{"thread":{"id":"2335","subject":"[PATCH] RFC: proxy-command support for git://","startedAt":"2005-11-03T15:55:24Z","lastAt":"2005-11-19T12:13:21Z","messageCount":13,"participants":["Paul Collins","Junio C Hamano","Linus Torvalds","Carl Baldwin"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"11065","messageId":"87fyqdbuab.fsf@briny.internal.ondioline.org","threadId":"2335","inReplyTo":null,"subject":"[PATCH] RFC: proxy-command support for git://","fromName":"Paul Collins","fromEmail":"paul@briny.ondioline.org","sentAt":"2005-11-03T15:55:24Z","receivedAt":"2005-11-03T15:55:24Z","isPatch":true,"sender":{"key":"paul@briny.ondioline.org","avatar":null},"body":"I spend some of my time using a network that only allows outgoing TCP\nconnections to certain ports, and the git-daemon port is not one of them.\nThis patch below implements an analogue to ssh's ProxyCommand feature\nfor git, as a less messy alternative to ssh port forwarding.  One can\nuse it to ssh to a bastion host and netcat to the destination:\n\n  $ cat ~/bin/my-git-proxy-command\n  #!/bin/sh\n  exec ssh bastionhost nc \"$1\" \"$2\"\n\nI've done a few pulls and a clone with it, and it seems to work.\n\n\nQuestions:\n\n* Can git already do this and I just failed to notice?\n\n* Where should git_use_proxy() look?  Some git configuration file?\n  An environment variable?  Both?  Somewhere else?\n\nIt also needs to support non-default ports and probably other things I missed.\n\n\ndiff --git a/connect.c b/connect.c\nindex c2badc7..646e26f 100644\n--- a/connect.c\n+++ b/connect.c\n@@ -448,6 +448,40 @@ static int git_tcp_connect(int fd[2], co\n \n #endif /* NO_IPV6 */\n \n+static int git_proxy_connect(int fd[2], const char *prog, char *host, char *path)\n+{\n+\tchar *command = \"my-git-proxy-command\"; /* FIXME: cf. git_use_proxy() */\n+\tchar *port = STR(DEFAULT_GIT_PORT);\n+\tint pipefd[2][2];\n+\tpid_t pid;\n+\n+\tif (pipe(pipefd[0]) < 0 || pipe(pipefd[1]) < 0)\n+\t\tdie(\"unable to create pipe pair for communication\");\n+\tpid = fork();\n+\tif (!pid) {\n+\t\tdup2(pipefd[1][0], 0);\n+\t\tdup2(pipefd[0][1], 1);\n+\t\tclose(pipefd[0][0]);\n+\t\tclose(pipefd[0][1]);\n+\t\tclose(pipefd[1][0]);\n+\t\tclose(pipefd[1][1]);\n+\t\texeclp(command, command, host, port, NULL);\n+\t\tdie(\"exec failed\");\n+\t}\n+\tfd[0] = pipefd[0][0];\n+\tfd[1] = pipefd[1][1];\n+\tclose(pipefd[0][1]);\n+\tclose(pipefd[1][0]);\n+\tpacket_write(fd[1], \"%s %s\\n\", prog, path);\n+\treturn pid;\n+}\n+\n+static int git_use_proxy(void)\n+{\n+\t/* FIXME: look for the proxy command somewhere - repo's config? environment? */\n+\treturn 1;\n+}\n+\n /*\n  * Yeah, yeah, fixme. Need to pass in the heads etc.\n  */\n@@ -482,8 +516,11 @@ int git_connect(int fd[2], char *url, co\n \t\t}\n \t}\n \n-\tif (protocol == PROTO_GIT)\n+\tif (protocol == PROTO_GIT) {\n+\t\tif (git_use_proxy())\n+\t\t\treturn git_proxy_connect(fd, prog, host, path);\n \t\treturn git_tcp_connect(fd, prog, host, path);\n+\t}\n \n \tif (pipe(pipefd[0]) < 0 || pipe(pipefd[1]) < 0)\n \t\tdie(\"unable to create pipe pair for communication\");\n\n-- \nDag vijandelijk luchtschip de huismeester is dood\n"},{"id":"11075","messageId":"7v8xw5h898.fsf@assigned-by-dhcp.cox.net","threadId":"2335","inReplyTo":"87fyqdbuab.fsf@briny.internal.ondioline.org","subject":"Re: [PATCH] RFC: proxy-command support for git://","fromName":"Junio C Hamano","fromEmail":"junkio@cox.net","sentAt":"2005-11-03T18:54:43Z","receivedAt":"2005-11-03T18:54:43Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Paul Collins <paul@briny.ondioline.org> writes:\n\n> I spend some of my time using a network that only allows outgoing TCP\n> connections to certain ports, and the git-daemon port is not one of them.