git.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Jeff King <peff@peff.net>
To: "Shawn O. Pearce" <spearce@spearce.org>
Cc: Arun Raghavan <ford_prefect@gentoo.org>, git@vger.kernel.org
Subject: Re: Removal of post-upload-hook
Date: Thu, 14 Jan 2010 15:43:05 -0500	[thread overview]
Message-ID: <20100114204305.GC26883@coredump.intra.peff.net> (raw)
In-Reply-To: <20100114194107.GA20033@spearce.org>

On Thu, Jan 14, 2010 at 11:41:07AM -0800, Shawn O. Pearce wrote:

> > Because receive-pack runs as the user who is pushing, not as the
> > repository owner. So by convincing you to push to my repository in a
> > multi-user environment, I convince you to run some arbitrary code of
> > mine.
> 
> Uhhh, this was in fetch/upload-pack Peff, not push/receive-pack.
> 
> Same issue though.

Errr...yeah. Sorry for the confusion. But yes, it's the same mechanism,
except that it is even easier to get people to pull from you (to get
them to push, you first have to get them to write a worthwhile code
contribution. ;) ).

-Peff

  parent reply	other threads:[~2010-01-14 20:43 UTC|newest]

Thread overview: 21+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2010-01-14 18:01 Removal of post-upload-hook Arun Raghavan
2010-01-14 19:36 ` Jeff King
2010-01-14 19:41   ` Shawn O. Pearce
2010-01-14 19:52     ` Arun Raghavan
2010-01-14 20:43     ` Jeff King [this message]
2010-01-14 21:06       ` Robin H. Johnson
2010-01-15 14:47         ` Jeff King
2010-01-15  6:12       ` Arun Raghavan
2010-01-15 11:52         ` Ilari Liusvaara
2010-01-15 12:14           ` Arun Raghavan
2010-02-01  8:32             ` [PATCH 0/2] upload-pack: pre- and post- hooks Arun Raghavan
2010-02-01  8:32               ` [PATCH 1/2] upload-pack: Reinstate the post-upload-pack hook Arun Raghavan
2010-02-01  8:32                 ` [PATCH 2/2] upload-pack: Add a pre-upload-pack hook Arun Raghavan
2010-02-01 15:20               ` [PATCH 0/2] upload-pack: pre- and post- hooks Shawn O. Pearce
2010-02-01 15:50                 ` Arun Raghavan
2010-02-01 16:01                   ` Shawn O. Pearce
2010-02-02  5:50                     ` Arun Raghavan
2010-02-01 16:30                 ` Nicolas Pitre
2010-02-01 16:36                   ` Shawn O. Pearce
2010-02-02  5:52                     ` Arun Raghavan
2010-02-02  6:15                       ` Nicolas Pitre

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20100114204305.GC26883@coredump.intra.peff.net \
    --to=peff@peff.net \
    --cc=ford_prefect@gentoo.org \
    --cc=git@vger.kernel.org \
    --cc=spearce@spearce.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).