{"thread":{"id":"4322","subject":"[PATCH] git-receive-pack needs to set umask(2)","startedAt":"2006-05-28T21:31:41Z","lastAt":"2006-05-29T21:50:35Z","messageCount":9,"participants":["Michael Richardson","Jakub Narebski","Petr Baudis","Johannes Schindelin","Salikh Zakirov","Shawn Pearce","Linus Torvalds","Alex Riesen"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"20839","messageId":"v0irnpn8ea.fsf@marajade.sandelman.ca","threadId":"4322","inReplyTo":null,"subject":"[PATCH] git-receive-pack needs to set umask(2)","fromName":"Michael Richardson","fromEmail":"mcr@sandelman.ottawa.on.ca","sentAt":"2006-05-28T21:31:41Z","receivedAt":"2006-05-28T21:31:41Z","isPatch":true,"sender":{"key":"mcr@sandelman.ottawa.on.ca","avatar":null},"body":"\nIf there is another way to solve this, please let me know.\nWrapping git-receive-pack with a shell script to call umask seemed like too\nglobal a change.\n(also http://git.openswan.org/git#umask_hack)\n\nWhen working with a common git repository, not all users are always clueful\nenough to set their umask properly --- nor should the default for the user\nalways be so permissive.\n\nThis change adds $GIT_DIR/umask to contain a single line, an integer\nwhich will be fed to umask(). This should also work for the git daemon,\nwhich I personally do not use, so this may be inappropriate.\n\nSigned-off-by: Michael Richardson <mcr@xelerance.com>\n\n---\n\n8698daf8fedc8618593ec44574df1efb9f31db84\n Documentation/git-receive-pack.txt |    3 +++\n cache.h                            |    1 +\n path.c                             |    2 ++\n setup.c                            |   19 +++++++++++++++++++\n 4 files changed, 25 insertions(+), 0 deletions(-)\n\n8698daf8fedc8618593ec44574df1efb9f31db84\ndiff --git a/Documentation/git-receive-pack.txt b/Documentation/git-receive-pack.txt\nindex 60debca..d3a8c11 100644\n--- a/Documentation/git-receive-pack.txt\n+++ b/Documentation/git-receive-pack.txt\n@@ -74,6 +74,9 @@ packed and is served via a dumb transpor\n There are other real-world examples of using update and\n post-update hooks found in the Documentation/howto directory.\n \n+The file $GIT_DIR/umask, if it exists will be opened, and the integer found\n+in it will be used to initialize the umask(2) for subsequent file creation\n+operations. \n \n OPTIONS\n -------\ndiff --git a/cache.h b/cache.h\nindex 3a46fb9..65d5124 100644\n--- a/cache.h\n+++ b/cache.h\n@@ -355,6 +355,7 @@ extern int git_config_bool(const char *,\n extern int git_config_set(const char *, const char *);\n extern int git_config_set_multivar(const char *, const char *, const char *, int);\n extern int check_repository_format_version(const char *var, const char *value);\n+extern void setup_umask();\n \n #define MAX_GITNAME (1000)\n extern char git_default_email[MAX_GITNAME];\ndiff --git a/path.c b/path.c\nindex 334b2bd..571ff01 100644\n--- a/path.c\n+++ b/path.c\n@@ -244,6 +244,8 @@ char *enter_repo(char *path, int strict)\n \tif (access(\"objects\", X_OK) == 0 && access(\"refs\", X_OK) == 0 &&\n \t    validate_symref(\"HEAD\") == 0) {\n \t\tputenv(\"GIT_DIR=.\");\n+\n+\t\tsetup_umask();\n \t\tcheck_repository_format();\n \t\treturn path;\n \t}\ndiff --git a/setup.c b/setup.c\nindex fe7f884..2129125 100644\n--- a/setup.c\n+++ b/setup.c\n@@ -228,6 +228,25 @@ int check_repository_format_version(cons\n        return 0;\n }\n \n+void setup_umask(void)\n+{\n+\tFILE *f;\n+\n+\tf = fopen(git_path(\"umask\"), \"r\");\n+\tif(f != NULL) {\n+\t\tchar maskstr[32];\n+\t\tif(fgets(maskstr, sizeof(maskstr), f) != NULL) {\n+\t\t\tchar *foo;\n+\t\t\tunsigned int mask = strtoul(maskstr, &foo, 0);\n+\t\t\t\n+\t\t\tif(foo != maskstr) {\n+\t\t\t\tumask(mask);\n+\t\t\t}\n+\t\t}\n+\t\tfclose(f);\n+\t}\n+}\n+\n int check_repository_format(void)\n {\n \tgit_config(check_repository_format_version);\n-- \n1.3.GIT\n\n\n\n\n\n-- \n]       ON HUMILITY: to err is human. To moo, bovine.           |  firewalls  [\n]   Michael Richardson,    Xelerance Corporation, Ottawa, ON    |net architect[\n] mcr@xelerance.com      http://www.sandelman.ottawa.on.ca/mcr/ |device driver[\n] panic(\"Just another Debian GNU/Linux using, kernel hacking, security guy\"); [\n\n    \"The Microsoft _Get the Facts CD_ does not work on Linux.\" - orospakr\n\n"},{"id":"20841","messageId":"e5d6i0$rnf$1@sea.gmane.org","threadId":"4322","inReplyTo":"v0irnpn8ea.fsf@marajade.sandelman.ca","subject":"Re: [PATCH] git-receive-pack needs to set umask(2)","fromName":"Jakub Narebski","fromEmail":"jnareb@gmail.com","sentAt":"2006-05-28T22:00:32Z","receivedAt":"2006-05-28T22:00:32Z","isPatch":true,"sender":{"key":"jnareb@gmail.com","avatar":"https://avatars.githubusercontent.com/u/2706?v=4"},"body":"Michael Richardson wrote:\n\n> This change adds $GIT_DIR/umask to contain a single line, an integer\n> which will be fed to umask(). This should also work for the git daemon,\n> which I personally do not use, so this may be inappropriate.