[Top][All Lists]
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Gnu-arch-users] expert needed: arch doesn't support multi-committer
From: |
Tom Lord |
Subject: |
Re: [Gnu-arch-users] expert needed: arch doesn't support multi-committer archives! |
Date: |
Tue, 7 Oct 2003 07:43:06 -0700 (PDT) |
This reminded me, by the way: the other solution that got brushed
aside but seems viable to me is to write a login-script that sets the
umask on the existing accounts appropriately for arch work when the
log-in is from an arch client. OpenSSH, at least, has ~/.ssh/rc
which seems to exist for just this kind of purpose (the question is
how that script should distinguish those logins where umask should be
changed).
Another solution, similar to that one, is to invoke ssh to run some
substem other than sftp, "archsftp" perhaps, and configure that
service appropriately server-side. While I don't approve of the
=meta-data or copy-permissions hacks, I would be willing to
parameterize src/tla/libarch/pfs-sftp.c so that the string "sftp" is
parameterized.
> From: Ethan Benson <address@hidden>
> On Mon, Oct 06, 2003 at 09:46:09AM -0700, Tom Lord wrote:
> > In short, I think James has nailed the answer cold and I'm not sure
> > why his solution was so glibly brushed aside in favor of all the other
> > discussion.
> because from a system administrators point of view shared accounts are
> simply unacceptable. they provide absolutly no accountability for who
> is doing what.
I think you must have skimmed over the part of my message that talked
about generalizations of the sftp-account solution.
When fs-like transports are used, certainly the possibility exists
that a compromised authorization can be used to remove or alter
archives arbitrarily. That's an entirely separate problem from
the one djw wanted to solve.
(It's also a fairly trivial problem to solve and would, as a side
effect, give yet-another work-around for the umask foo -- but it would
take more than the few days remaining to implement. Not much more but
more.)
-t
- Re: [Gnu-arch-users] expert needed: arch doesn't support multi-committer archives!, (continued)
- Re: [Gnu-arch-users] expert needed: arch doesn't support multi-committer archives!, Stephen J. Turnbull, 2003/10/09
- Re: [Gnu-arch-users] expert needed: arch doesn't support multi-committer archives!, Ethan Benson, 2003/10/07
- [Gnu-arch-users] Re: expert needed: arch doesn't support multi-committer archives!, Pau Aliagas, 2003/10/07
- [Gnu-arch-users] Re: expert needed: arch doesn't support multi-committer archives!, Ethan Benson, 2003/10/07
- [Gnu-arch-users] Re: expert needed: arch doesn't support multi-committer archives!, Pau Aliagas, 2003/10/07
- [Gnu-arch-users] Re: expert needed: arch doesn't support multi-committer archives!, Ethan Benson, 2003/10/07
- Re: [Gnu-arch-users] Re: expert needed: arch doesn't support multi-committer archives!, Tom Lord, 2003/10/07
- [Gnu-arch-users] Re: expert needed: arch doesn't support multi-committer archives!, James Blackwell, 2003/10/07
- Re: [Gnu-arch-users] Re: expert needed: arch doesn't support multi-committer archives!, Charles Duffy, 2003/10/07
- Re: [Gnu-arch-users] Re: expert needed: arch doesn't support multi-committer archives!, Ethan Benson, 2003/10/08
- Re: [Gnu-arch-users] expert needed: arch doesn't support multi-committer archives!,
Tom Lord <=
- Re: [Gnu-arch-users] expert needed: arch doesn't support multi-committer archives!, Paul Hedderly, 2003/10/14
Re: [Gnu-arch-users] expert needed: arch doesn't support multi-committer archives!, Andrew Suffield, 2003/10/06
Re: [Gnu-arch-users] expert needed: arch doesn't support multi-committer archives!, Ethan Benson, 2003/10/06
Re: [Gnu-arch-users] expert needed: arch doesn't support multi-committer archives!, Andrew Suffield, 2003/10/06
Re: [Gnu-arch-users] expert needed: arch doesn't support multi-committer archives!, Ethan Benson, 2003/10/06
Re: [Gnu-arch-users] expert needed: arch doesn't support multi-committer archives!, Andrew Suffield, 2003/10/06
Re: [Gnu-arch-users] expert needed: arch doesn't support multi-committer archives!, Jonathan Walther, 2003/10/06
Re: [Gnu-arch-users] expert needed: arch doesn't support multi-committer archives!, Ethan Benson, 2003/10/06