 85f505465e
			
		
	
	85f505465e
	
	
	
		
			
			Summary: Ref T2230. The SVN protocol has a sensible protocol format with a good spec here: http://svn.apache.org/repos/asf/subversion/trunk/subversion/libsvn_ra_svn/protocol Particularly, compare this statement to the clown show that is the Mercurial wire protocol: > It is possible to parse an item without knowing its type in advance. WHAT A REASONABLE STATEMENT TO BE ABLE TO MAKE ABOUT A WIRE PROTOCOL Although it makes substantially more sense than Mercurial, it's much heavier-weight than the Git or Mercurial protocols, since it isn't distributed. It's also not possible to figure out if a request is a write request (or even which repository it is against) without proxying some of the protocol frames. Finally, several protocol commands embed repository URLs, and we need to reach into the protocol and translate them. Test Plan: Ran various SVN commands over SSH (`svn log`, `svn up`, `svn commit`, etc). Reviewers: btrahan Reviewed By: btrahan CC: aran Maniphest Tasks: T2230 Differential Revision: https://secure.phabricator.com/D7556
		
			
				
	
	
		
			109 lines
		
	
	
		
			2.8 KiB
		
	
	
	
		
			PHP
		
	
	
		
			Executable File
		
	
	
	
	
			
		
		
	
	
			109 lines
		
	
	
		
			2.8 KiB
		
	
	
	
		
			PHP
		
	
	
		
			Executable File
		
	
	
	
	
| #!/usr/bin/env php
 | |
| <?php
 | |
| 
 | |
| $root = dirname(dirname(dirname(__FILE__)));
 | |
| require_once $root.'/scripts/__init_script__.php';
 | |
| 
 | |
| // First, figure out the authenticated user.
 | |
| $args = new PhutilArgumentParser($argv);
 | |
| $args->setTagline('receive SSH requests');
 | |
| $args->setSynopsis(<<<EOSYNOPSIS
 | |
| **ssh-exec** --phabricator-ssh-user __user__ [--ssh-command __commmand__]
 | |
|     Receive SSH requests.
 | |
| EOSYNOPSIS
 | |
| );
 | |
| 
 | |
| $args->parse(
 | |
|   array(
 | |
|     array(
 | |
|       'name'  => 'phabricator-ssh-user',
 | |
|       'param' => 'username',
 | |
|     ),
 | |
|     array(
 | |
|       'name' => 'ssh-command',
 | |
|       'param' => 'command',
 | |
|     ),
 | |
|   ));
 | |
| 
 | |
| try {
 | |
|   $user_name = $args->getArg('phabricator-ssh-user');
 | |
|   if (!strlen($user_name)) {
 | |
|     throw new Exception("No username.");
 | |
|   }
 | |
| 
 | |
|   $user = id(new PhabricatorUser())->loadOneWhere(
 | |
|     'userName = %s',
 | |
|     $user_name);
 | |
|   if (!$user) {
 | |
|     throw new Exception("Invalid username.");
 | |
|   }
 | |
| 
 | |
|   if ($user->getIsDisabled()) {
 | |
|     throw new Exception("You have been exiled.");
 | |
|   }
 | |
| 
 | |
|   if ($args->getArg('ssh-command')) {
 | |
|     $original_command = $args->getArg('ssh-command');
 | |
|   } else {
 | |
|     $original_command = getenv('SSH_ORIGINAL_COMMAND');
 | |
|   }
 | |
| 
 | |
|   // Now, rebuild the original command.
 | |
|   $original_argv = id(new PhutilShellLexer())
 | |
|     ->splitArguments($original_command);
 | |
|   if (!$original_argv) {
 | |
|     throw new Exception("No interactive logins.");
 | |
|   }
 | |
|   $command = head($original_argv);
 | |
|   array_unshift($original_argv, 'phabricator-ssh-exec');
 | |
| 
 | |
|   $original_args = new PhutilArgumentParser($original_argv);
 | |
| 
 | |
|   $workflows = array(
 | |
|     new ConduitSSHWorkflow(),
 | |
|     new DiffusionSSHSubversionServeWorkflow(),
 | |
|     new DiffusionSSHMercurialServeWorkflow(),
 | |
|     new DiffusionSSHGitUploadPackWorkflow(),
 | |
|     new DiffusionSSHGitReceivePackWorkflow(),
 | |
|   );
 | |
| 
 | |
|   $workflow_names = mpull($workflows, 'getName', 'getName');
 | |
|   if (empty($workflow_names[$command])) {
 | |
|     throw new Exception("Invalid command.");
 | |
|   }
 | |
| 
 | |
|   $workflow = $original_args->parseWorkflows($workflows);
 | |
|   $workflow->setUser($user);
 | |
| 
 | |
|   $sock_stdin = fopen('php://stdin', 'r');
 | |
|   if (!$sock_stdin) {
 | |
|     throw new Exception("Unable to open stdin.");
 | |
|   }
 | |
| 
 | |
|   $sock_stdout = fopen('php://stdout', 'w');
 | |
|   if (!$sock_stdout) {
 | |
|     throw new Exception("Unable to open stdout.");
 | |
|   }
 | |
| 
 | |
|   $sock_stderr = fopen('php://stderr', 'w');
 | |
|   if (!$sock_stderr) {
 | |
|     throw new Exception("Unable to open stderr.");
 | |
|   }
 | |
| 
 | |
|   $socket_channel = new PhutilSocketChannel(
 | |
|     $sock_stdin,
 | |
|     $sock_stdout);
 | |
|   $error_channel = new PhutilSocketChannel(null, $sock_stderr);
 | |
|   $metrics_channel = new PhutilMetricsChannel($socket_channel);
 | |
|   $workflow->setIOChannel($metrics_channel);
 | |
|   $workflow->setErrorChannel($error_channel);
 | |
| 
 | |
|   $err = $workflow->execute($original_args);
 | |
| 
 | |
|   $metrics_channel->flush();
 | |
|   $error_channel->flush();
 | |
| } catch (Exception $ex) {
 | |
|   fwrite(STDERR, "phabricator-ssh-exec: ".$ex->getMessage()."\n");
 | |
|   exit(1);
 | |
| }
 |