git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH] Allow git-shell to be used as a ssh forced-command

From
Mike Hommey <mh@glandium.org>
Date
Apr 16, 2009, 21:10 UTC
Message-ID
<1239916256-10878-1-git-send-email-mh@glandium.org>

When using a forced-command, OpenSSH sets the SSH_ORIGINAL_COMMAND variable to what would otherwise be passed to $SHELL -c. When this variable is set, we use it instead of the contents of argv.

Signed-off-by: Mike Hommey <mh@glandium.org>
---

I was unsure whether I needed to give more information about forced-commands in the commit message itself, anyways, just in case you don't know what it is: http://oreilly.com/catalog/sshtdg/chapter/ch08.html#22858

I'm not sure if it's worth adding a check for SSH2_ORIGINAL_COMMAND. Are people using the commercial SSH2 ?

 shell.c |   29 +++++++++++++++++------------
 1 files changed, 17 insertions(+), 12 deletions(-)
diff --git a/shell.c b/shell.c
index e339369..14ff266 100644
--- a/shell.c
+++ b/shell.c
@@ -62,20 +62,25 @@ int main(int argc, char **argv)
 		die("opening /dev/null failed (%s)", strerror(errno));
 	close (devnull_fd);
 
-	/*
-	 * Special hack to pretend to be a CVS server
-	 */
-	if (argc == 2 && !strcmp(argv[1], "cvs server"))
-		argv--;
+	/* Use original command if we were run from a ssh forced-command */
+	prog = getenv("SSH_ORIGINAL_COMMAND");
+	if (!prog) {
+		/*
+		 * Special hack to pretend to be a CVS server
+		 */
+		if (argc == 2 && !strcmp(argv[1], "cvs server"))
+			argv--;
 
-	/*
-	 * We do not accept anything but "-c" followed by "cmd arg",
-	 * where "cmd" is a very limited subset of git commands.
-	 */
-	else if (argc != 3 || strcmp(argv[1], "-c"))
-		die("What do you think I am? A shell?");
+		/*
+		 * We do not accept anything but "-c" followed by "cmd arg",
+		 * where "cmd" is a very limited subset of git commands.
+		 */
+		else if (argc != 3 || strcmp(argv[1], "-c"))
+			die("What do you think I am? A shell?");
+
+		prog = argv[2];
+	}
 
-	prog = argv[2];
 	if (!strncmp(prog, "git", 3) && isspace(prog[3]))
 		/* Accept "git foo" as if the caller said "git-foo". */
 		prog[3] = '-';
-- 
1.6.3.rc0.1.g8bd72.dirty
Next: Dmitry Potapov
Message 1 of 18 in “Allow git-shell to be used as a ssh forced-command”
  1. Allow git-shell to be used as a ssh forced-commandMike Hommey, Apr 16, 2009
  2. Dmitry PotapovApr 17, 2009
  3. Mike HommeyApr 17, 2009
  4. Dmitry PotapovApr 17, 2009
  5. Mike HommeyApr 17, 2009
  6. Shawn O. PearceApr 17, 2009
  7. Mike HommeyApr 17, 2009
  8. Matthieu MoyApr 18, 2009
  9. Junio C HamanoApr 17, 2009
  10. Tommi VirtanenApr 17, 2009
  11. Junio C HamanoApr 18, 2009
  12. Mike HommeyApr 18, 2009
  13. Allow git-shell to be used as a ssh forced-commandMike Hommey, Apr 21, 2009
  14. Dmitry PotapovApr 21, 2009
  15. Eygene RyabinkinApr 21, 2009
  16. Junio C HamanoApr 21, 2009
  17. Mike HommeyApr 21, 2009
  18. Dmitry PotapovApr 21, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.