git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH V4 1/1] Replace SID with domain/username

From
Junio C Hamano <gitster@pobox.com>
Date
Jan 3, 2024, 22:22 UTC
Message-ID
<xmqqil4a83b1.fsf@gitster.g>
In-Reply-To
<DB9P250MB0692C8B4D93ED92FEE680AA9A560A@DB9P250MB0692.EURP250.PROD.OUTLOOK.COM>
Matthias Aßhauer <mha1993@live.de> writes:
Show 10 quoted lines
> This patch only changes the output of our error message, though.
> It does not change what ownership information we actually compare.
> So if we had a hypothetical user Bob that was part of the  domain
> example.com (SID S-1-5-21-100000001-1000000001-10000001-1001) and
> had been moved over from the example.org domain (old SID S-1-5-21-
> 2000000002-2000000002-20000002-2002) and we would detect a repository
> owned by bobs old SID, we would now lookup the old SID, find it
> attached to a user named example.com\Bob, look up Bobs  current SID,
> find it belongs to a user named example.com\Bob and print a confusing
> error message.
Yup, that is exactly the kind of breakage I was worried about.
Perhaps we should do something along the lines of ...
 - The erroring out should be done purely by SID comparison, as that
   is what we have been doing to protect the users.
 - When creating a message, use LookupAccountSidA() to come up with
   a pair of domain\user strings for the directory and the process
   to be used in the error message:
   - If they are different (which is expected to be the normal
     case), we just use the pair of strings.
   - If they are the same, show old and new SID in stringified form
     (hopefully different SIDs would strigify to different
     strings?), and optionally we give the domain\user string next
     to it.
... then?  Then we would emit an error message (in the best case)
    'directory' is owned by:
    'bob@example.org'
    but the current user is:
    'charlie@example.com'
and in a bad case we would instead see something like:
    'directory' is owned by:
    SID S-1-5-21-100000001-1000000001-10000001-1001 ('bob@example.org')
    but the current user is:
    SID S-1-5-21-200000002-2000000002-20000002-2002 ('bob@example.org')
which may still be serviceable.  I dunno.
Previous: Matthias AßhauerNext: Sören Krecker
Message 13 of 28 in “Replace SID with domain/username on Windows”
  1. 0/1 Replace SID with domain/username on WindowsSören Krecker, Dec 29, 2023
  2. 1/1 Replace SID with domain/usernameSören Krecker, Dec 29, 2023
  3. Junio C HamanoJan 2, 2024
  4. Junio C HamanoJan 2, 2024
  5. Eric SunshineDec 31, 2023
  6. 0/1 Replace SID with domain/username on WindowsSören Krecker, Dec 31, 2023
  7. 1/1 Replace SID with domain/usernameSören Krecker, Dec 31, 2023
  8. Junio C HamanoJan 2, 2024
  9. 0/1 Replace SID with domain/username on WindowsSören Krecker, Jan 2, 2024
  10. 1/1 Replace SID with domain/usernameSören Krecker, Jan 2, 2024
  11. Junio C HamanoJan 3, 2024
  12. Matthias AßhauerJan 3, 2024
  13. Junio C HamanoJan 3, 2024
  14. 0/1 Replace SID with domain/username on WindowsSören Krecker, Jan 4, 2024
  15. 1/1 Adds domain/username to error messageSören Krecker, Jan 4, 2024
  16. Junio C HamanoJan 4, 2024
  17. 0/1 mingw: give more details about unsafe directory's ownershipSören Krecker, Jan 6, 2024
  18. 1/1 mingw: give more details about unsafe directory's ownershipSören Krecker, Jan 6, 2024
  19. Johannes SixtJan 7, 2024
  20. 0/1 mingw: give more details about unsafe directory'sSören Krecker, Jan 8, 2024
  21. 1/1 mingw: give more details about unsafe directory's ownershipSören Krecker, Jan 8, 2024
  22. Junio C HamanoJan 8, 2024
  23. Johannes SixtJan 9, 2024
  24. Junio C HamanoJan 9, 2024
  25. Johannes SixtJan 9, 2024
  26. Junio C HamanoJan 9, 2024
  27. Dragan SimicJan 8, 2024
  28. Eric SunshineDec 31, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.