git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH] git-upload-archive: add config option to allow only specified formats

From
Rene Scharfe <rene.scharfe@lsrfire.ath.cx>
Date
Sep 10, 2006, 15:58 UTC
Message-ID
<20060910155837.GA15974@lsrfire.ath.cx>
In-Reply-To
<7v1wqkt2v4.fsf_-_@assigned-by-dhcp.cox.net>
 Documentation/config.txt |    5 +++++
 builtin-upload-archive.c |   39 +++++++++++++++++++++++++++++++++++++++
 daemon.c                 |    2 ++
 3 files changed, 46 insertions(+)
diff --git a/Documentation/config.txt b/Documentation/config.txt
index ce722a2..5c3c6c7 100644
--- a/Documentation/config.txt
+++ b/Documentation/config.txt
@@ -236,6 +236,11 @@ tar.umask::
 	the same permissions as gitlink:git-checkout[1] would use. The default
 	value remains 0, which means world read-write.
 
+uploadarchive.daemonformats::
+	A comma-separated list of the git-archive formats allowed for upload
+	via git-daemon.  If this parameter is missing all formats are allowed
+	for upload.
+
 user.email::
 	Your email address to be recorded in any newly created commits.
 	Can be overridden by the 'GIT_AUTHOR_EMAIL' and 'GIT_COMMITTER_EMAIL'
diff --git a/builtin-upload-archive.c b/builtin-upload-archive.c
index 96f96bd..6a5245a 100644
--- a/builtin-upload-archive.c
+++ b/builtin-upload-archive.c
@@ -16,6 +16,37 @@ static const char upload_archive_usage[]
 static const char deadchild[] =
 "git-upload-archive: archiver died with error";
 
+static char *daemon_formats;
+
+static int upload_format_config(const char *var, const char *value)
+{
+	if (!strcmp(var, "uploadarchive.daemonformats"))
+		daemon_formats = xstrdup(value);
+	return 0;
+}
+
+static int is_in(const char *needle, const char *haystack, const char *delim)
+{
+	int len = strlen(needle);
+	const char *search = haystack;
+
+	for (;;) {
+		char *pos = strstr(search, needle);
+		if (!pos)
+			return 0;
+		search++;
+		if ((pos == haystack || strchr(delim, pos[-1])) &&
+		    (pos[len] == '\0' || strchr(delim, pos[len])))
+			return 1;
+	}
+}
+
+static int upload_format_allowed(const char *fmt)
+{
+	if (getenv("GIT_DAEMON"))
+		return daemon_formats ? is_in(fmt, daemon_formats, " \t,") : 1;
+	return 1;
+}
 
 static int run_upload_archive(int argc, const char **argv, const char *prefix)
 {
@@ -38,6 +69,8 @@ static int run_upload_archive(int argc, 
 	if (!enter_repo(buf, 0))
 		die("not a git archive");
 
+	git_config(upload_format_config);
+
 	/* put received options in sent_argv[] */
 	sent_argc = 1;
 	sent_argv[0] = "git-upload-archive";
@@ -67,6 +100,12 @@ static int run_upload_archive(int argc, 
 	/* parse all options sent by the client */
 	treeish_idx = parse_archive_args(sent_argc, sent_argv, &ar);
 
+	if (!upload_format_allowed(ar.name)) {
+		free(daemon_formats);
+		die("upload of %s format forbidden\n", ar.name);
+	}
+	free(daemon_formats);
+
 	parse_treeish_arg(sent_argv + treeish_idx, &ar.args, prefix);
 	parse_pathspec_arg(sent_argv + treeish_idx + 1, &ar.args);
 
diff --git a/daemon.c b/daemon.c
index a2954a0..2d58abe 100644
--- a/daemon.c
+++ b/daemon.c
@@ -304,6 +304,8 @@ static int run_service(char *dir, struct
 		return -1;
 	}
 
+	setenv("GIT_DAEMON", "I am your father.", 1);
+
 	/*
 	 * We'll ignore SIGTERM from now on, we have a
 	 * good client.
Previous: Junio C HamanoNext: Rene Scharfe
Message 7 of 28 in “archive: allow remote to have more formats than we understand.”
  1. 1/2 archive: allow remote to have more formats than we understand.Junio C Hamano, Sep 10, 2006
  2. 2/2 Add --verbose to git-archiveJunio C Hamano, Sep 10, 2006
  3. 1/3 Move sideband client side support into reusable form.Junio C Hamano, Sep 10, 2006
  4. Franck Bui-HuuSep 10, 2006
  5. Move sideband server side support into reusable form.Junio C Hamano, Sep 10, 2006
  6. 3/3 Add sideband status report to git-archive protocolJunio C Hamano, Sep 10, 2006
  7. git-upload-archive: add config option to allow only specified formatsRene Scharfe, Sep 10, 2006
  8. Rene ScharfeSep 10, 2006
  9. Junio C HamanoSep 10, 2006
  10. Rene ScharfeSep 11, 2006
  11. Jakub NarebskiSep 11, 2006
  12. Franck Bui-HuuSep 10, 2006
  13. Rene ScharfeSep 11, 2006
  14. Franck Bui-HuuSep 10, 2006
  15. Junio C HamanoSep 10, 2006
  16. Franck Bui-HuuSep 11, 2006
  17. Junio C HamanoSep 12, 2006
  18. Franck Bui-HuuSep 12, 2006
  19. Franck Bui-HuuSep 12, 2006
  20. connect.c: finish_connect(): allow null pid parameterFranck Bui-Huu, Sep 12, 2006
  21. Junio C HamanoSep 13, 2006
  22. Test return value of finish_connect()Franck Bui-Huu, Sep 13, 2006
  23. git_connect: change return type to pid_tFranck Bui-Huu, Sep 13, 2006
  24. Junio C HamanoSep 12, 2006
  25. Rene ScharfeSep 10, 2006
  26. Franck Bui-HuuSep 10, 2006
  27. Junio C HamanoSep 10, 2006
  28. Franck Bui-HuuSep 10, 2006

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.