git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] daemon: return "access denied" if a service is not allowed

From
Nguyen Thai Ngoc Duy <pclouds@gmail.com>
Date
Oct 13, 2011, 04:45 UTC
Message-ID
<20111013044544.GA27890@duynguyen-vnpc.dek-tpc.internal>
In-Reply-To
<20111012200916.GA1502@sigill.intra.peff.net>
On Wed, Oct 12, 2011 at 04:09:16PM -0400, Jeff King wrote:
Show 9 quoted lines
> On Tue, Oct 04, 2011 at 08:55:09AM +1100, Nguyen Thai Ngoc Duy wrote:
> 
> > The message is chosen to avoid leaking information, yet let users know
> > that they are deliberately not allowed to use the service, not a fault
> > in service configuration or the service itself.
> 
> I do think this is an improvement, but I wonder if the verbosity should
> be configurable. Then open sites like kernel.org could be friendlier to
> their users. Something like this instead:

How about allow users to select which messages they want to print? We can even go further, allowing users to specify the messages themselves..

I don't know. I'm not a real server admin so maybe I'm just too paranoid. Any admins care to speak up?

On the other hand, grouping all messages at one place may be easier to audit, even if we don't allow customization.

Anyway, two cents on top of your patch..
-- 8< --
diff --git a/daemon.c b/daemon.c
index ec88fd0..a846ef1 100644
--- a/daemon.c
+++ b/daemon.c
@@ -17,10 +17,25 @@
 #define initgroups(x, y) (0) /* nothing */
 #endif
 
+/* Must match messages[] order below */
+#define MSG_SERVICE_NOT_ENABLED     0
+#define MSG_NO_SUCH_REPOSITORY      1
+#define MSG_REPOSITORY_NOT_EXPORTED 2
+
+static struct daemon_message
+{
+	const char *message;
+	const char *config;
+	int enabled;
+} messages[] = {
+	{ "service not enabled", "message.serviceNotEnabled" },
+	{ "no such repository", "message.noSuchRepository" },
+	{ "repository not exported", "message.repositoryNotExported" },
+};
+
 static int log_syslog;
 static int verbose;
 static int reuseaddr;
-static int informative_errors;
 
 static const char daemon_usage[] =
 "git daemon [--verbose] [--syslog] [--export-all]\n"
@@ -238,20 +253,31 @@ static int service_enabled;
 
 static int git_daemon_config(const char *var, const char *value, void *cb)
 {
+	int i;
+
 	if (!prefixcmp(var, "daemon.") &&
 	    !strcmp(var + 7, service_looking_at->config_name)) {
 		service_enabled = git_config_bool(var, value);
 		return 0;
 	}
 
+	for (i = 0; i < ARRAY_SIZE(messages); i++)
+		if (!strcmp(var, messages[i].config)) {
+			messages[i].enabled = git_config_bool(var, value);
+			return 0;
+		}
+
 	/* we are not interested in parsing any other configuration here */
 	return 0;
 }
 
-static int daemon_error(const char *dir, const char *msg)
+static int daemon_error(const char *dir, int msg_id)
 {
-	if (!informative_errors)
+	const char *msg;
+	if (!messages[msg_id].enabled)
 		msg = "access denied";
+	else
+		msg = messages[msg_id].message;
 	packet_write(1, "ERR %s: %s", dir, msg);
 	return -1;
 }
@@ -266,11 +292,11 @@ static int run_service(char *dir, struct daemon_service *service)
 	if (!enabled && !service->overridable) {
 		logerror("'%s': service not enabled.", service->name);
 		errno = EACCES;
-		return daemon_error(dir, "service not enabled");
+		return daemon_error(dir, MSG_SERVICE_NOT_ENABLED);
 	}
 
 	if (!(path = path_ok(dir)))
-		return daemon_error(dir, "no such repository");
+		return daemon_error(dir, MSG_NO_SUCH_REPOSITORY);
 
