git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC] daemon whitelist handling (Re: git pull aborts in 50% of cases)

From
HAH. Peter Anvin <hpa@zytor.com>
Date
Dec 3, 2005, 20:45 UTC
Message-ID
<439203F6.1040505@zytor.com>
In-Reply-To
<7vvey6vsop.fsf@assigned-by-dhcp.cox.net>
Junio C Hamano wrote:
Show 13 quoted lines
> "H. Peter Anvin" <hpa@zytor.com> writes:
> 
>>At the very least, if you insist on using getcwd() names, you should 
>>pre-canonicalize the whitelist, too.
> 
> With the current "prefix" rule (and not allowing /ho to match
> /home) that sounds possible and sensivle, but that is not nice
> in the long run.  We may later want to say "/pub/git/**/*.git"
> for example to mean "any subdirectory under /pub/git but the
> base directory name must be something ending with '.git'".
> 
> Hmm...
> 

Yep, this stuff is hard. For example, on kernel.org I'm not concerned about symbolic links; the likelihood of an accidental symbolic link that would violate security is very small. Other applications might be different.

Arguably, the correct interface is to modularize it, and have both the user request, the post-DWIM output, and the

	-hpa
Previous: Junio C Hamano
Message 17 of 17 in “git pull aborts in 50% of cases”
  1. Alexey DobriyanDec 2, 2005
  2. H. Peter AnvinDec 2, 2005
  3. Alexey DobriyanDec 2, 2005
  4. H. Peter AnvinDec 2, 2005
  5. Junio C HamanoDec 2, 2005
  6. Johannes SchindelinDec 3, 2005
  7. Junio C HamanoDec 3, 2005
  8. H. Peter AnvinDec 3, 2005
  9. Junio C HamanoDec 3, 2005
  10. H. Peter AnvinDec 3, 2005
  11. [RFC] daemon whitelist handling (Re: git pull aborts in 50% of cases)Junio C Hamano, Dec 3, 2005
  12. H. Peter AnvinDec 3, 2005
  13. Linus TorvaldsDec 3, 2005
  14. Junio C HamanoDec 3, 2005
  15. Junio C HamanoDec 3, 2005
  16. Junio C HamanoDec 3, 2005
  17. H. Peter AnvinDec 3, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.