\n> This patch below implements an analogue to ssh's ProxyCommand feature\n> for git, as a less messy alternative to ssh port forwarding.\n\nWonderful.\n\n> Questions:\n>\n> * Can git already do this and I just failed to notice?\n\nMaybe I just failed to notice this too, but I do not think so.\n\n> * Where should git_use_proxy() look?  Some git configuration file?\n>   An environment variable?  Both?  Somewhere else?\n\nMy preference is put something in .git/config to describe which\nproxy command (maybe the same one with different argument) to\nuse depending on where you are going.  When you have internal\nhosts and external hosts you would want this to apply only to\nexternal hosts.  Maybe you have two or more gateways and\ndepending on which external host you are going you may want to\nuse different proxied connection.  On top of the config file,\nmaking it overridable from an environment variable would be\nsensible.\n"},{"id":"11077","messageId":"Pine.LNX.4.64.0511031117290.27915@g5.osdl.org","threadId":"2335","inReplyTo":"7v8xw5h898.fsf@assigned-by-dhcp.cox.net","subject":"Re: [PATCH] RFC: proxy-command support for git://","fromName":"Linus Torvalds","fromEmail":"torvalds@osdl.org","sentAt":"2005-11-03T19:22:35Z","receivedAt":"2005-11-03T19:22:35Z","isPatch":true,"sender":{"key":"torvalds@linux-foundation.org","avatar":"https://avatars.githubusercontent.com/u/1024025?v=4"},"body":"\n\nOn Thu, 3 Nov 2005, Junio C Hamano wrote:\n\n> Paul Collins <paul@briny.ondioline.org> writes:\n> \n> > I spend some of my time using a network that only allows outgoing TCP\n> > connections to certain ports, and the git-daemon port is not one of them.\n> > This patch below implements an analogue to ssh's ProxyCommand feature\n> > for git, as a less messy alternative to ssh port forwarding.\n> \n> Wonderful.\n> \n> > Questions:\n> >\n> > * Can git already do this and I just failed to notice?\n> \n> Maybe I just failed to notice this too, but I do not think so.\n\nActually, you could. TWO ways, in fact, afaik.\n\nJust use the \"ssh://host/pathname\" format (or just \"host:pathname\") and \nthe GIT_SSH environment variable.\n\nYou could also override the local command-name with\n\n\tgit-send-pack --exec=my-local-send-program /machine/repo/path\n\nwhere the \"my-local-send-program\" will parse /machine/repo/path thing. At \nleast that works with git-send-pack, but it's possible it doesn't work \nwith some other logic (ie \"git push\" might decide that it's unhappy that \n/machine/repo/path doesn't exist locally because it thinks it's a local \npath).\n\n\t\tLinus\n"},{"id":"11085","messageId":"20051103204137.GA1343@hpsvcnb.fc.hp.com","threadId":"2335","inReplyTo":"Pine.LNX.4.64.0511031117290.27915@g5.osdl.org","subject":"Re: [PATCH] RFC: proxy-command support for git://","fromName":"Carl Baldwin","fromEmail":"cnb@fc.hp.com","sentAt":"2005-11-03T20:41:37Z","receivedAt":"2005-11-03T20:41:37Z","isPatch":true,"sender":{"key":"cnb@fc.hp.com","avatar":null},"body":"Another way to do this would be using the ~/.ssh/config file.  It would\nlook something like this:\n\nHost host\n  ProxyCommand ...\n\nOr, more generically...\n\nHost *.*\n  ProxyCommand ...\n\nHost *.* assumes that if the machine name has a '.' in it then you are\ntrying to get outside the firewall.  This might not be a good assumption\nbut it works well where I am.