git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Useless error message?

From
Jonathan Nieder <jrnieder@gmail.com>
Date
Apr 22, 2010, 10:15 UTC
Message-ID
<20100422101535.GB625@progeny.tock>
In-Reply-To
<4BD01E09.8080504@op5.se>
Andreas Ericsson wrote:
> On 04/22/2010 11:42 AM, Jonathan Nieder wrote:
Show 7 quoted lines
>> [1] I do suspect that in the case of failing enter_repo() or missing
>> git-daemon-export-ok, saying “cannot read the specified repo” would be
>> fine.  Most of the time, there is not much value in disclosing a more
>> detailed reason, anyway.
>
> That would make it possible for random attackers to determine whether
> a specific user exists on the system, which is very bad indeed.
I guess I am missing something.  How would
(*) $ git clone git://git.example.com/~u/foo
    remote: Cannot read the specified repo

tell me whether that user existed on the system? If the daemon gives the same message for ENOENT, missing git-daemon-export-ok, EPERM, and so on so I cannot distinguish the cases, then I just don’t see the problem.

If the daemon failed for some other reason, like a flaky network, I would see

    $ git clone git://git.example.com/~u/foo
    fatal: The remote end hung up unexpectedly

So the extra information could still be helpful, without unwanted information disclosure. In the case (*) I learn definitively that the address I specified does not represent a repo I have access to, rather than this being some random, transient unexplained problem.

Thanks for the comment. Jonathan

Previous: Andreas EricssonNext: Andreas Ericsson
Message 7 of 13 in “Useless error message?”
  1. AghilesApr 21, 2010
  2. Kim EbertApr 21, 2010
  3. Jonathan NiederApr 21, 2010
  4. Junio C HamanoApr 22, 2010
  5. Jonathan NiederApr 22, 2010
  6. Andreas EricssonApr 22, 2010
  7. Jonathan NiederApr 22, 2010
  8. Andreas EricssonApr 22, 2010
  9. Jonathan NiederApr 22, 2010
  10. Ilari LiusvaaraApr 22, 2010
  11. daemon: report inaccessible repositories to userJonathan Nieder, Apr 22, 2010
  12. Petr BaudisApr 22, 2010
  13. AghilesApr 22, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.