.TH git-annex-shell 1 .SH NAME git-annex\-shell \- Restricted login shell for git-annex only SSH access .PP .SH SYNOPSIS git-annex\-shell [\-c] command [params ...] .PP .SH DESCRIPTION git-annex\-shell is a restricted shell, similar to git\-shell, which can be used as a login shell for SSH accounts. .PP Since its syntax is identical to git\-shell's, it can be used as a drop\-in replacement anywhere git\-shell is used. For example it can be used as a user's restricted login shell. .PP .SH COMMANDS Any command not listed below is passed through to git\-shell. .PP Note that the directory parameter should be an absolute path, otherwise it is assumed to be relative to the user's home directory. Also the first "/~/" or "/~user/" is expanded to the specified home directory. .PP .IP "configlist directory" This outputs a subset of the git configuration, in the same form as \fBgit config \-\-list\fP. This is used to get the annex.uuid of the remote repository. .IP When run in a repository that does not yet have an annex.uuid, one will be created, as long as a git-annex branch has already been pushed to the repository, or if the autoinit=1 flag is used to indicate initialization is desired. .IP .IP "p2pstdio directory uuid" This causes git-annex\-shell to communicate using the git-annex p2p protocol over stdio. .IP The uuid is the one belonging to the repository that will be communicating with git-annex\-shell. .IP .IP "notifychanges directory" This is used by \fBgit-annex remotedaemon\fP to be notified when refs in the remote repository are changed. .IP .IP "gcryptsetup directory gcryptid" Sets up a repository as a gcrypt repository. .IP .IP "inannex directory [key ...]" This checks if all specified keys are present in the annex, and exits zero if so. .IP Exits 1 if the key is certainly not present in the annex. Exits 100 if it's unable to tell (perhaps the key is in the process of being removed from the annex). .IP Used only by the gcrypt special remote. .IP .IP "recvkey directory key" This runs rsync in server mode to receive the content of a key, and stores the content in the annex. .IP Used only by the gcrypt special remote. .IP .IP "sendkey directory key" This runs rsync in server mode to transfer out the content of a key. .IP Used only by the gcrypt special remote. .IP .IP "dropkey directory [key ...]" This drops the annexed data for the specified keys. .IP Used only by the gcrypt special remote. .IP .SH OPTIONS .IP "\-\-uuid=UUID" .IP git-annex uses this to specify the UUID of the repository it was expecting git-annex\-shell to access. This is both a sanity check, and allows git-annex shell to proxy access to remotes, when configured by git-annex\-update\-proxy. .IP .IP "Also the git-annex\-common\-options(1) can be used." .IP "\-\- fields=val fields=val.. \-\-" Additional fields may be specified this way, to retain compatibility with past versions of git-annex\-shell (that ignore these, but would choke on new dashed options). .IP Currently used fields are autoinit= and remoteuuid= .IP .SH HOOK After content is received or dropped from the repository by git-annex\-shell, it runs a hook, \fB.git/hooks/annex\-content\fP (or \fBhooks/annex\-content\fP on a bare repository). The hook is not currently passed any information about what changed. .PP .SH ENVIRONMENT .IP "GIT_ANNEX_SHELL_READONLY" .IP If set, disallows any action that could modify the git-annex repository. .IP Note that this does not prevent passing commands on to git\-shell. For that, you also need ... .IP .IP "GIT_ANNEX_SHELL_LIMITED" If set, disallows running git\-shell to handle unknown commands. .IP .IP "GIT_ANNEX_SHELL_APPENDONLY" If set, allows data to be written to the git-annex repository, but does not allow data to be removed from it. .IP Note that this does not prevent passing commands on to git\-shell, so you will have to separately configure git to reject pushes that overwrite branches or are otherwise not appends. The git pre\-receive hook may be useful for accomplishing this. .IP It's a good idea to enable annex.securehashesonly in a repository that's set up this way. .IP .IP "GIT_ANNEX_SHELL_DIRECTORY" If set, git-annex\-shell will refuse to run commands that do not operate on the specified directory. .IP .SH EXAMPLES To make a \fB~/.ssh/authorized_keys\fP file that only allows git-annex\-shell to be run, and not other commands, pass the original command to the \-c option: .PP command="git-annex\-shell \-c \\"$SSH_ORIGINAL_COMMAND\\"",no\-agent\-forwarding,no\-port\-forwarding,no\-X11\-forwarding ssh\-rsa AAAAB3NzaC1y[...] user@example.com .PP To further restrict git-annex\-shell to a particular repository, and fully lock it down to read\-only mode: .PP command="GIT_ANNEX_SHELL_DIRECTORY=/srv/annex GIT_ANNEX_SHELL_LIMITED=true GIT_ANNEX_SHELL_READONLY=true git-annex\-shell \-c \\"$SSH_ORIGINAL_COMMAND\\"",restrict ssh\-rsa AAAAB3NzaC1y[...] user@example.com .PP Obviously, \fBssh\-rsa AAAAB3NzaC1y[...] user@example.com\fP needs to replaced with your SSH key. The above also assumes \fBgit-annex\-shell\fP is available in your \fB$PATH\fP, use an absolute path if it is not the case. Also note how the above uses the \fBrestrict\fP option instead of an explicit list of functionality to disallow. This only works in certain OpenSSH releases, starting from 7.1p2. .PP To only allow adding new objects to the repository, the \fBGIT_ANNEX_SHELL_APPENDONLY\fP variable can be used as well: .PP command="GIT_ANNEX_SHELL_DIRECTORY=/srv/annex GIT_ANNEX_SHELL_APPENDONLY=true git-annex\-shell \-c \\"$SSH_ORIGINAL_COMMAND\\"",restrict ssh\-rsa AAAAB3NzaC1y[...] user@example.com .PP This will not keep an attacker from destroying the git history, as explained above. For this you might want to disallow certain operations, like branch deletion and force\-push, with options from git\-config(1). For example: .PP git config receive.denyDeletes true git config receive.denyNonFastForwards true .PP With this configuration, git commits can still remove files, but they will still be available in the git history and git-annex will retain their contents. Changes to \fBgit-annex\fP branch, however, can negatively impact git-annex's location tracking information and might cause data loss. To work around this problem, more complex hooks are required, see for example the \fBupdate\-paranoid\fP hook in the git source distribution. .PP .SH SEE ALSO git-annex(1) .PP git\-shell(1) .PP .SH AUTHOR Joey Hess .PP .PP .PP