\n\nThen use host:pathname or ssh://host/pathname or whatever.\n\nThe advantage of using this is that it works for anything that uses ssh\nto get outside the firewall.  Not just git.  So, setup is minimal.\n\nCarl\n\nOn Thu, Nov 03, 2005 at 11:22:35AM -0800, Linus Torvalds wrote:\n> \n> \n> On Thu, 3 Nov 2005, Junio C Hamano wrote:\n> \n> > Paul Collins <paul@briny.ondioline.org> writes:\n> > \n> > > I spend some of my time using a network that only allows outgoing TCP\n> > > connections to certain ports, and the git-daemon port is not one of them.\n> > > This patch below implements an analogue to ssh's ProxyCommand feature\n> > > for git, as a less messy alternative to ssh port forwarding.\n> > \n> > Wonderful.\n> > \n> > > Questions:\n> > >\n> > > * Can git already do this and I just failed to notice?\n> > \n> > Maybe I just failed to notice this too, but I do not think so.\n> \n> Actually, you could. TWO ways, in fact, afaik.\n> \n> Just use the \"ssh://host/pathname\" format (or just \"host:pathname\") and \n> the GIT_SSH environment variable.\n> \n> You could also override the local command-name with\n> \n> \tgit-send-pack --exec=my-local-send-program /machine/repo/path\n> \n> where the \"my-local-send-program\" will parse /machine/repo/path thing. At \n> least that works with git-send-pack, but it's possible it doesn't work \n> with some other logic (ie \"git push\" might decide that it's unhappy that \n> /machine/repo/path doesn't exist locally because it thinks it's a local \n> path).\n> \n> \t\tLinus\n> -\n> To unsubscribe from this list: send the line \"unsubscribe git\" in\n> the body of a message to majordomo@vger.kernel.org\n> More majordomo info at  http://vger.kernel.org/majordomo-info.html\n> \n\n-- \n- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\n Carl Baldwin                        Systems VLSI Laboratory\n Hewlett Packard Company\n MS 88                               work: 970 898-1523\n 3404 E. Harmony Rd.                 work: Carl.N.Baldwin@hp.com\n Fort Collins, CO 80525              home: Carl@ecBaldwin.net\n- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\n"},{"id":"11089","messageId":"7vsludbeqc.fsf@assigned-by-dhcp.cox.net","threadId":"2335","inReplyTo":"20051103204137.GA1343@hpsvcnb.fc.hp.com","subject":"Re: [PATCH] RFC: proxy-command support for git://","fromName":"Junio C Hamano","fromEmail":"junkio@cox.net","sentAt":"2005-11-03T21:31:23Z","receivedAt":"2005-11-03T21:31:23Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Carl Baldwin <cnb@fc.hp.com> writes:\n\n> Another way to do this would be using the ~/.ssh/config file.  It would\n> look something like this:\n\nMaybe I am slow today, but wouldn't this require the other end\n(i.e. remote repo) to let you ssh in?\n\nI think the point of the original patch was to give proxied\nconnection to git:// transport, not git over ssh.\n"},{"id":"11123","messageId":"871x1wbgvn.fsf_-_@briny.internal.ondioline.org","threadId":"2335","inReplyTo":"7v8xw5h898.fsf@assigned-by-dhcp.cox.net","subject":"Re: [PATCH] v2: proxy-command support for git://","fromName":"Paul Collins","fromEmail":"paul@briny.ondioline.org","sentAt":"2005-11-04T14:57:16Z","receivedAt":"2005-11-04T14:57:16Z","isPatch":true,"sender":{"key":"paul@briny.ondioline.org","avatar":null},"body":"Junio C Hamano <junkio@cox.net> writes:\n\n> Paul Collins <paul@briny.ondioline.org> writes:\n>\n>> * Where should git_use_proxy() look?  Some git configuration file?\n>>   An environment variable?  Both?  Somewhere else?