git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v5 6/6] agent: advertise OS name via agent capability

From
Junio C Hamano <gitster@pobox.com>
Date
Feb 14, 2025, 22:07 UTC
Message-ID
<xmqq34ggkwnx.fsf@gitster.g>
In-Reply-To
<20250214123734.1403120-7-usmanakinyemi202@gmail.com>
Usman Akinyemi <usmanakinyemi202@gmail.com> writes:
Show 8 quoted lines
> As some issues that can happen with a Git client can be operating system
> specific, it can be useful for a server to know which OS a client is
> using. In the same way it can be useful for a client to know which OS
> a server is using.
>
> Our current agent capability is in the form of "package/version" (e.g.,
> "git/1.8.3.1"). Let's extend it to include the operating system name (os)
> i.e in the form "package/version os" (e.g., "git/1.8.3.1 Linux").

Shouldn't this be "git/1.8.3.1-Linux" or something to avoid SP? The capability list in protocol v1 is on a single line that is whitespace separated (cf. connect.c:parse_feature_value()) without any escape mechanism.

	Side note.  Does it pose a security hole, when we can set
	agent to any value?  I do not think so, as it controls what
	this end sends to the other.  If you are attacker in control
	of your own agent string to be sent to the other end, and
	use a string with a whitespace in it after "agent=" to claim
	that you support a capability you actually don't, that is
	not a new way to attack the other side available to you---you
	can write your own Git client to talk to the other side to
	send such a bogus capablity list anyway.
Show 14 quoted lines
> diff --git a/Documentation/gitprotocol-v2.txt b/Documentation/gitprotocol-v2.txt
> index 1652fef3ae..f4831a8787 100644
> --- a/Documentation/gitprotocol-v2.txt
> +++ b/Documentation/gitprotocol-v2.txt
> @@ -184,11 +184,14 @@ form `agent=X`) to notify the client that the server is running version
>  the `agent` capability with a value `Y` (in the form `agent=Y`) in its
>  request to the server (but it MUST NOT do so if the server did not
>  advertise the agent capability). The `X` and `Y` strings may contain any
> -printable ASCII characters except space (i.e., the byte range 32 < x <
> -127), and are typically of the form "package/version" (e.g.,
> -"git/1.8.3.1"). The agent strings are purely informative for statistics
> -and debugging purposes, and MUST NOT be used to programmatically assume
> -the presence or absence of particular features.
> +printable ASCII characters (i.e., the byte range 31 < x < 127), and are

Patches 1 & 2 redacted non-printables and SP separately, because SP is considered printable. With this change you are allowing SP to be passed without getting redacted? I do not think it is a good idea (see above).

While I'd prefer to keep the range the same as before, i.e. "any printable ASCII characters except space", "33 <= x <= 126" may be more readily recognisable that we are doing something unusual, as "32 <= x <= 126" is fairly easily recognisable as "ASCII printable".

> +typically of the form "package/version os" (e.g., "git/1.8.3.1 Linux")

So, I'd suggest using something other than " " between "version" and "os". Dot (as if the byte there were redacted) or slash or dash or whatever, anything that is not whitespace.

Show 6 quoted lines
> +where `os` is the operating system name (e.g., "Linux"). `X` and `Y` can
> +be configured using the GIT_USER_AGENT environment variable and it takes
> +priority. The `os` is retrieved using the 'sysname' field of the `uname(2)`
> +system call or its equivalent. The agent strings are purely informative for
> +statistics and debugging purposes, and MUST NOT be used to programmatically
> +assume the presence or absence of particular features.
Other than these nits, I find the above very well done.

As to the additional implementation of git_user_agent_sanitized(), except for that same "do we really want SP there?" question, I see nothing questionable there, either.

