-
Notifications
You must be signed in to change notification settings - Fork 139
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
credential-cache: respect request capabilities #1842
base: master
Are you sure you want to change the base?
Conversation
There are issues in commit 945b5c5: |
945b5c5
to
9197941
Compare
/submit |
Submitted as [email protected] To fetch this version into
To fetch this version to local tag
|
9197941
to
696780d
Compare
Submitted as [email protected] To fetch this version into
To fetch this version to local tag
|
On the Git mailing list, "brian m. carlson" wrote (reply to this): On 2025-01-06 at 19:52:11, M Hickford via GitGitGadget wrote:
> From: M Hickford <[email protected]>
>
> Previously, credential-cache responded with capability[]=authtype
> regardless of request.
That's the correct behaviour.
> The capabilities in a credential helper response should be a subset of
> the capabilities in the request.
No, it should not. Otherwise, it's impossible for Git to know whether
the helper does or does not support the capability. We rely on that
information to correctly pass data back when saving data.
> diff --git a/builtin/credential-cache--daemon.c b/builtin/credential-cache--daemon.c
> index bc22f5c6d24..692216cf83c 100644
> --- a/builtin/credential-cache--daemon.c
> +++ b/builtin/credential-cache--daemon.c
> @@ -134,17 +134,16 @@ static void serve_one_client(FILE *in, FILE *out)
> else if (!strcmp(action.buf, "get")) {
> struct credential_cache_entry *e = lookup_credential(&c);
> if (e) {
> - e->item.capa_authtype.request_initial = 1;
> - e->item.capa_authtype.request_helper = 1;
> -
> - fprintf(out, "capability[]=authtype\n");
> + if (credential_has_capability(&c.capa_authtype, CREDENTIAL_OP_RESPONSE)) {
> + fprintf(out, "capability[]=authtype\n");
> + }
This part is not correct.
> if (e->item.username)
> fprintf(out, "username=%s\n", e->item.username);
> if (e->item.password)
> fprintf(out, "password=%s\n", e->item.password);
> - if (credential_has_capability(&c.capa_authtype, CREDENTIAL_OP_HELPER) && e->item.authtype)
> + if (credential_has_capability(&c.capa_authtype, CREDENTIAL_OP_RESPONSE) && e->item.authtype)
> fprintf(out, "authtype=%s\n", e->item.authtype);
> - if (credential_has_capability(&c.capa_authtype, CREDENTIAL_OP_HELPER) && e->item.credential)
> + if (credential_has_capability(&c.capa_authtype, CREDENTIAL_OP_RESPONSE) && e->item.credential)
This part may very well be correct.
> fprintf(out, "credential=%s\n", e->item.credential);
> if (e->item.password_expiry_utc != TIME_MAX)
> fprintf(out, "password_expiry_utc=%"PRItime"\n",
> diff --git a/t/lib-credential.sh b/t/lib-credential.sh
> index 58b9c740605..324ecc792d5 100644
> --- a/t/lib-credential.sh
> +++ b/t/lib-credential.sh
> @@ -566,6 +566,21 @@ helper_test_authtype() {
> EOF
> '
>
> + test_expect_success "helper ($HELPER) get authtype only if request has authtype capability" '
> + check fill $HELPER <<-\EOF
> + protocol=https
> + host=git.example.com
> + --
> + protocol=https
> + host=git.example.com
> + username=askpass-username
> + password=askpass-password
> + --
> + askpass: Username for '\''https://git.example.com'\'':
> + askpass: Password for '\''https://[email protected]'\'':
> + EOF
> + '
> +
> test_expect_success "helper ($HELPER) stores authtype and credential with username" '
> check approve $HELPER <<-\EOF
> capability[]=authtype
>
> base-commit: 92999a42db1c5f43f330e4f2bca4026b5b81576f
> --
> gitgitgadget
--
brian m. carlson (they/them or he/him)
Toronto, Ontario, CA |
696780d
to
3129fdd
Compare
On the Git mailing list, M Hickford wrote (reply to this): On Mon, 6 Jan 2025 at 22:32, brian m. carlson
<[email protected]> wrote:
>
> On 2025-01-06 at 19:52:11, M Hickford via GitGitGadget wrote:
> > From: M Hickford <[email protected]>
> >
> > Previously, credential-cache responded with capability[]=authtype
> > regardless of request.
