git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] connect.c: add a way for git-daemon to pass an error back to client

From
Tom Preston-Werner <tom@github.com>
Date
Nov 1, 2008, 03:35 UTC
Message-ID
<b97024a40810312035v5416b578v51b5bed528ca8d39@mail.gmail.com>
In-Reply-To
<alpine.DEB.1.00.0811010334010.22125@pacific.mpi-cbg.de.mpi-cbg.de>

On Fri, Oct 31, 2008 at 7:35 PM, Johannes Schindelin <Johannes.Schindelin@gmx.de> wrote:

Show 35 quoted lines
> Hi,
>
> On Fri, 31 Oct 2008, Nicolas Pitre wrote:
>
>> On Sat, 1 Nov 2008, Johannes Schindelin wrote:
>>
>> > On Fri, 31 Oct 2008, Tom Preston-Werner wrote:
>> >
>> > > The current behavior of git-daemon is to simply close the connection
>> > > on any error condition. This leaves the client without any
>> > > information as to the cause of the failed fetch/push/etc.
>> > >
>> > > This patch allows get_remote_heads to accept a line prefixed with
>> > > "ERR" that it can display to the user in an informative fashion.
>> > > Once clients can understand this ERR line, git-daemon can be made to
>> > > properly report "repository not found", "permission denied", or
>> > > other errors.
>> > >
>> > > Example
>> > >
>> > > S: ERR No matching repository.
>> > > C: fatal: remote error: No matching repository.
>> >
>> > Makes sense to me.
>>
>> Note that this behavior of not returning any reason for failure was
>> argued to be a security feature in the past, by Linus I think.
>
> Yes.  And it might still be considered one.  You do not need to patch
> git-daemon to use that facility (note that Tom's patch was only for the
> client side).
>
> But for hosting sites such as repo.or.cz or GitHub, that security feature
> just does not make sense, but it makes for support requests that could be
> resolved better with a proper error message.

We could also have the error messages sent back conditionally based on a command line switch. I've begun porting the changes I made in our Erlang git-daemon back to the C code, so maybe I'll give that a try. We *definitely* need good error messages for GitHub and I see no security risk in doing so.

Maybe this is worth asking the question: does anybody use git-daemon for private code? If so, why are they not using SSH instead? And in that case, how are informative error messages a security risk?

Tom
Previous: Johannes SchindelinNext: Andreas Ericsson
Message 6 of 13 in “connect.c: add a way for git-daemon to pass an error back to client”
  1. connect.c: add a way for git-daemon to pass an error back to clientTom Preston-Werner, Nov 1, 2008
  2. Johannes SchindelinNov 1, 2008
  3. Tom Preston-WernerNov 1, 2008
  4. Nicolas PitreNov 1, 2008
  5. Johannes SchindelinNov 1, 2008
  6. Tom Preston-WernerNov 1, 2008
  7. Andreas EricssonNov 1, 2008
  8. Alex RiesenNov 1, 2008
  9. Andreas EricssonNov 1, 2008
  10. Junio C HamanoNov 1, 2008
  11. Tom Preston-WernerNov 1, 2008
  12. Shawn O. PearceNov 1, 2008
  13. Junio C HamanoNov 1, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.