git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 2/2] shell: pay attention to exit status from 'help' command

From
Junio C Hamano <gitster@pobox.com>
Date
Feb 11, 2013, 16:28 UTC
Message-ID
<7vip5yolvo.fsf@alter.siamese.dyndns.org>
In-Reply-To
<20130211075245.GO15329@elie.Belkin>
Jonathan Nieder <jrnieder@gmail.com> writes:
Show 36 quoted lines
> Junio C Hamano wrote:
>> Jonathan Nieder <jrnieder@gmail.com> writes:
>
>>> +To disable interactive logins, displaying a greeting instead:
>>> ++
>>> +----------------
>>> +$ chsh -s /usr/bin/git-shell
>>> +$ mkdir $HOME/git-shell-commands
>>> +$ cat >$HOME/git-shell-commands/help <<\EOF
>>> +#!/bin/sh
>>> +printf '%s\n' "Hi $USER! You've successfully authenticated, but I do not"
>>
>> Where in the sshd to git-shell exec chain is $USER variable set for
>> the user?  Just being curious if this is the simplest but one of the
>> more robust ways to get the user's name.
>
> That's a good question.  environment= in an authorized_keys file is
> obsolete, so USER generally represents the actual logged in user.
>
> That means the main way to base behavior on private key (letting one
> system user represent multiple people) is a gitolite-style command=
> wrapper that checks SSH_ORIGINAL_COMMAND.  In that setup, there is no
> reason to forward simple no-args "are you there?" requests to the
> git-shell, so we can forget about it here.
>
> So by the time we get to git-shell, most likely either
>
>  A) this is a generic system user, with a username like "git", and the
>     above example would insult the client with "Hi git!" or "Hi
>     project-x-git!"
>
> or
>
>  B) each person has a separate account on the system, perhaps to help
>     the admin to set filesystem permissions based on users and groups,
>     and the above would address the user by her normal name.

What return value getuid(2) would give us was not something I was worried about. Use of git-shell would be pointless if that does not work to offer isolation between users.

I was wondering who would set the $USER variable based on the uid assigned to the process during the remote login process and it is a behaviour we can rely on across platforms. It appears that when coming over ssh, it is the ssh daemon that sets USER (and LOGNAME, HOME, etc.) before running the login shell (session.c::do_child() that is called from do_exec_pty() or do_exec_no_pty() in openssh).

Previous: Jonathan NiederNext: Jeff King
Message 50 of 59 in “Git prompt”
  1. Ethan ReesorFeb 10, 2013
  2. Jonathan NiederFeb 10, 2013
  3. Ethan ReesorFeb 10, 2013
  4. Jeff KingFeb 10, 2013
  5. Junio C HamanoFeb 10, 2013
  6. Sitaram ChamartyFeb 11, 2013
  7. shell: allow 'help' command to disable interactive shellJonathan Nieder, Feb 11, 2013
  8. Junio C HamanoFeb 11, 2013
  9. Jonathan NiederFeb 11, 2013
  10. Junio C HamanoFeb 11, 2013
  11. Jonathan NiederFeb 11, 2013
  12. Jeff KingFeb 11, 2013
  13. Junio C HamanoFeb 11, 2013
  14. Ethan ReesorFeb 11, 2013
  15. Ethan ReesorFeb 11, 2013
  16. Jonathan NiederFeb 11, 2013
  17. Ethan ReesorFeb 11, 2013
  18. Jonathan NiederFeb 11, 2013
  19. Ethan ReesorFeb 11, 2013
  20. Jonathan NiederFeb 11, 2013
  21. Junio C HamanoFeb 11, 2013
  22. Jonathan NiederFeb 11, 2013
  23. Junio C HamanoFeb 11, 2013
  24. Jonathan NiederFeb 11, 2013
  25. Junio C HamanoFeb 11, 2013
  26. Jonathan NiederFeb 11, 2013
  27. Junio C HamanoFeb 11, 2013
  28. Jeff KingFeb 11, 2013
  29. Junio C HamanoFeb 11, 2013
  30. Jeff KingFeb 11, 2013
  31. Ethan ReesorFeb 11, 2013
  32. Ethan ReesorFeb 11, 2013
  33. Junio C HamanoFeb 11, 2013
  34. Ethan ReesorFeb 11, 2013
  35. Junio C HamanoFeb 11, 2013
  36. Jeff KingFeb 11, 2013
  37. Jonathan NiederFeb 11, 2013
  38. Jeff KingFeb 11, 2013
  39. Jonathan NiederFeb 11, 2013
  40. Jeff KingFeb 11, 2013
  41. 0/2 shell: allow 'help' command to disable interactive shellJonathan Nieder, Feb 11, 2013
  42. 1/2 shell doc: emphasize purpose and security modelJonathan Nieder, Feb 11, 2013
  43. Junio C HamanoFeb 11, 2013
  44. Jonathan NiederFeb 11, 2013
  45. Junio C HamanoFeb 11, 2013
  46. 2/2 shell: pay attention to exit status from 'help' commandJonathan Nieder, Feb 11, 2013
  47. Ethan ReesorFeb 11, 2013
  48. Junio C HamanoFeb 11, 2013
  49. Jonathan NiederFeb 11, 2013
  50. Junio C HamanoFeb 11, 2013
  51. Jeff KingFeb 11, 2013
  52. 0/2 shell: allow 'no-interactive-login' command to disable interactive shellJonathan Nieder, Mar 9, 2013
  53. 1/2 shell doc: emphasize purpose and security modelJonathan Nieder, Mar 9, 2013
  54. 2/2 shell: new no-interactive-login command to print a custom messageJonathan Nieder, Mar 9, 2013
  55. Junio C HamanoMar 10, 2013
  56. Jonathan NiederMar 10, 2013
  57. Ramkumar RamachandraMar 10, 2013
  58. Jonathan NiederMar 11, 2013
  59. Jeff KingMar 12, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.