git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] connect.c: add a way for git-daemon to pass an error back to client

From
Alex Riesen <raa.lkml@gmail.com>
Date
Nov 1, 2008, 14:39 UTC
Message-ID
<20081101143954.GB7157@steel.home>
In-Reply-To
<b97024a40810312035v5416b578v51b5bed528ca8d39@mail.gmail.com>
Tom Preston-Werner, Sat, Nov 01, 2008 04:35:20 +0100:
> Maybe this is worth asking the question: does anybody use git-daemon
> for private code? If so, why are they not using SSH instead? And in
> that case, how are informative error messages a security risk?

Yes. I use both in my private network, with only ssh open to the internet. git-daemon is smaller and faster (started from inetd). And I'm absolutely sure wont ever accidentally push something in the mirrored repos.

I never had the error reporting problem in this setup, though. It is a fully controled environment and I can just look in syslog.

I support the original reason for not doing the errors, BTW. It cannot be on by default.

Heh, try the patch for your private repos and private repos of your employer, who can sack you for exposing confidential information, and open them to internet. Than come back and tell us how safe you feel :)

Previous: Andreas EricssonNext: Andreas Ericsson
Message 8 of 13 in “connect.c: add a way for git-daemon to pass an error back to client”
  1. connect.c: add a way for git-daemon to pass an error back to clientTom Preston-Werner, Nov 1, 2008
  2. Johannes SchindelinNov 1, 2008
  3. Tom Preston-WernerNov 1, 2008
  4. Nicolas PitreNov 1, 2008
  5. Johannes SchindelinNov 1, 2008
  6. Tom Preston-WernerNov 1, 2008
  7. Andreas EricssonNov 1, 2008
  8. Alex RiesenNov 1, 2008
  9. Andreas EricssonNov 1, 2008
  10. Junio C HamanoNov 1, 2008
  11. Tom Preston-WernerNov 1, 2008
  12. Shawn O. PearceNov 1, 2008
  13. Junio C HamanoNov 1, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.