git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[RFC] daemon whitelist handling (Re: git pull aborts in 50% of cases)

From
Junio C Hamano <junkio@cox.net>
Date
Dec 3, 2005, 19:30 UTC
Message-ID
<7vzmnivuz8.fsf_-_@assigned-by-dhcp.cox.net>
In-Reply-To
<7vpsoezf6y.fsf@assigned-by-dhcp.cox.net>

Having slept over the patch I am responding to, I tend to think this is more trouble than its worth. Validating the directory enter_repo() chdir()'ed into and validated to be a good git repository should be done on its canonical name as getcwd() returns, not with a userland aliasing avoidance.

As an administrator, being able to say /pub/scm on the whitelist, knowing /pub to be a symbolic link points at somewhere today but maybe at different place tomorrow, and not having to adjust the whitelist whenever that happens, is indeed nice. We do not allow the remote requestor to say /../ in the path, so we trap him within the directories the whitelist describes.

Not.
For example, I can by mistake create a symbolic link:
	ln -s /home /pub/scm/git/git.git/oops

now accesses /pub/scm/git/oops/hpa/secret.git/ is not restricted. We could hand-resolve the each level from the request to see if no "funny" symbolic links are involved, but what is the definition of "funny"? When we see /pub pointing at somewhere in /mnt/disk47/slice31, we should not complain. When we see "oops" under git in the above example, we would want to complain. These things are hard to get right.

I tend to say that the 0.99.9k (and the current master) rule to make validation always work on what getcwd() gives back is easier to understand (which generally means safer). Can I talk you into adjusting your whitelist on kernel.org machines?

Previous: H. Peter AnvinNext: H. Peter Anvin
Message 11 of 17 in “git pull aborts in 50% of cases”
  1. Alexey DobriyanDec 2, 2005
  2. H. Peter AnvinDec 2, 2005
  3. Alexey DobriyanDec 2, 2005
  4. H. Peter AnvinDec 2, 2005
  5. Junio C HamanoDec 2, 2005
  6. Johannes SchindelinDec 3, 2005
  7. Junio C HamanoDec 3, 2005
  8. H. Peter AnvinDec 3, 2005
  9. Junio C HamanoDec 3, 2005
  10. H. Peter AnvinDec 3, 2005
  11. [RFC] daemon whitelist handling (Re: git pull aborts in 50% of cases)Junio C Hamano, Dec 3, 2005
  12. H. Peter AnvinDec 3, 2005
  13. Linus TorvaldsDec 3, 2005
  14. Junio C HamanoDec 3, 2005
  15. Junio C HamanoDec 3, 2005
  16. Junio C HamanoDec 3, 2005
  17. H. Peter AnvinDec 3, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.