git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [gitolite] repo config for delegated projects

From
Sitaram Chamarty <sitaramc@gmail.com>
Date
Feb 6, 2010, 00:50 UTC
Message-ID
<2e24e5b91002051650k3c7cf14ev8752d36b5616e9a4@mail.gmail.com>
In-Reply-To
<20100204040812.GC13411@lapse.rw.madduck.net>
On Thu, Feb 4, 2010 at 9:38 AM, martin f krafft <madduck@madduck.net> wrote:
Show 6 quoted lines
> also sprach Sitaram Chamarty <sitaram@atc.tcs.com> [2010.02.04.1418 +1300]:
>> how about
>>
>>     $DELEGATED_CONFIGS = "hooks.mailinglist,hooks.showrev";
>
> Excellent idea.
OK I've run into a little decision-point here.

The problem above is of making sure that a delegated admin cannot misuse the gitconfig mechanism to do stuff he's not allowed to do, but it's actually worse than that :(

First some background. For a long time I treated the "main" admin (anyone who has RW/RW+ rights to gitolite.conf) to be eqvt to having shell access. Then we started moving away from that, and that is good because having shell access allows him to bypass the logging that gitolite does, thus polluting the audit trail. Preventing that makes a lot of sense in a corporate environment, and lets you allow a lot more people to manage the gitolite access list.

Now I just looked up hooks.showrev, and it's supposed to be any shell command. Clearly this means anyone who can set that gitconfig option now has shell capability, and it's game over.

Regardless of how I look at it, I can't think of a cure for this short
of either:
  - putting all the allowed gitconfigs in the RC file, and not in the
config (writing the RC file requires shell access, and we presume the
"root of trust" person has enough smarts to know what to allow and
what not to allow), and allowing repo admins to *refer* to them to use
whichever they want
  - someone coming up with a list of gitconfig's that are "safe", and
specific values for those that are unsafe (like saying "if you use
showrev, you can only use this command  as the value", and forcing
only those.

I'm leaning toward the former; easier for me ;-) Meanwhile, I'm punting this to Teemu until the morning fog in my brain clears :)

Previous: martin f krafftNext: martin f krafft
Message 5 of 8 in “[gitolite] repo config for delegated projects”
  1. martin f krafftFeb 3, 2010
  2. Teemu MatilainenFeb 3, 2010
  3. Sitaram ChamartyFeb 4, 2010
  4. martin f krafftFeb 4, 2010
  5. Sitaram ChamartyFeb 6, 2010
  6. martin f krafftFeb 6, 2010
  7. Sitaram ChamartyFeb 6, 2010
  8. Teemu MatilainenFeb 6, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.