{"thread":{"id":"23965","subject":"http-smart-backend: can clone, cannot push","startedAt":"2010-06-01T12:28:21Z","lastAt":"2010-06-02T15:16:24Z","messageCount":9,"participants":["Jeremiah Foster","Tay Ray Chuan","Shawn O. Pearce","Erik Faye-Lund","Antonio García Domínguez"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"142678","messageId":"E66CC81A-CCED-4D8E-AE7C-C02FB0AF6F6C@pelagicore.com","threadId":"23965","inReplyTo":null,"subject":"http-smart-backend: can clone, cannot push","fromName":"Jeremiah Foster","fromEmail":"jeremiah.foster@pelagicore.com","sentAt":"2010-06-01T12:28:21Z","receivedAt":"2010-06-01T12:28:21Z","isPatch":false,"sender":{"key":"jeremiah.foster@pelagicore.com","avatar":"https://gravatar.com/avatar/f107bff0d3617df3e171850d6ae81df4acb6767072fe7435a8c9f22b3824e5bd?d=mp&s=160"},"body":"Hello,\n\n\tI've set up a directory to serve git repos under /var/www/git using:\n\n\t- apache2\n\t- git 1.7.1\n\t\n\tThe apache config file is literally pasted from the http-smart-backend documentation, modified for my installation. I clone successfully over https using the smart backend. I know this because when you use the smart backend you get this type of message:\n\n\tgit clone https://git.pelagicore.net/var/www/git/administrivia.git\n\tInitialized empty Git repository in /home/jeremiah/administrivia/.git/\n\tremote: Counting objects: 69, done.\n\tremote: Compressing objects: 100% (47/47), done.\n\tremote: Total 69 (delta 15), reused 0 (delta 0)\n\tUnpacking objects: 100% (69/69), done.\n\n\tAs opposed to a more terse message when using a 'dumb' http transport.\n\n\tI cannot push however. This is what git says:\n\t\n\t$ ~/administrivia >  git push origin master\n\terror: Cannot access URL https://git.pelagicore.net/var/www/git/administrivia.git/, return code 22\n\tfatal: git-http-push failed\n\n\tAnd this is what the logs say:\n\n\t[Tue Jun 01 14:25:54 2010] [error] [client 109.74.195.212] Request not supported: '/var/www/git/administrivia.git/'\n\n\tHow is that I can clone with the smart transport, and not push?\n\nThanks,\n\nJeremiah"},{"id":"142679","messageId":"AANLkTimqncJ7aqi_0AvjNimyIPsbVN1zSkAQ1LrPhwne@mail.gmail.com","threadId":"23965","inReplyTo":"E66CC81A-CCED-4D8E-AE7C-C02FB0AF6F6C@pelagicore.com","subject":"Re: http-smart-backend: can clone, cannot push","fromName":"Tay Ray Chuan","fromEmail":"rctay89@gmail.com","sentAt":"2010-06-01T13:15:45Z","receivedAt":"2010-06-01T13:15:45Z","isPatch":false,"sender":{"key":"rctay89@gmail.com","avatar":"https://avatars.githubusercontent.com/u/61553?v=4"},"body":"On Tue, Jun 1, 2010 at 8:28 PM, Jeremiah Foster\n<jeremiah.foster@pelagicore.com> wrote:\n>        I cannot push however. This is what git says:\n>\n>        $ ~/administrivia >  git push origin master\n>        error: Cannot access URL https://git.pelagicore.net/var/www/git/administrivia.git/, return code 22\n>        fatal: git-http-push failed\n\nCan you paste the output for\n\n  $ GIT_CURL_VERBOSE=1 git push origin master\n\n-- \nCheers,\nRay Chuan\n"},{"id":"142694","messageId":"B61D22CA-45BA-49DA-984B-A7F7090FAE55@pelagicore.com","threadId":"23965","inReplyTo":"AANLkTimqncJ7aqi_0AvjNimyIPsbVN1zSkAQ1LrPhwne@mail.gmail.com","subject":"Re: http-smart-backend: can clone, cannot push","fromName":"Jeremiah Foster","fromEmail":"jeremiah.foster@pelagicore.com","sentAt":"2010-06-01T15:24:25Z","receivedAt":"2010-06-01T15:24:25Z","isPatch":false,"sender":{"key":"jeremiah.foster@pelagicore.com","avatar":"https://gravatar.com/avatar/f107bff0d3617df3e171850d6ae81df4acb6767072fe7435a8c9f22b3824e5bd?d=mp&s=160"},"body":"\nOn