PEAR/PHP CVS karma solution
| From: | anatoly techtonik | Date: | Fri, 09 Sep 2005 10:35:01 +0000 |
| Subject: | PEAR/PHP CVS karma solution | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-39764@lists.php.net to get a copy of this message | ||
||*()*|| Greetings, Group.. PHP Group. =)
Abstract
This document contains technical solution for independent PEAR CVS
karma management secure for other parts of PHP CVS repository. This
document does not contain any materials regarding PHP CVS account
creation. The scope of this document is management of access levels
for existing PHP CVS account for pear/ subtree via "cvs_acls" script.
Part one: The Problem
I was investigating bottlenecks in PEAR development recently and
found that the main problem is old developer inactivity and inability
for new developers to get karma for their pear/* packages in time. The
reasons were long timeouts from group@php.net to get the access for
another PEAR package. I believe that group at php.net would like to
pass the control of this process to package maintainers and to some
members of PEAR group, who has more information/time and other details
necessary for crucial decision. But group can't allow just anyone to
mess with CVSROOT/avail file, because it affects other parts of PHP
repository.
Part two: CVSROOT/avail
The solution would be to move all pear/* and peardoc stuff from
CVSROOT/avail into CVSROOT/avail_pear file and add some trustworthy
accounts from PEAR group to avail for this file. There also must be
special account pear_karma created and credited with access to
avail_pear to allow PEAR package maintainers do rights assigment by
special pearweb script after proper validation via package, login
and other management logic as it suitable for PEAR development
process.
att: checkoutlist.patch.txt
att: avail.patch.txt
att: avail_pear.txt
Part three: avail_pear integration and security
To make avail_pear work "cvs_acls" should be adjusted to append
it to avail on processing stage. To make other part of PHP CVS secure
and isolate it from PEAR part some restrictions must be set and
checked on the contents of avail_pear file - in particular it should
contain only empty strings, comments and "^avail\|" strings which end
with "\|pear/" or "\|peardoc" locations only. This check should be
done in "cvs_acls" by regexp /^avail\|[\w\s,]+\|([pear(doc|\/\w+)],?)+$/
att: cvs_acls.patch.txt
I'm not including pearweb here, because of security - if avail_pear
interface will be compromised one day the impact would be on
pear/* and peardoc subtrees only. I suppose repository is backed up
anyway and there are unavoidable PHP-CVS reports to notice the
breach, but before the breach is noticed some time can pass and
during that time pearweb can sync already thus making user data in DB
exposed.
Please review the code as it is my first Perl script ever. =)
And not tested yet, because:
1. Even if I test it - it can contain serious flaws anyway;
2. It should be checked very carefully;
3. It should be checked by people who know perl;
4. And by people who aware of avail and cvs_acls security, can read
this "cvs_acls";
5. Checked also by people who have cvs.php.net/CVSROOT access;
6. I believe in collaboration;
7. I can't get PERL (well, I can, but it costs and I can be left
without i-net for some days).
Well, maybe the list is reversed, but who said life is easy nowadays?
=)
WBR, hope you will not take this too seriously and talk with me about
PHP politics, principles, regulation standards and such. Only
technical feedback, please.
