git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v7 8/8] config: allow specifying config entries via envvar pairs

From
Patrick Steinhardt <ps@pks.im>
Date
Jan 11, 2021, 08:37 UTC
Message-ID
<ac9e7787049d673c3227437660140f0f6de7e1cf.1610353895.git.ps@pks.im>
In-Reply-To
<cover.1610353895.git.ps@pks.im>

While we currently have the `GIT_CONFIG_PARAMETERS` environment variable which can be used to pass runtime configuration data to git processes, it's an internal implementation detail and not supposed to be used by end users.

Next to being for internal use only, this way of passing config entries has a major downside: the config keys need to be parsed as they contain both key and value in a single variable. As such, it is left to the user to escape any potentially harmful characters in the value, which is quite hard to do if values are controlled by a third party.

This commit thus adds a new way of adding config entries via the environment which gets rid of this shortcoming. If the user passes the `GIT_CONFIG_COUNT=$n` environment variable, Git will parse environment variable pairs `GIT_CONFIG_KEY_$i` and `GIT_CONFIG_VALUE_$i` for each `i` in `[0,n)`.

While the same can be achieved with `git -c <name>=<value>`, one may wish to not do so for potentially sensitive information. E.g. if one wants to set `http.extraHeader` to contain an authentication token, doing so via `-c` would trivially leak those credentials via e.g. ps(1), which typically also shows command arguments.

Signed-off-by: Patrick Steinhardt <ps@pks.im>
---
 Documentation/git-config.txt |  16 +++++
 cache.h                      |   1 +
 config.c                     |  67 +++++++++++++++++---
 environment.c                |   1 +
 t/t1300-config.sh            | 115 ++++++++++++++++++++++++++++++++++-
 5 files changed, 191 insertions(+), 9 deletions(-)
diff --git a/Documentation/git-config.txt b/Documentation/git-config.txt
index 0e9351d3cb..4b4cc5c5e8 100644
--- a/Documentation/git-config.txt
+++ b/Documentation/git-config.txt
@@ -346,6 +346,22 @@ GIT_CONFIG_NOSYSTEM::
 
 See also <<FILES>>.
 
+GIT_CONFIG_COUNT::
+GIT_CONFIG_KEY_<n>::
+GIT_CONFIG_VALUE_<n>::
+	If GIT_CONFIG_COUNT is set to a positive number, all environment pairs
+	GIT_CONFIG_KEY_<n> and GIT_CONFIG_VALUE_<n> up to that number will be
+	added to the process's runtime configuration. The config pairs are
+	zero-indexed. Any missing key or value is treated as an error. An empty
+	GIT_CONFIG_COUNT is treated the same as GIT_CONFIG_COUNT=0, namely no
+	pairs are processed. These environment variables will override values
+	in configuration files, but will be overridden by any explicit options
+	passed via `git -c`.
++
+This is useful for cases where you want to spawn multiple git commands
+with a common configuration but cannot depend on a configuration file,
+for example when writing scripts.
+
 
 [[EXAMPLES]]
 EXAMPLES
diff --git a/cache.h b/cache.h
index 7109765748..a2e318c62b 100644
--- a/cache.h
+++ b/cache.h
@@ -472,6 +472,7 @@ static inline enum object_type object_type(unsigned int mode)
 #define TEMPLATE_DIR_ENVIRONMENT "GIT_TEMPLATE_DIR"
 #define CONFIG_ENVIRONMENT "GIT_CONFIG"
 #define CONFIG_DATA_ENVIRONMENT "GIT_CONFIG_PARAMETERS"
+#define CONFIG_COUNT_ENVIRONMENT "GIT_CONFIG_COUNT"
 #define EXEC_PATH_ENVIRONMENT "GIT_EXEC_PATH"
 #define CEILING_DIRECTORIES_ENVIRONMENT "GIT_CEILING_DIRECTORIES"
 #define NO_REPLACE_OBJECTS_ENVIRONMENT "GIT_NO_REPLACE_OBJECTS"
diff --git a/config.c b/config.c
index 33099a3b0d..2627a05e91 100644
--- a/config.c
+++ b/config.c
@@ -8,6 +8,7 @@
 #include "cache.h"
 #include "branch.h"
 #include "config.h"
+#include "environment.h"
 #include "repository.h"
 #include "lockfile.h"
 #include "exec-cmd.h"
@@ -597,23 +598,73 @@ static int parse_config_env_list(char *env, config_fn_t fn, void *data)
 
