git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [msysGit] [PATCH/RFC 06/11] run-command: add kill_async() and is_async_alive()

From
Erik Faye-Lund <kusmabite@googlemail.com>
Date
Jan 9, 2010, 00:49 UTC
Message-ID
<40aa078e1001081649h5cb767d5t880110d923418300@mail.gmail.com>
In-Reply-To
<200912022027.23344.j6t@kdbg.org>
On Wed, Dec 2, 2009 at 8:27 PM, Johannes Sixt <j6t@kdbg.org> wrote:
Show 20 quoted lines
> On Mittwoch, 2. Dezember 2009, Erik Faye-Lund wrote:
>> On Fri, Nov 27, 2009 at 8:59 PM, Johannes Sixt <j6t@kdbg.org> wrote:
>> > "relatively small chance of stuff blowing up"? The docs of
>> > TerminateThread: "... the kernel32 state for the thread's process could
>> > be inconsistent." That's scary if we are talking about a process that
>> > should run for days or weeks without interruption.
>>
>> I think there's a misunderstanding here. I thought your suggestion was
>> to simply call die(), which would take down the main process. After
>> reading this explanation, I think you're talking about giving an error
>> and rejecting the connection instead. Which makes more sense than to
>> risk crashing the main-process, indeed.
>
> Just rejecting a connection is certainly the simplest do to keep the daemon
> process alive. But the server can be DoS-ed from a single source IP.
>
> Currently git-daemon can only be DDoS-ed because there is a maximum number of
> connections, which are not closed if all of them originate from different
> IPs.
>
After some testing I've found that git-daemon can very much be DoS-ed
from a single IP in it's current form. This is for two reasons:
1) The clever xcalloc + memcmp trick has a fault; the port for each
connection is different, so there will never be a match. I have a
patch[1] for this that I plan to send out soon.
2) Even with this patch the effect of the DoS-protection is kind of
limited. This is because it's a child process of the fork()'d process
again that does all the heavy lifting, and kill(pid, SIGHUP) doesn't
kill child processes. So, the connection gets to continue the action
until upload-pack (or whatever the current command is) finish. This
might be quite lengthy.

As I said, I have a patch for 1), but I don't quite know how to fix 2). Perhaps this is a good use for process groups? I'm a Windows-guy; my POSIX isn't exactly super-awesome...

I found these issues during my latest effort to port git-daemon to Windows. I managed to get this to work fine on Windows, by implementing a kill(x, SIGTERM) that terminated child-processes (because I was under the impression that this was what happened... I guess daemon.c lead me to believe that).

[1]: http://repo.or.cz/w/git/kusma.git/commit/b1d286d32f42c57b90a1db9b7b8d6775a5d1ad7b
-- 
Erik "kusma" Faye-Lund
Previous: Johannes SixtNext: Erik Faye-Lund
Message 33 of 54 in “daemon-win32”
  1. 00/11 daemon-win32Erik Faye-Lund, Nov 26, 2009
  2. 01/11 mingw: add network-wrappers for daemonErik Faye-Lund, Nov 26, 2009
  3. 02/11 strbuf: add non-variadic function strbuf_vaddf()Erik Faye-Lund, Nov 26, 2009
  4. 03/11 mingw: implement syslogErik Faye-Lund, Nov 26, 2009
  5. 04/11 compat: add inet_pton and inet_ntop prototypesErik Faye-Lund, Nov 26, 2009
  6. 05/11 inet_ntop: fix a couple of old-style declsErik Faye-Lund, Nov 26, 2009
  7. 06/11 run-command: add kill_async() and is_async_alive()Erik Faye-Lund, Nov 26, 2009
  8. 07/11 run-command: support input-fdErik Faye-Lund, Nov 26, 2009
  9. 08/11 daemon: use explicit file descriptorErik Faye-Lund, Nov 26, 2009
  10. 09/11 daemon: use run-command api for async servingErik Faye-Lund, Nov 26, 2009
  11. 10/11 daemon: use full buffered mode for stderrErik Faye-Lund, Nov 26, 2009
  12. 11/11 mingw: compile git-daemonErik Faye-Lund, Nov 26, 2009
  13. Johannes SixtNov 27, 2009
  14. Johannes SixtNov 27, 2009
  15. Erik Faye-LundDec 2, 2009
  16. Johannes SixtDec 2, 2009
  17. Erik Faye-LundDec 8, 2009
  18. Johannes SixtNov 26, 2009
  19. Erik Faye-LundNov 27, 2009
  20. Erik Faye-LundNov 27, 2009
  21. Johannes SixtNov 27, 2009
  22. Johannes SixtNov 27, 2009
  23. Erik Faye-LundDec 8, 2009
  24. Johannes SixtNov 26, 2009
  25. Erik Faye-LundNov 27, 2009
  26. Johannes SixtNov 27, 2009
  27. Erik Faye-LundDec 8, 2009
  28. Johannes SixtNov 26, 2009
  29. Erik Faye-LundNov 27, 2009
  30. Johannes SixtNov 27, 2009
  31. Erik Faye-LundDec 2, 2009
  32. Johannes SixtDec 2, 2009
  33. Erik Faye-LundJan 9, 2010
  34. Erik Faye-LundJan 10, 2010
  35. Johannes SixtNov 26, 2009
  36. Erik Faye-LundNov 27, 2009
  37. Johannes SixtNov 27, 2009
  38. Erik Faye-LundDec 8, 2009
  39. Junio C HamanoNov 26, 2009
  40. Erik Faye-LundNov 26, 2009
  41. Paolo BonziniNov 26, 2009
  42. Junio C HamanoNov 26, 2009
  43. Erik Faye-LundNov 26, 2009
  44. Johannes SixtNov 27, 2009
  45. Martin StorsjöNov 26, 2009
  46. Improve the mingw getaddrinfo stub to handle more use casesMartin Storsjö, Nov 26, 2009
  47. Erik Faye-LundNov 26, 2009
  48. Martin StorsjöNov 26, 2009
  49. Erik Faye-LundDec 2, 2009
  50. Martin StorsjöDec 2, 2009
  51. Erik Faye-LundDec 2, 2009
  52. Erik Faye-LundDec 2, 2009
  53. Johannes SixtDec 2, 2009
  54. Johannes SixtNov 26, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.