git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git clone against firewall

From
Junio C Hamano <gitster@pobox.com>
Date
Jan 15, 2010, 18:17 UTC
Message-ID
<7vzl4fz0zb.fsf@alter.siamese.dyndns.org>
In-Reply-To
<4B4FACB1.2080902@hartwork.org>
Sebastian Pipping <webmaster@hartwork.org> writes:
Show 11 quoted lines
> with a firewall blocking outgoing connections to port 9418 a
>
>   git clone git://...
>
> of git 1.6.6 seems to never return, i.e. loop forever.  in my rather
> automated environment (gentoo's tool layman calling git) this behavior
> is rather troublesome - i need some kind of abort-and-error instead:
> what i'm trying to do is loop over a number of clone URL alternatives of
> the same repository like ..
>
>   git://git.overlays.gentoo.org/dev/dberkholz.git
What do you exactly mean by "blocking"?
In my environment at work, there is a firewall and I immedately get this:
    $ git clone git://git.overlays.gentoo.org/dev/dberkholz.git/
    Initialized empty Git repository in /var/tmp/dberkholz/.git/
    fatal: Unable to look up git.overlays.gentoo.org (port 9418) (Name or service not known)

as my environment is quite isolated (it is not just a "NAT with selective port blocking").

I am guessing that you can resolve the hostname in your environment (i.e. you configured your NAT to let DNS go directly outside). What happens when you try the following?

    $ telnet git.overlays.gentoo.org 9418
Do you get:
    Trying 66.219.59.40...
    telnet: Unable to connect to remote host: Connection refused
If you get something like:
    Trying 66.219.59.40...
    Connected to pelican.gentoo.org.
    Escape character is '^]'.

then I don't think you are blocked, and if that is the case, there is not much we can do about it.

I think your firewall can help, though, by not pretending to be allowing the connection and then blocking you halfway.

Previous: Sebastian PippingNext: Sebastian Pipping
Message 2 of 8 in “git clone against firewall”
  1. Sebastian PippingJan 14, 2010
  2. Junio C HamanoJan 15, 2010
  3. Sebastian PippingJan 15, 2010
  4. Sebastian PippingJan 15, 2010
  5. Andreas SchwabJan 15, 2010
  6. Sebastian PippingJan 15, 2010
  7. Andreas KreyJan 15, 2010
  8. Sebastian PippingJan 18, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.