 int git_config_from_parameters(config_fn_t fn, void *data)
 {
-	const char *env = getenv(CONFIG_DATA_ENVIRONMENT);
+	const char *env;
+	struct strbuf envvar = STRBUF_INIT;
+	struct strvec to_free = STRVEC_INIT;
 	int ret = 0;
-	char *envw;
+	char *envw = NULL;
 	struct config_source source;
 
-	if (!env)
-		return 0;
-
 	memset(&source, 0, sizeof(source));
 	source.prev = cf;
 	source.origin_type = CONFIG_ORIGIN_CMDLINE;
 	cf = &source;
 
-	/* sq_dequote will write over it */
-	envw = xstrdup(env);
-	ret = parse_config_env_list(envw, fn, data);
+	env = getenv(CONFIG_COUNT_ENVIRONMENT);
+	if (env) {
+		unsigned long count;
+		char *endp;
+		int i;
 
+		count = strtoul(env, &endp, 10);
+		if (*endp) {
+			ret = error(_("bogus count in %s"), CONFIG_COUNT_ENVIRONMENT);
+			goto out;
+		}
+		if (count > INT_MAX) {
+			ret = error(_("too many entries in %s"), CONFIG_COUNT_ENVIRONMENT);
+			goto out;
+		}
+
+		for (i = 0; i < count; i++) {
+			const char *key, *value;
+
+			strbuf_addf(&envvar, "GIT_CONFIG_KEY_%d", i);
+			key = getenv_safe(&to_free, envvar.buf);
+			if (!key) {
+				ret = error(_("missing config key %s"), envvar.buf);
+				goto out;
+			}
+			strbuf_reset(&envvar);
+
+			strbuf_addf(&envvar, "GIT_CONFIG_VALUE_%d", i);
+			value = getenv_safe(&to_free, envvar.buf);
+			if (!value) {
+				ret = error(_("missing config value %s"), envvar.buf);
+				goto out;
+			}
+			strbuf_reset(&envvar);
+
+			if (config_parse_pair(key, value, fn, data) < 0) {
+				ret = -1;
+				goto out;
+			}
+		}
+	}
+
+	env = getenv(CONFIG_DATA_ENVIRONMENT);
+	if (env) {
+		/* sq_dequote will write over it */
+		envw = xstrdup(env);
+		if (parse_config_env_list(envw, fn, data) < 0) {
+			ret = -1;
+			goto out;
+		}
+	}
+
+out:
+	strbuf_release(&envvar);
+	strvec_clear(&to_free);
 	free(envw);
 	cf = source.prev;
 	return ret;
diff --git a/environment.c b/environment.c
index 2234af462c..2f27008424 100644
--- a/environment.c
+++ b/environment.c
@@ -117,6 +117,7 @@ const char * const local_repo_env[] = {
 	ALTERNATE_DB_ENVIRONMENT,
 	CONFIG_ENVIRONMENT,
 	CONFIG_DATA_ENVIRONMENT,
+	CONFIG_COUNT_ENVIRONMENT,
 	DB_ENVIRONMENT,
 	GIT_DIR_ENVIRONMENT,
 	GIT_WORK_TREE_ENVIRONMENT,
diff --git a/t/t1300-config.sh b/t/t1300-config.sh
index 0063e9f059..6ecf2c11a7 100755
--- a/t/t1300-config.sh
+++ b/t/t1300-config.sh
@@ -1423,6 +1423,117 @@ test_expect_success '--config-env handles keys with equals' '
 	test_cmp expect actual
 '
 
