{"thread":{"id":"40147","subject":"Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied","startedAt":"2015-08-21T11:36:49Z","lastAt":"2015-09-23T22:48:51Z","messageCount":20,"participants":["Joakim Tjernlund","Duy Nguyen","Johannes Schindelin","Junio C Hamano"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"268408","messageId":"1440157010.1759.83.camel@transmode.se","threadId":"40147","inReplyTo":null,"subject":"Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied","fromName":"Joakim Tjernlund","fromEmail":"joakim.tjernlund@transmode.se","sentAt":"2015-08-21T11:36:49Z","receivedAt":"2015-08-21T11:36:49Z","isPatch":false,"sender":{"key":"joakim.tjernlund@transmode.se","avatar":null},"body":"I cannot push:\n# > git push origin\nLogin for jocke@git.transmode.se\nPassword: \nCounting objects: 7, done.\nDelta compression using up to 4 threads.\nCompressing objects: 100% (7/7), done.\nWriting objects: 100% (7/7), 13.73 KiB | 0 bytes/s, done.\nTotal 7 (delta 4), reused 0 (delta 0)\nfatal: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied\nfatal: The remote end hung up unexpectedly\nfatal: The remote end hung up unexpectedly\ncu-km022 tmv3-target-overlay # ls -l\ntotal 0\ndrwxr-xr-x 1 root root  72 Aug 19 17:59 ./\ndrwxr-xr-x 1 root root  38 Aug 19 17:59 ../\ndrwxr-xr-x 1 root root 216 Aug 21 13:07 .git/\ndrwxr-xr-x 1 root root  22 Aug 19 17:59 metadata/\ndrwxr-xr-x 1 root root  58 Aug 19 18:27 profiles/\ndrwxr-xr-x 1 root root  74 Aug 19 17:59 sys-apps/\ndrwxr-xr-x 1 root root  42 Aug 19 17:59 sys-libs/\n\nOn server I have:\n# >ls -la\ntotal 24\ndr-xr-sr-x   6 apache tm-3000  123 Jun 10 15:25 .\ndrwxr-xr-x  36 root   root    4096 Jun 25 11:11 ..\n-r--r--r--   1 root   tm-3000  263 Jun 10 15:18 config\n-r--r--r--   1 apache tm-3000   73 Jun 10 15:18 description\n-rw-r--r--   1 root   tm-3000    0 Jun 10 15:25 git-daemon-export-ok\n-r--r--r--   1 apache tm-3000   23 Jun 10 15:18 HEAD\ndrwxr-sr-x   2 root   tm-3000 4096 Jun 10 15:18 hooks\ndrwxrwsr-x   2 apache tm-3000   20 Jun 10 15:18 info\ndrwxrwsr-x 135 apache tm-3000 4096 Aug 20 19:07 objects\ndrwxrwsr-x   4 apache tm-3000   29 Jun 10 15:18 refs\n\n\nI suspect this is because no one is allowed to write the repos top dir.\nIt would be much better if git allowed a tmp dir inside the repo and used that \nfor push etc.\nMeanwhile, is there some workaround I can use?\n\n Jocke"},{"id":"268409","messageId":"1440157845.1759.85.camel@transmode.se","threadId":"40147","inReplyTo":"1440157010.1759.83.camel@transmode.se","subject":"Re: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied","fromName":"Joakim Tjernlund","fromEmail":"joakim.tjernlund@transmode.se","sentAt":"2015-08-21T11:50:45Z","receivedAt":"2015-08-21T11:50:45Z","isPatch":false,"sender":{"key":"joakim.tjernlund@transmode.se","avatar":null},"body":"On Fri, 2015-08-21 at 13:36 +0200, Joakim Tjernlund wrote:\n> I cannot push:\n> # > git push origin\n> Login for jocke@git.transmode.se\n> Password: \n> Counting objects: 7, done.\n> Delta compression using up to 4 threads.\n> Compressing objects: 100% (7/7), done.\n> Writing objects: 100% (7/7), 13.73 KiB | 0 bytes/s, done.\n> Total 7 (delta 4), reused 0 (delta 0)\n> fatal: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied\n> fatal: The remote end hung up unexpectedly\n> fatal: The remote end hung up unexpectedly\n> cu-km022 tmv3-target-overlay # ls -l\n> total 0\n> drwxr-xr-x 1 root root  72 Aug 19 17:59 ./\n> drwxr-xr-x 1 root root  38 Aug 19 17:59 ../\n> drwxr-xr-x 1 root root 216 Aug 21 13:07 .git/\n> drwxr-xr-x 1 root root  22 Aug 19 17:59 metadata/\n> drwxr-xr-x 1 root root  58 Aug 19 18:27 profiles/\n> drwxr-xr-x 1 root root  74 Aug 19 17:59 sys-apps/\n> drwxr-xr-x 1 root root  42 Aug 19 17:59 sys-libs/\n> \n> On server I have:\n> # >ls -la\n> total 24\n> dr-xr-sr-x   6 apache tm-3000  123 Jun 10 15:25 .\n> drwxr-xr-x  36 root   root    4096 Jun 25 11:11 ..\n> -r--r--r--   1 root   tm-3000  263 Jun 10 15:18 config\n> -r--r--r--   1 apache tm-3000   73 Jun 10 15:18 description\n> -rw-r--r--   1 root   tm-3000    0 Jun 10 15:25 git-daemon-export-ok\n> -r--r--r--   1 apache tm-3000   23 Jun 10 15:18 HEAD\n> drwxr-sr-x   2 root   tm-3000 4096 Jun 10 15:18 hooks\n> drwxrwsr-x   2 apache tm-3000   20 Jun 10 15:18 info\n> drwxrwsr-x 135 apache tm-3000 4096 Aug 20 19:07 objects\n> drwxrwsr-x   4 apache tm-3000   29 Jun 10 15:18 refs\n> \n> \n> I suspect this is because no one is allowed to write the repos top dir.\n> It would be much better if git allowed a tmp dir inside the repo and used that \n> for push etc.\n> Meanwhile, is there some workaround I can use?\n\nThis error seems to only affect shallow clones.\nForgot, git version 2.4.6\n\n Jocke\n"},{"id":"268970","messageId":"1441011831.3349.150.camel@transmode.se","threadId":"40147","inReplyTo":"1440157845.1759.85.camel@transmode.se","subject":"Re: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied","fromName":"Joakim Tjernlund","fromEmail":"joakim.tjernlund@transmode.se","sentAt":"2015-08-31T09:03:51Z","receivedAt":"2015-08-31T09:03:51Z","isPatch":false,"sender":{"key":"joakim.tjernlund@transmode.se","avatar":null},"body":"On Fri, 2015-08-21 at 13:50 +0200, Joakim Tjernlund wrote:\n> On Fri, 2015-08-21 at 13:36 +0200, Joakim Tjernlund wrote:\n> > I cannot push:\n> > # > git push origin\n> > Login for jocke@git.transmode.se\n> > Password: \n> > Counting objects: 7, done.\n> > Delta compression using up to 4 threads.\n> > Compressing objects: 100% (7/7), done.\n> > Writing objects: 100% (7/7), 13.73 KiB | 0 bytes/s, done.