\n>\n> My preference is put something in .git/config to describe which\n> proxy command (maybe the same one with different argument) to\n> use depending on where you are going.  When you have internal\n> hosts and external hosts you would want this to apply only to\n> external hosts.  Maybe you have two or more gateways and\n> depending on which external host you are going you may want to\n> use different proxied connection.  On top of the config file,\n> making it overridable from an environment variable would be\n> sensible.\n\nHere is an updated patch that first looks for GIT_PROXY_COMMAND in the\nenvironment and then git.proxycommand in the repository's\nconfiguration file.  I have left the calling convention the same --\nargv[1] is the host and argv[2] is the port.\n\nI've taken the hostname parsing verbatim from git_tcp_connect(), so it\nshould now support an explicit port number and whatever that business\nwith the square brackets is.  (Should I move this to a helper function?)\n\nRegarding internal vs. external hosts, the proxy command can simply\nrun netcat locally to internal hosts, so perhaps that is sufficient.\n\n\ndiff --git a/connect.c b/connect.c\nindex c2badc7..43eec67 100644\n--- a/connect.c\n+++ b/connect.c\n@@ -448,6 +448,73 @@ static int git_tcp_connect(int fd[2], co\n \n #endif /* NO_IPV6 */\n \n+static char *git_proxy_command = NULL;\n+\n+static int git_proxy_command_options(const char *var, const char *value)\n+{\n+\tif (git_proxy_command == NULL) {\n+\t\tif (!strcmp(var, \"git.proxycommand\")) {\n+\t\t\tgit_proxy_command = xmalloc(strlen(value) + 1);\n+\t\t\tstrcpy(git_proxy_command, value);\n+\t\t\treturn 0;\n+\t\t}\n+\t}\n+\n+\treturn git_default_config(var, value);\n+}\n+\n+static int git_use_proxy(void)\n+{\n+\tgit_proxy_command = getenv(\"GIT_PROXY_COMMAND\");\n+\tgit_config(git_proxy_command_options);\n+\treturn git_proxy_command != NULL;\n+}\n+\n+static int git_proxy_connect(int fd[2], const char *prog, char *host, char *path)\n+{\n+\tchar *port = STR(DEFAULT_GIT_PORT);\n+\tchar *colon, *end;\n+\tint pipefd[2][2];\n+\tpid_t pid;\n+\n+\tif (host[0] == '[') {\n+\t\tend = strchr(host + 1, ']');\n+\t\tif (end) {\n+\t\t\t*end = 0;\n+\t\t\tend++;\n+\t\t\thost++;\n+\t\t} else\n+\t\t\tend = host;\n+\t} else\n+\t\tend = host;\n+\tcolon = strchr(end, ':');\n+\n+\tif (colon) {\n+\t\t*colon = 0;\n+\t\tport = colon + 1;\n+\t}\n+\n+\tif (pipe(pipefd[0]) < 0 || pipe(pipefd[1]) < 0)\n+\t\tdie(\"unable to create pipe pair for communication\");\n+\tpid = fork();\n+\tif (!pid) {\n+\t\tdup2(pipefd[1][0], 0);\n+\t\tdup2(pipefd[0][1], 1);\n+\t\tclose(pipefd[0][0]);\n+\t\tclose(pipefd[0][1]);\n+\t\tclose(pipefd[1][0]);\n+\t\tclose(pipefd[1][1]);\n+\t\texeclp(git_proxy_command, git_proxy_command, host, port, NULL);\n+\t\tdie(\"exec failed\");\n+\t}\n+\tfd[0] = pipefd[0][0];\n+\tfd[1] = pipefd[1][1];\n+\tclose(pipefd[0][1]);\n+\tclose(pipefd[1][0]);\n+\tpacket_write(fd[1], \"%s %s\\n\", prog, path);\n+\treturn pid;\n+}\n+\n /*\n  * Yeah, yeah, fixme. Need to pass in the heads etc.\n  */\n@@ -482,8 +549,11 @@ int git_connect(int fd[2], char *url, co\n \t\t}\n \t}\n \n-\tif (protocol == PROTO_GIT)\n+\tif (protocol == PROTO_GIT) {\n+\t\tif (git_use_proxy())\n+\t\t\treturn git_proxy_connect(fd, prog, host, path);\n \t\treturn git_tcp_connect(fd, prog, host, path);\n+\t}\n \n \tif (pipe(pipefd[0]) < 0 || pipe(pipefd[1]) < 0)\n \t\tdie(\"unable to create pipe pair for communication\");\n\n\n-- \nDag vijandelijk luchtschip de huismeester is dood\n"},{"id":"11133","messageId":"7v1x1wz7ae.fsf@assigned-by-dhcp.cox.net","threadId":"2335","inReplyTo":"871x1wbgvn.fsf_-_@briny.internal.ondioline.org","subject":"Re: [PATCH] v2: proxy-command support for git://","fromName":"Junio C Hamano","fromEmail":"junkio@cox.net","sentAt":"2005-11-04T16:50:33Z","receivedAt":"2005-11-04T16:50:33Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Paul Collins <paul@briny.ondioline.org> writes:\n\n> Regarding internal vs. external hosts, the proxy command can simply\n> run netcat locally to internal hosts, so perhaps that is sufficient.