git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 5/5] git-daemon support for user-relative paths.

From
Andreas Ericsson <ae@op5.se>
Date
Nov 18, 2005, 23:45 UTC
Message-ID
<437E67AC.2010400@op5.se>
In-Reply-To
<7voe4hfssj.fsf@assigned-by-dhcp.cox.net>
Junio C Hamano wrote:
> 
> I think it might make sense to inserting something like the
> attached untested patch in your series, between library and
> upload-pack.

I'll run the clone/fetch/push test-suite again tomorrow, with this applied. It looks good though.

>  The validation done by path_ok() in git-daemon
> probabaly needs to lose alternate checks and validate only the
> path returned by enter_repo().  This would make writing
> whitelist by git-daemon administrator a bit more cumbersome,

Not necessarily. The repositories in the whitelist should be validated (and possibly converted) using the path_ok() function. This will also make it possible to catch typos and permission errors that are just plain annoying for the admins.

In non-strict mode this isn't really a problem so long as all whitelist-paths are absolute and doesn't contain any symlinks, although we could use the chdir() + getcwd() thingie since we don't need the ability to go back to where we started and that's what will be used later when serving the repos.

-- 
Andreas Ericsson                   andreas.ericsson@op5.se
OP5 AB                             www.op5.se
Tel: +46 8-230225                  Fax: +46 8-230231
Previous: Junio C HamanoNext: Junio C Hamano
Message 8 of 12 in “git-daemon support for user-relative paths.”
  1. 5/5 git-daemon support for user-relative paths.Andreas Ericsson, Nov 17, 2005
  2. Junio C HamanoNov 18, 2005
  3. Andreas EricssonNov 18, 2005
  4. Matthias UrlichsNov 18, 2005
  5. H. Peter AnvinNov 18, 2005
  6. Junio C HamanoNov 18, 2005
  7. Junio C HamanoNov 18, 2005
  8. Andreas EricssonNov 18, 2005
  9. Junio C HamanoNov 21, 2005
  10. Junio C HamanoNov 21, 2005
  11. Andreas EricssonNov 21, 2005
  12. Junio C HamanoNov 21, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.