git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [gitolite] repo config for delegated projects

From
SCSitaram Chamarty <sitaram@atc.tcs.com>
Date
Feb 4, 2010, 01:18 UTC
Message-ID
<20100204011842.GB497@atcmail.atc.tcs.com>
In-Reply-To
<20100203202249.GA27125@lapse.rw.madduck.net>
On Thu, Feb 04, 2010 at 09:22:49AM +1300, martin f krafft wrote:
Show 13 quoted lines
> Dear Sitaram, dear Teemo, dear gitolite-fans,
> 
> src/gl-compile-conf:261 prohibits delegated repositories to make use
> of the functionality to configure config variables of the
> repositories:
> 
>   die "$WARN $fragment attempting to set repo configuration\n"
>     if $fragment ne 'master';
> 
> This is a bit unfortunate and makes me reconsider the use of
> delegations.
> 
> What is the reason for this restriction?

Like Teemu said, inability to think through all the possible repurcussions of allowing a delegated admin to set config variables. There are too many of them for me to go through, and they'll keep changing.

To recap, what gitolite wants to do is broadly the following:

  - no one who is not admin can do anything to a repo that
    the config file does not permit him to do (this is not
    affected by the topic of this email; just adding it for
    completeness)
  - the main admin (who has RW/RW+ access to all of the
    gitolite-admin repo) cannot get shell access on the
    server.  This is a relatively new restriction; initially
    I did not think to keep these two privileges separate
  - a delegated admin cannot manage any sort of access to
    repos that the main admin did not delegate to him.
Show 6 quoted lines
> 
> Are there settings that are potentially compromising?
> 
> Would it be worth to consider making it configurable (e.g.
> ~/.gitolite.rc) whether to allow delegated repos to set config
> variables?

I wouldn't mind making it configurable, with the default being off. Rather than a blanket

    $ALLOW_DELEGATE_CONFIGS = 1;
how about
    $DELEGATED_CONFIGS = "hooks.mailinglist,hooks.showrev";

(to take Teemu's example config file and the config variables he uses), so that you (or whoever has shell access, which is required for changing RC file) can sort of limit the potential damage.

And the defaults would all be commented out anyway so people who don't car about this will never have to worry about it.

Regards,
Sitaram
Previous: Teemu MatilainenNext: martin f krafft
Message 3 of 8 in “[gitolite] repo config for delegated projects”
  1. martin f krafftFeb 3, 2010
  2. Teemu MatilainenFeb 3, 2010
  3. Sitaram ChamartyFeb 4, 2010
  4. martin f krafftFeb 4, 2010
  5. Sitaram ChamartyFeb 6, 2010
  6. martin f krafftFeb 6, 2010
  7. Sitaram ChamartyFeb 6, 2010
  8. Teemu MatilainenFeb 6, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.