Jun 1, 2010, at 15:15, Tay Ray Chuan wrote:\n\n> On Tue, Jun 1, 2010 at 8:28 PM, Jeremiah Foster\n> <jeremiah.foster@pelagicore.com> wrote:\n>>        I cannot push however. This is what git says:\n>> \n>>        $ ~/administrivia >  git push origin master\n>>        error: Cannot access URL https://git.pelagicore.net/var/www/git/administrivia.git/, return code 22\n>>        fatal: git-http-push failed\n> \n> Can you paste the output for\n> \n>  $ GIT_CURL_VERBOSE=1 git push origin master\n\nThis is the output :\n\n   GIT_CURL_VERBOSE=1 git push origin master\n* About to connect() to git.pelagicore.net port 443 (#0)\n*   Trying 109.74.195.212... * connected\n* Connected to git.pelagicore.net (109.74.195.212) port 443 (#0)\n* found 142 certificates in /etc/ssl/certs/ca-certificates.crt\n*        server certificate verification SKIPPED\n*        common name: www.pelagicore.net (does not match 'git.pelagicore.net')\n*        server certificate expiration date OK\n*        server certificate activation date OK\n*        certificate public key: RSA\n*        certificate version: #1\n*        subject: CN=www.pelagicore.net\n*        start date: Mon, 08 Feb 2010 13:49:15 GMT\n*        expire date: Thu, 06 Feb 2020 13:49:15 GMT\n*        issuer: CN=www.pelagicore.net\n*        compression: NULL\n*        cipher: AES-128-CBC\n*        MAC: SHA1\n> GET /var/www/git/administrivia.git/info/refs?service=git-receive-pack HTTP/1.1\nUser-Agent: git/1.7.1\nHost: git.pelagicore.net\nAccept: */*\nPragma: no-cache\n\n* The requested URL returned error: 403\n* Closing connection #0\n* About to connect() to git.pelagicore.net port 443 (#0)\n*   Trying 109.74.195.212... * connected\n* Connected to git.pelagicore.net (109.74.195.212) port 443 (#0)\n* found 142 certificates in /etc/ssl/certs/ca-certificates.crt\n* SSL re-using session ID\n*        server certificate verification SKIPPED\n*        common name: www.pelagicore.net (does not match 'git.pelagicore.net')\n*        server certificate expiration date OK\n*        server certificate activation date OK\n*        certificate public key: RSA\n*        certificate version: #1\n*        subject: CN=www.pelagicore.net\n*        start date: Mon, 08 Feb 2010 13:49:15 GMT\n*        expire date: Thu, 06 Feb 2020 13:49:15 GMT\n*        issuer: CN=www.pelagicore.net\n*        compression: NULL\n*        cipher: AES-128-CBC\n*        MAC: SHA1\n> GET /var/www/git/administrivia.git/info/refs HTTP/1.1\nUser-Agent: git/1.7.1\nHost: git.pelagicore.net\nAccept: */*\nPragma: no-cache\n\n< HTTP/1.1 200 OK\n< Date: Tue, 01 Jun 2010 13:41:02 GMT\n< Server: Apache/2.2.15 (Debian)\n< Expires: Fri, 01 Jan 1980 00:00:00 GMT\n< Pragma: no-cache\n< Cache-Control: no-cache, max-age=0, must-revalidate\n< Content-Length: 59\n< Vary: Accept-Encoding\n< Content-Type: text/plain\n< \n* Connection #0 to host git.pelagicore.net left intact\n* Re-using existing connection! (#0) with host git.pelagicore.net\n* Connected to git.pelagicore.net (109.74.195.212) port 443 (#0)\n> GET /var/www/git/administrivia.git/HEAD HTTP/1.1\nUser-Agent: git/1.7.1\nHost: git.pelagicore.net\nAccept: */*\nPragma: no-cache\n\n< HTTP/1.1 200 OK\n< Date: Tue, 01 Jun 2010 13:41:03 GMT\n< Server: Apache/2.2.15 (Debian)\n< Expires: Fri, 01 Jan 1980 00:00:00 GMT\n< Pragma: no-cache\n< Cache-Control: no-cache, max-age=0, must-revalidate\n< Content-Length: 23\n< Last-Modified: Tue, 01 Jun 2010 08:29:13 GMT\n< Vary: Accept-Encoding\n< Content-Type: