{"thread":{"id":"4165","subject":"Fwd: [OT] Re: Git via a proxy server?","startedAt":"2006-05-16T12:13:56Z","lastAt":"2006-05-18T08:31:32Z","messageCount":7,"participants":["Sam Song","Petr Vandrovec","Jan-Benedict Glaw"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"20063","messageId":"20060516121356.11646.qmail@web32002.mail.mud.yahoo.com","threadId":"4165","inReplyTo":null,"subject":"Fwd: [OT] Re: Git via a proxy server?","fromName":"Sam Song","fromEmail":"samlinuxkernel@yahoo.com","sentAt":"2006-05-16T12:13:56Z","receivedAt":"2006-05-16T12:13:56Z","isPatch":false,"sender":{"key":"samlinuxkernel@yahoo.com","avatar":null},"body":"Hello,\n\nPetr Vandrovec <petr@vmware.com> wrote:\n> Date:\tMon, 27 Feb 2006 00:35:00 +0100\n> From:\tPetr Vandrovec <petr@vmware.com>\n> To:\tSergey Vlasov <vsu@altlinux.ru>\n> CC:\t\"Salyzyn, Mark\" <mark_salyzyn@adaptec.com>,\n> \tKernel Mailing List \n> <linux-kernel@vger.kernel.org>\n> > [snip]\n> > I have successfully used transconnect\n> > (http://sourceforge.net/projects/transconnect) for\n> > tunnelling git\n> > protocol through a HTTP proxy (squid in my case)\n> > supporting the CONNECT method.\n> >\n> > [snip] \n> > Note: most HTTP proxy servers allow CONNECT method\n> > to a very limited range of ports, and \n> > administrators will need to enable the git port\n> > (9418) explicitly.\n> > \n> I know I'm coming kinda late, but I'm using:\n> \n> export GIT_PROXY_COMMAND=/usr/local/bin/proxy-cmd.sh\n> \n> and proxy-cmd.sh is just single-line command glued\n> from what I found available in /bin:\n> \n> #! /bin/bash\n> \n> (echo \"CONNECT $1:$2 HTTP/1.0\"; echo; cat ) | socket\n> \n> proxy.ourcompany.com 3128 | (read a; read a; cat )\n> \n> Replace socket's arguments 'proxy.ourcompany.com\n> 3128' with your http proxy.  Fortunately our proxy\n> does not see anything wrong with git's port.\n> \t\tBest regards,\n> \t\t\tPetr Vandrovec\n\nWith above usage on GIT_PROXY_COMMAND, I still have\nproblem on connection with remote git repository.\n\nI also tried setting http_proxy directly but the same\nresult. It's first usage of git in our network. Well, \nneed I enable the git port 9418 at proxy server? Or \ndid I miss sth or what?\n\nI use git-2006-05-14.tar.gz package on FC3. \n\nMethod I : Use GIT_PROXY_COMMAND\n\n[root@sam u-boot]# git clone \\\ngit://www.denx.de/git/u-boot.git u-boot-denx.git\n\nfatal: exec failed\nfetch-pack from 'git://www.denx.de/git/u-boot.git' \nfailed.\n\n[root@sam u-boot]# git clone \\\nhttp://parisc-linux.org/git/linux-2.6.git/ parisc-2.6\n\nCannot get remote repository information.\nPerhaps git-update-server-info needs to be run there?\n[root@sam u-boot]#\n\n/usr/local/bin/proxy-cmd.sh \n\n#! /bin/bash\n\n(echo \"CONNECT $1:$2 HTTP/1.0\";echo;cat) | socket\n<um> <pwd> 192.168.40.99 80 | (read a;read a;cat)\n\nMethod II : Use http_proxy directly\n\n[root@sam u-boot]# export \\\nhttp_proxy=\"http://<username>:<pwd>@192.168.40.99:80\"\n[root@sam u-boot]# git clone \\ \nhttp://parisc-linux.org/git/linux-2.6.git/ parisc-2.6\n\nCannot get remote repository information.\nPerhaps git-update-server-info needs to be run there?