 	/*
 	 * Security on the cheap.
@@ -286,7 +312,7 @@ static int run_service(char *dir, struct daemon_service *service)
 	if (!export_all_trees && access("git-daemon-export-ok", F_OK)) {
 		logerror("'%s': repository not exported.", path);
 		errno = EACCES;
-		return daemon_error(dir, "repository not exported");
+		return daemon_error(dir, MSG_REPOSITORY_NOT_EXPORTED);
 	}
 
 	if (service->overridable) {
@@ -300,7 +326,7 @@ static int run_service(char *dir, struct daemon_service *service)
 		logerror("'%s': service not enabled for '%s'",
 			 service->name, path);
 		errno = EACCES;
-		return daemon_error(dir, "service not enabled");
+		return daemon_error(dir, MSG_SERVICE_NOT_ENABLED);
 	}
 
 	/*
@@ -1177,7 +1203,9 @@ int main(int argc, char **argv)
 			continue;
 		}
 		if (!prefixcmp(arg, "--informative-errors")) {
-			informative_errors = 1;
+			int i;
+			for (i = 0; i < ARRAY_SIZE(messages); i++)
+				messages[i].enabled = 1;
 			continue;
 		}
 		if (!strcmp(arg, "--")) {
-- 8< --
Previous: Jonathan NiederNext: Jonathan Nieder
Message 20 of 117 in “transport: do not allow to push over git:// protocol”
  1. transport: do not allow to push over git:// protocolNguyễn Thái Ngọc Duy, Oct 1, 2011
  2. Ilari LiusvaaraOct 1, 2011
  3. Nguyen Thai Ngoc DuyOct 1, 2011
  4. Jonathan NiederOct 1, 2011
  5. Nguyen Thai Ngoc DuyOct 3, 2011
  6. Jeff KingOct 3, 2011
  7. Johannes SixtOct 3, 2011
  8. Jeff KingOct 3, 2011
  9. Nguyen Thai Ngoc DuyOct 3, 2011
  10. Jeff KingOct 3, 2011
  11. Nguyen Thai Ngoc DuyOct 3, 2011
  12. Jonathan NiederOct 3, 2011
  13. daemon: print "access denied" if a service does not workNguyễn Thái Ngọc Duy, Oct 3, 2011
  14. Jonathan NiederOct 3, 2011
  15. Junio C HamanoOct 3, 2011
  16. daemon: return "access denied" if a service is not allowedNguyễn Thái Ngọc Duy, Oct 3, 2011
  17. Junio C HamanoOct 3, 2011
  18. Jeff KingOct 12, 2011
  19. Jonathan NiederOct 13, 2011
  20. Nguyen Thai Ngoc DuyOct 13, 2011
  21. Jonathan NiederOct 13, 2011
  22. Nguyen Thai Ngoc DuyOct 13, 2011
  23. Nguyen Thai Ngoc DuyOct 13, 2011
  24. Jeff KingOct 13, 2011
  25. Junio C HamanoOct 14, 2011
  26. Jeff KingOct 14, 2011
  27. Jeff KingOct 14, 2011
  28. Jeff KingOct 14, 2011
  29. Junio C HamanoOct 14, 2011
  30. Jeff KingOct 14, 2011
  31. Junio C HamanoOct 14, 2011
  32. Jeff KingOct 14, 2011
  33. Jonathan NiederOct 14, 2011
  34. Jonathan NiederOct 14, 2011
  35. Jonathan NiederOct 14, 2011
  36. Jeff KingOct 14, 2011
  37. [PATCHv3] daemon: give friendlier error messages to clientsJeff King, Oct 14, 2011
  38. Junio C HamanoOct 14, 2011
  39. Sitaram ChamartyOct 14, 2011
  40. Junio C HamanoOct 15, 2011
  41. Sitaram ChamartyOct 15, 2011
  42. Jakub NarebskiOct 15, 2011
  43. Jonathan NiederOct 15, 2011
  44. Junio C HamanoOct 15, 2011
  45. Jonathan NiederOct 15, 2011
  46. Sitaram ChamartyOct 16, 2011
  47. Nguyen Thai Ngoc DuyOct 15, 2011
  48. 1/2 daemon: add testsClemens Buchacher, Oct 16, 2011
