transport: refactor protocol whitelist code
The current callers only want to die when their transport is prohibited. But future callers want to query the mechanism without dying. Let's break out a few query functions, and also save the results in a static list so we don't have to re-parse for each query. Based-on-a-patch-by: Blake Burkhart <bburky@bburky.com> Signed-off-by: Jeff King <peff@peff.net> Signed-off-by: Junio C Hamano <gitster@pobox.com>
Jeff King committed
Sep 22, 2015 at 18:03 UTC
5088d3b38775f8ac12d7f77636775b16059b67ef
2 files changed
+43
-10
transport.c
+30
-8
@@ -909,18 +909,40 @@ static int external_specification_len(const char *url)
909
return strchr(url, ':') - url;
910
}
911
912
-void transport_check_allowed(const char *type)
912
+static const struct string_list *protocol_whitelist(void)
913
{
914
- struct string_list allowed = STRING_LIST_INIT_DUP;
915
- const char *v = getenv("GIT_ALLOW_PROTOCOL");
914
+ static int enabled = -1;
915
+ static struct string_list allowed = STRING_LIST_INIT_DUP;
916
+
917
+ if (enabled < 0) {
918
+ const char *v = getenv("GIT_ALLOW_PROTOCOL");
919
+ if (v) {
920
+ string_list_split(&allowed, v, ':', -1);
921
+ string_list_sort(&allowed);
922
+ enabled = 1;
923
+ } else {
924
+ enabled = 0;
925
+ }
926
+ }
927
917
- if (!v)
918
- return;
928
+ return enabled ? &allowed : NULL;
929
+}
930
+
931
+int is_transport_allowed(const char *type)
932
+{
933
+ const struct string_list *allowed = protocol_whitelist();
934
+ return !allowed || string_list_has_string(allowed, type);
935
+}
936
920
- string_list_split(&allowed, v, ':', -1);
921
- if (!unsorted_string_list_has_string(&allowed, type))
937
+void transport_check_allowed(const char *type)
938
+{
939
+ if (!is_transport_allowed(type))
940
die("transport '%s' not allowed", type);
923
- string_list_clear(&allowed, 0);
941
+}
942
+
943
+int transport_restrict_protocols(void)
944
+{
945
+ return !!protocol_whitelist();
946
}
947
948
struct transport *transport_get(struct remote *remote, const char *url)
transport.h
+13
-2
@@ -132,13 +132,24 @@ struct transport {
132
/* Returns a transport suitable for the url */
133
struct transport *transport_get(struct remote *, const char *);
134
135
+/*
136
+ * Check whether a transport is allowed by the environment. Type should
137
+ * generally be the URL scheme, as described in Documentation/git.txt
138
+ */
139
+int is_transport_allowed(const char *type);
140
+
141
/*
142
* Check whether a transport is allowed by the environment,
137
- * and die otherwise. type should generally be the URL scheme,
138
- * as described in Documentation/git.txt
143
+ * and die otherwise.
144
*/
145
void transport_check_allowed(const char *type);
146
147
+/*
148
+ * Returns true if the user has attempted to turn on protocol
149
+ * restrictions at all.
150
+ */
151
+int transport_restrict_protocols(void);
152
+
153
/* Transport options which apply to git:// and scp-style URLs */
154
155
/* The program to use on the remote side to send a pack */