git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 2/2] shell: pay attention to exit status from 'help' command

From
Ethan Reesor <firelizzard@gmail.com>
Date
Feb 11, 2013, 06:06 UTC
Message-ID
<CAE_TNikNH_8eUyX7s_zkY5FWEgyYXM617DG+j+3f1jOFC1Ud1w@mail.gmail.com>
In-Reply-To
<20130211055847.GG15329@elie.Belkin>

I feel like the suggestion I posted in response to Junio C Hamano <gitster@pobox.com>'s complaint on the RFC for this patch provides a more elegant solution to the problem of administrators wanting to prevent interactive sessions for users with their login shell set to git-prompt. The suggestion was as follows:

Show 7 quoted lines
> How is this for an alternative? Have shell.c look for a
>        [shell]
>                missing_commands_directory = "Stuff is broke."
> setting. If the setting is missing, then it prints the default message
> (the current message). That way, there's a default setting, there can
> be a system-wide message, there can be a user specific message, and
> those messages can be set via `git-config`.
On Mon, Feb 11, 2013 at 12:58 AM, Jonathan Nieder <jrnieder@gmail.com> wrote:
Show 99 quoted lines
> If I disable git-shell's interactive mode by removing the
> ~/git-shell-commands directory, then attempts to use 'ssh' with the
> git account interactively produce an error message intended for the
> administrator:
>
>         $ ssh git@myserver
>         fatal: Interactive git shell is not enabled.
>         hint: ~/git-shell-commands should exist and have read and execute access.
>         $
>
> That is helpful for the new admin who is wondering "What? Why isn't
> the git-shell I just set up working?", but once the site setup is
> finished, it is better to give the user a friendly hint that she is on
> the right track, like GitHub does:
>
>         Hi <username>! You've successfully authenticated, but
>         GitHub does not provide shell access.
>
> An appropriate greeting might even include more complex information,
> like a list of repositories the user has access to.  If the
> git-shell-commands directory exists and contains a "help" script, we
> already run it when the shell is run without any commands, giving the
> server a chance to provide a custom message.  Unfortunately, the
> presence of the git-shell-commands directory means we also enter an
> interactive mode, prompting and accepting commands (of which there may
> be none) from the user, which many servers would not want.  To solve
> this, we abort the interactive shell on a non-zero exit code from the
> "help" script.  This lets the server say whatever it likes, and then
> hang up.
>
> Downside: this will prevent interactive git-shell logins in existing
> setups where the "help" script exits with nonzero status by mistake.
> Hopefully those are rare enough to not cause much trouble in practice.
>
> Reported-by: Ethan Reesor <firelizzard@gmail.com>
> Signed-off-by: Jonathan Nieder <jrnieder@gmail.com>
> Improved-by: Jeff King <peff@peff.net>
> ---
>  Documentation/git-shell.txt | 20 ++++++++++++++++++++
>  shell.c                     | 10 ++++++++--
>  2 files changed, 28 insertions(+), 2 deletions(-)
>
> diff --git a/Documentation/git-shell.txt b/Documentation/git-shell.txt
> index 4fe93203..60051e63 100644
> --- a/Documentation/git-shell.txt
> +++ b/Documentation/git-shell.txt
> @@ -59,6 +59,26 @@ users to list repositories they have access to, create, delete, or
>  rename repositories, or change repository descriptions and
>  permissions.
>
> +If the `help` command exists and exits with nonzero status, the
> +interactive shell is aborted.
> +
> +EXAMPLE
> +-------
> +
> +To disable interactive logins, displaying a greeting instead:
> ++
> +----------------
> +$ chsh -s /usr/bin/git-shell
> +$ mkdir $HOME/git-shell-commands
> +$ cat >$HOME/git-shell-commands/help <<\EOF
> +#!/bin/sh
> +printf '%s\n' "Hi $USER! You've successfully authenticated, but I do not"
> +printf '%s\n' "provide interactive shell access."
> +exit 128
> +EOF
> +$ chmod +x $HOME/git-shell-commands/help
> +----------------
> +
>  SEE ALSO
>  --------
>  ssh(1),
> diff --git a/shell.c b/shell.c
> index 84b237fe..3abc2b84 100644
> --- a/shell.c
> +++ b/shell.c
> @@ -63,10 +63,16 @@ static void cd_to_homedir(void)
>
>  static void run_shell(void)
>  {
> -       int done = 0;
> +       int done = 0, status;
>         static const char *help_argv[] = { HELP_COMMAND, NULL };
>         /* Print help if enabled */
> -       run_command_v_opt(help_argv, RUN_SILENT_EXEC_FAILURE);
> +       status = run_command_v_opt(help_argv, RUN_SILENT_EXEC_FAILURE);
> +       if (!status)
> +               ; /* success */
> +       else if (status == -1 && errno == ENOENT)
> +               ; /* help disabled */
> +       else
> +               exit(status);
>
>         do {
>                 struct strbuf line = STRBUF_INIT;
> --
> 1.8.1.3
>