>
> That's the correct behaviour.
>
> > The capabilities in a credential helper response should be a subset of
> > the capabilities in the request.
>
> No, it should not. Otherwise, it's impossible for Git to know whether
> the helper does or does not support the capability. We rely on that
> information to correctly pass data back when saving data.
>
> > diff --git a/builtin/credential-cache--daemon.c b/builtin/credential-cache--daemon.c
> > index bc22f5c6d24..692216cf83c 100644
> > --- a/builtin/credential-cache--daemon.c
> > +++ b/builtin/credential-cache--daemon.c
> > @@ -134,17 +134,16 @@ static void serve_one_client(FILE *in, FILE *out)
> > else if (!strcmp(action.buf, "get")) {
> > struct credential_cache_entry *e = lookup_credential(&c);
> > if (e) {
> > - e->item.capa_authtype.request_initial = 1;
> > - e->item.capa_authtype.request_helper = 1;
> > -
> > - fprintf(out, "capability[]=authtype\n");
> > + if (credential_has_capability(&c.capa_authtype, CREDENTIAL_OP_RESPONSE)) {
> > + fprintf(out, "capability[]=authtype\n");
> > + }
>
> This part is not correct.
Thanks for the review. I'll revert this part and amend the commit message.
>
> > if (e->item.username)
> > fprintf(out, "username=%s\n", e->item.username);
> > if (e->item.password)
> > fprintf(out, "password=%s\n", e->item.password);
> > - if (credential_has_capability(&c.capa_authtype, CREDENTIAL_OP_HELPER) && e->item.authtype)
> > + if (credential_has_capability(&c.capa_authtype, CREDENTIAL_OP_RESPONSE) && e->item.authtype)
> > fprintf(out, "authtype=%s\n", e->item.authtype);
> > - if (credential_has_capability(&c.capa_authtype, CREDENTIAL_OP_HELPER) && e->item.credential)
> > + if (credential_has_capability(&c.capa_authtype, CREDENTIAL_OP_RESPONSE) && e->item.credential)
>
> This part may very well be correct.
>
> > fprintf(out, "credential=%s\n", e->item.credential);
> > if (e->item.password_expiry_utc != TIME_MAX)
> > fprintf(out, "password_expiry_utc=%"PRItime"\n",
> > diff --git a/t/lib-credential.sh b/t/lib-credential.sh
> > index 58b9c740605..324ecc792d5 100644
> > --- a/t/lib-credential.sh
> > +++ b/t/lib-credential.sh
> > @@ -566,6 +566,21 @@ helper_test_authtype() {
> > EOF
> > '
> >
> > + test_expect_success "helper ($HELPER) get authtype only if request has authtype capability" '
> > + check fill $HELPER <<-\EOF
> > + protocol=https
> > + host=git.example.com
> > + --
> > + protocol=https
> > + host=git.example.com
> > + username=askpass-username
> > + password=askpass-password
> > + --
> > + askpass: Username for '\''https://git.example.com'\'':
> > + askpass: Password for '\''https://[email protected]'\'':
> > + EOF
> > + '
> > +
> > test_expect_success "helper ($HELPER) stores authtype and credential with username" '
> > check approve $HELPER <<-\EOF
> > capability[]=authtype
> >
> > base-commit: 92999a42db1c5f43f330e4f2bca4026b5b81576f
> > --
> > gitgitgadget
>
> --
> brian m. carlson (they/them or he/him)
> Toronto, Ontario, CA |
3129fdd
to
e9851c5
Compare
Submitted as [email protected] To fetch this version into
To fetch this version to local tag
|
On the Git mailing list, "brian m. carlson" wrote (reply to this): On 2025-01-06 at 22:57:06, M Hickford wrote:
> On Mon, 6 Jan 2025 at 22:32, brian m. carlson
> <[email protected]> wrote:
> >
> > On 2025-01-06 at 19:52:11, M Hickford via GitGitGadget wrote:
> > > From: M Hickford <[email protected]>
> > > diff --git a/builtin/credential-cache--daemon.c b/builtin/credential-cache--daemon.c
> > > index bc22f5c6d24..692216cf83c 100644
> > > --- a/builtin/credential-cache--daemon.c
> > > +++ b/builtin/credential-cache--daemon.c
> > > @@ -134,17 +134,16 @@ static void serve_one_client(FILE *in, FILE *out)
> > > else if (!strcmp(action.buf, "get")) {
> > > struct credential_cache_entry *e = lookup_credential(&c);
> > > if (e) {
> > > - e->item.capa_authtype.request_initial = 1;
> > > - e->item.capa_authtype.request_helper = 1;
> > > -
> > > - fprintf(out, "capability[]=authtype\n");
> > > + if (credential_has_capability(&c.capa_authtype, CREDENTIAL_OP_RESPONSE)) {
> > > + fprintf(out, "capability[]=authtype\n");
> > > + }
> >
> > This part is not correct.
