git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC/PATCH] shell: allow 'help' command to disable interactive shell

From
Jeff King <peff@peff.net>
Date
Feb 11, 2013, 17:27 UTC
Message-ID
<20130211172752.GH16402@sigill.intra.peff.net>
In-Reply-To
<7v38x2ojl1.fsf@alter.siamese.dyndns.org>
On Mon, Feb 11, 2013 at 09:18:18AM -0800, Junio C Hamano wrote:
Show 15 quoted lines
> That "shell-disabled" thing was to allow customizing the existing
> die() that triggers here:
> [...]
> so it is more like
> 
> 	if ! test -d $HOME/git-shell-commands
> 	then
> 		if test -x /etc/git/shell-disabled
>                 then
> 			exec /etc/git/shell-disabled
> 		else
> 			die Interactive is not enabled
> 		fi
> 	fi
>         ... do whatever in run_shell() ...

OK, that is equivalent to what I said (or at least what I was trying to say :) ).

Show 13 quoted lines
> > That at least means you can apply _whether_ to disable the shell
> > selectively for each user (by providing or not a git-shell-commands
> > directory), but you cannot individually select the script that runs for
> > that user.  But it's probably still flexible enough;...
> 
> Such a flexibility is not a goal of /etc/git/shell-disabled.  The
> sole goal is to make the life easier for those site owners that do
> not want any interactive shell access to give more friendly and
> customized error message.
> 
> Those who want further flexibility can exit with non-zero from the
> "help" (which is still a misnomer for a hook to disable interactive
> for the user).

Ah, I thought you were proposing shell-disabled _instead_ of Jonathan's patch, not in addition to.

Show 6 quoted lines
> My primary objection is that implementing only that "more flexible
> but requires more configuration work" solution without giving
> simpler solution (i.e. just one thing to configure) to the majory of
> site owners who only have simpler problem to solve (i.e. just want
> to customize "no interactive here"), and saying that the latter can
> be done on top.  It is backwards mentality.

Oh, absolutely. The easy case should be easy, and the hard case possible. But another way of doing that (which would also make life easier for admins who want to share config besides shell-disabled) would be:

  1. Give Jonathan's magic meaning to ~/git-shell-commands/help's exit
     code.
  2. Make /etc/git/shell-commands a fallback if ~/git-shell-commands
     does not exist.

That turns your /etc/git/shell-disabled into /etc/git/shell-commands/help. It is just as simple to do a site-wide change, still allows per-user overrides, and additionally gives people who _do_ want the interactive commands the ability to configure them site-wide instead of symlinking a directory into everybody's homedir.

The only downside is that it has the confusing "create this directory to turn on interactivity, then create a file in it to turn it back off" feature.

I admit I don't care too much, though. I have never actually used git-shell, as my systems are all either too small (i.e., users are trusted and have shell access) or too big (grown well beyond a single server that connects users straight to git-shell). In fact, there seems to be a lot of guessing in this thread about what people would want, as it seems none of us actually uses the feature. Maybe that is a sign it is being over-engineered. :)

-Peff
Previous: Junio C HamanoNext: Ethan Reesor
Message 30 of 59 in “Git prompt”
  1. Ethan ReesorFeb 10, 2013
  2. Jonathan NiederFeb 10, 2013
  3. Ethan ReesorFeb 10, 2013
  4. Jeff KingFeb 10, 2013
  5. Junio C HamanoFeb 10, 2013
  6. Sitaram ChamartyFeb 11, 2013
  7. shell: allow 'help' command to disable interactive shellJonathan Nieder, Feb 11, 2013
  8. Junio C HamanoFeb 11, 2013
  9. Jonathan NiederFeb 11, 2013
  10. Junio C HamanoFeb 11, 2013
  11. Jonathan NiederFeb 11, 2013
  12. Jeff KingFeb 11, 2013
  13. Junio C HamanoFeb 11, 2013
  14. Ethan ReesorFeb 11, 2013
  15. Ethan ReesorFeb 11, 2013
  16. Jonathan NiederFeb 11, 2013
  17. Ethan ReesorFeb 11, 2013
  18. Jonathan NiederFeb 11, 2013
  19. Ethan ReesorFeb 11, 2013
  20. Jonathan NiederFeb 11, 2013
  21. Junio C HamanoFeb 11, 2013
  22. Jonathan NiederFeb 11, 2013
  23. Junio C HamanoFeb 11, 2013
  24. Jonathan NiederFeb 11, 2013
  25. Junio C HamanoFeb 11, 2013
  26. Jonathan NiederFeb 11, 2013
  27. Junio C HamanoFeb 11, 2013
  28. Jeff KingFeb 11, 2013
  29. Junio C HamanoFeb 11, 2013
  30. Jeff KingFeb 11, 2013
  31. Ethan ReesorFeb 11, 2013
  32. Ethan ReesorFeb 11, 2013
  33. Junio C HamanoFeb 11, 2013
  34. Ethan ReesorFeb 11, 2013
  35. Junio C HamanoFeb 11, 2013
  36. Jeff KingFeb 11, 2013
  37. Jonathan NiederFeb 11, 2013
  38. Jeff KingFeb 11, 2013
  39. Jonathan NiederFeb 11, 2013
  40. Jeff KingFeb 11, 2013
  41. 0/2 shell: allow 'help' command to disable interactive shellJonathan Nieder, Feb 11, 2013
  42. 1/2 shell doc: emphasize purpose and security modelJonathan Nieder, Feb 11, 2013
  43. Junio C HamanoFeb 11, 2013
  44. Jonathan NiederFeb 11, 2013
  45. Junio C HamanoFeb 11, 2013
  46. 2/2 shell: pay attention to exit status from 'help' commandJonathan Nieder, Feb 11, 2013
  47. Ethan ReesorFeb 11, 2013
  48. Junio C HamanoFeb 11, 2013
  49. Jonathan NiederFeb 11, 2013
  50. Junio C HamanoFeb 11, 2013
  51. Jeff KingFeb 11, 2013
  52. 0/2 shell: allow 'no-interactive-login' command to disable interactive shellJonathan Nieder, Mar 9, 2013
  53. 1/2 shell doc: emphasize purpose and security modelJonathan Nieder, Mar 9, 2013
  54. 2/2 shell: new no-interactive-login command to print a custom messageJonathan Nieder, Mar 9, 2013
  55. Junio C HamanoMar 10, 2013
  56. Jonathan NiederMar 10, 2013
  57. Ramkumar RamachandraMar 10, 2013
  58. Jonathan NiederMar 11, 2013
  59. Jeff KingMar 12, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.