git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] git-upload-archive: add config option to allow only specified formats

From
Junio C Hamano <junkio@cox.net>
Date
Sep 10, 2006, 18:00 UTC
Message-ID
<7vpse3sitc.fsf@assigned-by-dhcp.cox.net>
In-Reply-To
<20060910155837.GA15974@lsrfire.ath.cx>
Rene Scharfe <rene.scharfe@lsrfire.ath.cx> writes:
Show 18 quoted lines
>  Documentation/config.txt |    5 +++++
>  builtin-upload-archive.c |   39 +++++++++++++++++++++++++++++++++++++++
>  daemon.c                 |    2 ++
>  3 files changed, 46 insertions(+)
>
> diff --git a/Documentation/config.txt b/Documentation/config.txt
> index ce722a2..5c3c6c7 100644
> --- a/Documentation/config.txt
> +++ b/Documentation/config.txt
> @@ -236,6 +236,11 @@ tar.umask::
>  	the same permissions as gitlink:git-checkout[1] would use. The default
>  	value remains 0, which means world read-write.
>  
> +uploadarchive.daemonformats::
> +	A comma-separated list of the git-archive formats allowed for upload
> +	via git-daemon.  If this parameter is missing all formats are allowed
> +	for upload.
> +

Fine -- do we have any other "list-ish" configuration variable, by the way? I am just wondering if we earlier established a convention to use some delimiter to list out things and if we do have such a convention if delimiter is a comma or not.

Show 16 quoted lines
> diff --git a/builtin-upload-archive.c b/builtin-upload-archive.c
> index 96f96bd..6a5245a 100644
> --- a/builtin-upload-archive.c
> +++ b/builtin-upload-archive.c
> @@ -16,6 +16,37 @@ static const char upload_archive_usage[]
>  static const char deadchild[] =
>  "git-upload-archive: archiver died with error";
>  
> +static char *daemon_formats;
> +
> +static int upload_format_config(const char *var, const char *value)
> +{
> +	if (!strcmp(var, "uploadarchive.daemonformats"))
> +		daemon_formats = xstrdup(value);
> +	return 0;
> +}
This let's the repository owner to decide what can be used.
Show 6 quoted lines
> +static int upload_format_allowed(const char *fmt)
> +{
> +	if (getenv("GIT_DAEMON"))
> +		return daemon_formats ? is_in(fmt, daemon_formats, " \t,") : 1;
> +	return 1;
> +}

And limits the allowed format when the environment set to the value the repository owner decided.

Show 12 quoted lines
>  static int run_upload_archive(int argc, const char **argv, const char *prefix)
>  {
> @@ -67,6 +100,12 @@ static int run_upload_archive(int argc, 
>  	/* parse all options sent by the client */
>  	treeish_idx = parse_archive_args(sent_argc, sent_argv, &ar);
>  
> +	if (!upload_format_allowed(ar.name)) {
> +		free(daemon_formats);
> +		die("upload of %s format forbidden\n", ar.name);
> +	}
> +	free(daemon_formats);
> +

So we could enhance "--remote --list" to show what are supported (both codewise and policywise) on the remote end, with a bit of code restructuring?

Show 9 quoted lines
> diff --git a/daemon.c b/daemon.c
> index a2954a0..2d58abe 100644
> --- a/daemon.c
> +++ b/daemon.c
> @@ -304,6 +304,8 @@ static int run_service(char *dir, struct
>  		return -1;
>  	}
>  
> +	setenv("GIT_DAEMON", "I am your father.", 1);

I suspect "upload_format_allowed()" can be taught to see what is in this environment variable and sometimes take that as daemon_format without letting the repository to override it, so that the site administrator can limit the formats that can be used further, just like daemon service mechanism lets them be in control.

Previous: Rene ScharfeNext: Rene Scharfe
Message 9 of 28 in “archive: allow remote to have more formats than we understand.”
  1. 1/2 archive: allow remote to have more formats than we understand.Junio C Hamano, Sep 10, 2006
  2. 2/2 Add --verbose to git-archiveJunio C Hamano, Sep 10, 2006
  3. 1/3 Move sideband client side support into reusable form.Junio C Hamano, Sep 10, 2006
  4. Franck Bui-HuuSep 10, 2006
  5. Move sideband server side support into reusable form.Junio C Hamano, Sep 10, 2006
  6. 3/3 Add sideband status report to git-archive protocolJunio C Hamano, Sep 10, 2006
  7. git-upload-archive: add config option to allow only specified formatsRene Scharfe, Sep 10, 2006
  8. Rene ScharfeSep 10, 2006
  9. Junio C HamanoSep 10, 2006
  10. Rene ScharfeSep 11, 2006
  11. Jakub NarebskiSep 11, 2006
  12. Franck Bui-HuuSep 10, 2006
  13. Rene ScharfeSep 11, 2006
  14. Franck Bui-HuuSep 10, 2006
  15. Junio C HamanoSep 10, 2006
  16. Franck Bui-HuuSep 11, 2006
  17. Junio C HamanoSep 12, 2006
  18. Franck Bui-HuuSep 12, 2006
  19. Franck Bui-HuuSep 12, 2006
  20. connect.c: finish_connect(): allow null pid parameterFranck Bui-Huu, Sep 12, 2006
  21. Junio C HamanoSep 13, 2006
  22. Test return value of finish_connect()Franck Bui-Huu, Sep 13, 2006
  23. git_connect: change return type to pid_tFranck Bui-Huu, Sep 13, 2006
  24. Junio C HamanoSep 12, 2006
  25. Rene ScharfeSep 10, 2006
  26. Franck Bui-HuuSep 10, 2006
  27. Junio C HamanoSep 10, 2006
  28. Franck Bui-HuuSep 10, 2006

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.