>
> Thanks for the review. I'll revert this part and amend the commit message.
I applied this without that change and it does still pass the test,
which I think is good and shows that can be omitted. If I have some
time, I may send a follow-up patch to add some additional tests.
--
brian m. carlson (they/them or he/him)
Toronto, Ontario, CA |
e9851c5
to
23942f9
Compare
Submitted as [email protected] To fetch this version into
To fetch this version to local tag
|
On the Git mailing list, Junio C Hamano wrote (reply to this): "M Hickford via GitGitGadget" <[email protected]> writes:
> From: M Hickford <[email protected]>
>
> Previously, credential-cache populated authtype regardless of request.
OK, that may be a correct statement of the fact, but it does not
tell readers any of the following:
- If it is a bad thing to populate authtype regardless of request,
and if so why?
- What is the (negative) consequence of doing so, if any? What
breaks because it populates authtype regardless of request?
- What is the remedy? Instead of unconditionally populating the
authtype, how does the new code decide when to populate it and
with what value?
- Can there be downsides of fixing this? Are there use cases where
this unconditional population of authtype was relied upon?
- Where did the bug come from and what is its fix? We used to look
at OP_HELPER to decide when to emit authtype, but the updated
code checks OP_RESPONSE, which readers can see in the patch.
It would be nice if the proposed log message helped them by
briefly explaining their differences, for example.
which would help future "git log" readers what this fix was about.
Will queue for now, but the log message would want to be a bit more
helpful to the readers.
Thanks.
> Signed-off-by: M Hickford <[email protected]>
> ---
> credential-cache: respect request capabilities
>
> CC: [email protected]
>
> Patch v4 fixes test
>
> Published-As: https://github.com/gitgitgadget/git/releases/tag/pr-1842%2Fhickford%2Fcache-capability-v4
> Fetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-1842/hickford/cache-capability-v4
> Pull-Request: https://github.com/gitgitgadget/git/pull/1842
>
> Range-diff vs v3:
>
> 1: e9851c5c4ac ! 1: 23942f9fa47 credential-cache: respect request capabilities
> @@ t/lib-credential.sh: helper_test_authtype() {
> + protocol=https
> + host=git.example.com
> + --
> -+ capability[]=authtype
> + protocol=https
> + host=git.example.com
> + username=askpass-username
>
>
> builtin/credential-cache--daemon.c | 4 ++--
> t/lib-credential.sh | 15 +++++++++++++++
> 2 files changed, 17 insertions(+), 2 deletions(-)
>
> diff --git a/builtin/credential-cache--daemon.c b/builtin/credential-cache--daemon.c
> index bc22f5c6d24..e707618e743 100644
> --- a/builtin/credential-cache--daemon.c
> +++ b/builtin/credential-cache--daemon.c
> @@ -142,9 +142,9 @@ static void serve_one_client(FILE *in, FILE *out)
> fprintf(out, "username=%s\n", e->item.username);
> if (e->item.password)
> fprintf(out, "password=%s\n", e->item.password);
> - if (credential_has_capability(&c.capa_authtype, CREDENTIAL_OP_HELPER) && e->item.authtype)
> + if (credential_has_capability(&c.capa_authtype, CREDENTIAL_OP_RESPONSE) && e->item.authtype)
> fprintf(out, "authtype=%s\n", e->item.authtype);
> - if (credential_has_capability(&c.capa_authtype, CREDENTIAL_OP_HELPER) && e->item.credential)
> + if (credential_has_capability(&c.capa_authtype, CREDENTIAL_OP_RESPONSE) && e->item.credential)
> fprintf(out, "credential=%s\n", e->item.credential);
> if (e->item.password_expiry_utc != TIME_MAX)
> fprintf(out, "password_expiry_utc=%"PRItime"\n",