-- Ethan Reesor (Gmail)

Previous: Jonathan NiederNext: Junio C Hamano
Message 47 of 59 in “Git prompt”
  1. Ethan ReesorFeb 10, 2013
  2. Jonathan NiederFeb 10, 2013
  3. Ethan ReesorFeb 10, 2013
  4. Jeff KingFeb 10, 2013
  5. Junio C HamanoFeb 10, 2013
  6. Sitaram ChamartyFeb 11, 2013
  7. shell: allow 'help' command to disable interactive shellJonathan Nieder, Feb 11, 2013
  8. Junio C HamanoFeb 11, 2013
  9. Jonathan NiederFeb 11, 2013
  10. Junio C HamanoFeb 11, 2013
  11. Jonathan NiederFeb 11, 2013
  12. Jeff KingFeb 11, 2013
  13. Junio C HamanoFeb 11, 2013
  14. Ethan ReesorFeb 11, 2013
  15. Ethan ReesorFeb 11, 2013
  16. Jonathan NiederFeb 11, 2013
  17. Ethan ReesorFeb 11, 2013
  18. Jonathan NiederFeb 11, 2013
  19. Ethan ReesorFeb 11, 2013
  20. Jonathan NiederFeb 11, 2013
  21. Junio C HamanoFeb 11, 2013
  22. Jonathan NiederFeb 11, 2013
  23. Junio C HamanoFeb 11, 2013
  24. Jonathan NiederFeb 11, 2013
  25. Junio C HamanoFeb 11, 2013
  26. Jonathan NiederFeb 11, 2013
  27. Junio C HamanoFeb 11, 2013
  28. Jeff KingFeb 11, 2013
  29. Junio C HamanoFeb 11, 2013
  30. Jeff KingFeb 11, 2013
  31. Ethan ReesorFeb 11, 2013
  32. Ethan ReesorFeb 11, 2013
  33. Junio C HamanoFeb 11, 2013
  34. Ethan ReesorFeb 11, 2013
  35. Junio C HamanoFeb 11, 2013
  36. Jeff KingFeb 11, 2013
  37. Jonathan NiederFeb 11, 2013
  38. Jeff KingFeb 11, 2013
  39. Jonathan NiederFeb 11, 2013
  40. Jeff KingFeb 11, 2013
  41. 0/2 shell: allow 'help' command to disable interactive shellJonathan Nieder, Feb 11, 2013
  42. 1/2 shell doc: emphasize purpose and security modelJonathan Nieder, Feb 11, 2013
  43. Junio C HamanoFeb 11, 2013
  44. Jonathan NiederFeb 11, 2013
  45. Junio C HamanoFeb 11, 2013
  46. 2/2 shell: pay attention to exit status from 'help' commandJonathan Nieder, Feb 11, 2013
  47. Ethan ReesorFeb 11, 2013
  48. Junio C HamanoFeb 11, 2013
  49. Jonathan NiederFeb 11, 2013
  50. Junio C HamanoFeb 11, 2013
  51. Jeff KingFeb 11, 2013
  52. 0/2 shell: allow 'no-interactive-login' command to disable interactive shellJonathan Nieder, Mar 9, 2013
  53. 1/2 shell doc: emphasize purpose and security modelJonathan Nieder, Mar 9, 2013
  54. 2/2 shell: new no-interactive-login command to print a custom messageJonathan Nieder, Mar 9, 2013
  55. Junio C HamanoMar 10, 2013
  56. Jonathan NiederMar 10, 2013
  57. Ramkumar RamachandraMar 10, 2013
  58. Jonathan NiederMar 11, 2013
  59. Jeff KingMar 12, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.