text/plain\n< \n* Connection #0 to host git.pelagicore.net left intact\n* About to connect() to git.pelagicore.net port 443 (#0)\n*   Trying 109.74.195.212... * connected\n* Connected to git.pelagicore.net (109.74.195.212) port 443 (#0)\n* found 142 certificates in /etc/ssl/certs/ca-certificates.crt\n*        server certificate verification SKIPPED\n*        common name: www.pelagicore.net (does not match 'git.pelagicore.net')\n*        server certificate expiration date OK\n*        server certificate activation date OK\n*        certificate public key: RSA\n*        certificate version: #1\n*        subject: CN=www.pelagicore.net\n*        start date: Mon, 08 Feb 2010 13:49:15 GMT\n*        expire date: Thu, 06 Feb 2020 13:49:15 GMT\n*        issuer: CN=www.pelagicore.net\n*        compression: NULL\n*        cipher: AES-128-CBC\n*        MAC: SHA1\n> PROPFIND /var/www/git/administrivia.git/ HTTP/1.1\nUser-Agent: git/1.7.1\nHost: git.pelagicore.net\nAccept: */*\nDepth: 0\nContent-Type: text/xml\nContent-Length: 187\nExpect: 100-continue\n\n< HTTP/1.1 100 Continue\n* The requested URL returned error: 404\n* Closing connection #0\nerror: Cannot access URL https://git.pelagicore.net/var/www/git/administrivia.git/, return code 22\nfatal: git-http-push failed\n"},{"id":"142697","messageId":"AANLkTin43VO3FA9dEjAx9w6FRwLK7FpqqO5rA6wKFZgn@mail.gmail.com","threadId":"23965","inReplyTo":"B61D22CA-45BA-49DA-984B-A7F7090FAE55@pelagicore.com","subject":"Re: http-smart-backend: can clone, cannot push","fromName":"Tay Ray Chuan","fromEmail":"rctay89@gmail.com","sentAt":"2010-06-01T15:40:32Z","receivedAt":"2010-06-01T15:40:32Z","isPatch":false,"sender":{"key":"rctay89@gmail.com","avatar":"https://avatars.githubusercontent.com/u/61553?v=4"},"body":"Hi,\n\nOn Tue, Jun 1, 2010 at 11:24 PM, Jeremiah Foster\n<jeremiah.foster@pelagicore.com> wrote:\n>   GIT_CURL_VERBOSE=1 git push origin master\n> * About to connect() to git.pelagicore.net port 443 (#0)\n> *   Trying 109.74.195.212... * connected\n> * Connected to git.pelagicore.net (109.74.195.212) port 443 (#0)\n> * found 142 certificates in /etc/ssl/certs/ca-certificates.crt\n> *        server certificate verification SKIPPED\n> *        common name: www.pelagicore.net (does not match 'git.pelagicore.net')\n> *        server certificate expiration date OK\n> *        server certificate activation date OK\n> *        certificate public key: RSA\n> *        certificate version: #1\n> *        subject: CN=www.pelagicore.net\n> *        start date: Mon, 08 Feb 2010 13:49:15 GMT\n> *        expire date: Thu, 06 Feb 2020 13:49:15 GMT\n> *        issuer: CN=www.pelagicore.net\n> *        compression: NULL\n> *        cipher: AES-128-CBC\n> *        MAC: SHA1\n>> GET /var/www/git/administrivia.git/info/refs?service=git-receive-pack HTTP/1.1\n> User-Agent: git/1.7.1\n> Host: git.pelagicore.net\n> Accept: */*\n> Pragma: no-cache\n>\n> * The requested URL returned error: 403\n\nYou're getting a 403 Forbidden here. What authentication method were\nyou expecting?\n\nFYI, after this, the requests show that git is falling back to the\n\"dumb\"/WebDAV protocol, which the server doesn't seem to support.