PEAR/PHP CVS karma solution

From: Date: Fri, 09 Sep 2005 10:35:01 +0000
Subject: PEAR/PHP CVS karma solution
Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-39764@lists.php.net to get a copy of this message
||*()*|| Greetings, Group.. PHP Group. =) Abstract This document contains technical solution for independent PEAR CVS karma management secure for other parts of PHP CVS repository. This document does not contain any materials regarding PHP CVS account creation. The scope of this document is management of access levels for existing PHP CVS account for pear/ subtree via "cvs_acls" script. Part one: The Problem I was investigating bottlenecks in PEAR development recently and found that the main problem is old developer inactivity and inability for new developers to get karma for their pear/* packages in time. The reasons were long timeouts from group@php.net to get the access for another PEAR package. I believe that group at php.net would like to pass the control of this process to package maintainers and to some members of PEAR group, who has more information/time and other details necessary for crucial decision. But group can't allow just anyone to mess with CVSROOT/avail file, because it affects other parts of PHP repository. Part two: CVSROOT/avail The solution would be to move all pear/* and peardoc stuff from CVSROOT/avail into CVSROOT/avail_pear file and add some trustworthy accounts from PEAR group to avail for this file. There also must be special account pear_karma created and credited with access to avail_pear to allow PEAR package maintainers do rights assigment by special pearweb script after proper validation via package, login and other management logic as it suitable for PEAR development process. att: checkoutlist.patch.txt att: avail.patch.txt att: avail_pear.txt Part three: avail_pear integration and security To make avail_pear work "cvs_acls" should be adjusted to append it to avail on processing stage. To make other part of PHP CVS secure and isolate it from PEAR part some restrictions must be set and checked on the contents of avail_pear file - in particular it should contain only empty strings, comments and "^avail\|" strings which end with "\|pear/" or "\|peardoc" locations only. This check should be done in "cvs_acls" by regexp /^avail\|[\w\s,]+\|([pear(doc|\/\w+)],?)+$/ att: cvs_acls.patch.txt I'm not including pearweb here, because of security - if avail_pear interface will be compromised one day the impact would be on pear/* and peardoc subtrees only. I suppose repository is backed up anyway and there are unavoidable PHP-CVS reports to notice the breach, but before the breach is noticed some time can pass and during that time pearweb can sync already thus making user data in DB exposed. Please review the code as it is my first Perl script ever. =) And not tested yet, because: 1. Even if I test it - it can contain serious flaws anyway; 2. It should be checked very carefully; 3. It should be checked by people who know perl; 4. And by people who aware of avail and cvs_acls security, can read this "cvs_acls"; 5. Checked also by people who have cvs.php.net/CVSROOT access; 6. I believe in collaboration; 7. I can't get PERL (well, I can, but it costs and I can be left without i-net for some days). Well, maybe the list is reversed, but who said life is easy nowadays? =) WBR, hope you will not take this too seriously and talk with me about PHP politics, principles, regulation standards and such. Only technical feedback, please. .techtonik --