+test_expect_success 'git config handles environment config pairs' '
+	GIT_CONFIG_COUNT=2 \
+		GIT_CONFIG_KEY_0="pair.one" GIT_CONFIG_VALUE_0="foo" \
+		GIT_CONFIG_KEY_1="pair.two" GIT_CONFIG_VALUE_1="bar" \
+		git config --get-regexp "pair.*" >actual &&
+	cat >expect <<-EOF &&
+	pair.one foo
+	pair.two bar
+	EOF
+	test_cmp expect actual
+'
+
+test_expect_success 'git config ignores pairs without count' '
+	test_must_fail env GIT_CONFIG_KEY_0="pair.one" GIT_CONFIG_VALUE_0="value" \
+		git config pair.one 2>error &&
+	test_must_be_empty error
+'
+
+test_expect_success 'git config ignores pairs with zero count' '
+	test_must_fail env \
+		GIT_CONFIG_COUNT=0 \
+		GIT_CONFIG_KEY_0="pair.one" GIT_CONFIG_VALUE_0="value" \
+		git config pair.one
+'
+
+test_expect_success 'git config ignores pairs exceeding count' '
+	GIT_CONFIG_COUNT=1 \
+		GIT_CONFIG_KEY_0="pair.one" GIT_CONFIG_VALUE_0="value" \
+		GIT_CONFIG_KEY_1="pair.two" GIT_CONFIG_VALUE_1="value" \
+		git config --get-regexp "pair.*" >actual &&
+	cat >expect <<-EOF &&
+	pair.one value
+	EOF
+	test_cmp expect actual
+'
+
+test_expect_success 'git config ignores pairs with zero count' '
+	test_must_fail env \
+		GIT_CONFIG_COUNT=0 GIT_CONFIG_KEY_0="pair.one" GIT_CONFIG_VALUE_0="value" \
+		git config pair.one >error &&
+	test_must_be_empty error
+'
+
+test_expect_success 'git config ignores pairs with empty count' '
+	test_must_fail env \
+		GIT_CONFIG_COUNT= GIT_CONFIG_KEY_0="pair.one" GIT_CONFIG_VALUE_0="value" \
+		git config pair.one >error &&
+	test_must_be_empty error
+'
+
+test_expect_success 'git config fails with invalid count' '
+	test_must_fail env GIT_CONFIG_COUNT=10a git config --list 2>error &&
+	test_i18ngrep "bogus count" error &&
+	test_must_fail env GIT_CONFIG_COUNT=9999999999999999 git config --list 2>error &&
+	test_i18ngrep "too many entries" error
+'
+
+test_expect_success 'git config fails with missing config key' '
+	test_must_fail env GIT_CONFIG_COUNT=1 GIT_CONFIG_VALUE_0="value" \
+		git config --list 2>error &&
+	test_i18ngrep "missing config key" error
+'
+
+test_expect_success 'git config fails with missing config value' '
+	test_must_fail env GIT_CONFIG_COUNT=1 GIT_CONFIG_KEY_0="pair.one" \
+		git config --list 2>error &&
+	test_i18ngrep "missing config value" error
+'
+
+test_expect_success 'git config fails with invalid config pair key' '
+	test_must_fail env GIT_CONFIG_COUNT=1 \
+		GIT_CONFIG_KEY_0= GIT_CONFIG_VALUE_0=value \
+		git config --list &&
+	test_must_fail env GIT_CONFIG_COUNT=1 \
+		GIT_CONFIG_KEY_0=missing-section GIT_CONFIG_VALUE_0=value \
+		git config --list
+'
+
+test_expect_success 'environment overrides config file' '
+	test_when_finished "rm -f .git/config" &&
+	cat >.git/config <<-EOF &&
+	[pair]
+	one = value
+	EOF
+	GIT_CONFIG_COUNT=1 GIT_CONFIG_KEY_0=pair.one GIT_CONFIG_VALUE_0=override \
+		git config pair.one >actual &&
+	cat >expect <<-EOF &&
+	override
+	EOF
+	test_cmp expect actual
+'
+
+test_expect_success 'GIT_CONFIG_PARAMETERS overrides environment config' '
+	GIT_CONFIG_COUNT=1 GIT_CONFIG_KEY_0=pair.one GIT_CONFIG_VALUE_0=value \
+		GIT_CONFIG_PARAMETERS="${SQ}pair.one=override${SQ}" \
+		git config pair.one >actual &&
+	cat >expect <<-EOF &&
+	override
+	EOF
+	test_cmp expect actual
+'
+
+test_expect_success 'command line overrides environment config' '
+	GIT_CONFIG_COUNT=1 GIT_CONFIG_KEY_0=pair.one GIT_CONFIG_VALUE_0=value \
+		git -c pair.one=override config pair.one >actual &&
+	cat >expect <<-EOF &&
+	override
+	EOF
+	test_cmp expect actual
+'
+
 test_expect_success 'git config --edit works' '
 	git config -f tmp test.value no &&
 	echo test.value=yes >expect &&
@@ -1768,9 +1879,11 @@ test_expect_success '--show-origin with --list' '
 	file:.git/config	user.override=local
 	file:.git/config	include.path=../include/relative.include
 	file:.git/../include/relative.include	user.relative=include
+	command line:	user.environ=true
 	command line:	user.cmdline=true
 	EOF
-	git -c user.cmdline=true config --list --show-origin >output &&
+	GIT_CONFIG_COUNT=1 GIT_CONFIG_KEY_0=user.environ GIT_CONFIG_VALUE_0=true\
+		git -c user.cmdline=true config --list --show-origin >output &&
 	test_cmp expect output
 '
 