Overall very nicely done and presented.
Thanks.
Previous: Usman AkinyemiNext: Usman Akinyemi
Message 88 of 107 in “[Outreachy] Introduce os-version Capability with Configurable Options”
  1. 0/4 [Outreachy] Introduce os-version Capability with Configurable OptionsUsman Akinyemi, Jan 6, 2025
  2. 1/4 version: refactor redact_non_printables()Usman Akinyemi, Jan 6, 2025
  3. Eric SunshineJan 6, 2025
  4. Usman AkinyemiJan 8, 2025
  5. 2/4 version: refactor get_uname_info()Usman Akinyemi, Jan 6, 2025
  6. Junio C HamanoJan 6, 2025
  7. Usman AkinyemiJan 8, 2025
  8. 3/4 connect: advertise OS versionUsman Akinyemi, Jan 6, 2025
  9. Junio C HamanoJan 6, 2025
  10. Usman AkinyemiJan 8, 2025
  11. Junio C HamanoJan 8, 2025
  12. Usman AkinyemiJan 9, 2025
  13. Junio C HamanoJan 9, 2025
  14. Usman AkinyemiJan 10, 2025
  15. Junio C HamanoJan 10, 2025
  16. Usman AkinyemiJan 11, 2025
  17. Junio C HamanoJan 13, 2025
  18. Usman AkinyemiJan 13, 2025
  19. Junio C HamanoJan 13, 2025
  20. rsbecker@nexbridge.comJan 13, 2025
  21. Eric SunshineJan 6, 2025
  22. Usman AkinyemiJan 8, 2025
  23. 4/4 version: introduce osversion.command config for os-version outputUsman Akinyemi, Jan 6, 2025
  24. 0/6 [Outreachy] Introduce os-version Capability with Configurable OptionsUsman Akinyemi, Jan 17, 2025
  25. 1/6 version: refactor redact_non_printables()Usman Akinyemi, Jan 17, 2025
  26. Junio C HamanoJan 17, 2025
  27. Junio C HamanoJan 17, 2025
  28. Usman AkinyemiJan 20, 2025
  29. Christian CouderJan 21, 2025
  30. Junio C HamanoJan 21, 2025
  31. 2/6 version: refactor get_uname_info()Usman Akinyemi, Jan 17, 2025
  32. 3/6 version: extend get_uname_info() to hide system detailsUsman Akinyemi, Jan 17, 2025
  33. Junio C HamanoJan 17, 2025
  34. 4/6 t5701: add setup test to remove side-effect dependencyUsman Akinyemi, Jan 17, 2025
  35. Junio C HamanoJan 17, 2025
  36. Usman AkinyemiJan 20, 2025
  37. Junio C HamanoJan 20, 2025
  38. Usman AkinyemiJan 21, 2025
  39. 5/6 connect: advertise OS versionUsman Akinyemi, Jan 17, 2025
  40. Junio C HamanoJan 17, 2025
  41. Junio C HamanoJan 17, 2025
  42. rsbecker@nexbridge.comJan 17, 2025
  43. Junio C HamanoJan 17, 2025
  44. Usman AkinyemiJan 20, 2025
  45. Junio C HamanoJan 21, 2025
  46. 6/6 version: introduce osversion.command config for os-version outputUsman Akinyemi, Jan 17, 2025
  47. Eric SunshineJan 17, 2025
  48. Usman AkinyemiJan 20, 2025
  49. Eric SunshineJan 20, 2025
  50. Usman AkinyemiJan 20, 2025
  51. Junio C HamanoJan 17, 2025
  52. rsbecker@nexbridge.comJan 17, 2025
  53. Junio C HamanoJan 17, 2025
  54. rsbecker@nexbridge.comJan 17, 2025
  55. Usman AkinyemiJan 20, 2025
  56. Junio C HamanoJan 21, 2025
  57. rsbecker@nexbridge.comJan 21, 2025
  58. 0/6 [Outreachy] Introduce os-version Capability with Configurable OptionsUsman Akinyemi, Jan 24, 2025
  59. 1/6 version: replace manual ASCII checks with isprint() for clarityUsman Akinyemi, Jan 24, 2025
  60. Junio C HamanoJan 24, 2025