  49. 2/2 daemon: report permission denied error to clientsClemens Buchacher, Oct 16, 2011
  50. Jeff KingOct 17, 2011
  51. Clemens BuchacherOct 17, 2011
  52. Jeff KingOct 17, 2011
  53. Junio C HamanoOct 17, 2011
  54. Clemens BuchacherOct 18, 2011
  55. Clemens BuchacherOct 19, 2011
  56. 2/2 daemon: report permission denied error to clientsClemens Buchacher, Oct 17, 2011
  57. Junio C HamanoOct 21, 2011
  58. Jeff KingOct 17, 2011
  59. use test number as port numberClemens Buchacher, Oct 17, 2011
  60. Junio C HamanoOct 17, 2011
  61. Clemens BuchacherOct 18, 2011
  62. Clemens BuchacherOct 17, 2011
  63. Jeff KingOct 17, 2011
  64. Jonathan NiederJan 2, 2012
  65. Clemens BuchacherJan 2, 2012
  66. Jeff KingJan 3, 2012
  67. Junio C HamanoJan 3, 2012
  68. Clemens BuchacherJan 4, 2012
  69. 1/6 t5550: repack everything into one fileClemens Buchacher, Jan 4, 2012
  70. Junio C HamanoJan 4, 2012
  71. 2/6 daemon: add testsClemens Buchacher, Jan 4, 2012
  72. 3/6 avoid use of pkillClemens Buchacher, Jan 4, 2012
  73. 4/6 explain expected exit codeClemens Buchacher, Jan 4, 2012
  74. 5/6 t5570: repack everything into one fileClemens Buchacher, Jan 4, 2012
  75. 6/6 chmod: use lower-case xClemens Buchacher, Jan 4, 2012
  76. Junio C HamanoJan 4, 2012
  77. Junio C HamanoJan 4, 2012
  78. Clemens BuchacherJan 4, 2012
  79. Junio C HamanoJan 4, 2012
  80. Jeff KingJan 4, 2012
  81. Clemens BuchacherJan 5, 2012
  82. Junio C HamanoJan 5, 2012
  83. Clemens BuchacherJan 5, 2012
  84. Jeff KingJan 5, 2012
  85. Clemens BuchacherJan 5, 2012
  86. Jeff KingJan 6, 2012
  87. Clemens BuchacherJan 6, 2012
  88. Jeff KingJan 6, 2012
  89. credentials: unable to connect to cache daemonClemens Buchacher, Jan 7, 2012
  90. Jeff KingJan 7, 2012
  91. Junio C HamanoJan 6, 2012
  92. Clemens BuchacherJan 7, 2012
  93. 1/5 run-command: optionally kill children on exitClemens Buchacher, Jan 7, 2012
  94. Erik Faye-LundJan 7, 2012
  95. Clemens BuchacherJan 8, 2012
  96. Jeff KingJan 7, 2012
  97. 2/5 run-command: kill children on exit by defaultClemens Buchacher, Jan 7, 2012
  98. Jeff KingJan 7, 2012
  99. Junio C HamanoJan 8, 2012
  100. 2/5 dashed externals: kill children on exitClemens Buchacher, Jan 8, 2012
  101. Jeff KingJan 8, 2012
  102. 3/5 git-daemon: add testsClemens Buchacher, Jan 7, 2012
  103. 4/5 git-daemon: produce output when readyClemens Buchacher, Jan 7, 2012
  104. 5/5 git-daemon tests: wait until daemon is readyClemens Buchacher, Jan 7, 2012
  105. Jakub NarebskiJan 5, 2012
  106. Jeff KingJan 5, 2012
  107. Jakub NarebskiJan 6, 2012
  108. Clemens BuchacherJan 7, 2012
  109. Brian GernhardtJan 6, 2012
  110. Jakub NarebskiOct 3, 2011
  111. Jeff KingOct 3, 2011
  112. Ilari LiusvaaraOct 3, 2011
  113. Support ERR in remote archive like in fetch/pushJonathan Nieder, Oct 3, 2011
  114. René ScharfeOct 3, 2011
  115. Nguyen Thai Ngoc DuyOct 3, 2011
  116. Junio C HamanoOct 3, 2011
  117. Nguyen Thai Ngoc DuyOct 2, 2011

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.