git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Smart fetch via HTTP?

From
Shawn O. Pearce <spearce@spearce.org>
Date
May 19, 2007, 03:58 UTC
Message-ID
<20070519035856.GB3141@spearce.org>
In-Reply-To
<Pine.LNX.4.64.0705181742470.20116@asgard.lang.hm>
david@lang.hm wrote:
Show 8 quoted lines
> when a person browsing a hostile website will allow that website to take 
> over the machine the demand is created for 'malware filters' for http, to 
> do this the firewalls need to decode the http, and in the process limit 
> you to only doing legitimate http.
> 
> it's also the case that the companies that have firewalls paranoid enough 
> to not let you get to the git port are highly likely to be paranoid enough 
> to have a malware filtering http firewall.

I'm behind such a filter, and fetch git.git via HTTP just to keep my work system current with Junio. ;-)

Of course we're really really really paranoid about our firewall, but are also so paranoid that any other web browser *except* Microsoft Internet Explorer is thought to be a security risk and is more-or-less banned from the network.

The kicker is some of our developers create public websites, where testing your local webpage with Firefox and Safari is pretty much required... but those browsers still aren't as trusted as IE and require special clearances. *shakes head*

We're pretty much limited to:
 *) Running the native Git protocol SSL, where the remote system
 is answering to port 443.  It may not need to be HTTP at all,
 but it probably has to smell enough like SSL to get it through
 the malware filter.  Oh, what's that?  The filter cannot actually
 filter the SSL data?  Funny!  ;-)
 *) Using a single POST upload followed by response from server,
 formatted with minimal HTTP headers.  The real problem as people
 have pointed out is not the HTTP headers, but it is the single
 exchange.

One might think you could use HTTP pipelining to try and get a bi-directional channel with the remote system, but I'm sure proxy servers are not required to reuse the same TCP connection to the remote HTTP server when the inside client piplines a new request. So any sort of hack on pipelining won't work.

If you really want a stateful exchange you have to treat HTTP as though it were IP, but with reliable (and much more expensive) packet delivery, and make the Git daemon keep track of the protocol state with the client. Yes, that means that when the client suddenly goes away and doesn't tell you he went away you also have to garbage collect your state. No nice messages from your local kernel. :-(

-- 
Shawn.
Previous: david@lang.hmNext: david@lang.hm
Message 43 of 47 in “Smart fetch via HTTP?”
  1. Jan HudecMay 15, 2007
  2. A Large Angry SCMMay 15, 2007
  3. Shawn O. PearceMay 15, 2007
  4. Junio C HamanoMay 16, 2007
  5. Martin LanghoffMay 16, 2007
  6. Johannes SchindelinMay 16, 2007
  7. Martin LanghoffMay 16, 2007
  8. Jakub NarebskiMay 16, 2007
  9. Johannes SchindelinMay 17, 2007
  10. Shawn O. PearceMay 17, 2007
  11. david@lang.hmMay 17, 2007
  12. Shawn O. PearceMay 17, 2007
  13. Shawn O. PearceMay 17, 2007
  14. Theodore TsoMay 17, 2007
  15. Nicolas PitreMay 17, 2007
  16. Johannes SchindelinMay 17, 2007
  17. Nicolas PitreMay 17, 2007
  18. Martin LanghoffMay 17, 2007
  19. Nicolas PitreMay 17, 2007
  20. Jan HudecMay 17, 2007
  21. Nicolas PitreMay 17, 2007
  22. david@lang.hmMay 17, 2007
  23. Johannes SchindelinMay 18, 2007
  24. Jan HudecMay 18, 2007
  25. Matthieu MoyMay 17, 2007
  26. Martin LanghoffMay 17, 2007
  27. Johannes SchindelinMay 17, 2007
  28. Matthieu MoyMay 17, 2007
  29. Martin LanghoffMay 17, 2007
  30. Nicolas PitreMay 17, 2007
  31. Jakub NarebskiMay 17, 2007
  32. Nicolas PitreMay 17, 2007
  33. Petr BaudisMay 17, 2007
  34. Matthieu MoyMay 17, 2007
  35. Linus TorvaldsMay 18, 2007
  36. alanMay 18, 2007
  37. Joel BeckerMay 18, 2007
  38. Matthieu MoyMay 18, 2007
  39. Linus TorvaldsMay 18, 2007
  40. Joel BeckerMay 18, 2007
  41. Jan HudecMay 20, 2007
  42. david@lang.hmMay 19, 2007
  43. Shawn O. PearceMay 19, 2007
  44. david@lang.hmMay 19, 2007
  45. Jan HudecMay 17, 2007
  46. Nicolas PitreMay 17, 2007
  47. Jan HudecMay 18, 2007

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.