git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] Implement ACL module architecture and sample MySQL ACL module

From
Shawn Pearce <spearce@spearce.org>
Date
Aug 14, 2012, 16:27 UTC
Message-ID
<CAJo=hJtYz3OX1C6HS7ivhJKBOSg=Ex3rKEdTYSbcDfFT1Jh4hw@mail.gmail.com>
In-Reply-To
<7v1uj98nbj.fsf@alter.siamese.dyndns.org>
On Tue, Aug 14, 2012 at 9:12 AM, Junio C Hamano <gitster@pobox.com> wrote:
Show 8 quoted lines
> Michal Novotny <minovotn@redhat.com> writes:
>
>> Hi,
>> this is the patch to introduce the ACL module architecture into git
>> versioning system.
>
> No, it doesn't.  It adds something only to "git daemon", but does
> not affect any other uses of Git.

Yes, this part of the commit message also confused me until I read through the patch further. :-(

Show 16 quoted lines
>     Side note: I am not saying other uses of Git must be ACL
>     controlled by MySQL database.  They shouldn't be.  I am only
>     saying that the proposed commit log message must match what the
>     change does.
>
> Please familiarize yourself with Documentation/SubmittingPatches
> first, and then imitate the style in existing commits in the history
> and posted patches by the "good" developers (you can tell who they
> are by observing the list traffic for a few weeks), by the way.
>
> As "git daemon" already has a mechanism to specify what repositories
> are served with whitelist or blacklist, I am not sure if this patch
> adds enough value to the system to make us want to add further
> complexity only to carry more code to be audited for security.
>
> Opinions?

Traditionally Git has been about providing the plumbing to handle the protocol and storage, and other tools that wrap git manage access controls, e.g. UNIX filesystem or gitolite. I would strongly prefer to keep that arrangement.

Parsing the request line of git-daemon is easy. But we could make it easier. An alternative arrangement would be to add a new command line flag to git daemon like --command-filter that names an executable git-daemon will invoke after parsing the request line. It can pass along the client IP address, command request, repository name, and resolved repository path, and tie stdin/stdout to the client. This binary can decide to exec the proper git binary for the named command, or just exit to disconnect the client and refuse service. This makes it simple for a tool like gitolite to plug into the git-daemon authorization path, without needing to be the network daemon itself, worry about number of active connection slots, etc.

Previous: Junio C HamanoNext: Junio C Hamano
Message 3 of 9 in “Implement ACL module architecture and sample MySQL ACL module”
  1. Implement ACL module architecture and sample MySQL ACL moduleMichal Novotny, Aug 14, 2012
  2. Junio C HamanoAug 14, 2012
  3. Shawn PearceAug 14, 2012
  4. Junio C HamanoAug 14, 2012
  5. Shawn PearceAug 14, 2012
  6. Junio C HamanoAug 14, 2012
  7. daemon: --access-hook optionJunio C Hamano, Aug 15, 2012
  8. Shawn PearceAug 15, 2012
  9. Michal NovotnyAug 21, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.