--- checkoutlist_old. Sat Dec 15 21:03:02 2001 +++ checkoutlist Fri Sep 9 04:10:56 2005 @@ -22,5 +22,6 @@ loginfo.pl dolog.pl avail +avail_pear cvs_acls readers --- avail_old. Thu Sep 8 11:25:46 2005 +++ avail Fri Sep 9 04:39:48 2005 @@ -14,6 +14,11 @@ avail|sterling,goba,imajes,wez,iliaa,derick|CVSROOT +# And some people have access to the configuration file for +# managing karma to PEAR packages source subtree + +avail|techtonik,cellog,lsmith,arnaud,mj,sean,alexmerz,tony2001,dufuz,pear_karma|CVSROOT/avail_pear + # The PHP Developers have full access to the full source trees for # PHP and PEAR, as well as the documentation. @@ -67,9 +72,7 @@ avail|alan_k,chagenbu,cmv,cox,derick,dickmann,jon,mj,pajoye,richard,tal,antonio,alexmerz,jan,toby,draber,cellog,dufuz,danielc|pearweb avail|arnaud,bjoern,chregu,dams,david,jmcastagnetto,rashid,tuupola,silvano|pearweb/weeklynews -# Some people get access to the peardoc -avail|vincentlascaux,damian,techtonik,sroebke,thierry_bo,schst,mcgyver5,sousk,gurugeek,norbert_m,didou,poz,romain,haruki,jurbo,kusor,cipri,yannick,radzaw,adamg,justinpatrin,peterhuewe,ssttoo,jausions,mfonda,shimooka|peardoc -avail|elf|peardoc/ja +# For specific PEAR package karma see avail_pear # Some people get only access to specific languages for phpdoc avail|elf,shimooka,takagi|phpdoc-ja @@ -183,13 +186,7 @@ avail|steinm,uw|php-src/ext/pdf avail|jdonagher,david|php-src/ext/pfpro,pecl/pfpro avail|jah,chriskl|php-src/ext/pgsql,phpdoc/en/reference/pgsql,php-src/NEWS,php-src/ext/pdo_pgsql -avail|ostborn|php-src/ext/phpdoc,pecl/phpdoc,pecl/soap,pear/Image_GIS -avail|delatbabel,justinpatrin|pear/Text_Wiki -avail|clay|pear/VersionControl -avail|mfonda|pear/Crypt_HMAC -avail|mfonda|pear/Crypt_Blowfish -avail|firman|pear/Math,pear/Math_Numerical_RootFinding,pear/Contact_AddressBook -avail|herrwitten|pear/PEAR_Delegator +avail|ostborn|php-src/ext/phpdoc,pecl/phpdoc,pecl/soap avail|kk|php-src/ext/posix avail|amos|php-src/ext/qtdom avail|kk|php-src/ext/recode @@ -223,41 +220,25 @@ avail|areaz2|pecl/dazuko avail|nicos|php-src/ext/readline avail|mabouzou|php-src/ext/sqlanywhere -avail|cortesi,webdi,colder|peardoc avail|aditus|jpgraph avail|phallstrom|php-gtk-web/apps,php-gtk-web/include/apps.inc -avail|mohrt|pear/Date avail|tal,momo|php-src/ext/calendar avail|momo|php-src/ext/standard avail|mbretter,philippe|pecl/radius,pecl/mqseries avail|mcmontero,blade106|pecl/imagick -avail|schst,lucamariano|pear/Net_Server -avail|bjori|pear/Net_FTP -avail|cyberscribe|pear/Net_Monitor -avail|mroch|pear/XML_RPC -avail|olivierg|pear/XML_Indexing -avail|djg|pear/File_Ogg -avail|vincentlascaux|pear/File_Archive avail|mg|pecl/lzf avail|mg|pecl/tcpwrap avail|mg|pecl/xdiff avail|mg|pecl/xattr avail|xnoguer|pecl/valkyrie -avail|hfuecks|pear/XML_HTMLSax,pear/XML_SaxFilters,pear/Calendar -avail|hj|pear/Locale_Maketext -avail|ths|pear/HTML_QuickForm avail|ecolinet|pecl/win32std avail|aleigh|php-src/sapi/continuity avail|jwk|php-src/sapi/opengroupware -avail|makler|pear/Validate,pear/Numbers_Words,pecl/esmtp +avail|makler|pecl/esmtp avail|wenlong,shenkong|pecl/freeimage avail|marcot|pecl/pop3 -avail|jstump,cyberscribe|pear/Payment_Process avail|johannes|pecl/idn avail|jimi|smbc -avail|justinpatrin|pear/DB_DataObject_FormBuilder -avail|wiesemann|pear/DB_Table -avail|jausions|pear/Template avail|schst,luckec|pecl/id3 avail|gabe,jlesueur|pecl/zeroconf avail|curt|pecl/postparser @@ -266,27 +247,15 @@ avail|mksheoran|pecl/daffodildb avail|val|pecl/bcompiler,phpdoc avail|simenec,ttk|pecl/maxdb,phpdoc/en/reference -avail|ryansking|pear/Config avail|ksadlocha|pecl/simplesql -avail|cipri|pear/Mail_Mime,pear/File_DNS -avail|luckec|pear/HTTP_SessionServer,pear/Services_Ebay,pear/Date_Holidays -avail|jystewart|pear/Services_Technorati -avail|msmarcal|pear/Image_Barcode avail|uw|pecl/maxdb avail|magnus,michael|Zend/tests,ZendEngine2/tests avail|michael|php-src/tests avail|blindman|pecl/colorer avail|mike|pecl/http avail|gabe|pecl/intercept -avail|techtonik|pear/File_SearchReplace -avail|jausions|pear/Image_Transform,pear/Validate -avail|finex|pear/Image_Isometric avail|jon|phpweb/extra -avail|damian|pear/Auth_SASL,pear/Net_Cyrus,pear/Net_IMAP,pear/Net_LMTP,pear/Net_POP3,pear/Net_Sieve avail|scottmattocks|php-gtk/test -avail|pookey|pear/Validate -avail|jausions,mfonda|pear/Services_Webservice -avail|jstump|pear/Net_Curl avail|mboeren|pecl/dbx # Curl modules # Some people get access to the peardoc avail|vincentlascaux,damian,techtonik,sroebke,thierry_bo,schst,mcgyver5,sousk,gurugeek,norbert_m,didou,poz,romain,haruki,jurbo,kusor,cipri,yannick,radzaw,adamg,justinpatrin,peterhuewe,ssttoo,jausions,mfonda,shimooka|peardoc avail|elf|peardoc/ja avail|delatbabel,justinpatrin|pear/Text_Wiki avail|clay|pear/VersionControl avail|mfonda|pear/Crypt_HMAC avail|mfonda|pear/Crypt_Blowfish avail|firman|pear/Math,pear/Math_Numerical_RootFinding,pear/Contact_AddressBook avail|herrwitten|pear/PEAR_Delegator avail|cortesi,webdi,colder|peardoc avail|mohrt|pear/Date avail|schst,lucamariano|pear/Net_Server avail|bjori|pear/Net_FTP avail|cyberscribe|pear/Net_Monitor avail|mroch|pear/XML_RPC avail|olivierg|pear/XML_Indexing avail|djg|pear/File_Ogg avail|vincentlascaux|pear/File_Archive avail|hfuecks|pear/XML_HTMLSax,pear/XML_SaxFilters,pear/Calendar avail|hj|pear/Locale_Maketext avail|ths|pear/HTML_QuickForm avail|makler|pear/Validate,pear/Numbers_Words avail|jstump,cyberscribe|pear/Payment_Process avail|justinpatrin|pear/DB_DataObject_FormBuilder avail|wiesemann|pear/DB_Table avail|jausions|pear/Template avail|ryansking|pear/Config avail|cipri|pear/Mail_Mime,pear/File_DNS avail|luckec|pear/HTTP_SessionServer,pear/Services_Ebay,pear/Date_Holidays avail|jystewart|pear/Services_Technorati avail|msmarcal|pear/Image_Barcode avail|techtonik|pear/File_SearchReplace avail|jausions|pear/Image_Transform,pear/Validate avail|finex|pear/Image_Isometric avail|damian|pear/Auth_SASL,pear/Net_Cyrus,pear/Net_IMAP,pear/Net_LMTP,pear/Net_POP3,pear/Net_Sieve avail|pookey|pear/Validate avail|jausions,mfonda|pear/Services_Webservice avail|jstump|pear/Net_Curl --- cvs_acls_old. Fri Aug 5 21:39:20 2005 +++ cvs_acls Fri Sep 9 12:07:00 2005 @@ -77,6 +77,7 @@ $debug = 0; $cvsroot = $ENV{'CVSROOT'}; $availfile = $cvsroot . "/CVSROOT/avail"; +$availpear = $cvsroot . "/CVSROOT/avail_pear"; $myname = shift @ARGV; # Pass user id as first arg -RL #$myname = $ENV{"USER"} if !($myname = $ENV{"LOGNAME"}); @@ -93,8 +94,34 @@ $exit_val = 0; # Good Exit value $universal_off = 0; + open (AVAIL, $availfile) || exit(0); # It is ok for avail file not to exist -while (<AVAIL>) { +@avail_data = <AVAIL>; +close(AVAIL); + +if (open (AVAILPEAR, $availpear)) { # Syntax check of PEAR part of access rules + @availpear_data = <AVAILPEAR>; + close(AVAILPEAR); + chop(@availpear_data); + $pointer = 0; + while ($pointer <= $#availpear_data) { + $availstring = $availpear_data[$pointer]; + $pointer++; + next if ($availstring =~ /^\s*\#/); + next if ($availstring =~ /^\s*$/); + + # avail_pear strings can allow access to pear/* and peardoc parts only + next if ($availstring =~ /^avail\|[\w\s,]+\|([pear(doc|\/\w+)],?)+$/); + + # Complain about bad avail_pear syntax and exlude string from array + print "Bad avail_pear line: $availstring\n"; + splice(@availpear_data, $pointer - 1, 1); + } + # Append filtered avail_pear to avail for further processing + push(@avail_data, @availpear_data); +} + +foreach (@avail_data) { chop; next if /^\s*\#/; next if /^\s*$/; @@ -134,7 +161,6 @@ $exit_val = $flag if ($in_user && $in_repo); print "$$ ==== \$exit_val = $exit_val\n$$ ==== \$flag = $flag\n" if $debug; } -close(AVAIL); print "$$ ==== \$exit_val = $exit_val\n" if $debug; if ($exit_val) { print "**** Access denied: insufficient karma ($myname|$repos)\n";
« previous php.pear.dev (#39764) next »