git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] Implement ACL module architecture and sample MySQL ACL module

From
Shawn Pearce <spearce@spearce.org>
Date
Aug 14, 2012, 17:26 UTC
Message-ID
<CAJo=hJu7W6JnNLYvahaQ43ZNqDtrurTOLCnLfZacVJKeL6VMFg@mail.gmail.com>
In-Reply-To
<7vsjbp768y.fsf@alter.siamese.dyndns.org>
On Tue, Aug 14, 2012 at 10:06 AM, Junio C Hamano <gitster@pobox.com> wrote:
Show 18 quoted lines
> Shawn Pearce <spearce@spearce.org> writes:
>
>> Parsing the request line of git-daemon is easy. But we could make it
>> easier. An alternative arrangement would be to add a new command line
>> flag to git daemon like --command-filter that names an executable
>> git-daemon will invoke after parsing the request line. It can pass
>> along the client IP address, command request, repository name, and
>> resolved repository path, and tie stdin/stdout to the client. This
>> binary can decide to exec the proper git binary for the named command,
>> or just exit to disconnect the client and refuse service. This makes
>> it simple for a tool like gitolite to plug into the git-daemon
>> authorization path, without needing to be the network daemon itself,
>> worry about number of active connection slots, etc.
>
> I think that is a good direction to go in, except that I am unsure
> what kind of conversation do you want to allow between the "command
> filter" helper and the client by exposing standard input and output
> stream to to the helper.

Sorry, I was thinking the helper would exec the git command, and thus pass along the stdin/stdout socket.

Show 9 quoted lines
>  If the client side has a matching "pre
> negotiate command" helper support, then presumably the helpers can
> discuss what Git protocol proper does not care about before deciding
> to allow the connection go through, but until that happens, opening
> the stdio streams up to the helper sounds like an accident waiting
> to happen to me (e.g. "fetch-pack" connects, the server side helper
> reads the first pkt-line from the client, says "OK, you may proceed"
> to the daemon, then the daemon spawns the "upload-pack", which will
> obviously see a corrupt request stream from "fetch-pack").

But seeing this, yes, that is a bad idea. Better to treat that like a hook, where exit status 0 allows the connection to continue, and exit status non-zero causes the connection to be closed. Maybe with an error printed to stderr (if any) being echoed first to the client if possible using the ERR formatting notation.

Previous: Junio C HamanoNext: Junio C Hamano
Message 5 of 9 in “Implement ACL module architecture and sample MySQL ACL module”
  1. Implement ACL module architecture and sample MySQL ACL moduleMichal Novotny, Aug 14, 2012
  2. Junio C HamanoAug 14, 2012
  3. Shawn PearceAug 14, 2012
  4. Junio C HamanoAug 14, 2012
  5. Shawn PearceAug 14, 2012
  6. Junio C HamanoAug 14, 2012
  7. daemon: --access-hook optionJunio C Hamano, Aug 15, 2012
  8. Shawn PearceAug 15, 2012
  9. Michal NovotnyAug 21, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.