  61. 2/6 version: refactor redact_non_printables()Usman Akinyemi, Jan 24, 2025
  62. 3/6 version: refactor get_uname_info()Usman Akinyemi, Jan 24, 2025
  63. 4/6 version: extend get_uname_info() to hide system detailsUsman Akinyemi, Jan 24, 2025
  64. 5/6 t5701: add setup test to remove side-effect dependencyUsman Akinyemi, Jan 24, 2025
  65. Junio C HamanoJan 24, 2025
  66. 6/6 connect: advertise OS versionUsman Akinyemi, Jan 24, 2025
  67. 0/6 [Outreachy] extend agent capability to include OS nameUsman Akinyemi, Feb 5, 2025
  68. 1/6 version: replace manual ASCII checks with isprint() for clarityUsman Akinyemi, Feb 5, 2025
  69. 2/6 version: refactor redact_non_printables()Usman Akinyemi, Feb 5, 2025
  70. 3/6 version: refactor get_uname_info()Usman Akinyemi, Feb 5, 2025
  71. 4/6 version: extend get_uname_info() to hide system detailsUsman Akinyemi, Feb 5, 2025
  72. 6/6 agent: advertise OS name via agent capabilityUsman Akinyemi, Feb 5, 2025
  73. Junio C HamanoFeb 5, 2025
  74. Usman AkinyemiFeb 6, 2025
  75. Junio C HamanoFeb 6, 2025
  76. Usman AkinyemiFeb 7, 2025
  77. Junio C HamanoFeb 7, 2025
  78. Usman AkinyemiFeb 7, 2025
  79. 5/6 t5701: add setup test to remove side-effect dependencyUsman Akinyemi, Feb 5, 2025
  80. 0/6 [Outreachy] extend agent capability to include OS nameUsman Akinyemi, Feb 14, 2025
  81. 1/6 version: replace manual ASCII checks with isprint() for clarityUsman Akinyemi, Feb 14, 2025
  82. 2/6 version: refactor redact_non_printables()Usman Akinyemi, Feb 14, 2025
  83. 3/6 version: refactor get_uname_info()Usman Akinyemi, Feb 14, 2025
  84. 4/6 version: extend get_uname_info() to hide system detailsUsman Akinyemi, Feb 14, 2025
  85. 5/6 t5701: add setup test to remove side-effect dependencyUsman Akinyemi, Feb 14, 2025
  86. Junio C HamanoFeb 14, 2025
  87. 6/6 agent: advertise OS name via agent capabilityUsman Akinyemi, Feb 14, 2025
  88. Junio C HamanoFeb 14, 2025
  89. Usman AkinyemiFeb 15, 2025
  90. 0/6 [Outreachy] extend agent capability to include OS nameUsman Akinyemi, Feb 15, 2025
  91. 1/6 version: replace manual ASCII checks with isprint() for clarityUsman Akinyemi, Feb 15, 2025
  92. 2/6 version: refactor redact_non_printables()Usman Akinyemi, Feb 15, 2025
  93. 3/6 version: refactor get_uname_info()Usman Akinyemi, Feb 15, 2025
  94. 4/6 version: extend get_uname_info() to hide system detailsUsman Akinyemi, Feb 15, 2025
  95. 5/6 t5701: add setup test to remove side-effect dependencyUsman Akinyemi, Feb 15, 2025
  96. 6/6 agent: advertise OS name via agent capabilityUsman Akinyemi, Feb 15, 2025
  97. Junio C HamanoFeb 18, 2025
  98. Junio C HamanoFeb 18, 2025
  99. Junio C HamanoJan 24, 2025
  100. Christian CouderJan 27, 2025
  101. Junio C HamanoJan 27, 2025
  102. Christian CouderJan 31, 2025
  103. Junio C HamanoJan 31, 2025
  104. Usman AkinyemiJan 31, 2025
  105. Junio C HamanoJan 31, 2025
  106. Usman AkinyemiJan 31, 2025
  107. Junio C HamanoJan 31, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.