\n\n-- \nCheers,\nRay Chuan\n"},{"id":"142699","messageId":"3A4DAEA3-C7F4-4163-9ABA-37443BB025AB@pelagicore.com","threadId":"23965","inReplyTo":"AANLkTin43VO3FA9dEjAx9w6FRwLK7FpqqO5rA6wKFZgn@mail.gmail.com","subject":"Re: http-smart-backend: can clone, cannot push","fromName":"Jeremiah Foster","fromEmail":"jeremiah.foster@pelagicore.com","sentAt":"2010-06-01T15:53:59Z","receivedAt":"2010-06-01T15:53:59Z","isPatch":false,"sender":{"key":"jeremiah.foster@pelagicore.com","avatar":"https://gravatar.com/avatar/f107bff0d3617df3e171850d6ae81df4acb6767072fe7435a8c9f22b3824e5bd?d=mp&s=160"},"body":"\nOn Jun 1, 2010, at 17:40, Tay Ray Chuan wrote:\n> \n> On Tue, Jun 1, 2010 at 11:24 PM, Jeremiah Foster\n> <jeremiah.foster@pelagicore.com> wrote:\n>> \n>> * The requested URL returned error: 403\n> \n> You're getting a 403 Forbidden here. What authentication method were\n> you expecting?\n\nI thought that by exporting \"GIT_SSL_NO_VERIFY=true\" that it would not matter.\n> \n> FYI, after this, the requests show that git is falling back to the\n> \"dumb\"/WebDAV protocol, which the server doesn't seem to support.\n\nYeah, I can see in the logs that it is calling PROPFIND, which is clearly a webDav command. The weird thing is that I know this repo is checked out of a smart http transport dir, at least when I clone it. I don't understand how I could have set it up correctly for cloning and then not be able to push properly back. \n\nMaybe I _have_ to be authenticated since the documentation states:  \"If the client is authenticated, thereceive-pack service is enabled, which serves git send-pack clients, which is invoked from git push.\" \n\nJeremiah\n"},{"id":"142700","messageId":"20100601155833.GT16470@spearce.org","threadId":"23965","inReplyTo":"3A4DAEA3-C7F4-4163-9ABA-37443BB025AB@pelagicore.com","subject":"Re: http-smart-backend: can clone, cannot push","fromName":"Shawn O. Pearce","fromEmail":"spearce@spearce.org","sentAt":"2010-06-01T15:58:33Z","receivedAt":"2010-06-01T15:58:33Z","isPatch":false,"sender":{"key":"spearce@spearce.org","avatar":"https://avatars.githubusercontent.com/u/34844?v=4"},"body":"Jeremiah Foster <jeremiah.foster@pelagicore.com> wrote:\n> Maybe I _have_ to be authenticated since the documentation states:\n> \"If the client is authenticated, thereceive-pack service is enabled,\n> which serves git send-pack clients, which is invoked from git push.\"\n\nYes.\n\nA flaw of the smart HTTP transport is the servers are\nnearly impossible to configure for anonymous clone and\nauthenticated push via the same URL.  The servers just\ncan't seem to be configured to require authentication\nfor the $GIT_DIR/info/refs?service=git-receive-pack request.\n\n-- \nShawn.\n"},{"id":"142701","messageId":"AANLkTil5od-DIaK5H5UCxS2CCwGRnr2vQCfn167_PjXP@mail.gmail.com","threadId":"23965","inReplyTo":"3A4DAEA3-C7F4-4163-9ABA-37443BB025AB@pelagicore.com","subject":"Re: http-smart-backend: can clone, cannot push","fromName":"Erik Faye-Lund","fromEmail":"kusmabite@googlemail.com","sentAt":"2010-06-01T15:59:00Z","receivedAt":"2010-06-01T15:59:00Z","isPatch":false,"sender":{"key":"kusmabite@gmail.com","avatar":"https://avatars.githubusercontent.com/u/47073?v=4"},"body":"On Tue, Jun 1, 2010 at 5:53 PM, Jeremiah Foster\n<jeremiah.foster@pelagicore.com> wrote:\n>\n> On Jun 1, 2010, at 17:40, Tay Ray Chuan wrote:\n>>\n>> On Tue, Jun 1, 2010 at 11:24 PM, Jeremiah Foster\n>> <jeremiah.foster@pelagicore.com> wrote:\n>>>\n>>> * The requested URL returned error: 403\n>>\n>> You're getting a 403 Forbidden here. What authentication method were\n>> you expecting?\n>\n> I thought that by exporting \"GIT_SSL_NO_VERIFY=true\" that it would not matter.\n\nThis is about not verifying the SSL certificate, not the user.