git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Smart fetch via HTTP?

From
Ddavid@lang.hm <david@lang.hm>
Date
May 19, 2007, 04:58 UTC
Message-ID
<Pine.LNX.4.64.0705182154540.6938@asgard.lang.hm>
In-Reply-To
<20070519035856.GB3141@spearce.org>
On Fri, 18 May 2007, Shawn O. Pearce wrote:
Show 22 quoted lines
> david@lang.hm wrote:
>> when a person browsing a hostile website will allow that website to take
>> over the machine the demand is created for 'malware filters' for http, to
>> do this the firewalls need to decode the http, and in the process limit
>> you to only doing legitimate http.
>>
>> it's also the case that the companies that have firewalls paranoid enough
>> to not let you get to the git port are highly likely to be paranoid enough
>> to have a malware filtering http firewall.
>
> I'm behind such a filter, and fetch git.git via HTTP just to keep
> my work system current with Junio.  ;-)
>
> Of course we're really really really paranoid about our firewall,
> but are also so paranoid that any other web browser *except*
> Microsoft Internet Explorer is thought to be a security risk and
> is more-or-less banned from the network.
>
> The kicker is some of our developers create public websites, where
> testing your local webpage with Firefox and Safari is pretty much
> required...  but those browsers still aren't as trusted as IE and
> require special clearances.  *shakes head*
this isn't paranoia, this is just bullheadedness
Show 7 quoted lines
> We're pretty much limited to:
>
> *) Running the native Git protocol SSL, where the remote system
> is answering to port 443.  It may not need to be HTTP at all,
> but it probably has to smell enough like SSL to get it through
> the malware filter.  Oh, what's that?  The filter cannot actually
> filter the SSL data?  Funny!  ;-)

we're actually paranoid enough to have devices that do man-in-the-middle decryption for some sites, and are given copies of the encryption keys that other sites (and browsers) use so that it can decrypt the SSL and check it. I admit that this is far more paranoid then almost all sites though :-)

> *) Using a single POST upload followed by response from server,
> formatted with minimal HTTP headers.  The real problem as people
> have pointed out is not the HTTP headers, but it is the single
> exchange.
Show 6 quoted lines
> If you really want a stateful exchange you have to treat HTTP as
> though it were IP, but with reliable (and much more expensive)
> packet delivery, and make the Git daemon keep track of the protocol
> state with the client.  Yes, that means that when the client suddenly
> goes away and doesn't tell you he went away you also have to garbage
> collect your state.  No nice messages from your local kernel.  :-(
unfortunantly you are right about this.
David Lang
Previous: Shawn O. PearceNext: Jan Hudec
Message 44 of 47 in “Smart fetch via HTTP?”
  1. Jan HudecMay 15, 2007
  2. A Large Angry SCMMay 15, 2007
  3. Shawn O. PearceMay 15, 2007
  4. Junio C HamanoMay 16, 2007
  5. Martin LanghoffMay 16, 2007
  6. Johannes SchindelinMay 16, 2007
  7. Martin LanghoffMay 16, 2007
  8. Jakub NarebskiMay 16, 2007
  9. Johannes SchindelinMay 17, 2007
  10. Shawn O. PearceMay 17, 2007
  11. david@lang.hmMay 17, 2007
  12. Shawn O. PearceMay 17, 2007
  13. Shawn O. PearceMay 17, 2007
  14. Theodore TsoMay 17, 2007
  15. Nicolas PitreMay 17, 2007
  16. Johannes SchindelinMay 17, 2007
  17. Nicolas PitreMay 17, 2007
  18. Martin LanghoffMay 17, 2007
  19. Nicolas PitreMay 17, 2007
  20. Jan HudecMay 17, 2007
  21. Nicolas PitreMay 17, 2007
  22. david@lang.hmMay 17, 2007
  23. Johannes SchindelinMay 18, 2007
  24. Jan HudecMay 18, 2007
  25. Matthieu MoyMay 17, 2007
  26. Martin LanghoffMay 17, 2007
  27. Johannes SchindelinMay 17, 2007
  28. Matthieu MoyMay 17, 2007
  29. Martin LanghoffMay 17, 2007
  30. Nicolas PitreMay 17, 2007
  31. Jakub NarebskiMay 17, 2007
  32. Nicolas PitreMay 17, 2007
  33. Petr BaudisMay 17, 2007
  34. Matthieu MoyMay 17, 2007
  35. Linus TorvaldsMay 18, 2007
  36. alanMay 18, 2007
  37. Joel BeckerMay 18, 2007
  38. Matthieu MoyMay 18, 2007
  39. Linus TorvaldsMay 18, 2007
  40. Joel BeckerMay 18, 2007
  41. Jan HudecMay 20, 2007
  42. david@lang.hmMay 19, 2007
  43. Shawn O. PearceMay 19, 2007
  44. david@lang.hmMay 19, 2007
  45. Jan HudecMay 17, 2007
  46. Nicolas PitreMay 17, 2007
  47. Jan HudecMay 18, 2007

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.