-- 
2.30.0
Previous: Patrick SteinhardtNext: Patrick Steinhardt
Message 95 of 116 in “config: allow specifying config entries via envvar pairs”
  1. 0/2 config: allow specifying config entries via envvar pairsPatrick Steinhardt, Nov 24, 2020
  2. 1/2 config: extract function to parse config pairsPatrick Steinhardt, Nov 24, 2020
  3. 2/2 config: allow specifying config entries via envvar pairsPatrick Steinhardt, Nov 24, 2020
  4. Junio C HamanoNov 25, 2020
  5. Patrick SteinhardtNov 25, 2020
  6. Junio C HamanoNov 25, 2020
  7. Patrick SteinhardtNov 25, 2020
  8. Ævar Arnfjörð BjarmasonNov 25, 2020
  9. Ævar Arnfjörð BjarmasonNov 25, 2020
  10. Junio C HamanoNov 25, 2020
  11. Jeff KingNov 25, 2020
  12. Patrick SteinhardtNov 25, 2020
  13. Jeff KingNov 26, 2020
  14. Junio C HamanoNov 25, 2020
  15. brian m. carlsonNov 25, 2020
  16. Patrick SteinhardtNov 26, 2020
  17. Patrick SteinhardtDec 1, 2020
  18. Jeff KingDec 1, 2020
  19. 0/4 config: allow specifying config entries via envvar pairsPatrick Steinhardt, Dec 1, 2020
  20. 1/4 environment: make `getenv_safe()` non-staticPatrick Steinhardt, Dec 1, 2020
  21. 3/4 config: refactor parsing of GIT_CONFIG_PARAMETERSPatrick Steinhardt, Dec 1, 2020
  22. 2/4 config: extract function to parse config pairsPatrick Steinhardt, Dec 1, 2020
  23. 4/4 config: allow specifying config entries via envvar pairsPatrick Steinhardt, Dec 1, 2020
  24. 0/6 config: allow specifying config entries via envPatrick Steinhardt, Dec 9, 2020
  25. 1/6 git: add `--super-prefix` to usage stringPatrick Steinhardt, Dec 9, 2020
  26. 3/6 environment: make `getenv_safe()` non-staticPatrick Steinhardt, Dec 9, 2020
  27. 2/6 config: add new way to pass config via `--config-env`Patrick Steinhardt, Dec 9, 2020
  28. Ævar Arnfjörð BjarmasonDec 9, 2020
  29. Jeff KingDec 9, 2020
  30. Patrick SteinhardtDec 11, 2020
  31. Jeff KingDec 11, 2020
  32. Patrick SteinhardtDec 11, 2020
  33. Jeff KingDec 11, 2020
  34. Jeff KingDec 9, 2020
  35. 1/3 quote: make sq_dequote_step() a public functionJeff King, Dec 9, 2020
  36. 2/3 config: parse more robust format in GIT_CONFIG_PARAMETERSJeff King, Dec 9, 2020
  37. 3/3 config: store "git -c" variables using more robust formatJeff King, Dec 9, 2020
  38. Jeff KingDec 9, 2020
  39. Ævar Arnfjörð BjarmasonDec 10, 2020
  40. Junio C HamanoDec 10, 2020
  41. Jeff KingDec 11, 2020
  42. Junio C HamanoDec 10, 2020
  43. Jeff KingDec 10, 2020