\n> > Total 7 (delta 4), reused 0 (delta 0)\n> > fatal: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission \n> > denied\n> > fatal: The remote end hung up unexpectedly\n> > fatal: The remote end hung up unexpectedly\n> > cu-km022 tmv3-target-overlay # ls -l\n> > total 0\n> > drwxr-xr-x 1 root root  72 Aug 19 17:59 ./\n> > drwxr-xr-x 1 root root  38 Aug 19 17:59 ../\n> > drwxr-xr-x 1 root root 216 Aug 21 13:07 .git/\n> > drwxr-xr-x 1 root root  22 Aug 19 17:59 metadata/\n> > drwxr-xr-x 1 root root  58 Aug 19 18:27 profiles/\n> > drwxr-xr-x 1 root root  74 Aug 19 17:59 sys-apps/\n> > drwxr-xr-x 1 root root  42 Aug 19 17:59 sys-libs/\n> > \n> > On server I have:\n> > # >ls -la\n> > total 24\n> > dr-xr-sr-x   6 apache tm-3000  123 Jun 10 15:25 .\n> > drwxr-xr-x  36 root   root    4096 Jun 25 11:11 ..\n> > -r--r--r--   1 root   tm-3000  263 Jun 10 15:18 config\n> > -r--r--r--   1 apache tm-3000   73 Jun 10 15:18 description\n> > -rw-r--r--   1 root   tm-3000    0 Jun 10 15:25 git-daemon-export-ok\n> > -r--r--r--   1 apache tm-3000   23 Jun 10 15:18 HEAD\n> > drwxr-sr-x   2 root   tm-3000 4096 Jun 10 15:18 hooks\n> > drwxrwsr-x   2 apache tm-3000   20 Jun 10 15:18 info\n> > drwxrwsr-x 135 apache tm-3000 4096 Aug 20 19:07 objects\n> > drwxrwsr-x   4 apache tm-3000   29 Jun 10 15:18 refs\n> > \n> > \n> > I suspect this is because no one is allowed to write the repos top dir.\n> > It would be much better if git allowed a tmp dir inside the repo and used that \n> > for push etc.\n> > Meanwhile, is there some workaround I can use?\n> \n> This error seems to only affect shallow clones.\n> Forgot, git version 2.4.6\n\nPing?\n\n Jocke\n"},{"id":"268974","messageId":"CACsJy8DEDgsG4C4KvuGop_=_wOvcOUZ644NiaQJef67rFNYmgg@mail.gmail.com","threadId":"40147","inReplyTo":"1440157010.1759.83.camel@transmode.se","subject":"Re: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied","fromName":"Duy Nguyen","fromEmail":"pclouds@gmail.com","sentAt":"2015-08-31T09:56:09Z","receivedAt":"2015-08-31T09:56:09Z","isPatch":false,"sender":{"key":"pclouds@gmail.com","avatar":"https://avatars.githubusercontent.com/u/720?v=4"},"body":"On Fri, Aug 21, 2015 at 6:36 PM, Joakim Tjernlund\n<joakim.tjernlund@transmode.se> wrote:\n> I cannot push:\n> # > git push origin\n> Login for jocke@git.transmode.se\n> Password:\n> Counting objects: 7, done.\n> Delta compression using up to 4 threads.\n> Compressing objects: 100% (7/7), done.\n> Writing objects: 100% (7/7), 13.73 KiB | 0 bytes/s, done.\n> Total 7 (delta 4), reused 0 (delta 0)\n> fatal: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied\n> fatal: The remote end hung up unexpectedly\n> fatal: The remote end hung up unexpectedly\n\nNoted. Will try to fix (but probably not fast). At first I thought\nthis was an old bug, but that old bug [1] is in the fetch/clone path,\nnot push. Not sure if the same approach can be reused here (i.e.avoid\ntemp files altoghether).\n\n[1] b790e0f (upload-pack: send shallow info over stdin to pack-objects\n- 2014-03-11)\n-- \nDuy\n"},{"id":"269929","messageId":"1442245035.10125.18.camel@transmode.se","threadId":"40147","inReplyTo":"CACsJy8DEDgsG4C4KvuGop_=_wOvcOUZ644NiaQJef67rFNYmgg@mail.gmail.com","subject":"Re: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied","fromName":"Joakim Tjernlund","fromEmail":"joakim.tjernlund@transmode.se","sentAt":"2015-09-14T15:37:15Z","receivedAt":"2015-09-14T15:37:15Z","isPatch":false,"sender":{"key":"joakim.tjernlund@transmode.se","avatar":null},"body":"On Mon, 2015-08-31 at 16:56 +0700, Duy Nguyen wrote:\n> On Fri, Aug 21, 2015 at 6:36 PM, Joakim Tjernlund\n> <joakim.tjernlund@transmode.se> wrote:\n> > I cannot push:\n> > # > git push origin\n> > Login for jocke@git.transmode.se\n> > Password:\n> > Counting objects: 7, done.\n> > Delta compression using up to 4 threads.\n> > Compressing objects: 100% (7/7), done.\n> > Writing objects: 100% (7/7), 13.73 KiB | 0 bytes/s, done.\n> > Total 7 (delta 4), reused 0 (delta 0)\n> > fatal: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission\n> > denied\n> > fatal: The remote end hung up unexpectedly\n> > fatal: The remote end hung up unexpectedly\n> \n> Noted. Will try to fix (but probably not fast). At first I thought\n> this was an old bug, but that old bug [1] is in the fetch/clone path,\n> not push. Not sure if the same approach can be reused here (i.e.avoid\n> temp files altoghether).\n> \n> [1] b790e0f (upload-pack: send shallow info over stdin to pack-objects\n> - 2014-03-11)\n\nNoticed I had forgotten to reply ...\n\nAn even simpler fix would be to have an tmp dir within the repo, aka:\n /var/git/tmv3-target-overlay.git/tmp/shallow_Un8ZOR\nThis would cover all cases when one must create a tmp file\n\n Jocke"},{"id":"270209","messageId":"CACsJy8BAOXWt2aVge7W8Mk9v0HbHHGkSQFwySeioam9r+n6z_Q@mail.gmail.com","threadId":"40147","inReplyTo":"1442245035.10125.18.camel@transmode.se","subject":"Re: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied","fromName":"Duy Nguyen","fromEmail":"pclouds@gmail.com","sentAt":"2015-09-17T13:18:21Z","receivedAt":"2015-09-17T13:18:21Z","isPatch":false,"sender":{"key":"pclouds@gmail.com","avatar":"https://avatars.githubusercontent.com/u/720?v=4"},"body":"On Mon, Sep 14, 2015 at 10:37 PM, Joakim Tjernlund\n<joakim.tjernlund@transmode.se> wrote:\n> On Mon, 2015-08-31 at 16:56 +0700, Duy Nguyen wrote:\n>> On Fri, Aug 21, 2015 at 6:36 PM, Joakim Tjernlund\n>> <joakim.tjernlund@transmode.se> wrote:\n>> > I cannot push:\n>> > # > git push origin\n>> > Login for jocke@git.transmode.se\n>> > Password:\n>> > Counting objects: 7, done.\n>> > Delta compression using up to 4 threads.\n>> > Compressing objects: 100% (7/7), done.\n>> > Writing objects: 100% (7/7), 13.73 KiB | 0 bytes/s, done.\n>> > Total 7 (delta 4), reused 0 (delta 0)\n>> > fatal: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission\n>> > denied\n>> > fatal: The remote end hung up unexpectedly\n>> > fatal: The remote end hung up unexpectedly\n>>\n>> Noted. Will try to fix (but probably not fast). At first I thought\n>> this was an old bug, but that old bug [1] is in the fetch/clone path,\n>> not push. Not sure if the same approach can be reused here (i.e.avoid\n>> temp files altoghether).