git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] Allow git-shell to be used as a ssh forced-command

From
Matthieu Moy <matthieu.moy@imag.fr>
Date
Apr 18, 2009, 07:46 UTC
Message-ID
<vpqzleev1ym.fsf@bauges.imag.fr>
In-Reply-To
<20090417234425.GC17753@glandium.org>
Mike Hommey <mh@glandium.org> writes:
> However, the patch in its current form will definitely break gitosis if
> it doesn't unset SSH_ORIGINAL_COMMAND.

... and any home-made script without knowledge of this feature. If I wanted to add some restrictions to git-shell, it would seem natural to me to write a script like

#! /bin/sh
if [ ??? ]; then
	git-shell $whatever
else
	echo "Sorry, forbidden"
	exit 1
fi

(I never did this with Git because I never had to manage any kind of permission control with it, but I have a script like that for SVN that adds some argument to the SVN command)

If the command ignores its arguments, and use some other environment variable instead, then the security hole is not far.

-- 
Matthieu
Previous: Mike HommeyNext: Junio C Hamano
Message 8 of 18 in “Allow git-shell to be used as a ssh forced-command”
  1. Allow git-shell to be used as a ssh forced-commandMike Hommey, Apr 16, 2009
  2. Dmitry PotapovApr 17, 2009
  3. Mike HommeyApr 17, 2009
  4. Dmitry PotapovApr 17, 2009
  5. Mike HommeyApr 17, 2009
  6. Shawn O. PearceApr 17, 2009
  7. Mike HommeyApr 17, 2009
  8. Matthieu MoyApr 18, 2009
  9. Junio C HamanoApr 17, 2009
  10. Tommi VirtanenApr 17, 2009
  11. Junio C HamanoApr 18, 2009
  12. Mike HommeyApr 18, 2009
  13. Allow git-shell to be used as a ssh forced-commandMike Hommey, Apr 21, 2009
  14. Dmitry PotapovApr 21, 2009
  15. Eygene RyabinkinApr 21, 2009
  16. Junio C HamanoApr 21, 2009
  17. Mike HommeyApr 21, 2009
  18. Dmitry PotapovApr 21, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.