{"thread":{"id":"24103","subject":"How to prevent changes to repository by root","startedAt":"2010-06-14T03:12:35Z","lastAt":"2010-06-18T20:45:33Z","messageCount":5,"participants":["Nazri Ramliy","Nicolas Sebrecht","Aneurin Price","Pete Harlan"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"143623","messageId":"AANLkTikLixhYITdJKMFb3Hw2hZvaas1DtiV3x9ThCTZz@mail.gmail.com","threadId":"24103","inReplyTo":null,"subject":"How to prevent changes to repository by root","fromName":"Nazri Ramliy","fromEmail":"ayiehere@gmail.com","sentAt":"2010-06-14T03:12:35Z","receivedAt":"2010-06-14T03:12:35Z","isPatch":false,"sender":{"key":"ayiehere@gmail.com","avatar":"https://avatars.githubusercontent.com/u/164756?v=4"},"body":"I have a git repository owned by a non-privileged user account on a\nmachine that is logged into (via ssh) by multiple users. These multiple users,\nall of them (not at at the same time) do \"git pull\" on this repository.\n\nEverything is fine as long as they don't do the \"git pull\" as root.\n\nMurphy's law and all, someone is bound to do \"git pull\" as root on that repo\nand that would sometime cause problem for the non-privileged user (who 'own')\nthe git repo to do subsequent git operations on that repository.\n\nMy question is:\n\nHow do I limit any action on this repository to this non-privileged user only?\n\nI looked at \"git help hooks\" thinking that maybe I can use one of the hooks to\nadd return \"test $USER = foo\" but from the descriptions there it is\nnot clear which\nhook is the one that applies to this case (limit all repository action\non this repository\nto this user only)\n\nAny ideas?\n\nThanks in advance for any help.\n\nnazri.\n"},{"id":"143820","messageId":"20100616150951.GA13073@vidovic","threadId":"24103","inReplyTo":"AANLkTikLixhYITdJKMFb3Hw2hZvaas1DtiV3x9ThCTZz@mail.gmail.com","subject":"Re: How to prevent changes to repository by root","fromName":"Nicolas Sebrecht","fromEmail":"nicolas.s.dev@gmx.fr","sentAt":"2010-06-16T15:09:51Z","receivedAt":"2010-06-16T15:09:51Z","isPatch":false,"sender":{"key":"nicolas.s.dev@gmx.fr","avatar":null},"body":"The 14/06/10, Nazri Ramliy wrote:\n\n> I have a git repository owned by a non-privileged user account on a\n> machine that is logged into (via ssh) by multiple users. These multiple users,\n> all of them (not at at the same time) do \"git pull\" on this repository.\n> \n> Everything is fine as long as they don't do the \"git pull\" as root.\n> \n> Murphy's law and all, someone is bound to do \"git pull\" as root on that repo\n> and that would sometime cause problem for the non-privileged user (who 'own')\n> the git repo to do subsequent git operations on that repository.\n> \n> My question is:\n> \n> How do I limit any action on this repository to this non-privileged user only?\n\nDon't give root access to your users. This is the only sane thing to do\nin the unix world. ,-p\n\n-- \nNicolas Sebrecht\n"},{"id":"143823","messageId":"AANLkTikPNH1ueb5m8JpiB2hU4afd3hv-4qYqSO3QPujl@mail.gmail.com","threadId":"24103","inReplyTo":"AANLkTikLixhYITdJKMFb3Hw2hZvaas1DtiV3x9ThCTZz@mail.gmail.com","subject":"Re: How to prevent changes to repository by root","fromName":"Aneurin Price","fromEmail":"aneurin.price@gmail.com","sentAt":"2010-06-16T16:09:52Z","receivedAt":"2010-06-16T16:09:52Z","isPatch":false,"sender":{"key":"aneurin.price@gmail.com","avatar":null},"body":"On Mon, Jun 14, 2010 at 04:12, Nazri Ramliy <ayiehere@gmail.com> wrote:\n> I have a git repository owned by a non-privileged user account on a\n> machine that is logged into (via ssh) by multiple users. These multiple users,\n> all of them (not at at the same time) do \"git pull\" on this repository.\n>\n> Everything is fine as long as they don't do the \"git pull\" as root.\n>\n\nIs there ever any requirement for them to run git as root?\n\nHow are they becoming root? If they are using sudo you could forbid\nrunning git as root. If they are using su or logging in directly maybe\nyou can get away with some trivial thing like putting 'alias\ngit=/bin/false' in /root/.bashrc - or some wrapper which does\nsomething helpful rather than silently fail :-).\n\nNye\n"},{"id":"143843","messageId":"AANLkTimjIraq-qDaifACixJ4cCOYuvkf1v-hVpeaVt3u@mail.gmail.com","threadId":"24103","inReplyTo":"AANLkTikPNH1ueb5m8JpiB2hU4afd3hv-4qYqSO3QPujl@mail.gmail.com","subject":"Re: How to prevent changes to repository by root","fromName":"Nazri Ramliy","fromEmail":"ayiehere@gmail.com","sentAt":"2010-06-17T02:28:07Z","receivedAt":"2010-06-17T02:28:07Z","isPatch":false,"sender":{"key":"ayiehere@gmail.com","avatar":"https://avatars.githubusercontent.com/u/164756?v=4"},"body":"On Thu, Jun 17, 2010 at 12:09 AM, Aneurin Price <aneurin.price@gmail.com> wrote:\n> How are they becoming root? If they are using sudo you could forbid\n> running git as root. If they are using su or logging in directly maybe\n> you can get away with some trivial thing like putting 'alias\n> git=/bin/false' in /root/.bashrc - or some wrapper which does\n> something helpful rather than silently fail :-).\n\nThanks for dropping the hint on wrapper.\n\nI've implemented one that give the user a friendly reminder\nthat they are running git as root and ask whether to continue.\n\nnazri.\n"},{"id":"143920","messageId":"4C1BDAED.3030809@pcharlan.com","threadId":"24103","inReplyTo":"AANLkTimjIraq-qDaifACixJ4cCOYuvkf1v-hVpeaVt3u@mail.gmail.com","subject":"Re: How to prevent changes to repository by root","fromName":"Pete Harlan","fromEmail":"pgit@pcharlan.com","sentAt":"2010-06-18T20:45:33Z","receivedAt":"2010-06-18T20:45:33Z","isPatch":false,"sender":{"key":"pgit@pcharlan.com","avatar":null},"body":"On 06/16/2010 07:28 PM, Nazri Ramliy wrote:\n> On Thu, Jun 17, 2010 at 12:09 AM, Aneurin Price <aneurin.price@gmail.com> wrote:\n>> How are they becoming root? If they are using sudo you could forbid\n>> running git as root. If they are using su or logging in directly maybe\n>> you can get away with some trivial thing like putting 'alias\n>> git=/bin/false' in /root/.bashrc - or some wrapper which does\n>> something helpful rather than silently fail :-).\n> \n> Thanks for dropping the hint on wrapper.\n> \n> I've implemented one that give the user a friendly reminder\n> that they are running git as root and ask whether to continue.\n\nWhen I needed this I wrote a hook that refused a commit by root unless the commit message said something to the effect of:\n\nRoot commit performed by <person or script name>.\n\nIt's not that I minded so much that root was doing commits, it's the anonymity that was the problem.  So automated scripts that ran as root could perform commits too, they just had to include this note in the commit message so we knew which script was doing it.  It was all the honor-system, but it did what we wanted and prevented committing as root by accident.\n\n--Pete\n"}]}