect_success 'http.receivepack false' '\n \tGET info/refs?service=git-receive-pack \"403 Forbidden\" &&\n \tPOST git-receive-pack 0000 \"403 Forbidden\"\n '\n-\n run_backend() {\n \tREQUEST_METHOD=GET \\\n \tGIT_PROJECT_ROOT=\"$HTTPD_DOCUMENT_ROOT_PATH\" \\\n@@ -194,6 +207,28 @@ GET  /smart/repo.git/$LOOSE_URL HTTP/1.1 200\n GET  /smart/repo.git/$PACK_URL HTTP/1.1 200\n GET  /smart/repo.git/$IDX_URL HTTP/1.1 200\n \n+###  no git-daemon-export-ok\n+###\n+GET  /smart_noexport/repo.git/HEAD HTTP/1.1 404 -\n+GET  /smart_noexport/repo.git/info/refs HTTP/1.1 404 -\n+GET  /smart_noexport/repo.git/objects/info/packs HTTP/1.1 404 -\n+GET  /smart_noexport/repo.git/objects/info/alternates HTTP/1.1 404 -\n+GET  /smart_noexport/repo.git/objects/info/http-alternates HTTP/1.1 404 -\n+GET  /smart_noexport/repo.git/$LOOSE_URL HTTP/1.1 404 -\n+GET  /smart_noexport/repo.git/$PACK_URL HTTP/1.1 404 -\n+GET  /smart_noexport/repo.git/$IDX_URL HTTP/1.1 404 -\n+\n+###  git-daemon-export-ok\n+###\n+GET  /smart_noexport/repo.git/HEAD HTTP/1.1 200\n+GET  /smart_noexport/repo.git/info/refs HTTP/1.1 200\n+GET  /smart_noexport/repo.git/objects/info/packs HTTP/1.1 200\n+GET  /smart_noexport/repo.git/objects/info/alternates HTTP/1.1 200 -\n+GET  /smart_noexport/repo.git/objects/info/http-alternates HTTP/1.1 200 -\n+GET  /smart_noexport/repo.git/$LOOSE_URL HTTP/1.1 200\n+GET  /smart_noexport/repo.git/$PACK_URL HTTP/1.1 200\n+GET  /smart_noexport/repo.git/$IDX_URL HTTP/1.1 200\n+\n ###  getanyfile true\n ###\n GET  /smart/repo.git/HEAD HTTP/1.1 200\n-- \n1.6.6.1.g8d7b9\n"},{"id":"130442","messageId":"7vy6kmjfwo.fsf@alter.siamese.dyndns.org","threadId":"22027","inReplyTo":"1262036940-9678-1-git-send-email-tarmigan+git@gmail.com","subject":"Re: [PATCH] Smart-http: check if repository is OK to export before serving it","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2009-12-29T09:19:51Z","receivedAt":"2009-12-29T09:19:51Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Tarmigan Casebolt <tarmigan+git@gmail.com> writes:\n\n> Similar to how git-daemon checks whether a repository is OK to be\n> exported, smart-http should also check.  This check can be satisfied\n> in two different ways: the environmental variable GIT_HTTP_EXPORT_ALL\n> may be set to export all repositories, or the individual repository\n> may have the file git-daemon-export-ok.\n>\n> Acked-by: Shawn O. Pearce <spearce@spearce.org>\n> Signed-off-by: Tarmigan Casebolt <tarmigan+git@gmail.com>\n> ---\n> OK, I see what you're saying Shawn.  I've changed it back to \"404 \n> Not Found\" again.\n>\n> I've also reordered the new tests since the last time I sent it out.\n> The new tests use the same test as in\n> \"static file is ok\"\n> so put the new tests after that test in case that test breaks.\n\nLooks sane to me, although I am afraid that I am not as familiar with the\ncodepath involved as I should be.  Shawn, is your Ack still good?\n"},{"id":"130460","messageId":"20091229150016.GA6152@spearce.org","threadId":"22027","inReplyTo":"7vy6kmjfwo.fsf@alter.siamese.dyndns.org","subject":"Re: [PATCH] Smart-http: check if repository is OK to export before serving it","fromName":"Shawn O. Pearce","fromEmail":"spearce@spearce.org","sentAt":"2009-12-29T15:00:16Z","receivedAt":"2009-12-29T15:00:16Z","isPatch":true,"sender":{"key":"spearce@spearce.org","avatar":"https://avatars.githubusercontent.com/u/34844?v=4"},"body":"Junio C Hamano <gitster@pobox.com> wrote:\n> Tarmigan Casebolt <tarmigan+git@gmail.com> writes:\n> \n> > Similar to how git-daemon checks whether a repository is OK to be\n> > exported, smart-http should also check.  This check can be satisfied\n> > in two different ways: the environmental variable GIT_HTTP_EXPORT_ALL\n> > may be set to export all repositories, or the individual repository\n> > may have the file git-daemon-export-ok.\n> >\n> > Acked-by: Shawn O. Pearce <spearce@spearce.org>\n...\n> Looks sane to me, although I am afraid that I am not as familiar with the\n> codepath involved as I should be.  Shawn, is your Ack still good?\n\nYes, my ACK is still good.  :-)\n\n-- \nShawn.\n"}]}