git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] Implement ACL module architecture and sample MySQL ACL module

From
Junio C Hamano <gitster@pobox.com>
Date
Aug 14, 2012, 17:06 UTC
Message-ID
<7vsjbp768y.fsf@alter.siamese.dyndns.org>
In-Reply-To
<CAJo=hJtYz3OX1C6HS7ivhJKBOSg=Ex3rKEdTYSbcDfFT1Jh4hw@mail.gmail.com>
Shawn Pearce <spearce@spearce.org> writes:
Show 11 quoted lines
> Parsing the request line of git-daemon is easy. But we could make it
> easier. An alternative arrangement would be to add a new command line
> flag to git daemon like --command-filter that names an executable
> git-daemon will invoke after parsing the request line. It can pass
> along the client IP address, command request, repository name, and
> resolved repository path, and tie stdin/stdout to the client. This
> binary can decide to exec the proper git binary for the named command,
> or just exit to disconnect the client and refuse service. This makes
> it simple for a tool like gitolite to plug into the git-daemon
> authorization path, without needing to be the network daemon itself,
> worry about number of active connection slots, etc.

I think that is a good direction to go in, except that I am unsure what kind of conversation do you want to allow between the "command filter" helper and the client by exposing standard input and output stream to to the helper. If the client side has a matching "pre negotiate command" helper support, then presumably the helpers can discuss what Git protocol proper does not care about before deciding to allow the connection go through, but until that happens, opening the stdio streams up to the helper sounds like an accident waiting to happen to me (e.g. "fetch-pack" connects, the server side helper reads the first pkt-line from the client, says "OK, you may proceed" to the daemon, then the daemon spawns the "upload-pack", which will obviously see a corrupt request stream from "fetch-pack").

Previous: Shawn PearceNext: Shawn Pearce
Message 4 of 9 in “Implement ACL module architecture and sample MySQL ACL module”
  1. Implement ACL module architecture and sample MySQL ACL moduleMichal Novotny, Aug 14, 2012
  2. Junio C HamanoAug 14, 2012
  3. Shawn PearceAug 14, 2012
  4. Junio C HamanoAug 14, 2012
  5. Shawn PearceAug 14, 2012
  6. Junio C HamanoAug 14, 2012
  7. daemon: --access-hook optionJunio C Hamano, Aug 15, 2012
  8. Shawn PearceAug 15, 2012
  9. Michal NovotnyAug 21, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.