\n>>\n>> [1] b790e0f (upload-pack: send shallow info over stdin to pack-objects\n>> - 2014-03-11)\n>\n> Noticed I had forgotten to reply ...\n>\n> An even simpler fix would be to have an tmp dir within the repo, aka:\n>  /var/git/tmv3-target-overlay.git/tmp/shallow_Un8ZOR\n> This would cover all cases when one must create a tmp file\n\nSorry for my silence. I intend to put these temp files in $TMPDIR by\nresurrecting (part of) this patch [1]. Maybe tomorrow.\n\nBut if you build your own, you can put them in $GIT_DIR/tmp by\nreplacing \"shallow_XXXXXX\" in setup_temporary_shallow() in shallow.c\nwith \"tmp/shallow_XXXX\". You need to create the directory \"tmp\" in\nadvance though, or do\n\"safe_create_leading_directories_const(git_path(\"tmp/shallow_XXXXX\"));\"\nbefore xmkstemp()\n\n[1] http://article.gmane.org/gmane.comp.version-control.git/242787\n-- \nDuy\n"},{"id":"270235","messageId":"1442508864.21964.26.camel@transmode.se","threadId":"40147","inReplyTo":"CACsJy8BAOXWt2aVge7W8Mk9v0HbHHGkSQFwySeioam9r+n6z_Q@mail.gmail.com","subject":"Re: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied","fromName":"Joakim Tjernlund","fromEmail":"joakim.tjernlund@transmode.se","sentAt":"2015-09-17T16:54:25Z","receivedAt":"2015-09-17T16:54:25Z","isPatch":false,"sender":{"key":"joakim.tjernlund@transmode.se","avatar":null},"body":"On Thu, 2015-09-17 at 20:18 +0700, Duy Nguyen wrote:\n> On Mon, Sep 14, 2015 at 10:37 PM, Joakim Tjernlund\n> <joakim.tjernlund@transmode.se> wrote:\n> > On Mon, 2015-08-31 at 16:56 +0700, Duy Nguyen wrote:\n> > > On Fri, Aug 21, 2015 at 6:36 PM, Joakim Tjernlund\n> > > <joakim.tjernlund@transmode.se> wrote:\n> > > > I cannot push:\n> > > > # > git push origin\n> > > > Login for jocke@git.transmode.se\n> > > > Password:\n> > > > Counting objects: 7, done.\n> > > > Delta compression using up to 4 threads.\n> > > > Compressing objects: 100% (7/7), done.\n> > > > Writing objects: 100% (7/7), 13.73 KiB | 0 bytes/s, done.\n> > > > Total 7 (delta 4), reused 0 (delta 0)\n> > > > fatal: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission\n> > > > denied\n> > > > fatal: The remote end hung up unexpectedly\n> > > > fatal: The remote end hung up unexpectedly\n> > > \n> > > Noted. Will try to fix (but probably not fast). At first I thought\n> > > this was an old bug, but that old bug [1] is in the fetch/clone path,\n> > > not push. Not sure if the same approach can be reused here (i.e.avoid\n> > > temp files altoghether).\n> > > \n> > > [1] b790e0f (upload-pack: send shallow info over stdin to pack-objects\n> > > - 2014-03-11)\n> > \n> > Noticed I had forgotten to reply ...\n> > \n> > An even simpler fix would be to have an tmp dir within the repo, aka:\n> >  /var/git/tmv3-target-overlay.git/tmp/shallow_Un8ZOR\n> > This would cover all cases when one must create a tmp file\n> \n> Sorry for my silence. I intend to put these temp files in $TMPDIR by\n> resurrecting (part of) this patch [1]. Maybe tomorrow.\n> \n> But if you build your own, you can put them in $GIT_DIR/tmp by\n> replacing \"shallow_XXXXXX\" in setup_temporary_shallow() in shallow.c\n> with \"tmp/shallow_XXXX\". You need to create the directory \"tmp\" in\n> advance though, or do\n> \"safe_create_leading_directories_const(git_path(\"tmp/shallow_XXXXX\"));\"\n> before xmkstemp()\n\nI think you should do both, safe_create_leading_directories_const(git_path(\"tmp/shallow_XXXXX\")) and\nTMPDIR.\n\nAnyhow, can you send me a patch when you are done?\n\n  Jocke\n"},{"id":"270324","messageId":"CACsJy8DFpLLtc7+Mix1d=Hy8h-duUqt4Y8WYsRL1nEryizoeww@mail.gmail.com","threadId":"40147","inReplyTo":"1442508864.21964.26.camel@transmode.se","subject":"Re: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied","fromName":"Duy Nguyen","fromEmail":"pclouds@gmail.com","sentAt":"2015-09-19T02:21:53Z","receivedAt":"2015-09-19T02:21:53Z","isPatch":false,"sender":{"key":"pclouds@gmail.com","avatar":"https://avatars.githubusercontent.com/u/720?v=4"},"body":"On Thu, Sep 17, 2015 at 11:54 PM, Joakim Tjernlund\n<joakim.tjernlund@transmode.se> wrote:\n> On Thu, 2015-09-17 at 20:18 +0700, Duy Nguyen wrote:\n>> On Mon, Sep 14, 2015 at 10:37 PM, Joakim Tjernlund\n>> <joakim.tjernlund@transmode.se> wrote:\n>> > On Mon, 2015-08-31 at 16:56 +0700, Duy Nguyen wrote:\n>> > > On Fri, Aug 21, 2015 at 6:36 PM, Joakim Tjernlund\n>> > > <joakim.tjernlund@transmode.se> wrote:\n>> > > > I cannot push:\n>> > > > # > git push origin\n>> > > > Login for jocke@git.transmode.se\n>> > > > Password:\n>> > > > Counting objects: 7, done.\n>> > > > Delta compression using up to 4 threads.\n>> > > > Compressing objects: 100% (7/7), done.\n>> > > > Writing objects: 100% (7/7), 13.73 KiB | 0 bytes/s, done.\n>> > > > Total 7 (delta 4), reused 0 (delta 0)\n>> > > > fatal: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission\n>> > > > denied\n\nI'm about to do it, but now I'm not sure if I should move\nshallow_XXXXXX out of $GIT_DIR. It will not be the only command that\nmay write to $GIT_DIR. \"git gc --auto\" (which can be triggered at the\nserver side at push time) can write $GIT_DIR/gc.pid (and soon,\ngc.log). Even if you disable gc --auto and run it periodically (with\ncron or something), it will write gc.pid.\n\nIs it really necessary to remove write access in $GIT_DIR? Do we (git\ndevs) have some guidelines about things in $GIT_DIR?