git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: is gitosis secure?

From
Stephen R. van den Berg <srb@cuci.nl>
Date
Feb 5, 2009, 07:52 UTC
Message-ID
<20090205075243.GA29080@cuci.nl>
In-Reply-To
<20090204182650.GC1970@eagain.net>
Tommi Virtanen wrote:
>On Wed, Feb 04, 2009 at 01:12:04PM +0100, Stephen R. van den Berg wrote:
>> I installed gitosis a year ago.
>> Then I tried to audit the code.
>> I couldn't, the whole thing is too much spaghetti code.
>Huh. It's about 1000 lines of python, with about 2000 lines of unit
>tests. It has 3 top-level operations: init, serve, run_hook. That
>still counts as "tiny" in my mind. I'm sorry if following the code was
>too hard. I guess there's no accounting for taste.

It would help if there were a 10 to 60 line synopsis of what it does in the critical cases. I mean, I don't care about features, but I care about the critical parts that interact with the shell and ssh. In order to audit that I need a concise 60 line max piece of code or text where I can get all the info from. 1000 lines for that is too much.

>> Auditing gitosis turned out to be too painful to be worth the trouble,
>> so I reverted to a manually maintained git-shell solution which is so
>> simple that I can actually audit it, and therefore is provably secure
>> (which gitosis is not).
>This word, "provably", tends to mean something else than what you use
>it for. Definitely a simple audit doesn't prove anything. Most
>real-world software is complex enough to be practically unprovable for
>anything.

What I meant by "provably secure" in this context is that in addition to basic security holes already/still present in the OS, /bin/sh and ssh, my scripts do not introduce extra security holes.

As a matter of fact, I replaced gitosis by two shell scripts of 31 and 50 lines each (including empty lines). I.e. the pieces of code needing auditing are exactly 81 lines total.

I'm not saying that gitosis has security holes, it's just that it's rather difficult to assure that it doesn't, given the size.

-- 
Sincerely,
           Stephen R. van den Berg.
Auto repair rates: basic labor $40/hour; if you wait, $60; if you watch, $80;
if you ask questions, $100; if you help, $120; if you laugh, $140.
Previous: Tommi VirtanenNext: Tommi Virtanen
Message 10 of 41 in “is gitosis secure?”
  1. Thomas KochDec 9, 2008
  2. Sam VilainDec 9, 2008
  3. Florian WeimerJan 18, 2009
  4. Boyd Stephen Smith Jr.Jan 18, 2009
  5. Florian WeimerJan 18, 2009
  6. Boyd Stephen Smith Jr.Jan 18, 2009
  7. Tommi VirtanenFeb 3, 2009
  8. Stephen R. van den BergFeb 4, 2009
  9. Tommi VirtanenFeb 4, 2009
  10. Stephen R. van den BergFeb 5, 2009
  11. Tommi VirtanenFeb 5, 2009
  12. R. Tyler BallanceDec 9, 2008
  13. Tommi VirtanenFeb 3, 2009
  14. Sverre RabbelierDec 9, 2008
  15. NixDec 13, 2008
  16. Sverre RabbelierDec 13, 2008
  17. Sitaram ChamartyDec 14, 2008
  18. david@lang.hmDec 14, 2008
  19. martinDec 14, 2008
  20. david@lang.hmDec 14, 2008
  21. Jakub NarebskiDec 14, 2008
  22. david@lang.hmDec 15, 2008
  23. martinDec 14, 2008
  24. david@lang.hmDec 15, 2008
  25. Mike HommeyDec 15, 2008
  26. david@lang.hmDec 15, 2008
  27. Mike HommeyDec 15, 2008
  28. TaitDec 15, 2008
  29. Sitaram ChamartyDec 14, 2008
  30. david@lang.hmDec 15, 2008
  31. Jakub NarebskiDec 14, 2008
  32. david@lang.hmDec 15, 2008
  33. Rogan DawesDec 15, 2008
  34. david@lang.hmDec 15, 2008
  35. Rogan DawesDec 15, 2008
  36. Jakub NarebskiDec 14, 2008
  37. NixDec 15, 2008
  38. david@lang.hmDec 15, 2008
  39. Asheesh LaroiaDec 15, 2008
  40. david@lang.hmDec 15, 2008
  41. Garry DolleyDec 9, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.