{"thread":{"id":"10949","subject":"[PATCH] When re-initializing, set shared permissions on all directories.","startedAt":"2007-11-21T03:48:58Z","lastAt":"2007-11-21T06:45:17Z","messageCount":2,"participants":["Jon Jensen","Junio C Hamano"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"60454","messageId":"Pine.LNX.4.64.0711202045140.4046@ybpnyubfg.ybpnyqbznva","threadId":"10949","inReplyTo":null,"subject":"[PATCH] When re-initializing, set shared permissions on all directories.","fromName":"Jon Jensen","fromEmail":"jon@endpoint.com","sentAt":"2007-11-21T03:48:58Z","receivedAt":"2007-11-21T03:48:58Z","isPatch":true,"sender":{"key":"jon@endpoint.com","avatar":"https://avatars.githubusercontent.com/u/3811?v=4"},"body":"Hi.\n\nBelow is a small patch to make git-init --shared change permissions not \njust of .git/refs/ but of the other directories too.\n\nAlso a documentation patch for git-init, though after reading discussion \nin the list archives from a few weeks ago, I realize people may not be \ninterested in documentation that shows explicit UNIX commands that may not \napply or could be considered pedantic. Let me know if there's a better way \nI can approach this.\n\nThanks,\nJon\n\n\n--\nFrom b2895649165d7e6c4bcbe6484d66c84ea7124bd9 Mon Sep 17 00:00:00 2001\nFrom: Jon Jensen <jon@endpoint.com>\nDate: Tue, 20 Nov 2007 20:01:14 -0700\nSubject: [PATCH] When re-initializing, set shared permissions on all directories.\n\nBefore this patch, when re-initializing an existing repository e.g.\nas --shared=group, only .git/refs/ was set chmod g+ws. Now the\nother directories get that too.\n\nThis is probably only helpful when not much has been done with the\nrepository yet, since it doesn't include subdirectories and files,\nso add an example to the documentation to point the way for people\nto finish the job.\n---\n  Documentation/git-init.txt |   13 +++++++++++++\n  builtin-init-db.c          |    8 +++++++-\n  2 files changed, 20 insertions(+), 1 deletions(-)\n\ndiff --git a/Documentation/git-init.txt b/Documentation/git-init.txt\nindex 07484a4..c4a4757 100644\n--- a/Documentation/git-init.txt\n+++ b/Documentation/git-init.txt\n@@ -101,6 +101,19 @@ $ git-add .     <2>\n  <2> add all existing file to the index\n\n\n+Adjust an existing git repository to work as if it had been created with git init --shared::\n++\n+----------------\n+$ GIT_DIR=/path/to/my/.git git-init --shared  <1>\n+$ chgrp -R mygroup /path/to/my/.git  <2>\n+$ find /path/to/my/.git -type d -exec chmod g+ws {} \\;  <3>\n+----------------\n++\n+<1> adjust configuration for shared repository\n+<2> correct group ownership of any existing directories and files; needed if group shared by users is different than the group ownership of repository files\n+<3> make all directories set group ownership of newly created files correctly in the future\n+\n+\n  Author\n  ------\n  Written by Linus Torvalds <torvalds@osdl.org>\ndiff --git a/builtin-init-db.c b/builtin-init-db.c\nindex 763fa55..d16efa5 100644\n--- a/builtin-init-db.c\n+++ b/builtin-init-db.c\n@@ -24,7 +24,13 @@ static void safe_create_dir(const char *dir, int share)\n  \t\t\texit(1);\n  \t\t}\n  \t}\n-\telse if (share && adjust_shared_perm(dir))\n+\n+    /*\n+     * If the directory already existed, we may still need\n+     * to adjust permissions if this is a reinitialization\n+     * for a shared repository.\n+     */\n+\tif (share && adjust_shared_perm(dir))\n  \t\tdie(\"Could not make %s writable by group\\n\", dir);\n  }\n\n-- \n1.5.3.6.737.gb2895\n"},{"id":"60462","messageId":"7vk5ochzb6.fsf@gitster.siamese.dyndns.org","threadId":"10949","inReplyTo":"Pine.LNX.4.64.0711202045140.4046@ybpnyubfg.ybpnyqbznva","subject":"Re: [PATCH] When re-initializing, set shared permissions on all directories.","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2007-11-21T06:45:17Z","receivedAt":"2007-11-21T06:45:17Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Jon Jensen <jon@endpoint.com> writes:\n\n> Below is a small patch to make git-init --shared change permissions\n> not just of .git/refs/ but of the other directories too.\n\nThose existing calls to adjust_shared_perm() are not about\nchanging permissions for existing directories, but are meant to\nchange the ones we _create_ under the user's umask() during the\ninitialization.\n\nAs you said, your change does not go far enough and you have to\ntell the users to run \"chmod\" (and \"chgrp\") anyway.  If we were\nto update init-db, then it would need to do the recursive chmod\nand chgrp itself.\n\nHowever, the user need to do recursive chmod and chgrp to\ncorrect earlier screwups and to adjust to the new reality anyway\n(see below), and doing so using vanilla filesystem tools is\noften easier.  It might be better to train them early how to do\nso, instead of making git-init a specialized command that knows\nhow to run chmod and chgrp in $GIT_DIR, as one of the major\nstrength of git comes from the fact that its implementation is\ntransparent.  People who can read or write under $GIT_DIR can\naccess or build on the history --- it's just that simple.\nExposing users to the filesystem enhances that transparency.\n\nTwo reasons for correcting an initial screw-up, and two reasons\nfor adjusting the new reality are:\n\n (A) making a non-shared repository to a shared one; you need\n\n     $ find .git -type d -print | xargs chmod g+rwxs\n     $ find .git -type f -print | xargs chmod g+rX\n\n (B) the same as above but the repository is owned by your\n     personal group, not project; you further need\n\n     $ chgrp -R projectgroup .git\n\n (C) an already shared project repository is transferred to a\n     new group; you need\n\n     $ chgrp -R newprojectgroup .git\n\n (D) a shared repository is turned back to a private one; you\n     may need (if you are paranoid and do not want them to be\n     read):\n\n     $ find .git -type d -print | xargs chmod go=\n     $ find .git -type f -print | xargs chmod go=\n\n    or (if you only want to refuse writing)\n\n     $ find .git -type d -print | xargs chmod g-w\n     $ find .git -type f -print | xargs chmod g-w\n\nOf course the above assumes that your umask is at most 077 (iow,\nyou did not forbid any access to yourself).\n\nSo I'd suggest us to do this in three steps:\n\n Step #1. Documentation.\n\n   (1) How to transform a personal, non-shared project to a shared\n       one;\n\n   (2) How to transfer a shared project from one group to another;\n\n   (3) How to transform a shared project to a non-shared,\n       private one (two variants);\n\n   I think your documentation patch is a good start, but notice\n   the differences from the above (A)-(D).\n\n Step #2. Teach \"git-init --shared\" to do (1),\n\n Step #3. Discuss if we want to teach the \"re-initialization\"\n          mode of git-init to do (2) and (3) as well, and if so,\n          design and code it.  We'd need new options to name the\n          desired group and such so it would involve an\n          interface change.\n\nPersonally, I suspect that we do not need to go any further than\nStep #1 above, but people who like \"magic\" may disagree.  Don't\ntake my suspicion as a rejection.\n"}]}