git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 2/3] git-daemon: use getnameinfo to resolve hostname

From
Jeff King <peff@peff.net>
Date
Jan 14, 2009, 12:25 UTC
Message-ID
<20090114122536.GA5939@coredump.intra.peff.net>
In-Reply-To
<alpine.LSU.2.00.0901141148130.16109@fbirervta.pbzchgretzou.qr>
On Wed, Jan 14, 2009 at 11:48:38AM +0100, Jan Engelhardt wrote:
> This is much shorter than inet_ntop'ing, and also translated
> unresolvable addresses into a string.

Er, doesn't this totally change the meaning of REMOTE_ADDR from an IP address to a hostname? That seems bad because:

  - people already have hooks that compare REMOTE_ADDR against an
    address, so we are breaking their hooks
  - we are losing IP information in favor of hostname information; since
    (I assume) this is primarily intended for IP-based access control,
    we are adding an extra layer of indirection in the middle of our
    security model (i.e., I used to have to spoof an IP to fool your
    hook, but now I can do that _or_ spoof DNS).

So at the very least, you should be adding REMOTE_HOST in _addition_ to REMOTE_ADDR, not instead of. But that still leaves one final concern, which is that some git-daemon admins might not want to pay the cost for a reverse lookup for every request. It's extra network traffic, and adds extra latency to the process (but I don't personally run git-daemon, and I don't know whether big sites like kernel.org actually care about this).

-Peff
Previous: Jan EngelhardtNext: Adeodato Simó
Message 8 of 13 in “git-daemon: single-line logs”
  1. 1/3 git-daemon: single-line logsJan Engelhardt, Jan 14, 2009
  2. 2/3 git-daemon: use getnameinfo to resolve hostnameJan Engelhardt, Jan 14, 2009
  3. 3/3 git-daemon: vhost supportJan Engelhardt, Jan 14, 2009
  4. Junio C HamanoJan 14, 2009
  5. Jan EngelhardtJan 14, 2009
  6. Junio C HamanoJan 14, 2009
  7. Jan EngelhardtJan 14, 2009
  8. Jeff KingJan 14, 2009
  9. Adeodato SimóJan 14, 2009
  10. Jay SoffianJan 14, 2009
  11. Jan EngelhardtJan 14, 2009
  12. Junio C HamanoJan 14, 2009
  13. Jan EngelhardtJan 14, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.