.techtonik
--
--- checkoutlist_old. Sat Dec 15 21:03:02 2001 +++ checkoutlist Fri Sep 9 04:10:56 2005 @@ -22,5 +22,6 @@ loginfo.pl dolog.pl avail +avail_pear cvs_acls readers --- avail_old. Thu Sep 8 11:25:46 2005 +++ avail Fri Sep 9 04:39:48 2005 @@ -14,6 +14,11 @@ avail|sterling,goba,imajes,wez,iliaa,derick|CVSROOT +# And some people have access to the configuration file for +# managing karma to PEAR packages source subtree + +avail|techtonik,cellog,lsmith,arnaud,mj,sean,alexmerz,tony2001,dufuz,pear_karma|CVSROOT/avail_pear + # The PHP Developers have full access to the full source trees for # PHP and PEAR, as well as the documentation. @@ -67,9 +72,7 @@ avail|alan_k,chagenbu,cmv,cox,derick,dickmann,jon,mj,pajoye,richard,tal,antonio,alexmerz,jan,toby,draber,cellog,dufuz,danielc|pearweb avail|arnaud,bjoern,chregu,dams,david,jmcastagnetto,rashid,tuupola,silvano|pearweb/weeklynews -# Some people get access to the peardoc -avail|vincentlascaux,damian,techtonik,sroebke,thierry_bo,schst,mcgyver5,sousk,gurugeek,norbert_m,didou,poz,romain,haruki,jurbo,kusor,cipri,yannick,radzaw,adamg,justinpatrin,peterhuewe,ssttoo,jausions,mfonda,shimooka|peardoc -avail|elf|peardoc/ja +# For specific PEAR package karma see avail_pear # Some people get only access to specific languages for phpdoc avail|elf,shimooka,takagi|phpdoc-ja @@ -183,13 +186,7 @@ avail|steinm,uw|php-src/ext/pdf avail|jdonagher,david|php-src/ext/pfpro,pecl/pfpro avail|jah,chriskl|php-src/ext/pgsql,phpdoc/en/reference/pgsql,php-src/NEWS,php-src/ext/pdo_pgsql -avail|ostborn|php-src/ext/phpdoc,pecl/phpdoc,pecl/soap,pear/Image_GIS -avail|delatbabel,justinpatrin|pear/Text_Wiki -avail|clay|pear/VersionControl -avail|mfonda|pear/Crypt_HMAC -avail|mfonda|pear/Crypt_Blowfish -avail|firman|pear/Math,pear/Math_Numerical_RootFinding,pear/Contact_AddressBook -avail|herrwitten|pear/PEAR_Delegator +avail|ostborn|php-src/ext/phpdoc,pecl/phpdoc,pecl/soap avail|kk|php-src/ext/posix avail|amos|php-src/ext/qtdom avail|kk|php-src/ext/recode @@ -223,41 +220,25 @@ avail|areaz2|pecl/dazuko avail|nicos|php-src/ext/readline avail|mabouzou|php-src/ext/sqlanywhere -avail|cortesi,webdi,colder|peardoc avail|aditus|jpgraph avail|phallstrom|php-gtk-web/apps,php-gtk-web/include/apps.inc -avail|mohrt|pear/Date avail|tal,momo|php-src/ext/calendar avail|momo|php-src/ext/standard avail|mbretter,philippe|pecl/radius,pecl/mqseries avail|mcmontero,blade106|pecl/imagick -avail|schst,lucamariano|pear/Net_Server -avail|bjori|pear/Net_FTP -avail|cyberscribe|pear/Net_Monitor -avail|mroch|pear/XML_RPC -avail|olivierg|pear/XML_Indexing -avail|djg|pear/File_Ogg -avail|vincentlascaux|pear/File_Archive avail|mg|pecl/lzf avail|mg|pecl/tcpwrap avail|mg|pecl/xdiff avail|mg|pecl/xattr avail|xnoguer|pecl/valkyrie -avail|hfuecks|pear/XML_HTMLSax,pear/XML_SaxFilters,pear/Calendar -avail|hj|pear/Locale_Maketext -avail|ths|pear/HTML_QuickForm avail|ecolinet|pecl/win32std avail|aleigh|php-src/sapi/continuity avail|jwk|php-src/sapi/opengroupware -avail|makler|pear/Validate,pear/Numbers_Words,pecl/esmtp +avail|makler|pecl/esmtp avail|wenlong,shenkong|pecl/freeimage