{"thread":{"id":"22972","subject":"init --shared=0666 isn't","startedAt":"2010-03-09T22:31:56Z","lastAt":"2010-03-09T23:51:38Z","messageCount":2,"participants":["Steve Folly","Junio C Hamano"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"136473","messageId":"loom.20100309T224207-485@post.gmane.org","threadId":"22972","inReplyTo":null,"subject":"init --shared=0666 isn't","fromName":"Steve Folly","fromEmail":"steve@spfweb.co.uk","sentAt":"2010-03-09T22:31:56Z","receivedAt":"2010-03-09T22:31:56Z","isPatch":false,"sender":{"key":"steve@spfweb.co.uk","avatar":null},"body":"Using git 1.7.0.2 on Mac OS X 10.6.2:\n\n$ git init --bare --shared=0666 /tmp/shared.git\n$ git --git-dir=/tmp/shared.git remote add --mirror \\\n        origin git://git.kernel.org/pub/scm/git/git.git\n$ git --git-dir=/tmp/shared.git fetch origin\n\n# login as someone else; different uid, different gid, then:\n\n$ git --git-dir=/tmp/shared.git fetch origin\n\nerror: cannot open /tmp/shared.git/FETCH_HEAD: Permission denied\n\n\nFETCH_HEAD is owned by the original user, with 0644 permissions,\n not 0666 as originally requested.\n\nI've only had a quick glance at the source - my first guess\n is that in builtin-fetch.c, store_updated_refs and \ntruncate_fetch_head should call adjust_shared_perm after\nclosing the file being written? Or, should an empty FETCH_HEAD\nwith appropriate shared perms be written during init?\n\nIn my case I'm using /tmp/shared.git as a mirror for other\n local repositories init'ed with --reference=/path/to/mirror.git\nand all I'll be doing if fetching into it periodically, so I think fixing \nFETCH_HEAD will suffice for me. \n\nBut, I wonder if there are other files written that will need fixing\nalso - ORIG_HEAD, MERGE_HEAD?\n\nIs there a workaround for this or am I doing something wrong? \nThanks for any help.\n\nRegards,\nSteve\n"},{"id":"136480","messageId":"7vy6i1uk8l.fsf@alter.siamese.dyndns.org","threadId":"22972","inReplyTo":"loom.20100309T224207-485@post.gmane.org","subject":"Re: init --shared=0666 isn't","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2010-03-09T23:51:38Z","receivedAt":"2010-03-09T23:51:38Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Steve Folly <steve@spfweb.co.uk> writes:\n\n> $ git --git-dir=/tmp/shared.git fetch origin\n>\n> error: cannot open /tmp/shared.git/FETCH_HEAD: Permission denied\n>\n> FETCH_HEAD is owned by the original user, with 0644 permissions,\n\nThe shared repository support was [*1*] designed to help people setting up\na \"shared\" repository like CVS/SVN, a central place people meet and\nexchange their histories by pushing into it and fetching from it.  It was\nnever designed to be used with a repository with a working tree, hence it\nwas never designed to be used in repositories you would run \"git pull\" or\n\"git merge\" in.\n\nHowever, it is not implausible for a sane workflow that you have to fetch\ninto a central meeting place.  You might be setting up a shared repository\nthat also serves as a redistribution center for an external source, and in\nsuch a set-up, you would\n\n (1) clone/fetch from external \"upstream\";\n (2) allow people to fetch from it;\n (3) allow people to push into it.\n\nSo in that sense, allowing \"git fetch\" in such a shared central meeting\nplace is not something we would want to actively forbid.  But I thought we\nunlinked existing FETCH_HEAD and then opened to create it anew, so I am a\nbit puzzled why it matters who owns it and who can write into it.\n\n    ... goes and looks ...\n\nAh, truncate_fetch_head() just opens it without unlinking.  Probably a\nbetter fix might be to unlink and create the file, like the attached patch\ndoes, instead of running adjust_shared_perm().\n\n> But, I wonder if there are other files written that will need fixing\n> also - ORIG_HEAD, MERGE_HEAD?\n\nThese are created by \"merge\" and \"reset\", so it shouldn't matter.\n\nBy the way, the same applies to files in the working tree.  We never call\nadjust_shared_perm() when creating them, and I do not think this is likely\nto change.\n\n\n[Footnote]\n\n*1* Notice the past tense---this is merely a statement of historical fact\nto help you understand _why_ the current system behaves that way and the\nconclusion does not necessarily have to be \"hence it must remain that\nway\".\n\n\n\ndiff --git a/builtin-fetch.c b/builtin-fetch.c\nindex b6c5b34..d73fa19 100644\n--- a/builtin-fetch.c\n+++ b/builtin-fetch.c\n@@ -654,8 +654,11 @@ static void check_not_current_branch(struct ref *ref_map)\n static int truncate_fetch_head(void)\n {\n \tchar *filename = git_path(\"FETCH_HEAD\");\n-\tFILE *fp = fopen(filename, \"w\");\n+\tFILE *fp;\n \n+\tif (unlink(filename) && errno != ENOENT)\n+\t\treturn error(\"cannot unlink %s\\n\", filename);\n+\tfp = fopen(filename, \"w\");\n \tif (!fp)\n \t\treturn error(\"cannot open %s: %s\\n\", filename, strerror(errno));\n \tfclose(fp);\n"}]}