{"thread":{"id":"57013","subject":"[PATCH 2/2] http-backend: give a hint that web browser access is not supported","startedAt":"2021-12-02T00:12:53Z","lastAt":"2021-12-02T07:31:58Z","messageCount":3,"participants":["Jan Engelhardt","Junio C Hamano"],"isPatch":true,"patchVersion":1,"patchTotal":2},"messages":[{"id":"442832","messageId":"20211202001238.21808-2-jengelh@inai.de","threadId":"57013","inReplyTo":"20211202001238.21808-1-jengelh@inai.de","subject":"[PATCH 2/2] http-backend: give a hint that web browser access is not supported","fromName":"Jan Engelhardt","fromEmail":"jengelh@inai.de","sentAt":"2021-12-02T00:12:38Z","receivedAt":"2021-12-02T00:12:53Z","isPatch":true,"sender":{"key":"jengelh@inai.de","avatar":"https://avatars.githubusercontent.com/u/8861948?v=4"},"body":"Add a paragraph that browsing to http-backend is not something\nthat should normally be done\n a webserver is configured to unconditionally pass requests\nto git-http-backend, without any diversion to a gitweb frontend,\nit is helpful to at least be told this.\n\nSigned-off-by: Jan Engelhardt <jengelh@inai.de>\n---\n http-backend.c | 11 +++++++++--\n 1 file changed, 9 insertions(+), 2 deletions(-)\n\ndiff --git http-backend.c http-backend.c\nindex 8f1b69d127..06e17d45a4 100644\n--- http-backend.c\n+++ http-backend.c\n@@ -775,8 +775,15 @@ int cmd_main(int argc, const char **argv)\n \t\tregfree(&re);\n \t}\n \n-\tif (!cmd)\n-\t\tnot_found(&hdr, \"Request not supported: '%s'\", dir);\n+\tif (!cmd) {\n+\t\tconst char *hint = \"\";\n+\t\tif (strcmp(method, \"GET\") == 0)\n+\t\t\thint = \"You cannot use regular web browsing to access \"\n+\t\t\t       \"this URL. Only git operations like \"\n+\t\t\t       \"clone/ls-remote/etc. will work.\\n\";\n+\t\tnot_found(&hdr, \"%s request not supported on '%s'.\\n%s\",\n+\t\t\t  method, dir, hint);\n+\t}\n \n \tsetup_path();\n \tif (!enter_repo(dir, 0))\n-- \n2.34.0\n\n"},{"id":"442833","messageId":"20211202001238.21808-1-jengelh@inai.de","threadId":"57013","inReplyTo":null,"subject":"[PATCH 1/2] http-backend: CGI error messages need to be output on stdout","fromName":"Jan Engelhardt","fromEmail":"jengelh@inai.de","sentAt":"2021-12-02T00:12:37Z","receivedAt":"2021-12-02T00:13:11Z","isPatch":true,"sender":{"key":"jengelh@inai.de","avatar":"https://avatars.githubusercontent.com/u/8861948?v=4"},"body":"Accessing a clone-only URL with a browser would always show a blank\npage, because the reason string \"Request is not supported\" was\nsent to the wrong file descriptor.\n\nSigned-off-by: Jan Engelhardt <jengelh@inai.de>\n---\n http-backend.c          |  4 ++--\n t/t5561-http-backend.sh | 46 ++++++++++++++++++++---------------------\n 2 files changed, 25 insertions(+), 25 deletions(-)\n\ndiff --git http-backend.c http-backend.c\nindex 3d6e2ff17f..8f1b69d127 100644\n--- http-backend.c\n+++ http-backend.c\n@@ -134,7 +134,7 @@ static NORETURN void not_found(struct strbuf *hdr, const char *err, ...)