avail|marcot|pecl/pop3 -avail|jstump,cyberscribe|pear/Payment_Process avail|johannes|pecl/idn avail|jimi|smbc -avail|justinpatrin|pear/DB_DataObject_FormBuilder -avail|wiesemann|pear/DB_Table -avail|jausions|pear/Template avail|schst,luckec|pecl/id3 avail|gabe,jlesueur|pecl/zeroconf avail|curt|pecl/postparser @@ -266,27 +247,15 @@ avail|mksheoran|pecl/daffodildb avail|val|pecl/bcompiler,phpdoc avail|simenec,ttk|pecl/maxdb,phpdoc/en/reference -avail|ryansking|pear/Config avail|ksadlocha|pecl/simplesql -avail|cipri|pear/Mail_Mime,pear/File_DNS -avail|luckec|pear/HTTP_SessionServer,pear/Services_Ebay,pear/Date_Holidays -avail|jystewart|pear/Services_Technorati -avail|msmarcal|pear/Image_Barcode avail|uw|pecl/maxdb avail|magnus,michael|Zend/tests,ZendEngine2/tests avail|michael|php-src/tests avail|blindman|pecl/colorer avail|mike|pecl/http avail|gabe|pecl/intercept -avail|techtonik|pear/File_SearchReplace -avail|jausions|pear/Image_Transform,pear/Validate -avail|finex|pear/Image_Isometric avail|jon|phpweb/extra -avail|damian|pear/Auth_SASL,pear/Net_Cyrus,pear/Net_IMAP,pear/Net_LMTP,pear/Net_POP3,pear/Net_Sieve avail|scottmattocks|php-gtk/test -avail|pookey|pear/Validate -avail|jausions,mfonda|pear/Services_Webservice -avail|jstump|pear/Net_Curl avail|mboeren|pecl/dbx # Curl modules # Some people get access to the peardoc avail|vincentlascaux,damian,techtonik,sroebke,thierry_bo,schst,mcgyver5,sousk,gurugeek,norbert_m,didou,poz,romain,haruki,jurbo,kusor,cipri,yannick,radzaw,adamg,justinpatrin,peterhuewe,ssttoo,jausions,mfonda,shimooka|peardoc avail|elf|peardoc/ja avail|delatbabel,justinpatrin|pear/Text_Wiki avail|clay|pear/VersionControl avail|mfonda|pear/Crypt_HMAC avail|mfonda|pear/Crypt_Blowfish avail|firman|pear/Math,pear/Math_Numerical_RootFinding,pear/Contact_AddressBook avail|herrwitten|pear/PEAR_Delegator avail|cortesi,webdi,colder|peardoc avail|mohrt|pear/Date avail|schst,lucamariano|pear/Net_Server avail|bjori|pear/Net_FTP avail|cyberscribe|pear/Net_Monitor avail|mroch|pear/XML_RPC avail|olivierg|pear/XML_Indexing avail|djg|pear/File_Ogg avail|vincentlascaux|pear/File_Archive avail|hfuecks|pear/XML_HTMLSax,pear/XML_SaxFilters,pear/Calendar avail|hj|pear/Locale_Maketext avail|ths|pear/HTML_QuickForm avail|makler|pear/Validate,pear/Numbers_Words avail|jstump,cyberscribe|pear/Payment_Process avail|justinpatrin|pear/DB_DataObject_FormBuilder avail|wiesemann|pear/DB_Table avail|jausions|pear/Template avail|ryansking|pear/Config avail|cipri|pear/Mail_Mime,pear/File_DNS avail|luckec|pear/HTTP_SessionServer,pear/Services_Ebay,pear/Date_Holidays avail|jystewart|pear/Services_Technorati avail|msmarcal|pear/Image_Barcode avail|techtonik|pear/File_SearchReplace avail|jausions|pear/Image_Transform,pear/Validate avail|finex|pear/Image_Isometric avail|damian|pear/Auth_SASL,pear/Net_Cyrus,pear/Net_IMAP,pear/Net_LMTP,pear/Net_POP3,pear/Net_Sieve avail|pookey|pear/Validate avail|jausions,mfonda|pear/Services_Webservice avail|jstump|pear/Net_Curl --- cvs_acls_old. Fri Aug 5 21:39:20 2005 +++ cvs_acls Fri Sep 9 12:07:00 2005 @@ -77,6 +77,7 @@ $debug = 0; $cvsroot = $ENV{'CVSROOT'}; $availfile = $cvsroot . "/CVSROOT/avail"; +$availpear = $cvsroot . "/CVSROOT/avail_pear"; $myname = shift @ARGV; # Pass user id as first arg -RL #$myname = $ENV{"USER"} if !