\n-- \nDuy\n"},{"id":"270325","messageId":"CACsJy8BLHw_n=PEHOGNah+-YrQgkVmie6m+PzpkNLHeV4tT4zg@mail.gmail.com","threadId":"40147","inReplyTo":"CACsJy8DFpLLtc7+Mix1d=Hy8h-duUqt4Y8WYsRL1nEryizoeww@mail.gmail.com","subject":"Re: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied","fromName":"Duy Nguyen","fromEmail":"pclouds@gmail.com","sentAt":"2015-09-19T02:26:21Z","receivedAt":"2015-09-19T02:26:21Z","isPatch":false,"sender":{"key":"pclouds@gmail.com","avatar":"https://avatars.githubusercontent.com/u/720?v=4"},"body":"On Sat, Sep 19, 2015 at 9:21 AM, Duy Nguyen <pclouds@gmail.com> wrote:\n> Even if you disable gc --auto and run it periodically (with\n> cron or something), it will write gc.pid.\n\nIgnore this sentence. Of course you can run manual gc using a\ndifferent user and with write access.\n-- \nDuy\n"},{"id":"270328","messageId":"b80246c46079167db6f90ee70de4368b@dscho.org","threadId":"40147","inReplyTo":"CACsJy8DFpLLtc7+Mix1d=Hy8h-duUqt4Y8WYsRL1nEryizoeww@mail.gmail.com","subject":"Re: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2015-09-19T07:13:23Z","receivedAt":"2015-09-19T07:13:23Z","isPatch":false,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi Duy,\n\nOn 2015-09-19 04:21, Duy Nguyen wrote:\n> On Thu, Sep 17, 2015 at 11:54 PM, Joakim Tjernlund\n> <joakim.tjernlund@transmode.se> wrote:\n>> On Thu, 2015-09-17 at 20:18 +0700, Duy Nguyen wrote:\n>>> On Mon, Sep 14, 2015 at 10:37 PM, Joakim Tjernlund\n>>> <joakim.tjernlund@transmode.se> wrote:\n>>> > On Mon, 2015-08-31 at 16:56 +0700, Duy Nguyen wrote:\n>>> > > On Fri, Aug 21, 2015 at 6:36 PM, Joakim Tjernlund\n>>> > > <joakim.tjernlund@transmode.se> wrote:\n>>> > > > I cannot push:\n>>> > > > # > git push origin\n>>> > > > Login for jocke@git.transmode.se\n>>> > > > Password:\n>>> > > > Counting objects: 7, done.\n>>> > > > Delta compression using up to 4 threads.\n>>> > > > Compressing objects: 100% (7/7), done.\n>>> > > > Writing objects: 100% (7/7), 13.73 KiB | 0 bytes/s, done.\n>>> > > > Total 7 (delta 4), reused 0 (delta 0)\n>>> > > > fatal: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission\n>>> > > > denied\n> \n> I'm about to do it, but now I'm not sure if I should move\n> shallow_XXXXXX out of $GIT_DIR. It will not be the only command that\n> may write to $GIT_DIR. \"git gc --auto\" (which can be triggered at the\n> server side at push time) can write $GIT_DIR/gc.pid (and soon,\n> gc.log). Even if you disable gc --auto and run it periodically (with\n> cron or something), it will write gc.pid.\n> \n> Is it really necessary to remove write access in $GIT_DIR? Do we (git\n> devs) have some guidelines about things in $GIT_DIR?\n\nIMO it makes little sense to remove write access from users who you want to push.\n\nThey need to write objects to the directory, after all, and update refs.\n\nThis problem sounds more like the doing of an overzealous sysadmin to me than a careful one who researched diligently what locations require write access for the intended operations.\n\nPersonally, I see little sense in bending over to try to support such an intentionally tampered setup.\n\nCiao,\nDscho\n"},{"id":"270333","messageId":"1442652278.21964.52.camel@transmode.se","threadId":"40147","inReplyTo":"CACsJy8DFpLLtc7+Mix1d=Hy8h-duUqt4Y8WYsRL1nEryizoeww@mail.gmail.com","subject":"Re: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied","fromName":"Joakim Tjernlund","fromEmail":"joakim.tjernlund@transmode.se","sentAt":"2015-09-19T08:44:39Z","receivedAt":"2015-09-19T08:44:39Z","isPatch":false,"sender":{"key":"joakim.tjernlund@transmode.se","avatar":null},"body":"On Sat, 2015-09-19 at 09:21 +0700, Duy Nguyen wrote:\n> On Thu, Sep 17, 2015 at 11:54 PM, Joakim Tjernlund\n> <joakim.tjernlund@transmode.se> wrote:\n> > On Thu, 2015-09-17 at 20:18 +0700, Duy Nguyen wrote:\n> > > On Mon, Sep 14, 2015 at 10:37 PM, Joakim Tjernlund\n> > > <joakim.tjernlund@transmode.se> wrote:\n> > > > On Mon, 2015-08-31 at 16:56 +0700, Duy Nguyen wrote:\n> > > > > On Fri, Aug 21, 2015 at 6:36 PM, Joakim Tjernlund\n> > > > > <joakim.tjernlund@transmode.se> wrote:\n> > > > > > I cannot push:\n> > > > > > # > git push origin\n> > > > > > Login for jocke@git.transmode.se\n> > > > > > Password:\n> > > > > > Counting objects: 7, done.\n> > > > > > Delta compression using up to 4 threads.\n> > > > > > Compressing objects: 100% (7/7), done.\n> > > > > > Writing objects: 100% (7/7), 13.73 KiB | 0 bytes/s, done.\n> > > > > > Total 7 (delta 4), reused 0 (delta 0)\n> > > > > > fatal: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR':\n> > > > > > Permission\n> > > > > > denied\n> \n> I'm about to do it, but now I'm not sure if I should move\n> shallow_XXXXXX out of $GIT_DIR. It will not be the only command that\n> may write to $GIT_DIR. \"git gc --auto\" (which can be triggered at the\n> server side at push time) can write $GIT_DIR/gc.pid (and soon,\n> gc.log). Even if you disable gc --auto and run it periodically (with\n> cron or something), it will write gc.pid.\n> \n> Is it really necessary to remove write access in $GIT_DIR? Do we (git\n> devs) have some guidelines about things in $GIT_DIR?\n\nIt feels a lot cleaner to not let everybody create stuff in $GIT_DIR\nwe have:\n# > ls -l\ntotal 24\ndr-xr-sr-x   6 apache tm-3000  123 Jun 10 15:30 ./\ndrwxr-xr-x  36 root   root    4096 Jun 25 11:11 ../\n-r--r--r--   1 root   tm-3000  263 Jun 10 15:28 config\n-r--r--r--   1 apache tm-3000   73 Jun 10 15:28 description\n-rw-r--r--   1 root   tm-3000    0 Jun 10 15:30 git-daemon-export-ok\n-r--r--r--   1 apache tm-3000   23 Jun 10 15:28 HEAD\ndrwxr-sr-x   2 root   tm-3000 4096 Jun 10 15:28 hooks/\ndrwxrwsr-x   2 apache tm-3000   20 Jun 10 15:28 info/\ndrwxrwsr-x 157 apache tm-3000 4096 Jul 14 15:06 objects/\ndrwxrwsr-x   4 apache tm-3000   29 Jun 10 15:28 refs/\n\nWhy mess this up with tmp files? Would be cleaner to have a specific tmp dir in $GIT_DIR for that.