git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] daemon: return "access denied" if a service is not allowed

From
Jonathan Nieder <jrnieder@gmail.com>
Date
Oct 14, 2011, 21:02 UTC
Message-ID
<20111014210251.GD16371@elie.hsd1.il.comcast.net>
In-Reply-To
<20111014192326.GA7713@sigill.intra.peff.net>
Jeff King wrote:
Show 5 quoted lines
> When the git-daemon is asked about an inaccessible
> repository, it simply hangs up the connection without saying
> anything further. This makes it hard to distinguish between
> a repository we cannot access (e.g., due to typo), and a
> service or network outage.
*nod*
> Instead, let's print an "ERR" line, which git clients
> understand since v1.6.1 (2008-12-24).

Just to be clear, "git archive --remote" does not understand ERR lines in the 'master' branch (though 908aaceb makes it understand them in 'next'). But I consider even distinguishing

 a. fatal: git archive: protocol error
 b. fatal: git archive: expected ACK/NAK, got EOF

[(a) is how an ERR response is reported, and (b) a remote hangup] to be progress, so it's not so important. :)

> Because there is a risk of leaking information about
> non-exported repositories, by default all errors simply say
> "access denied". Open sites can pass a flag to turn on more
> specific messages.

I'm not sure what an "open site" is. :) But having this flag for sites to declare whether they consider whether a repository exists to be privileged information seems reasonable to me.

Note that this really would be privileged information in some not-too-weird cases. For example, if many users have a repository at ~/.git, ~/.config/.git, or ~/src/linux/.git, then someone might try to access

	/home/alice/.git
	/home/alice/.config/.git
	/home/alice/src/linux/.git
	/home/bob/.git
	...

in turn to find a valid username, as reconnaisance for a later attack not involving git.

Luckily, this can be avoided with
	git daemon --user-path=public_git --base-path=/pub/git

which only allows access to subdirectories of /pub/git and public_git in home directories. With

	git daemon --base-path=/pub/git

there is still no problem, since access to home directories is not allowed at all in that case. I suppose the documentation should mention that --informative-errors is best not used unless --base-path is also in use. (Almost everyone is already using --base-path, so this isn't a very serious problem.)

> --- a/daemon.c
> +++ b/daemon.c
> @@ -20,6 +20,7 @@
[...]
Show 13 quoted lines
> @@ -1167,6 +1176,14 @@ int main(int argc, char **argv)
>  			make_service_overridable(arg + 18, 0);
>  			continue;
>  		}
> +		if (!prefixcmp(arg, "--informative-errors")) {
> +			informative_errors = 1;
> +			continue;
> +		}
> +		else if (!prefixcmp(arg, "--no-informative-errors")) {
> +			informative_errors = 0;
> +			continue;
> +		}
>  		if (!strcmp(arg, "--")) {
Micronit: uncuddled "else".  The style of the surrounding code is to
just not include the "else" at all and rely on "continue" to
short-circuit things.

Anyway, except for the documentation nits mentioned above (and Junio's nit, too),