($myname = $ENV{"LOGNAME"}); @@ -93,8 +94,34 @@ $exit_val = 0; # Good Exit value $universal_off = 0; + open (AVAIL, $availfile) || exit(0); # It is ok for avail file not to exist -while (<AVAIL>) { +@avail_data = <AVAIL>; +close(AVAIL); + +if (open (AVAILPEAR, $availpear)) { # Syntax check of PEAR part of access rules + @availpear_data = <AVAILPEAR>; + close(AVAILPEAR); + chop(@availpear_data); + $pointer = 0; + while ($pointer <= $#availpear_data) { + $availstring = $availpear_data[$pointer]; + $pointer++; + next if ($availstring =~ /^\s*\#/); + next if ($availstring =~ /^\s*$/); + + # avail_pear strings can allow access to pear/* and peardoc parts only + next if ($availstring =~ /^avail\|[\w\s,]+\|([pear(doc|\/\w+)],?)+$/); + + # Complain about bad avail_pear syntax and exlude string from array + print "Bad avail_pear line: $availstring\n"; + splice(@availpear_data, $pointer - 1, 1); + } + # Append filtered avail_pear to avail for further processing + push(@avail_data, @availpear_data); +} + +foreach (@avail_data) { chop; next if /^\s*\#/; next if /^\s*$/; @@ -134,7 +161,6 @@ $exit_val = $flag if ($in_user && $in_repo); print "$$ ==== \$exit_val = $exit_val\n$$ ==== \$flag = $flag\n" if $debug; } -close(AVAIL); print "$$ ==== \$exit_val = $exit_val\n" if $debug; if ($exit_val) { print "**** Access denied: insufficient karma ($myname|$repos)\n";
--- checkoutlist_old. Sat Dec 15 21:03:02 2001 +++ checkoutlist Fri Sep 9 04:10:56 2005 @@ -22,5 +22,6 @@ loginfo.pl dolog.pl avail +avail_pear cvs_acls readers --- avail_old. Thu Sep 8 11:25:46 2005 +++ avail Fri Sep 9 04:39:48 2005 @@ -14,6 +14,11 @@ avail|sterling,goba,imajes,wez,iliaa,derick|CVSROOT +# And some people have access to the configuration file for +# managing karma to PEAR packages source subtree + +avail|techtonik,cellog,lsmith,arnaud,mj,sean,alexmerz,tony2001,dufuz,pear_karma|CVSROOT/avail_pear + # The PHP Developers have full access to the full source trees for # PHP and PEAR, as well as the documentation. @@ -67,9 +72,7 @@ avail|alan_k,chagenbu,cmv,cox,derick,dickmann,jon,mj,pajoye,richard,tal,antonio,alexmerz,jan,toby,draber,cellog,dufuz,danielc|pearweb avail|arnaud,bjoern,chregu,dams,david,jmcastagnetto,rashid,tuupola,silvano|pearweb/weeklynews -# Some people get access to the peardoc -avail|vincentlascaux,damian,techtonik,sroebke,thierry_bo,schst,mcgyver5,sousk,gurugeek,norbert_m,didou,poz,romain,haruki,jurbo,kusor,cipri,yannick,radzaw,adamg,justinpatrin,peterhuewe,ssttoo,jausions,mfonda,shimooka|peardoc -avail|elf|peardoc/ja +# For specific PEAR package karma see avail_pear # Some people get only access to specific languages for phpdoc avail|elf,shimooka,takagi|phpdoc-ja @@ -183,13 +186,7 @@ avail|steinm,uw|php-src/ext/pdf avail|jdonagher,david|php-src/ext/pfpro,pecl/pfpro avail|jah,chriskl|php-src/ext/pgsql,phpdoc/en/reference/pgsql,php-src/NEWS,php-src/ext/pdo_pgsql -avail|ostborn|php-src/ext/phpdoc,pecl/phpdoc,pecl/soap,pear/Image_GIS -avail|delatbabel,justinpatrin|pear/Text_Wiki -avail|clay|pear/VersionControl -avail|mfonda|pear/Crypt_HMAC -avail|mfonda|pear/Crypt_Blowfish -avail|firman|pear/Math,pear/Math_Numerical_RootFinding,pear/Contact_AddressBook -avail|herrwitten|pear/PEAR_Delegator +avail|ostborn|php-src/ext/phpdoc,pecl/phpdoc,pecl/soap avail|kk|php-src/ext/posix avail|amos|php-src/ext/qtdom avail|kk|php-src/ext/recode @@ -223,41 +220,25 @@ avail|areaz2|pecl/dazuko avail|nicos|php-src/ext/readline avail|mabouzou|php-src/ext/sqlanywhere -avail|cortesi,webdi,colder|peardoc avail|aditus|jpgraph avail|phallstrom|php-gtk-web/apps,php-gtk-web/include/apps.inc -avail|mohrt|pear/Date avail|tal,momo|php-src/ext/calendar avail|momo|php-src/ext/standard avail|mbretter,philippe|pecl/radius,pecl/mqseries avail|mcmontero,blade106|pecl/imagick -avail|schst,lucamariano|pear/Net_Server -avail|bjori|pear/Net_FTP -avail|cyberscribe|pear/Net_Monitor -avail|mroch|pear/XML_RPC -avail|olivierg|pear/XML_Indexing -avail|djg|pear/File_Ogg -avail|vincentlascaux|pear/File_Archive avail|mg|pecl/lzf avail|mg|pecl/tcpwrap avail|mg|pecl/xdiff avail|mg|pecl/xattr avail|xnoguer|pecl/valkyrie -avail|hfuecks|pear/XML_HTMLSax,pear/XML_SaxFilters,pear/Calendar -avail|hj|pear/Locale_Maketext -avail|ths|pear/HTML_QuickForm avail|ecolinet|pecl/win32std avail|aleigh|php-src/sapi/continuity avail|jwk|php-src/sapi/opengroupware -avail|makler|pear/Validate,pear/Numbers_Words,pecl/esmtp +avail|makler|pecl/esmtp avail|wenlong,shenkong|pecl/freeimage avail|marcot|pecl/pop3 -avail|jstump,cyberscribe|pear/Payment_Process avail|johannes|pecl/idn avail|jimi|smbc -avail|justinpatrin|pear/DB_DataObject_FormBuilder -avail|wiesemann|pear/DB_Table -avail|jausions|pear/Template avail|schst,luckec|pecl/id3 avail|gabe,jlesueur|pecl/zeroconf avail|curt|pecl/postparser @@ -266,27 +247,15 @@ avail|mksheoran|pecl/daffodildb avail|val|pecl/bcompiler,phpdoc avail|simenec,ttk|pecl/maxdb,phpdoc/en/reference -avail|ryansking|pear/Config avail|ksadlocha|pecl/simplesql -avail|cipri|pear/Mail_Mime,pear/File_DNS -avail|luckec|pear/HTTP_SessionServer,pear/Services_Ebay,pear/Date_Holidays -avail|jystewart|pear/Services_Technorati -avail|msmarcal|pear/Image_Barcode avail|uw|pecl/maxdb avail|magnus,michael|Zend/tests,ZendEngine2/tests avail|michael|php-src/tests avail|blindman|pecl/colorer avail|mike|pecl/http avail|gabe|pecl/intercept -avail|techtonik|pear/File_SearchReplace -avail|jausions|pear/Image_Transform,pear/Validate -avail|finex|pear/Image_Isometric avail|jon|phpweb/extra -avail|damian|pear/Auth_SASL,pear/Net_Cyrus,pear/Net_IMAP,pear/Net_LMTP,pear/Net_POP3,pear/Net_Sieve avail|scottmattocks|php-gtk/test -avail|pookey|pear/Validate -avail|jausions,mfonda|pear/Services_Webservice -avail|jstump|pear/Net_Curl avail|mboeren|pecl/dbx # Curl modules # Some people get access to the peardoc avail|vincentlascaux,damian,techtonik,sroebke,thierry_bo,schst,mcgyver5,sousk,gurugeek,norbert_m,didou,poz,romain,haruki,jurbo,kusor,cipri,yannick,radzaw,adamg,justinpatrin,peterhuewe,ssttoo,jausions,mfonda,shimooka|peardoc