git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC] daemon whitelist handling (Re: git pull aborts in 50% of cases)

From
HAH. Peter Anvin <hpa@zytor.com>
Date
Dec 3, 2005, 19:41 UTC
Message-ID
<4391F4DD.2060002@zytor.com>
In-Reply-To
<7vzmnivuz8.fsf_-_@assigned-by-dhcp.cox.net>
Junio C Hamano wrote:
Show 13 quoted lines
> 
> For example, I can by mistake create a symbolic link:
> 
> 	ln -s /home /pub/scm/git/git.git/oops
> 
> now accesses /pub/scm/git/oops/hpa/secret.git/ is not
> restricted.  We could hand-resolve the each level from the
> request to see if no "funny" symbolic links are involved, but
> what is the definition of "funny"?  When we see /pub pointing at
> somewhere in /mnt/disk47/slice31, we should not complain.  When
> we see "oops" under git in the above example, we would want to
> complain.  These things are hard to get right.
> 

Actually, it's a policy decision whether or not symlinks should be allowed to exit space like that; in Apache, for example, it's a configurable.

> I tend to say that the 0.99.9k (and the current master) rule to
> make validation always work on what getcwd() gives back is
> easier to understand (which generally means safer).  Can I talk
> you into adjusting your whitelist on kernel.org machines?

I'm not happy about it, but it's not a huge deal on kernel.org. However, I think it's the wrong thing, especially in the light of allowing user-relative paths.

At the very least, if you insist on using getcwd() names, you should pre-canonicalize the whitelist, too.

	-hpa
Previous: Junio C HamanoNext: Linus Torvalds
Message 12 of 17 in “git pull aborts in 50% of cases”
  1. Alexey DobriyanDec 2, 2005
  2. H. Peter AnvinDec 2, 2005
  3. Alexey DobriyanDec 2, 2005
  4. H. Peter AnvinDec 2, 2005
  5. Junio C HamanoDec 2, 2005
  6. Johannes SchindelinDec 3, 2005
  7. Junio C HamanoDec 3, 2005
  8. H. Peter AnvinDec 3, 2005
  9. Junio C HamanoDec 3, 2005
  10. H. Peter AnvinDec 3, 2005
  11. [RFC] daemon whitelist handling (Re: git pull aborts in 50% of cases)Junio C Hamano, Dec 3, 2005
  12. H. Peter AnvinDec 3, 2005
  13. Linus TorvaldsDec 3, 2005
  14. Junio C HamanoDec 3, 2005
  15. Junio C HamanoDec 3, 2005
  16. Junio C HamanoDec 3, 2005
  17. H. Peter AnvinDec 3, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.