{"thread":{"id":"13039","subject":"[PATCH] Add core.sharedRepository == read-only-group","startedAt":"2008-04-09T19:37:19Z","lastAt":"2008-04-09T19:37:19Z","messageCount":1,"participants":["Heikki Orsila"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"73973","messageId":"20080409193719.GB24451@jolt.modeemi.cs.tut.fi","threadId":"13039","inReplyTo":null,"subject":"[PATCH] Add core.sharedRepository == read-only-group","fromName":"Heikki Orsila","fromEmail":"shd@modeemi.fi","sentAt":"2008-04-09T19:37:19Z","receivedAt":"2008-04-09T19:37:19Z","isPatch":true,"sender":{"key":"shd@modeemi.fi","avatar":null},"body":"The attached patch adds a new permission mode for core.sharedRepository. \n\n-- \nHeikki Orsila\nheikki.orsila@iki.fi\nhttp://www.iki.fi/shd\n\n\n>From bbfa25faa17bb67e98107edabae114d833f1b838 Mon Sep 17 00:00:00 2001\nFrom: Heikki Orsila <heikki.orsila@iki.fi>\nDate: Wed, 9 Apr 2008 22:29:34 +0300\nSubject: [PATCH] Add core.sharedRepository == read-only-group\n\ncore.sharedRepository == read-only-group allows setting Git repository\nfiles group readable when the default umask of the user masks off group\nreading. This can be useful for people with protective umasks (0077).\n\nNote, PERM_READONLY_GROUP is added to the last position in\n\"enum sharedrepo\" to avoid problems with old Git repositories, because\ngit init --shared stores numbers instead of symbolic names.\n\nSigned-off-by: Heikki Orsila <heikki.orsila@iki.fi>\n---\n Documentation/config.txt   |    5 +++--\n Documentation/git-init.txt |    5 ++++-\n cache.h                    |    3 ++-\n path.c                     |   33 +++++++++++++++++++--------------\n setup.c                    |    2 ++\n 5 files changed, 30 insertions(+), 18 deletions(-)\n\ndiff --git a/Documentation/config.txt b/Documentation/config.txt\nindex fe43b12..6330b63 100644\n--- a/Documentation/config.txt\n+++ b/Documentation/config.txt\n@@ -258,8 +258,9 @@ core.repositoryFormatVersion::\n core.sharedRepository::\n \tWhen 'group' (or 'true'), the repository is made shareable between\n \tseveral users in a group (making sure all the files and objects are\n-\tgroup-writable). When 'all' (or 'world' or 'everybody'), the\n-\trepository will be readable by all users, additionally to being\n+\tgroup-writable). When 'read-only-group', the repository is made\n+\treadable for users in a group. When 'all' (or 'world' or 'everybody'),\n+\tthe repository will be readable by all users, additionally to being\n \tgroup-shareable. When 'umask' (or 'false'), git will use permissions\n \treported by umask(2). See linkgit:git-init[1]. False by default.\n \ndiff --git a/Documentation/git-init.txt b/Documentation/git-init.txt\nindex 62914da..e0613f9 100644\n--- a/Documentation/git-init.txt\n+++ b/Documentation/git-init.txt\n@@ -31,7 +31,7 @@ structure, some suggested \"exclude patterns\", and copies of non-executing\n \"hook\" files.  The suggested patterns and hook files are all modifiable and\n extensible.\n \n---shared[={false|true|umask|group|all|world|everybody}]::\n+--shared[={false|true|umask|group|read-only-group|all|world|everybody}]::\n \n Specify that the git repository is to be shared amongst several users.  This\n allows users belonging to the same group to push into that\n@@ -49,6 +49,9 @@ is given:\n  - 'group' (or 'true'): Make the repository group-writable, (and g+sx, since\n    the git group may be not the primary group of all users).\n \n+ - 'read-only-group': Make the repository group-readable (and g+sx for\n+   directories)\n+\n  - 'all' (or 'world' or 'everybody'): Same as 'group', but make the repository\n    readable by all users.\n \ndiff --git a/cache.h b/cache.h\nindex 2a1e7ec..37f5e4a 100644\n--- a/cache.h\n+++ b/cache.h\n@@ -477,7 +477,8 @@ int git_mkstemp(char *path, size_t n, const char *template);\n enum sharedrepo {\n \tPERM_UMASK = 0,\n \tPERM_GROUP,\n-\tPERM_EVERYBODY\n+\tPERM_EVERYBODY,\n+\tPERM_READONLY_GROUP,\n };\n int git_config_perm(const char *var, const char *value);\n int adjust_shared_perm(const char *path);\ndiff --git a/path.c b/path.c\nindex f4ed979..d3d68b8 100644\n--- a/path.c\n+++ b/path.c\n@@ -266,22 +266,27 @@ int adjust_shared_perm(const char *path)\n \tif (lstat(path, &st) < 0)\n \t\treturn -1;\n \tmode = st.st_mode;\n-\tif (mode & S_IRUSR)\n-\t\tmode |= (shared_repository == PERM_GROUP\n-\t\t\t ? S_IRGRP\n-\t\t\t : (shared_repository == PERM_EVERYBODY\n-\t\t\t    ? (S_IRGRP|S_IROTH)\n-\t\t\t    : 0));\n-\n-\tif (mode & S_IWUSR)\n+\tif (mode & S_IRUSR) {\n+\t\tif (shared_repository == PERM_GROUP ||\n+\t\t    shared_repository == PERM_READONLY_GROUP) {\n+\t\t\tmode |= S_IRGRP;\n+\t\t} else if (shared_repository == PERM_EVERYBODY) {\n+\t\t\tmode |= S_IRGRP | S_IROTH;\n+\t\t}\n+\t}\n+\n+\tif ((mode & S_IWUSR) && shared_repository != PERM_READONLY_GROUP)\n \t\tmode |= S_IWGRP;\n \n-\tif (mode & S_IXUSR)\n-\t\tmode |= (shared_repository == PERM_GROUP\n-\t\t\t ? S_IXGRP\n-\t\t\t : (shared_repository == PERM_EVERYBODY\n-\t\t\t    ? (S_IXGRP|S_IXOTH)\n-\t\t\t    : 0));\n+\tif (mode & S_IXUSR) {\n+\t\tif (shared_repository == PERM_GROUP ||\n+\t\t    shared_repository == PERM_READONLY_GROUP) {\n+\t\t\tmode |= S_IXGRP;\n+\t\t} else if (shared_repository == PERM_EVERYBODY) {\n+\t\t\tmode |= S_IXGRP | S_IXOTH;\n+\t\t}\n+\t}\n+\n \tif (S_ISDIR(mode))\n \t\tmode |= FORCE_DIR_SET_GID;\n \tif ((mode & st.st_mode) != mode && chmod(path, mode) < 0)\ndiff --git a/setup.c b/setup.c\nindex 3d2d958..f5d05dc 100644\n--- a/setup.c\n+++ b/setup.c\n@@ -434,6 +434,8 @@ int git_config_perm(const char *var, const char *value)\n \t\t\treturn PERM_UMASK;\n \t\tif (!strcmp(value, \"group\"))\n \t\t\treturn PERM_GROUP;\n+\t\tif (!strcmp(value, \"read-only-group\"))\n+\t\t\treturn PERM_READONLY_GROUP;\n \t\tif (!strcmp(value, \"all\") ||\n \t\t    !strcmp(value, \"world\") ||\n \t\t    !strcmp(value, \"everybody\"))\n-- \n1.5.4.4\n\n"}]}