\n\nI was hoping this to become a bit more generalized mechanism\nthan that; for example using outgoing plug over HTTP Connect or\ntelnet proxy using tn-gw-nav.\n"},{"id":"11143","messageId":"7v7jbow8ae.fsf@assigned-by-dhcp.cox.net","threadId":"2335","inReplyTo":"7v1x1wz7ae.fsf@assigned-by-dhcp.cox.net","subject":"Re: [PATCH] v2: proxy-command support for git://","fromName":"Junio C Hamano","fromEmail":"junkio@cox.net","sentAt":"2005-11-04T18:57:13Z","receivedAt":"2005-11-04T18:57:13Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Junio C Hamano <junkio@cox.net> writes:\n\n> Paul Collins <paul@briny.ondioline.org> writes:\n>\n>> Regarding internal vs. external hosts, the proxy command can simply\n>> run netcat locally to internal hosts, so perhaps that is sufficient.\n>\n> I was hoping this to become a bit more generalized mechanism\n> than that; for example using outgoing plug over HTTP Connect or\n> telnet proxy using tn-gw-nav.\n\nI realize the above does not really convey my real objection.\n\nYour \"ssh to the proxy/firewall host and run netcat to the\ndestination\" would not work for me to reach the internal hosts\nat all (while it would work for external ones), because my\nfirewall does not know names of our internal hosts (the same for\nusing tn-gw-nav to cross http or telnet proxy).\n"},{"id":"11149","messageId":"87ll049l8a.fsf@briny.internal.ondioline.org","threadId":"2335","inReplyTo":"7v7jbow8ae.fsf@assigned-by-dhcp.cox.net","subject":"Re: [PATCH] v2: proxy-command support for git://","fromName":"Paul Collins","fromEmail":"paul@briny.ondioline.org","sentAt":"2005-11-04T21:06:13Z","receivedAt":"2005-11-04T21:06:13Z","isPatch":true,"sender":{"key":"paul@briny.ondioline.org","avatar":null},"body":"Junio C Hamano <junkio@cox.net> writes:\n\n> Junio C Hamano <junkio@cox.net> writes:\n>\n>> Paul Collins <paul@briny.ondioline.org> writes:\n>>\n>>> Regarding internal vs. external hosts, the proxy command can simply\n>>> run netcat locally to internal hosts, so perhaps that is sufficient.\n>>\n>> I was hoping this to become a bit more generalized mechanism\n>> than that; for example using outgoing plug over HTTP Connect or\n>> telnet proxy using tn-gw-nav.\n\n\"Run a program and talk to it via stdin/stdout\" is as general as it\ngets, isn't it?  ssh+netcat is just what I happen to use.\n\n> I realize the above does not really convey my real objection.\n>\n> Your \"ssh to the proxy/firewall host and run netcat to the\n> destination\" would not work for me to reach the internal hosts\n> at all (while it would work for external ones), because my\n> firewall does not know names of our internal hosts (the same for\n> using tn-gw-nav to cross http or telnet proxy).\n\nIt doesn't have to be unconditional.  For example, one could have:\n\n    if on_blargco_network; then\n        # internal\n        case \"$1\" in\n            *.blargco.com)\n                exec nc \"$1\" \"$2\"\n                ;;\n            *)\n                exec ssh bastion.blargco.com nc \"$1\" \"$2\"\n                ;;\n        esac\n    else\n        # external\n        case \"$1\" in\n            *.blargco.com)\n                exec ssh bastion.blargco.com nc \"$1\" \"$2\"\n                ;;\n            *)\n                exec ssh bastion nc \"$1\" \"$2\"\n                ;;\n        esac\n    fi\n\nBut perhaps I do not really understand your objection.