\n \n \tva_start(params, err);\n \tif (err && *err)\n-\t\tvfprintf(stderr, err, params);\n+\t\tvprintf(err, params);\n \tva_end(params);\n \texit(0);\n }\n@@ -150,7 +150,7 @@ static NORETURN void forbidden(struct strbuf *hdr, const char *err, ...)\n \n \tva_start(params, err);\n \tif (err && *err)\n-\t\tvfprintf(stderr, err, params);\n+\t\tvprintf(err, params);\n \tva_end(params);\n \texit(0);\n }\ndiff --git t/t5561-http-backend.sh t/t5561-http-backend.sh\nindex 9c57d84315..d8add36fb4 100755\n--- t/t5561-http-backend.sh\n+++ t/t5561-http-backend.sh\n@@ -44,7 +44,7 @@ grep '^[^#]' >exp <<EOF\n \n ###  refs/heads/main\n ###\n-GET  /smart/repo.git/refs/heads/main HTTP/1.1 404 -\n+GET  /smart/repo.git/refs/heads/main HTTP/1.1 404\n \n ###  getanyfile default\n ###\n@@ -59,14 +59,14 @@ GET  /smart/repo.git/$IDX_URL HTTP/1.1 200\n \n ###  no git-daemon-export-ok\n ###\n-GET  /smart_noexport/repo.git/HEAD HTTP/1.1 404 -\n-GET  /smart_noexport/repo.git/info/refs HTTP/1.1 404 -\n-GET  /smart_noexport/repo.git/objects/info/packs HTTP/1.1 404 -\n-GET  /smart_noexport/repo.git/objects/info/alternates HTTP/1.1 404 -\n-GET  /smart_noexport/repo.git/objects/info/http-alternates HTTP/1.1 404 -\n-GET  /smart_noexport/repo.git/$LOOSE_URL HTTP/1.1 404 -\n-GET  /smart_noexport/repo.git/$PACK_URL HTTP/1.1 404 -\n-GET  /smart_noexport/repo.git/$IDX_URL HTTP/1.1 404 -\n+GET  /smart_noexport/repo.git/HEAD HTTP/1.1 404\n+GET  /smart_noexport/repo.git/info/refs HTTP/1.1 404\n+GET  /smart_noexport/repo.git/objects/info/packs HTTP/1.1 404\n+GET  /smart_noexport/repo.git/objects/info/alternates HTTP/1.1 404\n+GET  /smart_noexport/repo.git/objects/info/http-alternates HTTP/1.1 404\n+GET  /smart_noexport/repo.git/$LOOSE_URL HTTP/1.1 404\n+GET  /smart_noexport/repo.git/$PACK_URL HTTP/1.1 404\n+GET  /smart_noexport/repo.git/$IDX_URL HTTP/1.1 404\n \n ###  git-daemon-export-ok\n ###\n@@ -92,14 +92,14 @@ GET  /smart/repo.git/$IDX_URL HTTP/1.1 200\n \n ###  getanyfile false\n ###\n-GET  /smart/repo.git/HEAD HTTP/1.1 403 -\n-GET  /smart/repo.git/info/refs HTTP/1.1 403 -\n-GET  /smart/repo.git/objects/info/packs HTTP/1.1 403 -\n-GET  /smart/repo.git/objects/info/alternates HTTP/1.1 403 -\n-GET  /smart/repo.git/objects/info/http-alternates HTTP/1.1 403 -\n-GET  /smart/repo.git/$LOOSE_URL HTTP/1.1 403 -\n-GET  /smart/repo.git/$PACK_URL HTTP/1.1 403 -\n-GET  /smart/repo.git/$IDX_URL HTTP/1.1 403 -\n+GET  /smart/repo.git/HEAD HTTP/1.1 403\n+GET  /smart/repo.git/info/refs HTTP/1.1 403\n+GET  /smart/repo.git/objects/info/packs HTTP/1.1 403\n+GET  /smart/repo.git/objects/info/alternates HTTP/1.1 403\n+GET  /smart/repo.git/objects/info/http-alternates HTTP/1.1 403\n+GET  /smart/repo.git/$LOOSE_URL HTTP/1.1 403\n+GET  /smart/repo.git/$PACK_URL HTTP/1.1 403\n+GET  /smart/repo.git/$IDX_URL HTTP/1.1 403\n \n ###  uploadpack default\n ###\n@@ -113,13 +113,13 @@ POST /smart/repo.git/git-upload-pack HTTP/1.1 200 -\n \n ###  uploadpack false\n ###\n-GET  /smart/repo.git/info/refs?service=git-upload-pack