{"thread":{"id":"15843","subject":"Git newbie question: permissions","startedAt":"2008-10-09T20:20:10Z","lastAt":"2008-10-10T14:44:52Z","messageCount":6,"participants":["Ed Schofield","Marc Weber","Samuel Lucas Vaz de Mello","Samuel Tardieu"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"92699","messageId":"1b5a37350810091320l72ae0a86m39db4258c9f4827e@mail.gmail.com","threadId":"15843","inReplyTo":null,"subject":"Git newbie question: permissions","fromName":"Ed Schofield","fromEmail":"edschofield@gmail.com","sentAt":"2008-10-09T20:20:10Z","receivedAt":"2008-10-09T20:20:10Z","isPatch":false,"sender":{"key":"edschofield@gmail.com","avatar":null},"body":"Hi everyone,\n\nI have a bare git repository that users in a particular group\n(\"webdev\") are pulling from and pushing to using the ssh transport.\nOne of the users has just reported this error during a push:\n\nCounting objects: 103, done.\nCompressing objects: 100% (68/68), done.\nerror: unable to write sha1 filename\n./objects/4f/\n973ce5c66f082af5087948cec57001f0c4da50: Permission denied\n\nfatal: failed to write object\nerror: pack-objects died with strange error\nerror: failed to push some refs to '/var/git/myrepo.git'\n\nI'd appreciate some help on getting my repository back to a sane\nstate, allowing this user to finish his push, and making sure\npermissions are right in the future.\n\nI don't think I specified \"--shared=group\" when initializing the\nrepository. Afterwards I manually set all files to have 660\npermissions, dirs as 770, and set the group ownership to \"webdev\", but\nI probably made a mistake by not setting the setgid bit on\ndirectories. Now there are some objects directories with 755\npermissions and different group ownership (the default groups of the\nother users).\n\nI have now run \"git --bare init --shared=group\" to reinitialize the\nrepository. This seems to have changed the directories to be g+sx. (Is\nthis all it did?). There are still some objects directories with 755\npermissions rather than 770, which I presume I want, and the group\nownership of these is wrong. Shall I change these by hand? The sha1\nfiles all have 444 permissions; is this right?\n\nThe last question I have is how to ensure that git creates object\nfiles etc. with the right permissions when users push in future.\n\nI'd appreciate any help!\n\n-- Ed\n"},{"id":"92708","messageId":"48EE7232.5080107@datacom.ind.br","threadId":"15843","inReplyTo":"1b5a37350810091320l72ae0a86m39db4258c9f4827e@mail.gmail.com","subject":"Re: Git newbie question: permissions","fromName":"Samuel Lucas Vaz de Mello","fromEmail":"samuellucas@datacom.ind.br","sentAt":"2008-10-09T21:05:54Z","receivedAt":"2008-10-09T21:05:54Z","isPatch":false,"sender":{"key":"samuellucas@datacom.ind.br","avatar":null},"body":"Ed Schofield wrote:\n> I don't think I specified \"--shared=group\" when initializing the\n> repository. Afterwards I manually set all files to have 660\n> permissions, dirs as 770, and set the group ownership to \"webdev\", but\n> I probably made a mistake by not setting the setgid bit on\n> directories. Now there are some objects directories with 755\n> permissions and different group ownership (the default groups of the\n> other users).\n>   \nHi Ed!\n\nI'm also a newbie here and I have a very similar setup to yours.\n\nThe only difference is that my repository was created using \ngit-cvsimport and afterwards I used git-config to set \ncore.sharedrepository=1 and manually set up the permissions.\n\nI also got objects created with the users' default group, but for now I \njust changed the deafault group for those users until I find a better \nsolution.\n\nAnother issue with this setup: if I run git-gc in the shared repo, it \nrecreate the files in logs/refs/heads with 644 permissions, which \nprevents users to push until I manually fix the permissions.\n\nSomeone else have faced these kind of problems?\n\nRegards,\n\n - Samuel\n"},{"id":"92707","messageId":"20081009212925.GA7891@gmx.de","threadId":"15843","inReplyTo":"1b5a37350810091320l72ae0a86m39db4258c9f4827e@mail.gmail.com","subject":"Re: Git newbie question: permissions","fromName":"Marc Weber","fromEmail":"marco-oweber@gmx.de","sentAt":"2008-10-09T21:29:25Z","receivedAt":"2008-10-09T21:29:25Z","isPatch":false,"sender":{"key":"marco-oweber@gmx.de","avatar":null},"body":"> The last question I have is how to ensure that git creates object\n> files etc. with the right permissions when users push in future.\nHave a look at the config file. It should contain\n\n[core]\n        sharedrepository = 1\nnow.