git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v4 15/15] daemon: opt-out on features that require posix

From
Erik Faye-Lund <kusmabite@gmail.com>
Date
Oct 21, 2010, 21:16 UTC
Message-ID
<AANLkTik3Di=dcC=CxW+Lou515E2wXq8_OaR99mghC+vF@mail.gmail.com>
In-Reply-To
<20101018163134.GA6343@burratino>
On Mon, Oct 18, 2010 at 6:31 PM, Jonathan Nieder <jrnieder@gmail.com> wrote:
> A response to the general questions.
Thanks!
Show 22 quoted lines
> Erik Faye-Lund wrote:
>> On Fri, Oct 15, 2010 at 11:16 PM, Junio C Hamano <gitster@pobox.com> wrote:
>
>>> Why does the signature even have to be different between the two to begin
>>> with? I _think_ you have gid_t over there
>>
>> We don't, so this is the primary reason.
>
> Just to throw an idea out: you can also do something like
>
> #ifndef NO_POSIX_GOODIES
> struct credentials {
> };
> #else
> struct credentials {
>        struct passwd *pass;
>        gid_t gid;
> }
> #endif
>
> and pass a pointer to credentials around.
>

Yes, but that structure still needs to be filled somehow. I'm not sure how this solves anything, really. Isn't it essentially another way of wrapping an ifdef around the parameters inside main() (at least when I've inlined serve() into main())?

Show 66 quoted lines
>>> This is especially
>>> true if you are making the "drop-privileges" part a helper function, no?
>>
>> I don't follow this part. What exactly becomes more true by having a
>> drop-privileges function?
>
> (See linux-2.6.git:Documentation/SubmittingPatches, section "#ifdefs
> are ugly".)
>
> The ideal: never an #ifdef within a function.  (Well, the ideal is
> no #ifdef-s in .c files, but that's harder to take seriously.)
>
> #ifndef HAVE_POSIX_GOODIES
> static int drop_privileges(...)
> {
>        return error("--user and --group not supported on this platform");
> }
> #endif
> static int drop_privileges(...)
> {
>        ...
>        do
>        something
>        ...
> }
> #endif
>
> would make serve() look like
>
> static int serve(...)
> {
>        int socknum, *socklist;
>
>        ... setup socket ...
>
>        if (want to drop privileges) {
>                if (drop_privileges(...))
>                        return -1;
>        }
>
>        return service_loop(socknum, socklist);
> }
>
> which should be quite readable even to a person only interested in the
> !HAVE_POSIX_GOODIES case imho.  With some code rearrangement it could
> be made nicer.  Now compare:
>
> static int serve(...)
> {
>        int socknum, *socklist;
>
>        ... setup socket ...
>
> #ifdef HAVE_POSIX_GOODIES
>        ...
>        do
>        things
>        ...
> #endif
>
>        return service_loop(socknum, socklist);
> }
>
> Just my two cents.  Sorry I do not have something more substantive to
> say.
>

You're leaving out the troublesome part, namely the glue between "if (user_name)" in main(), and the "want to drop privileges"-stuff in serve().

I could do a "struct credentials *cred = NULL;" in main(), and assign that inside "if (user_name)". But that'd leave a warning about unreachable code in drop_privileges(), no?

I'm also getting the feeling that I'm being hinted at to implement proper credential-dropping (ie filling out the windows-versions of the code with something that makes sense for windows), but this isn't how these things work on Windows. Daemons run as services on Windows, and what user to run a service under is a system-administrator setting. In fact, you can't even impersonate another user without having it's password.

Turning git-daemon into a service is something that can be done later. I've looked into it, and what seems to make the most sense is to have a separate mode on git-daemon (or even another program), that starts git-daemon as a subprocess. This is because of the way Windows communicates with the service, requiring a message-loop that can be terminated.

Previous: Jonathan NiederNext: Erik Faye-Lund
Message 39 of 47 in “daemon-win32”
  1. 00/15 daemon-win32Erik Faye-Lund, Oct 11, 2010
  2. 01/15 mingw: add network-wrappers for daemonErik Faye-Lund, Oct 11, 2010
  3. Jonathan NiederOct 11, 2010
  4. 02/15 mingw: implement syslogErik Faye-Lund, Oct 11, 2010
  5. Jonathan NiederOct 11, 2010
  6. Erik Faye-LundOct 11, 2010
  7. Jonathan NiederOct 11, 2010
  8. Erik Faye-LundOct 13, 2010
  9. Eric SunshineOct 13, 2010
  10. Pat ThoytsOct 13, 2010
  11. Erik Faye-LundOct 14, 2010
  12. 03/15 compat: add inet_pton and inet_ntop prototypesErik Faye-Lund, Oct 11, 2010
  13. 04/15 inet_ntop: fix a couple of old-style declsErik Faye-Lund, Oct 11, 2010
  14. 05/15 mingw: use real pidErik Faye-Lund, Oct 11, 2010
  15. 06/15 mingw: support waitpid with pid > 0 and WNOHANGErik Faye-Lund, Oct 11, 2010
  16. 07/15 mingw: add kill emulationErik Faye-Lund, Oct 11, 2010
  17. 08/15 daemon: use run-command api for async servingErik Faye-Lund, Oct 11, 2010
  18. Junio C HamanoOct 13, 2010
  19. Erik Faye-LundOct 14, 2010
  20. Junio C HamanoOct 17, 2010
  21. 09/15 daemon: use full buffered mode for stderrErik Faye-Lund, Oct 11, 2010
  22. 10/15 Improve the mingw getaddrinfo stub to handle more use casesErik Faye-Lund, Oct 11, 2010
  23. 11/15 daemon: report connection from root-processErik Faye-Lund, Oct 11, 2010
  24. Junio C HamanoOct 13, 2010
  25. Erik Faye-LundOct 14, 2010
  26. Junio C HamanoOct 17, 2010
  27. Erik Faye-LundOct 17, 2010
  28. 12/15 mingw: import poll-emulation from gnulibErik Faye-Lund, Oct 11, 2010
  29. 13/15 mingw: use poll-emulation from gnulibErik Faye-Lund, Oct 11, 2010
  30. 14/15 daemon: use socklen_tErik Faye-Lund, Oct 11, 2010
  31. 15/15 daemon: opt-out on features that require posixErik Faye-Lund, Oct 11, 2010
  32. Junio C HamanoOct 13, 2010
  33. Erik Faye-LundOct 14, 2010
  34. Junio C HamanoOct 15, 2010
  35. Erik Faye-LundOct 18, 2010
  36. Jonathan NiederOct 18, 2010
  37. Andreas SchwabOct 18, 2010
  38. empty structsJonathan Nieder, Oct 18, 2010
  39. Erik Faye-LundOct 21, 2010
  40. Erik Faye-LundOct 21, 2010
  41. Jonathan NiederOct 21, 2010
  42. Erik Faye-LundOct 21, 2010
  43. Junio C HamanoOct 21, 2010
  44. Junio C HamanoOct 18, 2010
  45. Erik Faye-LundOct 21, 2010
  46. Jonathan NiederOct 21, 2010
  47. Erik Faye-LundOct 21, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.