\n\n[root@sam u-boot]# git clone \\\ngit://www.denx.de/git/u-boot.git u-boot-denx.git\nfatal: unable to connect a socket (Connection timed \nout)\nfetch-pack from 'git://www.denx.de/git/u-boot.git' \nfailed.\n[root@sam u-boot]#\n\nThanks in advance,\n\nSam\n\nP.S. I forward this thread from LKML for better \ndiscussion. Hope Petr wouldn't mind.\n\n__________________________________________________\nDo You Yahoo!?\nTired of spam?  Yahoo! Mail has the best spam\nprotection around \nhttp://mail.yahoo.com \n\n__________________________________________________\nDo You Yahoo!?\nTired of spam?  Yahoo! Mail has the best spam protection around \nhttp://mail.yahoo.com \n"},{"id":"20064","messageId":"4469CF92.2010002@vmware.com","threadId":"4165","inReplyTo":"20060516121356.11646.qmail@web32002.mail.mud.yahoo.com","subject":"Re: Fwd: [OT] Re: Git via a proxy server?","fromName":"Petr Vandrovec","fromEmail":"petr@vmware.com","sentAt":"2006-05-16T13:11:46Z","receivedAt":"2006-05-16T13:11:46Z","isPatch":false,"sender":{"key":"petr@vmware.com","avatar":null},"body":"Sam Song wrote:\n> Hello,\n> \n> Petr Vandrovec <petr@vmware.com> wrote:\n> \n>>Date:\tMon, 27 Feb 2006 00:35:00 +0100\n>>From:\tPetr Vandrovec <petr@vmware.com>\n>>To:\tSergey Vlasov <vsu@altlinux.ru>\n>>CC:\t\"Salyzyn, Mark\" <mark_salyzyn@adaptec.com>,\n>>\tKernel Mailing List \n>><linux-kernel@vger.kernel.org>\n>>\n>>>[snip]\n>>>I have successfully used transconnect\n>>>(http://sourceforge.net/projects/transconnect) for\n>>>tunnelling git\n>>>protocol through a HTTP proxy (squid in my case)\n>>>supporting the CONNECT method.\n>>>\n>>>[snip] \n>>>Note: most HTTP proxy servers allow CONNECT method\n>>>to a very limited range of ports, and \n>>>administrators will need to enable the git port\n>>>(9418) explicitly.\n>>>\n>>\n>>I know I'm coming kinda late, but I'm using:\n>>\n>>export GIT_PROXY_COMMAND=/usr/local/bin/proxy-cmd.sh\n>>\n>>and proxy-cmd.sh is just single-line command glued\n>>from what I found available in /bin:\n>>\n>>#! /bin/bash\n>>\n>>(echo \"CONNECT $1:$2 HTTP/1.0\"; echo; cat ) | socket\n>>\n>>proxy.ourcompany.com 3128 | (read a; read a; cat )\n>>\n>>Replace socket's arguments 'proxy.ourcompany.com\n>>3128' with your http proxy.  Fortunately our proxy\n>>does not see anything wrong with git's port.\n>>\t\tBest regards,\n>>\t\t\tPetr Vandrovec\n> \n> \n> With above usage on GIT_PROXY_COMMAND, I still have\n> problem on connection with remote git repository.\n> \n> I also tried setting http_proxy directly but the same\n> result. It's first usage of git in our network. Well, \n> need I enable the git port 9418 at proxy server? Or \n> did I miss sth or what?\n\nYes.  Try running 'socket 192.168.40.99 80', and type\nCONNECT 204.152.191.37:9418 HTTP/1.0\nProxy-Authorization: Basic <yoursecret,f.e.wget -d should reveal this to you>\n<empty line>\n\nYou should get back user readable diagnostics what went wrong.  Yes, your admin \nmust allow CONNECT method for target port 9418.\n\n> I use git-2006-05-14.tar.gz package on FC3. \n> \n> Method I : Use GIT_PROXY_COMMAND\n> \n> [root@sam u-boot]# git clone \\\n> git://www.denx.de/git/u-boot.git u-boot-denx.git\n> \n> fatal: exec failed\n> fetch-pack from 'git://www.denx.de/git/u-boot.git' \n> failed.\n\nIs $GIT_PROXY_COMMAND executable? (just in case...)  