HTTP/1.1 403 -\n-POST /smart/repo.git/git-upload-pack HTTP/1.1 403 -\n+GET  /smart/repo.git/info/refs?service=git-upload-pack HTTP/1.1 403\n+POST /smart/repo.git/git-upload-pack HTTP/1.1 403\n \n ###  receivepack default\n ###\n-GET  /smart/repo.git/info/refs?service=git-receive-pack HTTP/1.1 403 -\n-POST /smart/repo.git/git-receive-pack HTTP/1.1 403 -\n+GET  /smart/repo.git/info/refs?service=git-receive-pack HTTP/1.1 403\n+POST /smart/repo.git/git-receive-pack HTTP/1.1 403\n \n ###  receivepack true\n ###\n@@ -128,8 +128,8 @@ POST /smart/repo.git/git-receive-pack HTTP/1.1 200 -\n \n ###  receivepack false\n ###\n-GET  /smart/repo.git/info/refs?service=git-receive-pack HTTP/1.1 403 -\n-POST /smart/repo.git/git-receive-pack HTTP/1.1 403 -\n+GET  /smart/repo.git/info/refs?service=git-receive-pack HTTP/1.1 403\n+POST /smart/repo.git/git-receive-pack HTTP/1.1 403\n EOF\n test_expect_success 'server request log matches test results' '\n \tcheck_access_log exp\n-- \n2.34.0\n\n"},{"id":"442855","messageId":"xmqqk0gnwjh6.fsf@gitster.g","threadId":"57013","inReplyTo":"20211202001238.21808-1-jengelh@inai.de","subject":"Re: [PATCH 1/2] http-backend: CGI error messages need to be output on stdout","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-12-02T07:31:49Z","receivedAt":"2021-12-02T07:31:58Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Jan Engelhardt <jengelh@inai.de> writes:\n\n> Accessing a clone-only URL with a browser would always show a blank\n> page, because the reason string \"Request is not supported\" was\n\n\"is not supported\" -> \"not supported\", I think.\n\n> sent to the wrong file descriptor.\n\nI looked at the messages given to not_found() and forbidden().  Most\nof them do look like they are meant to be given to the remote user,\nbut some reveal the server side paths, and I am reluctant to judge\nthe security implication to start giving them, which have been\nhidden so far, to the remote users.\n\nI am not sure how strictly it is enforced these days, but at least\nin early days we were fairly paranoid and aimed to make sure that a\nremote user cannot tell a repository that does not exist from a\nrepository that the user does not have access to by throwing random\nrequests at the server.\n\nhttp-backend.c:161:\t\tforbidden(hdr, \"Unsupported service: getanyfile\");\n\nThis one should be safe, I would think.\n\nhttp-backend.c:184:\t\tnot_found(hdr, \"Cannot open '%s': %s\", p, strerror(errno));\n\nThe 'p' is a path to a file in the repository like\n'objects/alternates', that is ready to be given to open(2), so it\nclearly leaks the path on the server.\n\nhttp-backend.c:260:\t\tforbidden(hdr, \"Unsupported service: '%s'\", name);\nhttp-backend.c:271:\t\tforbidden(hdr, \"Unsupported service: '%s'\", name);\nhttp-backend.c:278:\t\tforbidden(hdr, \"Service not enabled: '%s'\", svc->name);\n\nThese I think should be benign, but I have to admit that I didn't\nthink too deep about them.\n"}]}