\n\n Jocke"},{"id":"270337","messageId":"1442756186.4802.5.camel@transmode.se","threadId":"40147","inReplyTo":"b80246c46079167db6f90ee70de4368b@dscho.org","subject":"Re: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied","fromName":"Joakim Tjernlund","fromEmail":"joakim.tjernlund@transmode.se","sentAt":"2015-09-20T13:36:26Z","receivedAt":"2015-09-20T13:36:26Z","isPatch":false,"sender":{"key":"joakim.tjernlund@transmode.se","avatar":null},"body":"On Sat, 2015-09-19 at 09:13 +0200, Johannes Schindelin wrote:\n> Hi Duy,\n> \n> On 2015-09-19 04:21, Duy Nguyen wrote:\n> > On Thu, Sep 17, 2015 at 11:54 PM, Joakim Tjernlund\n> > <joakim.tjernlund@transmode.se> wrote:\n> > > On Thu, 2015-09-17 at 20:18 +0700, Duy Nguyen wrote:\n> > > > On Mon, Sep 14, 2015 at 10:37 PM, Joakim Tjernlund\n> > > > <joakim.tjernlund@transmode.se> wrote:\n> > > > > On Mon, 2015-08-31 at 16:56 +0700, Duy Nguyen wrote:\n> > > > > > On Fri, Aug 21, 2015 at 6:36 PM, Joakim Tjernlund\n> > > > > > <joakim.tjernlund@transmode.se> wrote:\n> > > > > > > I cannot push:\n> > > > > > > # > git push origin\n> > > > > > > Login for jocke@git.transmode.se\n> > > > > > > Password:\n> > > > > > > Counting objects: 7, done.\n> > > > > > > Delta compression using up to 4 threads.\n> > > > > > > Compressing objects: 100% (7/7), done.\n> > > > > > > Writing objects: 100% (7/7), 13.73 KiB | 0 bytes/s, done.\n> > > > > > > Total 7 (delta 4), reused 0 (delta 0)\n> > > > > > > fatal: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR':\n> > > > > > > Permission\n> > > > > > > denied\n> > \n> > I'm about to do it, but now I'm not sure if I should move\n> > shallow_XXXXXX out of $GIT_DIR. It will not be the only command that\n> > may write to $GIT_DIR. \"git gc --auto\" (which can be triggered at the\n> > server side at push time) can write $GIT_DIR/gc.pid (and soon,\n> > gc.log). Even if you disable gc --auto and run it periodically (with\n> > cron or something), it will write gc.pid.\n> > \n> > Is it really necessary to remove write access in $GIT_DIR? Do we (git\n> > devs) have some guidelines about things in $GIT_DIR?\n> \n> IMO it makes little sense to remove write access from users who you want to push.\n> \n> They need to write objects to the directory, after all, and update refs.\n> \n> This problem sounds more like the doing of an overzealous sysadmin to me than a careful one who researched\n> diligently what locations require write access for the intended operations.\n\nWe did and it all worked just fine , uses can push as they should. It is just shallow clones\nthat are non working. Why are pushes against normal clones and shallow clones not handled the\nsame way w.r.t tmp file creation?\n\n> \n> Personally, I see little sense in bending over to try to support such an intentionally tampered setup.\n\nBefore bringing out your shootgun, make sure you are aiming it the right target.\n\n Jocke\n"},{"id":"270402","messageId":"xmqqpp1bbtvz.fsf@gitster.mtv.corp.google.com","threadId":"40147","inReplyTo":"CACsJy8DFpLLtc7+Mix1d=Hy8h-duUqt4Y8WYsRL1nEryizoeww@mail.gmail.com","subject":"Re: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2015-09-21T16:48:48Z","receivedAt":"2015-09-21T16:48:48Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Duy Nguyen <pclouds@gmail.com> writes:\n\n> Is it really necessary to remove write access in $GIT_DIR? Do we (git\n> devs) have some guidelines about things in $GIT_DIR?\n\nThose who are allowed to \"git push\" into it should be able to write\nthere.  It is a different matter that \"git\" program itself may make\na policy decision to disallow some operations that the filesystem\nbits alone would have allowed (e.g. you can arrange the \"pusher\" to\nonly come over the wire via \"receive-pack\" and \"receive-pack\" may\ndeliberately lack support for writing into $GIT_DIR/config).\n"},{"id":"270404","messageId":"1442855328.29498.30.camel@transmode.se","threadId":"40147","inReplyTo":"xmqqpp1bbtvz.fsf@gitster.mtv.corp.google.com","subject":"Re: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied","fromName":"Joakim Tjernlund","fromEmail":"joakim.tjernlund@transmode.se","sentAt":"2015-09-21T17:08:49Z","receivedAt":"2015-09-21T17:08:49Z","isPatch":false,"sender":{"key":"joakim.tjernlund@transmode.se","avatar":null},"body":"On Mon, 2015-09-21 at 09:48 -0700, Junio C Hamano wrote:\n> Duy Nguyen <pclouds@gmail.com> writes:\n> \n> > Is it really necessary to remove write access in $GIT_DIR? Do we (git\n> > devs) have some guidelines about things in $GIT_DIR?\n> \n> Those who are allowed to \"git push\" into it should be able to write\n> there.  It is a different matter that \"git\" program itself may make\n> a policy decision to disallow some operations that the filesystem\n> bits alone would have allowed (e.g. you can arrange the \"pusher\" to\n> only come over the wire via \"receive-pack\" and \"receive-pack\" may\n> deliberately lack support for writing into $GIT_DIR/config).\n> \n\nI view $GIT_DIR similar to \"/\" and \"/tmp\". Normally one does not let normal users write to \"/\"\nas you want to keep this level clean. It is not obvious to everybody what files are important\nunder $GIT_DIR when mixed with tmp files etc.\n$GIT_DIR/tmp would solve this nicely.\n\n Jocke"},{"id":"270520","messageId":"37ca95b3fef79e348fb5ba68cd21c590@dscho.org","threadId":"40147","inReplyTo":"1442855328.29498.30.camel@transmode.se","subject":"Re: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2015-09-22T20:00:08Z","receivedAt":"2015-09-22T20:00:08Z","isPatch":false,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi Joakim,\n\nOn 2015-09-21 19:08, Joakim Tjernlund wrote:\n> On Mon, 2015-09-21 at 09:48 -0700, Junio C Hamano wrote:\n>> Duy Nguyen <pclouds@gmail.com> writes:\n>>\n>> > Is it really necessary to remove write access in $GIT_DIR? Do we (git\n>> > devs) have some guidelines about things in $GIT_DIR?\n>>\n>> Those who are allowed to \"git push\" into it should be able to write\n>> there.  