Try 'strace -f git clone \n...', it should tell you what's going on.\n\n> #! /bin/bash\n> \n> (echo \"CONNECT $1:$2 HTTP/1.0\";echo;cat) | socket\n> <um> <pwd> 192.168.40.99 80 | (read a;read a;cat)\n\nWhat is '<um>' and '<pwd>' ?  socket just connects somewhere, so if you are \nsupposed to use <username>:<pwd> to connect to your proxy, you must add \nProxy-Authorization header yourself:\n\n(echo \"CONNECT $1:$2 HTTP/1.0\";\n  echo \"Proxy-Authorization: Basic <base64encoded um:pwd>\";\n  echo;\n  cat ) | socket 192.168.40.99 80 | (read a; read a; cat)\n\nBest to test this is to start 'socket 192.168.40.99 80' from command line and \nthen type these two lines above, plus one empty line.  You should get back '200 \nOK', empty line, and then you can start communicating using git protocol - if \nyou can do that...\n\n> Method II : Use http_proxy directly\n> \n> [root@sam u-boot]# export \\\n> http_proxy=\"http://<username>:<pwd>@192.168.40.99:80\"\n> [root@sam u-boot]# git clone \\ \n> http://parisc-linux.org/git/linux-2.6.git/ parisc-2.6\n\nAs far as I can tell, http_proxy is ignored (Debian's git 1.3.2-1/cogito 0.17.2-1).\n\t\t\t\t\t\t\t\tPetr\n"},{"id":"20103","messageId":"20060517035639.40450.qmail@web32004.mail.mud.yahoo.com","threadId":"4165","inReplyTo":"4469CF92.2010002@vmware.com","subject":"Re: Fwd: [OT] Re: Git via a proxy server?","fromName":"Sam Song","fromEmail":"samlinuxkernel@yahoo.com","sentAt":"2006-05-17T03:56:39Z","receivedAt":"2006-05-17T03:56:39Z","isPatch":false,"sender":{"key":"samlinuxkernel@yahoo.com","avatar":null},"body":"Petr Vandrovec <petr@vmware.com> wrote:\n> Best to test this is to start 'socket 192.168.40.99\n> 80' from command line and \n> then type these two lines above, plus one empty\n> line.  You should get back '200 \n> OK', empty line, and then you can start\n> communicating using git protocol - if \n> you can do that...\n\nI cannot run \"socket\" and \"CONNECT\" on Fedora Core 3.\nIt simply told me that no such command. How could I \ndo this task in my case?\n\n> As far as I can tell, http_proxy is ignored\n> (Debian's git 1.3.2-1/cogito 0.17.2-1).\n\nSeems you tried proxy-cmd.sh on Debian. Which \ndistribution did you use? \n\nThanks a lot,\n\nSam\n\n\n__________________________________________________\nDo You Yahoo!?\nTired of spam?  Yahoo! Mail has the best spam protection around \nhttp://mail.yahoo.com \n"},{"id":"20115","messageId":"20060517083845.GC23642@lug-owl.de","threadId":"4165","inReplyTo":"20060517035639.40450.qmail@web32004.mail.mud.yahoo.com","subject":"Re: Fwd: [OT] Re: Git via a proxy server?","fromName":"Jan-Benedict Glaw","fromEmail":"jbglaw@lug-owl.de","sentAt":"2006-05-17T08:38:45Z","receivedAt":"2006-05-17T08:38:45Z","isPatch":false,"sender":{"key":"jbglaw@lug-owl.de","avatar":null},"body":"On Tue, 2006-05-16 20:56:39 -0700, Sam Song <samlinuxkernel@yahoo.com> wrote:\n> Petr Vandrovec <petr@vmware.com> wrote:\n> > Best to test this is to start 'socket 192.168.40.99\n> > 80' from command line and \n> > then type these two lines above, plus one empty\n> > line.  You should get back '200 \n> > OK', empty line, and then you can start\n> > communicating using git protocol - if \n> > you can do that...