\n\n-- \nDag vijandelijk luchtschip de huismeester is dood\n"},{"id":"11153","messageId":"7v3bmct7i3.fsf@assigned-by-dhcp.cox.net","threadId":"2335","inReplyTo":"87ll049l8a.fsf@briny.internal.ondioline.org","subject":"Re: [PATCH] v2: proxy-command support for git://","fromName":"Junio C Hamano","fromEmail":"junkio@cox.net","sentAt":"2005-11-04T21:42:28Z","receivedAt":"2005-11-04T21:42:28Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Paul Collins <paul@briny.ondioline.org> writes:\n\n> But perhaps I do not really understand your objection.\n\nNo, I think you are getting it right.\n\nI just wanted to avoid using the proxy script for some hosts,\ndepending on where you are going.  Obviously you can teach the\nproxy script to do passthru for some hosts like you did in your\nmessage.  The only difference is where the configuration is\nspecified.  I wanted it to be in the git configuration file\n(i.e. using different proxy script or no script, depending on\nthe host).  Your example has that configuration wired in the\nsingle script that is always called regardless of the\ndestination, and the script itself switches how it proxies,\ndepending on where it is going, perhaps using its own\nconfiguration file or hardcoding.\n"},{"id":"11155","messageId":"87hdas9ijp.fsf@briny.internal.ondioline.org","threadId":"2335","inReplyTo":"7v3bmct7i3.fsf@assigned-by-dhcp.cox.net","subject":"Re: [PATCH] v2: proxy-command support for git://","fromName":"Paul Collins","fromEmail":"paul@briny.ondioline.org","sentAt":"2005-11-04T22:04:10Z","receivedAt":"2005-11-04T22:04:10Z","isPatch":true,"sender":{"key":"paul@briny.ondioline.org","avatar":null},"body":"Junio C Hamano <junkio@cox.net> writes:\n\n> Paul Collins <paul@briny.ondioline.org> writes:\n>\n>> But perhaps I do not really understand your objection.\n>\n> No, I think you are getting it right.\n>\n> I just wanted to avoid using the proxy script for some hosts,\n> depending on where you are going.  Obviously you can teach the\n> proxy script to do passthru for some hosts like you did in your\n> message.  The only difference is where the configuration is\n> specified.  I wanted it to be in the git configuration file\n> (i.e. using different proxy script or no script, depending on\n> the host).  Your example has that configuration wired in the\n> single script that is always called regardless of the\n> destination, and the script itself switches how it proxies,\n> depending on where it is going, perhaps using its own\n> configuration file or hardcoding.\n\nI had some ideas along those lines, but I didn't like any of them.\n\n * Extend the proxy-command \"protocol\" with a third argument, an\n   action.  For example if 'query $host $port' returns successfully,\n   then git should run it with arguments 'connect $host $port',\n   otherwise use git_tcp_connect().