It is a different matter that \"git\" program itself may make\n>> a policy decision to disallow some operations that the filesystem\n>> bits alone would have allowed (e.g. you can arrange the \"pusher\" to\n>> only come over the wire via \"receive-pack\" and \"receive-pack\" may\n>> deliberately lack support for writing into $GIT_DIR/config).\n>>\n> \n> I view $GIT_DIR similar to \"/\" and \"/tmp\". Normally one does not let\n> normal users write to \"/\"\n> as you want to keep this level clean. It is not obvious to everybody\n> what files are important\n> under $GIT_DIR when mixed with tmp files etc.\n> $GIT_DIR/tmp would solve this nicely.\n\nBy now it is pretty clear that you won't find many people here you share your opinion about locking down the Git directory.\n\nThe reason should be easy to understand: Git's concept is based on the idea that you have full control over your repository. Other repositories you might only have read access.\n\nBut this idea you have, to somehow introduce fine-grained levels of control, this idea would imply that all of a sudden Git is no longer free to write to its files as it likes. And as far as Git is concerned, everything inside .git/ *are* its files.\n\nSo in essence, the core concept of Git -- you clone a repository you cannot write to so that you have a local repository you can do *anything you like* to -- is pretty much incompatible with this idea of a selective lock down of files in .git/ that not only would require you to know very exactly what files Git might want to write, but also to keep yourself up-to-date with Git's development as to which files it might want to write for *every* new version. Making only .git/tmp/ a writable location further fails to acknowledge the fact that the hierarchy of to-be-written files follows the function of those files, not any write permission hierarchy. Since the idea seems so alien to Git's core concept, I called it \"overzealous\". If that hurt your feelings, I am sorry and would like to apologize\n .\n\nHaving said all that, I believe that reiterating this idea without pointing to any benefit will continue to fail to convince people that the idea is sound and that Git's core concept should change. If you need to exert more control in a specific repository, you simply make it accessible only as a non-file-system remote (where only `git`, `git-receive-pack` and `git-upload-pack` are allowed to be executed) and define hooks that can accept or deny on a *much* finer level than file system permissions ever could, after all.\n\nCiao,\nJohannes\n"},{"id":"270528","messageId":"1442955525.29498.94.camel@transmode.se","threadId":"40147","inReplyTo":"37ca95b3fef79e348fb5ba68cd21c590@dscho.org","subject":"Re: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied","fromName":"Joakim Tjernlund","fromEmail":"joakim.tjernlund@transmode.se","sentAt":"2015-09-22T20:58:45Z","receivedAt":"2015-09-22T20:58:45Z","isPatch":false,"sender":{"key":"joakim.tjernlund@transmode.se","avatar":null},"body":"On Tue, 2015-09-22 at 22:00 +0200, Johannes Schindelin wrote:\n> Hi Joakim,\n> \n> On 2015-09-21 19:08, Joakim Tjernlund wrote:\n> > On Mon, 2015-09-21 at 09:48 -0700, Junio C Hamano wrote:\n> > > Duy Nguyen <pclouds@gmail.com> writes:\n> > > \n> > > > Is it really necessary to remove write access in $GIT_DIR? Do we (git\n> > > > devs) have some guidelines about things in $GIT_DIR?\n> > > \n> > > Those who are allowed to \"git push\" into it should be able to write\n> > > there.  It is a different matter that \"git\" program itself may make\n> > > a policy decision to disallow some operations that the filesystem\n> > > bits alone would have allowed (e.g. you can arrange the \"pusher\" to\n> > > only come over the wire via \"receive-pack\" and \"receive-pack\" may\n> > > deliberately lack support for writing into $GIT_DIR/config).\n> > > \n> > \n> > I view $GIT_DIR similar to \"/\" and \"/tmp\". Normally one does not let\n> > normal users write to \"/\"\n> > as you want to keep this level clean. It is not obvious to everybody\n> > what files are important\n> > under $GIT_DIR when mixed with tmp files etc.\n> > $GIT_DIR/tmp would solve this nicely.\n> \n> By now it is pretty clear that you won't find many people here you share your opinion about locking down the\n> Git directory.\n\nSo I note.\n\n> \n> The reason should be easy to understand: Git's concept is based on the idea that you have full control over\n> your repository. Other repositories you might only have read access.\n\nYes and some repos I only have partial write access to(config, hooks etc. might be readonly) \n\n> \n> But this idea you have, to somehow introduce fine-grained levels of control, this idea would imply that all\n> of a sudden Git is no longer free to write to its files as it likes. And as far as Git is concerned,\n> everything inside .git/ *are* its files.\n\nThis does not compute for me, files inside git are git's files, I only think that not all users\nto a repo should have the same (write) access. In this case it mostly to protect the repo from \"creative\"\nusers and accidents.\n\n> \n> So in essence, the core concept of Git -- you clone a repository you cannot write to so that you have a\n> local repository you can do *anything you like* to -- is pretty much incompatible with this idea of a\n> selective lock down of files in .git/ that not only would require you to know very exactly what files Git\n> might want to write, but also to keep yourself up-to-date with Git's development as to which files it might\n\n\nDon't see how I can avoid some of that if you want to protect areas of the repo from accidents etc.\n\n> want to write for *every* new version. Making only .git/tmp/ a writable location further fails to\n> acknowledge the fact that the hierarchy of to-be-written files follows the function of those files, not any\n\n\nCurious, how would you set up some level of protection on a repo?