git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [Proposal] Clonable scripts

From
Niels Basjes <niels@basjes.nl>
Date
Sep 9, 2013, 21:23 UTC
Message-ID
<CADoiZqqKSX+=yHjU=tTz=0iP_JKzkQvsDancdVXQ3rjkbch9eg@mail.gmail.com>
In-Reply-To
<CAE1pOi0TioYa2pWCe=8kFbrSNp847rHDUbxXdxBAe=jN3BkWxg@mail.gmail.com>

On Mon, Sep 9, 2013 at 11:13 PM, Hilco Wijbenga <hilco.wijbenga@gmail.com> wrote:

Show 7 quoted lines
> On 9 September 2013 13:48, Niels Basjes <Niels@basjes.nl> wrote:
>> So I propose the following new feature:
>>
>> 1) A scripting language is put inside git. Perhaps a version of python
>> or ruby or go or ... (no need for a 'new' language)
>
> That sounds nice but ...
Show 7 quoted lines
>> 2) If a project contains a folder called .githooks in the root of the
>> code base then the rules/scripts that are present there are executed
>> ONLY on the system doing the actual commit. These scripts are run in
>> such a limited way that they can only read the files in the
>> repository, they cannot do any networking/write to disk/etc and they
>> can only do a limited set op actions against the current operation at
>> hand (i.e. do checks, parse messages, etc).
> ... how would you prevent Ruby/Python/Go/$GeneralProgLang from
> executing arbitrary code?
Some kind of sandbox?
Show 8 quoted lines
>> Like I said, this is just a proposal and I would like to know what you
>> guys think.
>
> I love the idea but I'm not sure how feasible it is. I think you would
> be forced to copy an existing language and somehow "make it secure"
> (seems like a maintenance nightmare) or to create your own language
> (potentially a lot of work). But perhaps something more declarative
> might be usable?

As far as I'm concerned it should be the 'best suitable' language for the task at hand.

-- 
Best regards / Met vriendelijke groeten,

Niels Basjes
Previous: Hilco WijbengaNext: Ramkumar Ramachandra
Message 3 of 7 in “[Proposal] Clonable scripts”
  1. Niels BasjesSep 9, 2013
  2. Hilco WijbengaSep 9, 2013
  3. Niels BasjesSep 9, 2013
  4. Ramkumar RamachandraSep 9, 2013
  5. Niels BasjesSep 10, 2013
  6. Sitaram ChamartySep 10, 2013
  7. Andreas KreySep 10, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.