git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCHv3] Updated patch series for providing mechanism to list available repositories

From
Greg Brockman <gdb@mit.edu>
Date
Jul 28, 2010, 07:06 UTC
Message-ID
<AANLkTikE16GnoRmJ2mxzYJ7hB+5tUbBjvFmZkj12k9+C@mail.gmail.com>
In-Reply-To
<20100728064251.GB743@dert.cs.uchicago.edu>
> Agh, it’s getting late.  In my last message I completely
> forgot about the make_cmd() step.  Sorry to waste your time
> on that.

No problem. It was good to have some pushback so I had to justify my assumptions.

Show 13 quoted lines
>> This will be an arbitrary directory if a user can 'su' to the
>> git-shell user.
>
> That would be an odd setup, but I guess with shared repositories
> there's a reason to do it.
>
>> (I am however starting to lean towards always
>> chdir'ing into the git-shell user's $HOME, do people feel strongly
>> about this in either direction?)
>
> I don't feel strongly either way.  It would be a good way to
> put the worry about that attack vector to rest (if you use
> getpwent instead of getenv to fetch $HOME).
Sure, I'll add some logic to do this.
> Thanks for the patient explanations.
No problem.  Thanks for taking the time to read them :).

Anyway, I'll create an updated version of this patch series that deals with the chdir'ing to the user's home directory, and that includes the 2>/dev/null line in 'list'.

Previous: Jonathan NiederNext: Anders Kaseorg
Message 18 of 23 in “[PATCHv3] Updated patch series for providing mechanism to list available repositories”
  1. Greg BrockmanJul 21, 2010
  2. 1/3 Allow creation of arbitrary git-shell commandsGreg Brockman, Jul 21, 2010
  3. 2/3 Add interactive mode to git-shell for user-friendlinessGreg Brockman, Jul 21, 2010
  4. 3/3 Add sample commands for git-shellGreg Brockman, Jul 21, 2010
  5. Greg BrockmanJul 26, 2010
  6. Ævar Arnfjörð BjarmasonJul 26, 2010
  7. Greg BrockmanJul 26, 2010
  8. Jakub NarebskiJul 27, 2010
  9. Jonathan NiederJul 26, 2010
  10. Greg BrockmanJul 27, 2010
  11. Jonathan NiederJul 27, 2010
  12. Johannes SixtJul 27, 2010
  13. Jonathan NiederJul 27, 2010
  14. Greg BrockmanJul 27, 2010
  15. Jonathan NiederJul 28, 2010
  16. Greg BrockmanJul 28, 2010
  17. Jonathan NiederJul 28, 2010
  18. Greg BrockmanJul 28, 2010
  19. Anders KaseorgJul 28, 2010
  20. Jonathan NiederJul 28, 2010
  21. Greg BrockmanJul 29, 2010
  22. Jonathan NiederJul 29, 2010
  23. Jonathan NiederJul 28, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.