> diff --git a/t/lib-credential.sh b/t/lib-credential.sh
> index 58b9c740605..cc6bf9aa5f3 100644
> --- a/t/lib-credential.sh
> +++ b/t/lib-credential.sh
> @@ -566,6 +566,21 @@ helper_test_authtype() {
> EOF
> '
>
> + test_expect_success "helper ($HELPER) gets authtype and credential only if request has authtype capability" '
> + check fill $HELPER <<-\EOF
> + protocol=https
> + host=git.example.com
> + --
> + protocol=https
> + host=git.example.com
> + username=askpass-username
> + password=askpass-password
> + --
> + askpass: Username for '\''https://git.example.com'\'':
> + askpass: Password for '\''https://[email protected]'\'':
> + EOF
> + '
> +
> test_expect_success "helper ($HELPER) stores authtype and credential with username" '
> check approve $HELPER <<-\EOF
> capability[]=authtype
>
> base-commit: 92999a42db1c5f43f330e4f2bca4026b5b81576f |
This patch series was integrated into seen via git@d970fe7. |
This patch series was integrated into seen via git@485116e. |
Previously, credential-cache populated authtype regardless whether "get" request had authtype capability. As documented in git-credential.txt, authtype "should not be sent unless the appropriate capability ... is provided". Add test. Without this change, the test failed because "credential fill" printed an incomplete credential with only protocol and host attributes (the unexpected authtype attribute was discarded by credential.c). Signed-off-by: M Hickford <[email protected]>
23942f9
to
db575d9
Compare
/submit |
Submitted as [email protected] To fetch this version into
To fetch this version to local tag
|
This branch is now known as |
This patch series was integrated into seen via git@5160d3a. |
This patch series was integrated into seen via git@15ef9d2. |
This patch series was integrated into seen via git@1ca2557. |
This patch series was integrated into seen via git@062b28a. |
This patch series was integrated into seen via git@cf184fa. |
There was a status update in the "New Topics" section about the branch The "cache" credential back-end did not handle authtype correctly, which has been corrected. source: <[email protected]> |
This patch series was integrated into seen via git@6526132. |
This patch series was integrated into seen via git@d72136d. |
This patch series was integrated into seen via git@30eb8c2. |
There was a status update in the "Cooking" section about the branch The "cache" credential back-end did not handle authtype correctly, which has been corrected. source: <[email protected]> |
This patch series was integrated into seen via git@0356a7b. |
This patch series was integrated into seen via git@7b15374. |
This patch series was integrated into seen via git@1776310. |
This patch series was integrated into seen via git@8ba9b63. |
This patch series was integrated into seen via git@63e744a. |
There was a status update in the "Cooking" section about the branch The "cache" credential back-end did not handle authtype correctly, which has been corrected. source: <[email protected]> |
On the Git mailing list, M Hickford wrote (reply to this): On 2025-01-09 22:45, M Hickford via GitGitGadget wrote:
> From: M Hickford <[email protected]>
> > Previously, credential-cache populated authtype regardless whether
> "get" request had authtype capability. As documented in
> git-credential.txt, authtype "should not be sent unless the appropriate
> capability ... is provided".
> > Add test. Without this change, the test failed because "credential fill"
> printed an incomplete credential with only protocol and host attributes
> (the unexpected authtype attribute was discarded by credential.c).