\n\nI've never used that option before but I think this option should be\nenough to ensure that it works in the future if it did for other repos\nin the past..\n\nMarc Weber\n"},{"id":"92711","messageId":"2008-10-09-23-41-14+trackit+sam@rfc1149.net","threadId":"15843","inReplyTo":"1b5a37350810091320l72ae0a86m39db4258c9f4827e@mail.gmail.com","subject":"Re: Git newbie question: permissions","fromName":"Samuel Tardieu","fromEmail":"sam@rfc1149.net","sentAt":"2008-10-09T21:41:14Z","receivedAt":"2008-10-09T21:41:14Z","isPatch":false,"sender":{"key":"sam@rfc1149.net","avatar":"https://avatars.githubusercontent.com/u/44656?v=4"},"body":">>>>> \"Ed\" == Ed Schofield <edschofield@gmail.com> writes:\n\nEd> I have now run \"git --bare init --shared=group\" to reinitialize\nEd> the repository. This seems to have changed the directories to be\nEd> g+sx. (Is this all it did?). There are still some objects\nEd> directories with 755 permissions rather than 770, which I presume\nEd> I want, and the group ownership of these is wrong. Shall I change\nEd> these by hand? The sha1 files all have 444 permissions; is this\nEd> right?\n\nEd> The last question I have is how to ensure that git creates object\nEd> files etc. with the right permissions when users push in future.\n\nAs Marc said, you should first make sure that \"config\" contains\n\"sharedrepository = 1\" in the \"[core]\" section.\n\nThen you can do the following:\n\n  - remove all permissions for \"others\":  chmod -R o-rwx .\n  - mirror \"user\" permissions to \"group\": chmod -R g=u .\n  - add +s flag to directories:           find . -type d | xargs chmod g+s\n\nThis should fix your current situation. The \"sharedrepository = 1\"\nwill tell git to maintain a proper shared state in the future\non objects it creates (i.e. mirror \"user\" permission to \"group\" ones).\n\n  Sam\n-- \nSamuel Tardieu -- sam@rfc1149.net -- http://www.rfc1149.net/\n"},{"id":"92720","messageId":"1b5a37350810091559y151e244t43710d4e4c3dabcf@mail.gmail.com","threadId":"15843","inReplyTo":"2008-10-09-23-41-14+trackit+sam@rfc1149.net","subject":"Re: Git newbie question: permissions","fromName":"Ed Schofield","fromEmail":"edschofield@gmail.com","sentAt":"2008-10-09T22:59:40Z","receivedAt":"2008-10-09T22:59:40Z","isPatch":false,"sender":{"key":"edschofield@gmail.com","avatar":null},"body":"On Thu, Oct 9, 2008 at 10:41 PM, Samuel Tardieu <sam@rfc1149.net> wrote:\n>>>>>> \"Ed\" == Ed Schofield <edschofield@gmail.com> writes:\n>\n> Ed> I have now run \"git --bare init --shared=group\" to reinitialize\n> Ed> the repository. This seems to have changed the directories to be\n> Ed> g+sx. (Is this all it did?). There are still some objects\n> Ed> directories with 755 permissions rather than 770, which I presume\n> Ed> I want, and the group ownership of these is wrong. Shall I change\n> Ed> these by hand? The sha1 files all have 444 permissions; is this\n> Ed> right?\n>\n> Ed> The last question I have is how to ensure that git creates object\n> Ed> files etc. with the right permissions when users push in future.\n>\n> As Marc said, you should first make sure that \"config\" contains\n> \"sharedrepository = 1\" in the \"[core]\" section.\n>\n> Then you can do the following:\n>\n>  - remove all permissions for \"others\":  chmod -R o-rwx .\n>  - mirror \"user\" permissions to \"group\": chmod -R g=u .\n>  - add +s flag to directories:           find . -type d | xargs chmod g+s\n>\n> This should fix your current situation. The \"sharedrepository = 1\"\n> will tell git to maintain a proper shared state in the future\n> on objects it creates (i.e. mirror \"user\" permission to \"group\" ones).\n\nThis worked beautifully. Thanks Sam, thanks Marc!\n\n-- Ed\n"},{"id":"92757","messageId":"48EF6A64.9060203@datacom.ind.br","threadId":"15843","inReplyTo":"2008-10-09-23-41-14+trackit+sam@rfc1149.net","subject":"Re: Git newbie question: permissions","fromName":"Samuel Lucas Vaz de Mello","fromEmail":"samuellucas@datacom.ind.br","sentAt":"2008-10-10T14:44:52Z","receivedAt":"2008-10-10T14:44:52Z","isPatch":false,"sender":{"key":"samuellucas@datacom.ind.br","avatar":null},"body":"Samuel Tardieu wrote:\n> This should fix your current situation. The \"sharedrepository = 1\"\n> will tell git to maintain a proper shared state in the future\n> on objects it creates (i.e. mirror \"user\" permission to \"group\" ones).\n>   \nIs git-gc supposed to respect sharedrepository=1 and create \ngroup-writable files?\nFor me, it's recreating the files under logs/refs/heads with 644 \npermissions.\n\nBR,\n\n - Samuel\n"}]}