git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] daemon: Set up PATH properly on startup.

From
MWMark Wooding <mdw@distorted.org.uk>
Date
Feb 12, 2008, 09:31 UTC
Message-ID
<slrnfr2pqp.gs1.mdw@metalzone.distorted.org.uk>
In-Reply-To
<20080210200027.169BD5B0E7@dx.sixt.local>
Johannes Sixt <johannes.sixt@telecom.at> wrote:
Show 7 quoted lines
> There are 2 reason, *not* to do this:
>
> 1. It's not needed. You can use
>
>     /usr/local/bin/git --exec-path=/usr/local/bin daemon --inetd ...
>
> to inject the exec-path.

Don't need the `exec-path': git knows the right one already. So this is entirely equivalent to my suggestion, except that the user has to jump through this stupid hoop.

Besides, I don't want to run `git' from inetd -- it makes distinguishing things in /etc/hosts.deny harder. Unless I write wrapper scripts or make symlinks for everything, I suppose, but doesn't it seem mad to invent wrapper scripts to distinguish between things which are already distinct but glommed together for some strange reason.

> 2. Security. Those inetds launder the environment for a reason. Assume inetd
> sets PATH=/usr/bin:/bin and git-daemon is installed
> as /usr/sbin/git-daemon. With your patch now all hooks run with the path
> set to /usr/sbin:/usr/bin:/bin.

Yes, of course. Silly me. It's much better that the service fail to work at all than that it have something strange like /usr/local/bin on its PATH.

Besides, the only things git-daemon will actually run are git-upload-pack, upload-archive and receive-pack.

  * git-upload-pack in turn runs git-pack-objects, which is a builtin
    and therefore runs setup_path in main.  Anything that does will
    therefore certainly have the same evil on its PATH as would have
    been inserted by my patch -- though I don't think it actually execs
    anything else.
  * git-upload-archive is another builtin, so the same applies; again, I
    don't think it actually execs anything else.
  * git-receive-pack is not something you enable if you care about
    security anyway.

Besides, if there /are/ scripts and so on run by git-daemon, then they'll be hook scripts, and will also fail if the Git tools aren't on the PATH.

Your argument, if I might stoop to caricature, seems to be `No, we mustn't have git-daemon set up the path itself -- it might actually /work/.'

-- [mdw]
Previous: Johannes Sixt
Message 3 of 3 in “daemon: Set up PATH properly on startup.”
  1. daemon: Set up PATH properly on startup.Mark Wooding, Feb 9, 2008
  2. Johannes SixtFeb 10, 2008
  3. Mark WoodingFeb 12, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.