\n\n-- \nErik \"kusma\" Faye-Lund\n"},{"id":"142713","messageId":"201006011900.01926.antonio.garciadominguez@uca.es","threadId":"23965","inReplyTo":"20100601155833.GT16470@spearce.org","subject":"Re: http-smart-backend: can clone, cannot push","fromName":"Antonio García Domínguez","fromEmail":"antonio.garciadominguez@uca.es","sentAt":"2010-06-01T16:59:58Z","receivedAt":"2010-06-01T16:59:58Z","isPatch":false,"sender":{"key":"antonio.garciadominguez@uca.es","avatar":null},"body":"Hi all,\n\n> A flaw of the smart HTTP transport is the servers are\n> nearly impossible to configure for anonymous clone and\n> authenticated push via the same URL.  The servers just\n> can't seem to be configured to require authentication\n> for the $GIT_DIR/info/refs?service=git-receive-pack request.\n\nYeah, the problem seems to be that query string. Apache's <Location> doesn't \nhelp with that. However, you could add a custom authentication handler which \nchecks the query part of the URL, right?\n\n<shameless plug>\nIn fact, I submitted a patch which adds smart HTTP integration to Redmine's \nPerl auth module at [1] and does just this. I've tested on a server I set up \nat my uni, and pretty much nowhere else :-/. Lines 250-254 should do just \nthat: check the unparsed URI (possibly including the query string) for git-\nreceive-pack at the end. That includes .../git-receive-pack and \n.../refs?service=git-receive-pack.\n\nPerhaps you could take just the parts you need from the patched Redmine.pm \nfile.\n</shameless plug>\n\nAnother option could be using RewriteCond to set an environment variable \ndepending on REQUEST_URI and QUERY_STRING [2] and use \"Allow from env=...\" \n[3]. I think it should be simpler than writing and installing an \nauthentication handler, but I'm not sure, either. I'm mostly limited to Apache \nhere: perhaps it can be easier with other web servers.\n\n[1]: http://www.redmine.org/attachments/3300/0001-Redmine.pm-add-Git-smart-\nHTTP-support-v4.patch\n[2]: http://www.phwinfo.com/forum/alt-apache-configuration/329880-regular-\nexpressions-locationmatch.html#post1483835\n[3]: http://httpd.apache.org/docs/2.2/mod/mod_authz_host.html#allow\n\nRegards,\nAntonio\n"},{"id":"142825","messageId":"825A1E57-48AE-4BA5-AD5C-431DA8E959DA@pelagicore.com","threadId":"23965","inReplyTo":"20100601155833.GT16470@spearce.org","subject":"Re: http-smart-backend: can clone, cannot push","fromName":"Jeremiah Foster","fromEmail":"jeremiah.foster@pelagicore.com","sentAt":"2010-06-02T15:16:24Z","receivedAt":"2010-06-02T15:16:24Z","isPatch":false,"sender":{"key":"jeremiah.foster@pelagicore.com","avatar":"https://gravatar.com/avatar/f107bff0d3617df3e171850d6ae81df4acb6767072fe7435a8c9f22b3824e5bd?d=mp&s=160"},"body":"\nOn Jun 1, 2010, at 17:58, Shawn O. Pearce wrote:\n\nThanks Shawn, and everyone else who commented on this thread - I appreciate the help.\n\n> Jeremiah Foster <jeremiah.foster@pelagicore.com> wrote:\n>> Maybe I _have_ to be authenticated since the documentation states:\n>> \"If the client is authenticated, thereceive-pack service is enabled,\n>> which serves git send-pack clients, which is invoked from git push.\"\n> \n> Yes.\n> \n> A flaw of the smart HTTP transport is the servers are\n> nearly impossible to configure for anonymous clone and\n> authenticated push via the same URL.  The servers just\n> can't seem to be configured to require authentication\n> for the $GIT_DIR/info/refs?service=git-receive-pack request.\n\nI created a system to authenticate and then I could push and pull with the same URL. Thanks again for the help and I'm going to try to write up a short blog post about using this because I think it is a really great way to share git repos.\n\nJeremiah\n"}]}