\n> \n> I cannot run \"socket\" and \"CONNECT\" on Fedora Core 3.\n> It simply told me that no such command. How could I \n> do this task in my case?\n\nWell, install some package to have `socket' available? Debian calls\nthe packet `socket', too, so I guess Fedora may have something\nsimilar.\n\nMfG, JBG\n\n-- \nJan-Benedict Glaw       jbglaw@lug-owl.de    . +49-172-7608481             _ O _\n\"Eine Freie Meinung in  einem Freien Kopf    | Gegen Zensur | Gegen Krieg  _ _ O\n für einen Freien Staat voll Freier Bürger\"  | im Internet! |   im Irak!   O O O\nret = do_actions((curr | FREE_SPEECH) & ~(NEW_COPYRIGHT_LAW | DRM | TCPA));\n"},{"id":"20132","messageId":"446B00CE.9000609@vmware.com","threadId":"4165","inReplyTo":"20060517083845.GC23642@lug-owl.de","subject":"Re: Fwd: [OT] Re: Git via a proxy server?","fromName":"Petr Vandrovec","fromEmail":"petr@vmware.com","sentAt":"2006-05-17T10:54:06Z","receivedAt":"2006-05-17T10:54:06Z","isPatch":false,"sender":{"key":"petr@vmware.com","avatar":null},"body":"Jan-Benedict Glaw wrote:\n> On Tue, 2006-05-16 20:56:39 -0700, Sam Song <samlinuxkernel@yahoo.com> wrote:\n> \n>>Petr Vandrovec <petr@vmware.com> wrote:\n>>\n>>>Best to test this is to start 'socket 192.168.40.99\n>>>80' from command line and \n>>>then type these two lines above, plus one empty\n>>>line.  You should get back '200 \n>>>OK', empty line, and then you can start\n>>>communicating using git protocol - if \n>>>you can do that...\n>>\n>>I cannot run \"socket\" and \"CONNECT\" on Fedora Core 3.\n>>It simply told me that no such command. How could I \n>>do this task in my case?\n> \n> \n> Well, install some package to have `socket' available? Debian calls\n> the packet `socket', too, so I guess Fedora may have something\n> similar.\n\nSurprisingly they do not...  You should be able to replace 'socket' with \n'netcat' - and I believe that netcat/nc package is available for Fedora.  For \nthis purpose they have same command line & behavior.\n\t\t\t\t\t\t\tPetr\n"},{"id":"20200","messageId":"20060518034428.42456.qmail@web32002.mail.mud.yahoo.com","threadId":"4165","inReplyTo":"446B00CE.9000609@vmware.com","subject":"Re: Fwd: [OT] Re: Git via a proxy server?","fromName":"Sam Song","fromEmail":"samlinuxkernel@yahoo.com","sentAt":"2006-05-18T03:44:28Z","receivedAt":"2006-05-18T03:44:28Z","isPatch":false,"sender":{"key":"samlinuxkernel@yahoo.com","avatar":null},"body":"Petr Vandrovec <petr@vmware.com> wrote:\n> Jan-Benedict Glaw <jbglaw@lug-owl.de> wrote:\n> > Well, install some package to have `socket'\n> > available? Debian calls\n> > the packet `socket', too, so I guess Fedora may\n> > have something similar.\n> \n> Surprisingly they do not...  You should be able to\n> replace 'socket' with \n> 'netcat' - and I believe that netcat/nc package is\n> available for Fedora.  For \n> this purpose they have same command line & behavior.\n\nUmmm, I am trying on that. nc is avaiable for Fedora.\nBut what could be the replacement for CONNECT in\nFedora? :-)\n\nThanks for your kind support,\n\nSam\n\n\n\n__________________________________________________\nDo You Yahoo!?\nTired of spam?  