Reviewed-by: Jonathan Nieder <jrnieder@gmail.com>
Thanks a lot for this.
Previous: Jonathan NiederNext: Jeff King
Message 35 of 117 in “transport: do not allow to push over git:// protocol”
  1. transport: do not allow to push over git:// protocolNguyễn Thái Ngọc Duy, Oct 1, 2011
  2. Ilari LiusvaaraOct 1, 2011
  3. Nguyen Thai Ngoc DuyOct 1, 2011
  4. Jonathan NiederOct 1, 2011
  5. Nguyen Thai Ngoc DuyOct 3, 2011
  6. Jeff KingOct 3, 2011
  7. Johannes SixtOct 3, 2011
  8. Jeff KingOct 3, 2011
  9. Nguyen Thai Ngoc DuyOct 3, 2011
  10. Jeff KingOct 3, 2011
  11. Nguyen Thai Ngoc DuyOct 3, 2011
  12. Jonathan NiederOct 3, 2011
  13. daemon: print "access denied" if a service does not workNguyễn Thái Ngọc Duy, Oct 3, 2011
  14. Jonathan NiederOct 3, 2011
  15. Junio C HamanoOct 3, 2011
  16. daemon: return "access denied" if a service is not allowedNguyễn Thái Ngọc Duy, Oct 3, 2011
  17. Junio C HamanoOct 3, 2011
  18. Jeff KingOct 12, 2011
  19. Jonathan NiederOct 13, 2011
  20. Nguyen Thai Ngoc DuyOct 13, 2011
  21. Jonathan NiederOct 13, 2011
  22. Nguyen Thai Ngoc DuyOct 13, 2011
  23. Nguyen Thai Ngoc DuyOct 13, 2011
  24. Jeff KingOct 13, 2011
  25. Junio C HamanoOct 14, 2011
  26. Jeff KingOct 14, 2011
  27. Jeff KingOct 14, 2011
  28. Jeff KingOct 14, 2011
  29. Junio C HamanoOct 14, 2011
  30. Jeff KingOct 14, 2011
  31. Junio C HamanoOct 14, 2011
  32. Jeff KingOct 14, 2011
  33. Jonathan NiederOct 14, 2011
  34. Jonathan NiederOct 14, 2011
  35. Jonathan NiederOct 14, 2011
  36. Jeff KingOct 14, 2011
  37. [PATCHv3] daemon: give friendlier error messages to clientsJeff King, Oct 14, 2011
  38. Junio C HamanoOct 14, 2011
  39. Sitaram ChamartyOct 14, 2011
  40. Junio C HamanoOct 15, 2011
  41. Sitaram ChamartyOct 15, 2011
  42. Jakub NarebskiOct 15, 2011
  43. Jonathan NiederOct 15, 2011
  44. Junio C HamanoOct 15, 2011
  45. Jonathan NiederOct 15, 2011
  46. Sitaram ChamartyOct 16, 2011
  47. Nguyen Thai Ngoc DuyOct 15, 2011
  48. 1/2 daemon: add testsClemens Buchacher, Oct 16, 2011
  49. 2/2 daemon: report permission denied error to clientsClemens Buchacher, Oct 16, 2011
  50. Jeff KingOct 17, 2011
  51. Clemens BuchacherOct 17, 2011
  52. Jeff KingOct 17, 2011
  53. Junio C HamanoOct 17, 2011
  54. Clemens BuchacherOct 18, 2011
  55. Clemens BuchacherOct 19, 2011
  56. 2/2 daemon: report permission denied error to clientsClemens Buchacher, Oct 17, 2011
  57. Junio C HamanoOct 21, 2011
  58. Jeff KingOct 17, 2011
  59. use test number as port numberClemens Buchacher, Oct 17, 2011
  60. Junio C HamanoOct 17, 2011
  61. Clemens BuchacherOct 18, 2011
  62. Clemens BuchacherOct 17, 2011
  63. Jeff KingOct 17, 2011
  64. Jonathan NiederJan 2, 2012
  65. Clemens BuchacherJan 2, 2012
  66. Jeff KingJan 3, 2012
  67. Junio C HamanoJan 3, 2012
  68. Clemens BuchacherJan 4, 2012
  69. 1/6 t5550: repack everything into one fileClemens Buchacher, Jan 4, 2012
  70. Junio C HamanoJan 4, 2012
  71. 2/6 daemon: add testsClemens Buchacher, Jan 4, 2012
  72. 3/6 avoid use of pkillClemens Buchacher, Jan 4, 2012
  73. 4/6 explain expected exit codeClemens Buchacher, Jan 4, 2012
  74. 5/6 t5570: repack everything into one fileClemens Buchacher, Jan 4, 2012
  75. 6/6 chmod: use lower-case xClemens Buchacher, Jan 4, 2012
  76. Junio C HamanoJan 4, 2012
  77. Junio C HamanoJan 4, 2012
  78. Clemens BuchacherJan 4, 2012
  79. Junio C HamanoJan 4, 2012
  80. Jeff KingJan 4, 2012
  81. Clemens BuchacherJan 5, 2012
  82. Junio C HamanoJan 5, 2012
  83. Clemens BuchacherJan 5, 2012
  84. Jeff KingJan 5, 2012
  85. Clemens BuchacherJan 5, 2012
  86. Jeff KingJan 6, 2012
  87. Clemens BuchacherJan 6, 2012
  88. Jeff KingJan 6, 2012
  89. credentials: unable to connect to cache daemonClemens Buchacher, Jan 7, 2012
  90. Jeff KingJan 7, 2012
  91. Junio C HamanoJan 6, 2012
  92. Clemens BuchacherJan 7, 2012
  93. 1/5 run-command: optionally kill children on exitClemens Buchacher, Jan 7, 2012
  94. Erik Faye-LundJan 7, 2012
  95. Clemens BuchacherJan 8, 2012
  96. Jeff KingJan 7, 2012
  97. 2/5 run-command: kill children on exit by defaultClemens Buchacher, Jan 7, 2012
  98. Jeff KingJan 7, 2012
  99. Junio C HamanoJan 8, 2012
  100. 2/5 dashed externals: kill children on exitClemens Buchacher, Jan 8, 2012
  101. Jeff KingJan 8, 2012
  102. 3/5 git-daemon: add testsClemens Buchacher, Jan 7, 2012
  103. 4/5 git-daemon: produce output when readyClemens Buchacher, Jan 7, 2012
  104. 5/5 git-daemon tests: wait until daemon is readyClemens Buchacher, Jan 7, 2012
  105. Jakub NarebskiJan 5, 2012
  106. Jeff KingJan 5, 2012
  107. Jakub NarebskiJan 6, 2012
  108. Clemens BuchacherJan 7, 2012
  109. Brian GernhardtJan 6, 2012
  110. Jakub NarebskiOct 3, 2011
  111. Jeff KingOct 3, 2011
  112. Ilari LiusvaaraOct 3, 2011
  113. Support ERR in remote archive like in fetch/pushJonathan Nieder, Oct 3, 2011
  114. René ScharfeOct 3, 2011
  115. Nguyen Thai Ngoc DuyOct 3, 2011
  116. Junio C HamanoOct 3, 2011
  117. Nguyen Thai Ngoc DuyOct 2, 2011

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.