\n\n * Add a Proxy-Command field to the files in .git/remotes, e.g.:\n\n     URL: git://git.kernel.org/pub/scm/git/git.git/\n     Pull: master:origin\n     Proxy-command: my-git-proxy-command\n\n * If the git config syntax is extended to allow dots in section or\n   key names:\n\n     [proxy]\n     git.kernel.org = \"ssh-to-bastion-proxy-command\"\n     git.blargco.com = \"blargco-proxy-command\"\n\n   or perhaps\n\n     [git.kernel.org]\n     proxycommand = \"ssh-to-bastion-proxy-command\"\n     [git.blargco.com]\n     proxycommand = \"blargco-proxy-command\"\n\n-- \nDag vijandelijk luchtschip de huismeester is dood\n"},{"id":"11157","messageId":"Pine.LNX.4.64.0511041409180.28804@g5.osdl.org","threadId":"2335","inReplyTo":"87hdas9ijp.fsf@briny.internal.ondioline.org","subject":"Re: [PATCH] v2: proxy-command support for git://","fromName":"Linus Torvalds","fromEmail":"torvalds@osdl.org","sentAt":"2005-11-04T22:15:58Z","receivedAt":"2005-11-04T22:15:58Z","isPatch":true,"sender":{"key":"torvalds@linux-foundation.org","avatar":"https://avatars.githubusercontent.com/u/1024025?v=4"},"body":"\n\nOn Fri, 4 Nov 2005, Paul Collins wrote:\n> \n>  * If the git config syntax is extended to allow dots in section or\n>    key names:\n> \n>      [proxy]\n>      git.kernel.org = \"ssh-to-bastion-proxy-command\"\n>      git.blargco.com = \"blargco-proxy-command\"\n\nI would suggest\n\n\t[proxy]\n\t\tcommand = \"ssh-to-bastion-proxy-command\" for git.kernel.org\n\nand then it's easy enough to just parse the value \"proxy.command\" with \ncode like\n\n\thost = value;\n\tcmd = strstr(value, \" for \");\n\tif (!cmd)\n\t\treturn -1;\n\t*cmd = 0;\n\tcmd += 5;\n\nwhich would do the right thing..\n\nThe thing is, it's not just \".\". I could well imagine that you'd have\n\n\t[proxy]\n\t\tcommand=\"ssh\" for \"ssh://kernel.org/\"\n\t\tcommand=\"proxy-command\" for kernel.org\n\t\tcommand=\"myprotocol-command\" for \"my://\"\n\nwhich would actually allow you to literally add your own protocol names \n(it would see that the target starts with \"my://\", and decide that it \nshoul drun the \"myprotocol-command\" for the proxy).\n\nI'd rather allow free-form strings for the values than for the key names. \nIf we allow free-form key-names, then random text files suddenly often \nbecome valid (but strange) config files.\n\nRight now the non-free-form key names are the strongest syntax checker of \nthe whole protocol.\n\n\t\tLinus\n"},{"id":"12323","messageId":"7vd5kw6djy.fsf_-_@assigned-by-dhcp.cox.net","threadId":"2335","inReplyTo":"871x1wbgvn.fsf_-_@briny.internal.ondioline.org","subject":"[PATCH] git-proxy updates.","fromName":"Junio C Hamano","fromEmail":"junkio@cox.net","sentAt":"2005-11-19T12:13:21Z","receivedAt":"2005-11-19T12:13:21Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Paul Collins <paul@briny.ondioline.org> writes:\n\n> Here is an updated patch that first looks for GIT_PROXY_COMMAND in the\n> environment and then git.proxycommand in the repository's\n> configuration file.\n\nSorry for holding onto your patch without any action (other than\nlooking at it, which from your end you cannot tell I was doing\n;-).  I think we will benefit from your patch in some form, and\nhere is what I tried on top to update it to the multivalue\nconfiguration syntax Linus suggested during the list discussion.\nRequesting for comments the original author and from the general\npublic.\n\nI suspect this touches the same area as the user-path series\nAndreas Ericsson has been working on, so it might need some\nadjusting after that patch series goes in.  I'll see that soon\nenough when I make the proposed updates branch tomorrow.\n\n -- >8 --\n\nThis builds on top of the git-proxy mechanism Paul Collins did,\nand updates its configuration mechanism.\n\n * GIT_PROXY_COMMAND environment variable is used as the\n   catch-all fallback, as in the original.  This has not\n   changed.