avail|elf|peardoc/ja avail|delatbabel,justinpatrin|pear/Text_Wiki avail|clay|pear/VersionControl avail|mfonda|pear/Crypt_HMAC avail|mfonda|pear/Crypt_Blowfish avail|firman|pear/Math,pear/Math_Numerical_RootFinding,pear/Contact_AddressBook avail|herrwitten|pear/PEAR_Delegator avail|cortesi,webdi,colder|peardoc avail|mohrt|pear/Date avail|schst,lucamariano|pear/Net_Server avail|bjori|pear/Net_FTP avail|cyberscribe|pear/Net_Monitor avail|mroch|pear/XML_RPC avail|olivierg|pear/XML_Indexing avail|djg|pear/File_Ogg avail|vincentlascaux|pear/File_Archive avail|hfuecks|pear/XML_HTMLSax,pear/XML_SaxFilters,pear/Calendar avail|hj|pear/Locale_Maketext avail|ths|pear/HTML_QuickForm avail|makler|pear/Validate,pear/Numbers_Words avail|jstump,cyberscribe|pear/Payment_Process avail|justinpatrin|pear/DB_DataObject_FormBuilder avail|wiesemann|pear/DB_Table avail|jausions|pear/Template avail|ryansking|pear/Config avail|cipri|pear/Mail_Mime,pear/File_DNS avail|luckec|pear/HTTP_SessionServer,pear/Services_Ebay,pear/Date_Holidays avail|jystewart|pear/Services_Technorati avail|msmarcal|pear/Image_Barcode avail|techtonik|pear/File_SearchReplace avail|jausions|pear/Image_Transform,pear/Validate avail|finex|pear/Image_Isometric avail|damian|pear/Auth_SASL,pear/Net_Cyrus,pear/Net_IMAP,pear/Net_LMTP,pear/Net_POP3,pear/Net_Sieve avail|pookey|pear/Validate avail|jausions,mfonda|pear/Services_Webservice avail|jstump|pear/Net_Curl --- cvs_acls_old. Fri Aug 5 21:39:20 2005 +++ cvs_acls Fri Sep 9 12:07:00 2005 @@ -77,6 +77,7 @@ $debug = 0; $cvsroot = $ENV{'CVSROOT'}; $availfile = $cvsroot . "/CVSROOT/avail"; +$availpear = $cvsroot . "/CVSROOT/avail_pear"; $myname = shift @ARGV; # Pass user id as first arg -RL #$myname = $ENV{"USER"} if !($myname = $ENV{"LOGNAME"}); @@ -93,8 +94,34 @@ $exit_val = 0; # Good Exit value $universal_off = 0; + open (AVAIL, $availfile) || exit(0); # It is ok for avail file not to exist -while (<AVAIL>) { +@avail_data = <AVAIL>; +close(AVAIL); + +if (open (AVAILPEAR, $availpear)) { # Syntax check of PEAR part of access rules + @availpear_data = <AVAILPEAR>; + close(AVAILPEAR); + chop(@availpear_data); + $pointer = 0; + while ($pointer <= $#availpear_data) { + $availstring = $availpear_data[$pointer]; + $pointer++; + next if ($availstring =~ /^\s*\#/); + next if ($availstring =~ /^\s*$/); + + # avail_pear strings can allow access to pear/* and peardoc parts only + next if ($availstring =~ /^avail\|[\w\s,]+\|([pear(doc|\/\w+)],?)+$/); + + # Complain about bad avail_pear syntax and exlude string from array + print "Bad avail_pear line: $availstring\n"; + splice(@availpear_data, $pointer - 1, 1); + } + # Append filtered avail_pear to avail for further processing + push(@avail_data, @availpear_data); +} + +foreach (@avail_data) { chop; next if /^\s*\#/; next if /^\s*$/; @@ -134,7 +161,6 @@ $exit_val = $flag if ($in_user && $in_repo); print "$$ ==== \$exit_val = $exit_val\n$$ ==== \$flag = $flag\n" if $debug; } -close(AVAIL); print "$$ ==== \$exit_val = $exit_val\n" if $debug; if ($exit_val) { print "**** Access denied: insufficient karma ($myname|$repos)\n";