  44. Junio C HamanoDec 10, 2020
  45. Patrick SteinhardtDec 11, 2020
  46. Jeff KingDec 11, 2020
  47. 4/6 config: extract function to parse config pairsPatrick Steinhardt, Dec 9, 2020
  48. Ævar Arnfjörð BjarmasonDec 9, 2020
  49. 6/6 config: allow specifying config entries via envvar pairsPatrick Steinhardt, Dec 9, 2020
  50. 5/6 config: refactor parsing of GIT_CONFIG_PARAMETERSPatrick Steinhardt, Dec 9, 2020
  51. Ævar Arnfjörð BjarmasonDec 9, 2020
  52. Patrick SteinhardtDec 11, 2020
  53. Jeff KingDec 11, 2020
  54. Jeff KingDec 11, 2020
  55. Patrick SteinhardtDec 11, 2020
  56. Patrick SteinhardtDec 11, 2020
  57. Ævar Arnfjörð BjarmasonDec 11, 2020
  58. Jeff KingDec 11, 2020
  59. 0/8 config: allow specifying config entries via envPatrick Steinhardt, Dec 16, 2020
  60. 1/8 git: add `--super-prefix` to usage stringPatrick Steinhardt, Dec 16, 2020
  61. 2/8 config: add new way to pass config via `--config-env`Patrick Steinhardt, Dec 16, 2020
  62. Junio C HamanoDec 23, 2020
  63. 4/8 config: extract function to parse config pairsPatrick Steinhardt, Dec 16, 2020
  64. 8/8 config: allow specifying config entries via envvar pairsPatrick Steinhardt, Dec 16, 2020
  65. Junio C HamanoDec 23, 2020
  66. Junio C HamanoDec 23, 2020
  67. Patrick SteinhardtJan 6, 2021
  68. Junio C HamanoJan 6, 2021
  69. 7/8 environment: make `getenv_safe()` a public functionPatrick Steinhardt, Dec 16, 2020
  70. 6/8 config: parse more robust format in GIT_CONFIG_PARAMETERSPatrick Steinhardt, Dec 16, 2020
  71. Phillip WoodDec 16, 2020
  72. 3/8 quote: make sq_dequote_step() a public functionPatrick Steinhardt, Dec 16, 2020
  73. 5/8 config: store "git -c" variables using more robust formatPatrick Steinhardt, Dec 16, 2020
  74. 0/8 config: allow specifying config entries via envPatrick Steinhardt, Jan 7, 2021
  75. 4/8 config: extract function to parse config pairsPatrick Steinhardt, Jan 7, 2021
  76. 1/8 git: add `--super-prefix` to usage stringPatrick Steinhardt, Jan 7, 2021
  77. 2/8 config: add new way to pass config via `--config-env`Patrick Steinhardt, Jan 7, 2021
  78. Simon RuderichJan 10, 2021
  79. Junio C HamanoJan 11, 2021
  80. Patrick SteinhardtJan 11, 2021
  81. 3/8 quote: make sq_dequote_step() a public functionPatrick Steinhardt, Jan 7, 2021
  82. 5/8 config: store "git -c" variables using more robust formatPatrick Steinhardt, Jan 7, 2021
  83. 6/8 config: parse more robust format in GIT_CONFIG_PARAMETERSPatrick Steinhardt, Jan 7, 2021
