git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCHv3] Updated patch series for providing mechanism to list available repositories

From
Jonathan Nieder <jrnieder@gmail.com>
Date
Jul 28, 2010, 00:33 UTC
Message-ID
<20100728003336.GA2248@dert.cs.uchicago.edu>
In-Reply-To
<AANLkTikr5jjZJa2irLb2rNew8ngJcv3rhcFV+pNRpRrw@mail.gmail.com>
Greg Brockman wrote:
> Hmm, ok.  So if I'm not mistaken, the only outstanding issue is
> whether to provide a way to globally disable git-shell-commands.  Do
> you have a particular threat model in mind?

No, it was only a vague thing. I do not even use git-shell myself, so it was a vague worry for a scenario I am not even involved in. So if you have thought it over and decided it is not an issue, that is good enough for me.

What would be most comforting is an explanation like this:
 "Uses not using this feature will not be impacted by patch 1,
  since all it adds is:
  
   - some memory allocation
   - a call to split_cmdline, which I have audited and
     seems to be safe
   - an execv that does not permit . or / characters and so
     can only run commands from the directory the user is
     in (which would be safe because..."

Actually if I understand correctly I am not comforted at all, because a former user at a multi-user installation that only has git-shell access now can suddenly run arbitrary commands from the home directory once git is upgraded.

Jonathan
Previous: Greg BrockmanNext: Greg Brockman
Message 15 of 23 in “[PATCHv3] Updated patch series for providing mechanism to list available repositories”
  1. Greg BrockmanJul 21, 2010
  2. 1/3 Allow creation of arbitrary git-shell commandsGreg Brockman, Jul 21, 2010
  3. 2/3 Add interactive mode to git-shell for user-friendlinessGreg Brockman, Jul 21, 2010
  4. 3/3 Add sample commands for git-shellGreg Brockman, Jul 21, 2010
  5. Greg BrockmanJul 26, 2010
  6. Ævar Arnfjörð BjarmasonJul 26, 2010
  7. Greg BrockmanJul 26, 2010
  8. Jakub NarebskiJul 27, 2010
  9. Jonathan NiederJul 26, 2010
  10. Greg BrockmanJul 27, 2010
  11. Jonathan NiederJul 27, 2010
  12. Johannes SixtJul 27, 2010
  13. Jonathan NiederJul 27, 2010
  14. Greg BrockmanJul 27, 2010
  15. Jonathan NiederJul 28, 2010
  16. Greg BrockmanJul 28, 2010
  17. Jonathan NiederJul 28, 2010
  18. Greg BrockmanJul 28, 2010
  19. Anders KaseorgJul 28, 2010
  20. Jonathan NiederJul 28, 2010
  21. Greg BrockmanJul 29, 2010
  22. Jonathan NiederJul 29, 2010
  23. Jonathan NiederJul 28, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.