\n\n * Renames proxy configuration variables to core.gitproxy; this\n   has become a multi-value variable per list discussion, most\n   notably from suggestion by Linus.\n\n\t[core]\n\t;# matches www.kernel.org as well\n\tgitproxy = netcatter for kernel.org\n\tgitproxy = netscatter for sample.xz\n\tgitproxy = none for mydomain.xz\n\tgitproxy = netcatter-default\n\n   The values are command names, followed by an optional \" for \"\n   and domainname; the first tail-match of the domainname\n   determines which proxy command is used.  An entry without \"\n   for \" matches any domain and can be used as the default.\n\n   The command name \"none\" is special -- it tells the mechanism\n   not to use any proxy command and use the native git://\n   connection.\n\nSigned-off-by: Junio C Hamano <junkio@cox.net>\n\n---\n\n connect.c |   52 +++++++++++++++++++++++++++++++++++++++++++++-------\n 1 files changed, 45 insertions(+), 7 deletions(-)\n\napplies-to: d4a5ace05fd892cb455f330d379cdaa69dc6005c\nc1d7ac7b4680202d3549a72188f372367ac8837c\ndiff --git a/connect.c b/connect.c\nindex 43eec67..11a804f 100644\n--- a/connect.c\n+++ b/connect.c\n@@ -449,25 +449,63 @@ static int git_tcp_connect(int fd[2], co\n #endif /* NO_IPV6 */\n \n static char *git_proxy_command = NULL;\n+static const char *rhost_name = NULL;\n+static int rhost_len;\n \n static int git_proxy_command_options(const char *var, const char *value)\n {\n-\tif (git_proxy_command == NULL) {\n-\t\tif (!strcmp(var, \"git.proxycommand\")) {\n-\t\t\tgit_proxy_command = xmalloc(strlen(value) + 1);\n-\t\t\tstrcpy(git_proxy_command, value);\n+\tif (!strcmp(var, \"core.gitproxy\")) {\n+\t\tif (git_proxy_command)\n \t\t\treturn 0;\n+\t\t/* [core]\n+\t\t * ;# matches www.kernel.org as well\n+\t\t * gitproxy = netcatter-1 for kernel.org\n+\t\t * gitproxy = netcatter-2 for sample.xz\n+\t\t * gitproxy = netcatter-default\n+\t\t */\n+\t\tconst char *for_pos = strstr(value, \" for \");\n+\t\tint matchlen = -1;\n+\t\tint hostlen;\n+\n+\t\tif (!for_pos)\n+\t\t\t/* matches everybody */\n+\t\t\tmatchlen = strlen(value);\n+\t\telse {\n+\t\t\thostlen = strlen(for_pos + 5);\n+\t\t\tif (rhost_len < hostlen)\n+\t\t\t\tmatchlen = -1;\n+\t\t\telse if (!strncmp(for_pos + 5,\n+\t\t\t\t\t  rhost_name + rhost_len - hostlen,\n+\t\t\t\t\t  hostlen) &&\n+\t\t\t\t ((rhost_len == hostlen) ||\n+\t\t\t\t  rhost_name[rhost_len - hostlen -1] == '.'))\n+\t\t\t\tmatchlen = for_pos - value;\n+\t\t\telse\n+\t\t\t\tmatchlen = -1;\n+\t\t}\n+\t\tif (0 <= matchlen) {\n+\t\t\t/* core.gitproxy = none for kernel.org */\n+\t\t\tif (matchlen == 4 && \n+\t\t\t    !memcmp(value, \"none\", 4))\n+\t\t\t\tmatchlen = 0;\n+\t\t\tgit_proxy_command = xmalloc(matchlen + 1);\n+\t\t\tmemcpy(git_proxy_command, value, matchlen);\n+\t\t\tgit_proxy_command[matchlen] = 0;\n \t\t}\n+\t\treturn 0;\n \t}\n \n \treturn git_default_config(var, value);\n }\n \n-static int git_use_proxy(void)\n+static int git_use_proxy(const char *host)\n {\n+\trhost_name = host;\n+\trhost_len = strlen(host);\n \tgit_proxy_command = getenv(\"GIT_PROXY_COMMAND\");\n \tgit_config(git_proxy_command_options);\n-\treturn git_proxy_command != NULL;\n+\trhost_name = NULL;\n+\treturn (git_proxy_command && *git_proxy_command);\n }\n \n static int git_proxy_connect(int fd[2], const char *prog, char *host, char *path)\n@@ -550,7 +588,7 @@ int git_connect(int fd[2], char *url, co\n \t}\n \n \tif (protocol == PROTO_GIT) {\n-\t\tif (git_use_proxy())\n+\t\tif (git_use_proxy(host))\n \t\t\treturn git_proxy_connect(fd, prog, host, path);\n \t\treturn git_tcp_connect(fd, prog, host, path);\n \t}\n---\n0.99.9.GIT\n \n"}]}