  84. 7/8 environment: make `getenv_safe()` a public functionPatrick Steinhardt, Jan 7, 2021
  85. 8/8 config: allow specifying config entries via envvar pairsPatrick Steinhardt, Jan 7, 2021
  86. 0/8 config: allow specifying config entries via envvar pairsPatrick Steinhardt, Jan 11, 2021
  87. 2/8 config: add new way to pass config via `--config-env`Patrick Steinhardt, Jan 11, 2021
  88. Junio C HamanoJan 11, 2021
  89. 3/8 quote: make sq_dequote_step() a public functionPatrick Steinhardt, Jan 11, 2021
  90. 1/8 git: add `--super-prefix` to usage stringPatrick Steinhardt, Jan 11, 2021
  91. 4/8 config: extract function to parse config pairsPatrick Steinhardt, Jan 11, 2021
  92. 5/8 config: store "git -c" variables using more robust formatPatrick Steinhardt, Jan 11, 2021
  93. 7/8 environment: make `getenv_safe()` a public functionPatrick Steinhardt, Jan 11, 2021
  94. 6/8 config: parse more robust format in GIT_CONFIG_PARAMETERSPatrick Steinhardt, Jan 11, 2021
  95. 8/8 config: allow specifying config entries via envvar pairsPatrick Steinhardt, Jan 11, 2021
  96. 0/8 config: allow specifying config entries via envvar pairsPatrick Steinhardt, Jan 12, 2021
  97. 2/8 config: add new way to pass config via `--config-env`Patrick Steinhardt, Jan 12, 2021
  98. Ævar Arnfjörð BjarmasonApr 16, 2021
  99. Jeff KingApr 17, 2021
  100. Patrick SteinhardtApr 19, 2021
  101. Ævar Arnfjörð BjarmasonApr 20, 2021
  102. Ævar Arnfjörð BjarmasonApr 20, 2021
  103. Jeff KingApr 23, 2021
  104. Ævar Arnfjörð BjarmasonMay 19, 2021
  105. 4/8 config: extract function to parse config pairsPatrick Steinhardt, Jan 12, 2021
  106. 1/8 git: add `--super-prefix` to usage stringPatrick Steinhardt, Jan 12, 2021
  107. 3/8 quote: make sq_dequote_step() a public functionPatrick Steinhardt, Jan 12, 2021
  108. 6/8 config: parse more robust format in GIT_CONFIG_PARAMETERSPatrick Steinhardt, Jan 12, 2021
  109. 8/8 config: allow specifying config entries via envvar pairsPatrick Steinhardt, Jan 12, 2021
  110. 5/8 config: store "git -c" variables using more robust formatPatrick Steinhardt, Jan 12, 2021
  111. Jeff KingJan 15, 2021
  112. Patrick SteinhardtJan 20, 2021
  113. Junio C HamanoJan 20, 2021
  114. Patrick SteinhardtJan 20, 2021
  115. Junio C HamanoJan 20, 2021
  116. 7/8 environment: make `getenv_safe()` a public functionPatrick Steinhardt, Jan 12, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.