git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: chrooting git daemon?

From
KLKlas Lindberg <klas.lindberg@gmail.com>
Date
Jun 11, 2009, 21:27 UTC
Message-ID
<37C1FAEE-FCE3-4A38-AC89-0AAF3B1174DF@gmail.com>
In-Reply-To
<200906111530.31160.janklodvan@gmail.com>
11 jun 2009 kl. 17.30 skrev Jan Klod:
Show 5 quoted lines
> Hello,
> please, is that hard / complicated to run git daemon in chroot and  
> what are
> the steps to do it best?
> Do you consider it useless precaution there?

You do know that chroot is not a security tool, right? If you do want security measures, I'd suggest setting up SSH accounts with the login shell set to git-shell. The main difference is that you can have any number of trees served from the same machine without handling them all by the same service instance. If you wanted to accomplish the same with git-daemon, you'd have to let all of them listen to different ports. At least that's how I understand it.

BR / Klas
Previous: Jan Klod
Message 2 of 2 in “chrooting git daemon?”
  1. Jan KlodJun 11, 2009
  2. Klas LindbergJun 11, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.