git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [gitolite] repo config for delegated projects

From
Teemu Matilainen <teemu.matilainen@iki.fi>
Date
Feb 6, 2010, 18:21 UTC
Message-ID
<20100206182133.GL2530@reaktor.fi>
In-Reply-To
<2e24e5b91002051650k3c7cf14ev8752d36b5616e9a4@mail.gmail.com>
On Sat, 06 Feb 2010, Sitaram Chamarty wrote:
> Now I just looked up hooks.showrev, and it's supposed to be any shell
> command.  Clearly this means anyone who can set that gitconfig option
> now has shell capability, and it's game over.

But of course you need to have a hook that runs the command. And setting hooks requires shell access.

Sorry for not thinking any problems with the config thing. I personally don't use the delegation and on the other hand all our gitolite administrators anyway have shell access to the server...

Show 7 quoted lines
> Regardless of how I look at it, I can't think of a cure for this short
> of either:
>   - putting all the allowed gitconfigs in the RC file, and not in the
> config (writing the RC file requires shell access, and we presume the
> "root of trust" person has enough smarts to know what to allow and
> what not to allow), and allowing repo admins to *refer* to them to use
> whichever they want
This sounds better solution for me.
>   - someone coming up with a list of gitconfig's that are "safe", and
> specific values for those that are unsafe (like saying "if you use
> showrev, you can only use this command  as the value", and forcing
> only those.

Might get too complicated. Anyway the person setting the hook script should know what it does and which configuration keys it uses and how.

-- 
	- Teemu
Previous: Sitaram Chamarty
Message 8 of 8 in “[gitolite] repo config for delegated projects”
  1. martin f krafftFeb 3, 2010
  2. Teemu MatilainenFeb 3, 2010
  3. Sitaram ChamartyFeb 4, 2010
  4. martin f krafftFeb 4, 2010
  5. Sitaram ChamartyFeb 6, 2010
  6. martin f krafftFeb 6, 2010
  7. Sitaram ChamartyFeb 6, 2010
  8. Teemu MatilainenFeb 6, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.