> > Signed-off-by: M Hickford <[email protected]>
> ---
> credential-cache: respect request capabilities
> > CC: [email protected] CC: [email protected]
> > Patch v5 adds details to the commit message
> > Published-As: https://github.com/gitgitgadget/git/releases/tag/pr-1842%2Fhickford%2Fcache-capability-v5
> Fetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-1842/hickford/cache-capability-v5
> Pull-Request: https://github.com/gitgitgadget/git/pull/1842
> > Range-diff vs v4:
> > 1: 23942f9fa47 ! 1: db575d9d116 credential-cache: respect request capabilities
> @@ Metadata
> Author: M Hickford <[email protected]>
> > ## Commit message ##
> - credential-cache: respect request capabilities
> + credential-cache: respect authtype capability
> > - Previously, credential-cache populated authtype regardless of request.
> + Previously, credential-cache populated authtype regardless whether
> + "get" request had authtype capability. As documented in
> + git-credential.txt, authtype "should not be sent unless the appropriate
> + capability ... is provided".
> +
> + Add test. Without this change, the test failed because "credential fill"
> + printed an incomplete credential with only protocol and host attributes
> + (the unexpected authtype attribute was discarded by credential.c).
> > Signed-off-by: M Hickford <[email protected]>
> > > > builtin/credential-cache--daemon.c | 4 ++--
> t/lib-credential.sh | 15 +++++++++++++++
> 2 files changed, 17 insertions(+), 2 deletions(-)
> > diff --git a/builtin/credential-cache--daemon.c b/builtin/credential-cache--daemon.c
> index bc22f5c6d24..e707618e743 100644
> --- a/builtin/credential-cache--daemon.c
> +++ b/builtin/credential-cache--daemon.c
> @@ -142,9 +142,9 @@ static void serve_one_client(FILE *in, FILE *out)
> fprintf(out, "username=%s\n", e->item.username);
> if (e->item.password)
> fprintf(out, "password=%s\n", e->item.password);
> - if (credential_has_capability(&c.capa_authtype, CREDENTIAL_OP_HELPER) && e->item.authtype)
> + if (credential_has_capability(&c.capa_authtype, CREDENTIAL_OP_RESPONSE) && e->item.authtype)
> fprintf(out, "authtype=%s\n", e->item.authtype);
> - if (credential_has_capability(&c.capa_authtype, CREDENTIAL_OP_HELPER) && e->item.credential)
> + if (credential_has_capability(&c.capa_authtype, CREDENTIAL_OP_RESPONSE) && e->item.credential)
> fprintf(out, "credential=%s\n", e->item.credential);
> if (e->item.password_expiry_utc != TIME_MAX)
> fprintf(out, "password_expiry_utc=%"PRItime"\n",
> diff --git a/t/lib-credential.sh b/t/lib-credential.sh
> index 58b9c740605..cc6bf9aa5f3 100644
> --- a/t/lib-credential.sh
> +++ b/t/lib-credential.sh
> @@ -566,6 +566,21 @@ helper_test_authtype() {
> EOF
> '
> > + test_expect_success "helper ($HELPER) gets authtype and credential only if request has authtype capability" '
> + check fill $HELPER <<-\EOF
> + protocol=https
> + host=git.example.com
> + --
> + protocol=https
> + host=git.example.com
> + username=askpass-username
> + password=askpass-password
> + --
> + askpass: Username for '\''https://git.example.com'\'':
> + askpass: Password for '\''https://[email protected]'\'':
> + EOF
> + '
> +
> test_expect_success "helper ($HELPER) stores authtype and credential with username" '
> check approve $HELPER <<-\EOF
> capability[]=authtype
> > base-commit: 92999a42db1c5f43f330e4f2bca4026b5b81576f
Hi Brian. Any further comments on patch v5? This addresses your comments on v2 and expands the commit message as encouraged by Junio. (Thank you both for the review so far.)
https://lore.kernel.org/git/[email protected]/
https://lore.kernel.org/git/[email protected]/ |
On the Git mailing list, "brian m. carlson" wrote (reply to this): On 2025-01-18 at 20:09:50, M Hickford wrote:
> Hi Brian. Any further comments on patch v5? This addresses your comments on
> v2 and expands the commit message as encouraged by Junio. (Thank you both
> for the review so far.)
I think this looks fine.
--
brian m. carlson (they/them or he/him)
Toronto, Ontario, CA |
User |
CC: [email protected], [email protected]
Patch v5 adds details to the commit message
cc: "brian m. carlson" [email protected]