\n\nA .git/tmp/ would make housekeeping easier, you would know that every file under .git\nshould be there and if you find something you don't recognize you would react.\n\n> write permission hierarchy. Since the idea seems so alien to Git's core concept, I called it \"overzealous\".\n> If that hurt your feelings, I am sorry and would like to apologize.\n\nNo feelings hurt, I too regret my choise of words.\n\n> Having said all that, I believe that reiterating this idea without pointing to any benefit will continue to\n> fail to convince people that the idea is sound and that Git's core concept should change. If you need to\n> exert more control in a specific repository, you simply make it accessible only as a non-file-system remote\n> (where only `git`, `git-receive-pack` and `git-upload-pack` are allowed to be executed) and define hooks\n> that can accept or deny on a *much* finer level than file system permissions ever could, after all.\n\nEven if I did go through this hassle, I would prefer if temporary data were put somewhere else\nthan .git/ as I think mixing config/persistent data with temporary data in the same directory is something\nthat should be avoided.\n\nAnyhow, I see that this idea is not something upstream agrees on so I will back off now.\n\n  Jocke"},{"id":"270572","messageId":"5f56381a3cf5a5ccf6a1e4e3ea48f516@dscho.org","threadId":"40147","inReplyTo":"1442955525.29498.94.camel@transmode.se","subject":"Re: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2015-09-23T11:10:35Z","receivedAt":"2015-09-23T11:10:35Z","isPatch":false,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi Joakim,\n\nOn 2015-09-22 22:58, Joakim Tjernlund wrote:\n> On Tue, 2015-09-22 at 22:00 +0200, Johannes Schindelin wrote:\n>>\n>> The reason should be easy to understand: Git's concept is based on the idea that you have full control over\n>> your repository. Other repositories you might only have read access.\n> \n> Yes and some repos I only have partial write access to(config, hooks\n> etc. might be readonly)\n\nThe partial write access idea is definitely not part of the original idea of Git, and your use case is actually the first I heard of.\n\nThe original idea was really that you either own your repository, or you do not. And that includes the repositories that can be accessed publicly: you own them or you don't.\n\nNow, I know that in particular in some corporate setups, there needs to be a permission system in place that disallows certain users from doing certain things (such as editing the config).\n\nThe Git solution is to set up a server, usually with SSH, and allow users to push and fetch from the repositories, but nothing else (i.e. no shell access), then set up hooks to implement the permission system.\n\nThis is much less error prone than partially locking down a repository on some network drive because the file system structure simply does not reflect the permission structure. That is where all your troubles come from.\n\n>> But this idea you have, to somehow introduce fine-grained levels of control, this idea would imply that all\n>> of a sudden Git is no longer free to write to its files as it likes. And as far as Git is concerned,\n>> everything inside .git/ *are* its files.\n> \n> This does not compute for me, files inside git are git's files, I only\n> think that not all users\n> to a repo should have the same (write) access.\n\nBut then it is your duty to tell *Git* what it can and what it cannot do. Typically via those hooks I mentioned.\n\n> A .git/tmp/ would make housekeeping easier, you would know that every\n> file under .git\n> should be there and if you find something you don't recognize you would react.\n\nNo, it would actually make it harder. I seem to recall that there was some problem with renaming a file unless it was already in the same directory as the destination. If all files were to be written to .git/tmp/ first...\n\n>> If you need to exert more control in a specific repository, you simply make it accessible only as a non-file-system remote\n>> (where only `git`, `git-receive-pack` and `git-upload-pack` are allowed to be executed) and define hooks\n>> that can accept or deny on a *much* finer level than file system permissions ever could, after all.\n> \n> Even if I did go through this hassle, I would prefer if temporary data\n> were put somewhere else\n> than .git/ as I think mixing config/persistent data with temporary\n> data in the same directory is something\n> that should be avoided.\n\nSure, I understand what you ask for. It's just that Git worked in a different direction for 10 years now ;-)\n\nCiao,\nJohannes\n"},{"id":"270579","messageId":"xmqqwpvhxj63.fsf@gitster.mtv.corp.google.com","threadId":"40147","inReplyTo":"5f56381a3cf5a5ccf6a1e4e3ea48f516@dscho.org","subject":"Re: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2015-09-23T15:13:56Z","receivedAt":"2015-09-23T15:13:56Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Johannes Schindelin <johannes.schindelin@gmx.de> writes:\n\n>> A .git/tmp/ would make housekeeping easier, you would know that every\n>> file under .git\n>> should be there and if you find something you don't recognize you would react.\n>\n> No, it would actually make it harder. I seem to recall that there was\n> some problem with renaming a file unless it was already in the same\n> directory as the destination. If all files were to be written to\n> .git/tmp/ first...\n\nI agree with you here.  This \"some filesystems do not like\ncross-directory renames\" was also why I thought the idea to create\neverything in $GIT_DIR/tmp and moving to the final destination would\nnot fly well.