Yahoo! Mail has the best spam protection around \nhttp://mail.yahoo.com \n"},{"id":"20217","messageId":"20060518083132.GG23642@lug-owl.de","threadId":"4165","inReplyTo":"20060518034428.42456.qmail@web32002.mail.mud.yahoo.com","subject":"Re: Fwd: [OT] Re: Git via a proxy server?","fromName":"Jan-Benedict Glaw","fromEmail":"jbglaw@lug-owl.de","sentAt":"2006-05-18T08:31:32Z","receivedAt":"2006-05-18T08:31:32Z","isPatch":false,"sender":{"key":"jbglaw@lug-owl.de","avatar":null},"body":"On Wed, 2006-05-17 20:44:28 -0700, Sam Song <samlinuxkernel@yahoo.com> wrote:\n> Petr Vandrovec <petr@vmware.com> wrote:\n> > Jan-Benedict Glaw <jbglaw@lug-owl.de> wrote:\n> > > Well, install some package to have `socket'\n> > > available? Debian calls\n> > > the packet `socket', too, so I guess Fedora may\n> > > have something similar.\n> > \n> > Surprisingly they do not...  You should be able to\n> > replace 'socket' with \n> > 'netcat' - and I believe that netcat/nc package is\n> > available for Fedora.  For \n> > this purpose they have same command line & behavior.\n> \n> Ummm, I am trying on that. nc is avaiable for Fedora.\n> But what could be the replacement for CONNECT in\n> Fedora? :-)\n\nErm, you haven't understood what you're doing there, have you?\n\nWith the GIT_PROXY_COMMAND helper, you're expected to create a clean\ntunnel which in turn git can use to transfer its data.\n\nYou've only got some limited internet connectivity via a HTTP proxy\navailable, so you need to use this. This means:\n\n  * The proxy administrator needs to allos outgoing connections for\n    the CONNECT method with git's TCP port.\n  * You need to have some minimalistic program to initially speak HTTP\n    with the proxy and later on just stream the raw git protocol\n    through the link.\n  * You may or may not need to strip anything that came into the git\n    stream by accident because you tunnled it through a HTTP proxy. A\n    reply message from the proxy server is an example for this.\n\nSo this little script (using \"CONNECT\" and netcat or socket) does the\nfirst part: it talks in the language HTTP with the proxy server. It\nmay be enough to just use CONNECT, but you may need to speak some more\nlines, eg. for proxy authorization.\n\nThe first `cat' in there is just for pushing the git protocol though the\nHTTP proxy connection later on (hopefully after the proxy was made to\naccept the the CONNECT request.)  Once the proxy accepted it, it'll\nsend you a HTTP/200 message (or something like that) and an empty\nline. This is what the two reads are for; the next `cat' simply again\ntransfers all the rest (the git protocol).\n\nTo draw the line, there's not _one_ solution to HTTP proxy tunneling,\nthere are many, and you'll need to design one that fits your network.\nIt should be quite simple, given that you've got nice tools like\n`strace' and `tcpdump', which will help you to understand how the\nproxy reacts and so on.\n\nMfG, JBG\n\n-- \nJan-Benedict Glaw       jbglaw@lug-owl.de    . +49-172-7608481             _ O _\n\"Eine Freie Meinung in  einem Freien Kopf    | Gegen Zensur | Gegen Krieg  _ _ O\n für einen Freien Staat voll Freier Bürger\"  | im Internet! |   im Irak!   O O O\nret = do_actions((curr | FREE_SPEECH) & ~(NEW_COPYRIGHT_LAW | DRM | TCPA));\n"}]}