Skip to content

Commit ff8b489

Browse files
author
epriestley
committedNov 20, 2013
Simplify Repository remote and local command construction
Summary: This cleans up some garbage: - We were specifying environmental variables with `X=y git ...`, but now have `setEnv()` on both `ExecFuture` and `PhutilExecPassthru`. Use `setEnv()`. - We were specifying the working directory with `(cd %s && git ...)`, but now have `setCWD()` on both `ExecFuture` and `PhutilExecPassthru`. Use `setCWD()`. - We were specifying the Git credentials with `ssh-agent -c (ssh-add ... && git ...)`. We can do this more cleanly with `GIT_SSH`. Use `GIT_SSH`. - Since we have to write a script for `GIT_SSH` anyway, use the same script for Subversion and Mercurial. This fixes two specific issues: - Previously, we were not able to set `-o StrictHostKeyChecking=no` on Git commands, so the first time you cloned a git repo the daemons would generally prompt you to add `github.com` or whatever to `known_hosts`. Since this was non-interactive, things would mysteriously hang, in effect. With `GIT_SSH`, we can specify the flag, reducing the number of ways things can go wrong. - This adds `LANG=C`, which probably (?) forces the language to English for all commands. Apparently you need to install special language packs or something, so I don't know that this actually works, but at least two users with non-English languages have claimed it does (see <phacility/arcanist#114> for a similar issue in Arcanist). At some point in the future I might want to combine the Arcanist code for command execution with the Phabricator code for command execution (they share some stuff like LANG and HGPLAIN). However, credential management is kind of messy, so I'm adopting a "wait and see" approach for now. I expect to split this at least somewhat in the future, for Drydock/Automerge if nothing else. Also I'm not sure if we use the passthru stuff at all anymore, I may just be able to delete that. I'll check in a future diff. Test Plan: Browsed and pulled Git, Subversion and Mercurial repositories. Reviewers: btrahan Reviewed By: btrahan CC: aran Maniphest Tasks: T2230 Differential Revision: https://secure.phabricator.com/D7600
1 parent 08bdfac commit ff8b489

File tree

3 files changed

+238
-137
lines changed

3 files changed

+238
-137
lines changed
 

‎bin/ssh-connect

+1
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
../scripts/ssh/ssh-connect.php

‎scripts/ssh/ssh-connect.php

+71
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,71 @@
1+
#!/usr/bin/env php
2+
<?php
3+
4+
// This is a wrapper script for Git, Mercurial, and Subversion. It primarily
5+
// serves to inject "-o StrictHostKeyChecking=no" into the SSH arguments.
6+
7+
$root = dirname(dirname(dirname(__FILE__)));
8+
require_once $root.'/scripts/__init_script__.php';
9+
10+
$target_name = getenv('PHABRICATOR_SSH_TARGET');
11+
if (!$target_name) {
12+
throw new Exception(pht("No 'PHABRICATOR_SSH_TARGET' in environment!"));
13+
}
14+
15+
$repository = id(new PhabricatorRepositoryQuery())
16+
->setViewer(PhabricatorUser::getOmnipotentUser())
17+
->withCallsigns(array($target_name))
18+
->executeOne();
19+
if (!$repository) {
20+
throw new Exception(pht('No repository with callsign "%s"!', $target_name));
21+
}
22+
23+
$pattern = array();
24+
$arguments = array();
25+
26+
$pattern[] = 'ssh';
27+
28+
$pattern[] = '-o';
29+
$pattern[] = 'StrictHostKeyChecking=no';
30+
31+
$login = $repository->getSSHLogin();
32+
if (strlen($login)) {
33+
$pattern[] = '-l';
34+
$pattern[] = '%P';
35+
$arguments[] = new PhutilOpaqueEnvelope($login);
36+
}
37+
38+
$ssh_identity = null;
39+
40+
$key = $repository->getDetail('ssh-key');
41+
$keyfile = $repository->getDetail('ssh-keyfile');
42+
if ($keyfile) {
43+
$ssh_identity = $keyfile;
44+
} else if ($key) {
45+
$tmpfile = new TempFile('phabricator-repository-ssh-key');
46+
chmod($tmpfile, 0600);
47+
Filesystem::writeFile($tmpfile, $key);
48+
$ssh_identity = (string)$tmpfile;
49+
}
50+
51+
if ($ssh_identity) {
52+
$pattern[] = '-i';
53+
$pattern[] = '%P';
54+
$arguments[] = new PhutilOpaqueEnvelope($keyfile);
55+
}
56+
57+
$pattern[] = '--';
58+
59+
$passthru_args = array_slice($argv, 1);
60+
foreach ($passthru_args as $passthru_arg) {
61+
$pattern[] = '%s';
62+
$arguments[] = $passthru_arg;
63+
}
64+
65+
$pattern = implode(' ', $pattern);
66+
array_unshift($arguments, $pattern);
67+
68+
$err = newv('PhutilExecPassthru', $arguments)
69+
->execute();
70+
71+
exit($err);

0 commit comments

Comments
 (0)
Failed to load comments.