\n\nFor the specific issue with the shallow-cutoff list temporarily\ncreated, however, it is created, written to, read from and removed\nwithout ever leaving the original place, so we could designate one\nwritable \"temporary\" place somewhere under $GIT_DIR, and $GIT_DIR/tmp\ncould certainly that designated temporary place.\n\nBy the way, the temporary shallow-cutoff-list is created by callingy\nxmks_tempfile().  I wonder if it can safely changed to use\nmks_tempfile() instead.  That way, people can set up a wrapper for\nreceive-pack that sets up a suitable TMPDIR exported to the real\nthing to relocate it.\n"},{"id":"270605","messageId":"1443040900.29498.119.camel@transmode.se","threadId":"40147","inReplyTo":"5f56381a3cf5a5ccf6a1e4e3ea48f516@dscho.org","subject":"Re: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied","fromName":"Joakim Tjernlund","fromEmail":"joakim.tjernlund@transmode.se","sentAt":"2015-09-23T20:41:40Z","receivedAt":"2015-09-23T20:41:40Z","isPatch":false,"sender":{"key":"joakim.tjernlund@transmode.se","avatar":null},"body":"On Wed, 2015-09-23 at 13:10 +0200, Johannes Schindelin wrote:\n> Hi Joakim,\n> \n> On 2015-09-22 22:58, Joakim Tjernlund wrote:\n> > On Tue, 2015-09-22 at 22:00 +0200, Johannes Schindelin wrote:\n> > > \n> > > The reason should be easy to understand: Git's concept is based on the idea that you have full control\n> > > over\n> > > your repository. Other repositories you might only have read access.\n> > \n> > Yes and some repos I only have partial write access to(config, hooks\n> > etc. might be readonly)\n> \n> The partial write access idea is definitely not part of the original idea of Git, and your use case is\n> actually the first I heard of.\n\nOuch, that cannot be so?? The first thing one would do for some level of accident protection \nwould be to just change privs on a few selected files/dirs. \n\n> \n> The original idea was really that you either own your repository, or you do not. And that includes the\n> repositories that can be accessed publicly: you own them or you don't.\n> \n> Now, I know that in particular in some corporate setups, there needs to be a permission system in place that\n> disallows certain users from doing certain things (such as editing the config).\n\nExactly! This is what we are doing.\n\n> \n> The Git solution is to set up a server, usually with SSH, and allow users to push and fetch from the\n> repositories, but nothing else (i.e. no shell access), then set up hooks to implement the permission system.\n\nBut this is too big of an ax just to get any protection at all. Dedicating a server just for this\nis very costly, both the physical/virtual server and to maintain it. \n\n> \n> This is much less error prone than partially locking down a repository on some network drive because the\n> file system structure simply does not reflect the permission structure. That is where all your troubles come\n> from.\n\nSure, but here is room for improvement.\n\n Jocke\n"},{"id":"270608","messageId":"815b23cb50fa299d5a70b99f6ff04225@dscho.org","threadId":"40147","inReplyTo":"1443040900.29498.119.camel@transmode.se","subject":"Re: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2015-09-23T22:48:51Z","receivedAt":"2015-09-23T22:48:51Z","isPatch":false,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi Joakim,\n\nOn 2015-09-23 22:41, Joakim Tjernlund wrote:\n> On Wed, 2015-09-23 at 13:10 +0200, Johannes Schindelin wrote:\n>>\n>> On 2015-09-22 22:58, Joakim Tjernlund wrote:\n>> > On Tue, 2015-09-22 at 22:00 +0200, Johannes Schindelin wrote:\n>> > >\n>> > > The reason should be easy to understand: Git's concept is based on the idea that you have full control\n>> > > over\n>> > > your repository. Other repositories you might only have read access.\n>> >\n>> > Yes and some repos I only have partial write access to(config, hooks\n>> > etc. might be readonly)\n>>\n>> The partial write access idea is definitely not part of the original idea of Git, and your use case is\n>> actually the first I heard of.\n> \n> Ouch, that cannot be so??\n\nYes, it can be so. In fat, it is so.\n\nPlease note that I *did* encounter valid scenarios where some operations might not be desirable (and therefore need to be prevented).\n\nOne such scenario (maybe even the first one) was to prevent non-fast-forward pushes. But you will certainly agree that this cannot be prevented by mere file system permission: they are not fine-grained enough. So we introduced a config option -- because in contrast to file system permissions, Git *does* have the means to enforce that rule.\n\nSo it all comes back to the point I made earlier, and that I really would like you to understand: Git's concepts do not align well with file system permissions. Not well at all, in fact.\n\nSo the method of choice is indeed what you called that \"big axe\" which is not such a big axe after all. You just need to set up an SSH server and define very clearly in the hooks what you consider permissible. Yep, that's a bit of work, but it is less work than would be required of Git to bend it so the same could be done via file system permissions. And stay that way.\n\nNow, it might be possible for some operations, to *make* Git align with that permission system. But that sounds more and more like the desired changes would require Git developers to put in a lot of work in favor of others being able to avoid work, just for the sake of keeping with an idea that has been demonstrated to be flawed. If you are looking for fans of that idea, count me out ;-) Of course, if you are willing to put in the work to make it possible to restrict certain Git operations simply by using `chmod`, and to pay attention that it stays that way, go right ahead and submit a patch series to that end... Junio already indicated that he would not be flatly opposed to accept such changes ;-)\n\nCiao,\nJohannes\n"}]}