\n\nShouldn't it be done rather via $GIT_DIR/config file, and \ngit-repo-config? I.e. instead of adding new file to repository layout,\n$GIT_DIR/umask, add core.umask to git configuration?\n\n-- \nJakub Narebski\nWarsaw, Poland\n"},{"id":"20843","messageId":"20060528220628.GE10488@pasky.or.cz","threadId":"4322","inReplyTo":"v0irnpn8ea.fsf@marajade.sandelman.ca","subject":"Re: [PATCH] git-receive-pack needs to set umask(2)","fromName":"Petr Baudis","fromEmail":"pasky@ucw.cz","sentAt":"2006-05-28T22:06:28Z","receivedAt":"2006-05-28T22:06:28Z","isPatch":true,"sender":{"key":"pasky@ucw.cz","avatar":"https://avatars.githubusercontent.com/u/18439?v=4"},"body":"Dear diary, on Sun, May 28, 2006 at 11:31:41PM CEST, I got a letter\nwhere Michael Richardson <mcr@sandelman.ottawa.on.ca> said that...\n> If there is another way to solve this, please let me know.\n\nWell, you didn't write what do you actually want to solve. Why do you\nneed to fiddle with the umask at all?\n\nThe object database is considered \"append-only\" unless you do git-prune\n(and you should better not let anyone do that), thus it's enough if you\nset all directories group-writable. Other than access the object\ndatabase, the users probably only want to update the refs - the solution\nis to make refs/heads/ and refs/tags/ group-writable and setgid. This is\nalso what git-init-db --shared (or tools like cg-admin-setuprepo) should\nalready set up for you.\n\nSo, what did break?\n\n-- \n\t\t\t\tPetr \"Pasky\" Baudis\nStuff: http://pasky.or.cz/\nA person is just about as big as the things that make them angry.\n"},{"id":"20868","messageId":"Pine.LNX.4.63.0605290910210.8863@wbgn013.biozentrum.uni-wuerzburg.de","threadId":"4322","inReplyTo":"e5d6i0$rnf$1@sea.gmane.org","subject":"Re: [PATCH] git-receive-pack needs to set umask(2)","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2006-05-29T07:13:18Z","receivedAt":"2006-05-29T07:13:18Z","isPatch":true,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi,\n\nOn Mon, 29 May 2006, Jakub Narebski wrote:\n\n> Michael Richardson wrote:\n> \n> > This change adds $GIT_DIR/umask to contain a single line, an integer\n> > which will be fed to umask(). This should also work for the git daemon,\n> > which I personally do not use, so this may be inappropriate.\n> \n> Shouldn't it be done rather via $GIT_DIR/config file, and \n> git-repo-config? I.e. instead of adding new file to repository layout,\n> $GIT_DIR/umask, add core.umask to git configuration?\n\nSee also\n\nhttp://thread.gmane.org/gmane.comp.version-control.git/13856/focus=13876\n\nThe essence of the thread: If you want to do anything useful in a non-bare \nrepository, you are likely using other tools than git, which do not \ninterpret core.umask or $GIT_DIR/umask.\n\nIf you use a bare repository, just make it shared. No need for an umask.\n\nHth,\nDscho\n"},{"id":"20884","messageId":"447ADAEF.3030806@Intel.com","threadId":"4322","inReplyTo":"Pine.LNX.4.63.0605290910210.8863@wbgn013.biozentrum.uni-wuerzburg.de","subject":"Re: [PATCH] git-receive-pack needs to set umask(2)","fromName":"Salikh Zakirov","fromEmail":"salikh.zakirov@intel.com","sentAt":"2006-05-29T11:28:47Z","receivedAt":"2006-05-29T11:28:47Z","isPatch":true,"sender":{"key":"salikh.zakirov@gmail.com","avatar":null},"body":"Johannes Schindelin wrote:\n> See also\n> \n> http://thread.gmane.org/gmane.comp.version-control.git/13856/focus=13876\n\nI've read the thread, but couldn't find a practical solution there.\n \n> The essence of the thread: If you want to do anything useful in a non-bare \n> repository, you are likely using other tools than git, which do not \n> interpret core.umask or $GIT_DIR/umask.\n> \n> If you use a bare repository, just make it shared. No need for an umask.\n\nCould you please elaborate on what does it mean \"make it shared\"?\n\nMy setup: I have a bare GIT repository on a machine, where everybody can\nSSH into (with full shell access). I've assigned the repo to a special group\nwhere everybody belongs, and done a 'find repo.git -type d | xargs chmod 2775'\n\nThe problem: After someone pushed to the repository, the object directories \n(i.e repo.git/objects/??)\nget created with 755 access rights, and effectively prevent everyone else from pushing\nobjects starting with the same prefix.\n\nThe obvious solution to use umask 002 is not applicable, because\n1) It does not seem practical to enforce umask 002 in everyone's rc files, \nbecause just one forgetful or careless person can break access for all others\n2) I have 'umask 002' in my ~/.profile. Somehow, it does not help,\nbecause ~/.profile is not read on non-interactive SSH sessions\n(to verify that, just try to do 'ssh somehost umask')\n\nThe current workaround for the problem is a cron script, which\nmakes 'find | xargs chmod 2775' every 5 minutes. It works, but is ugly.\n\nIs there any better way to keep correct access rights in a shared repository?\n\nThanks a lot!\n"},{"id":"20885","messageId":"20060529113318.GA27254@spearce.org","threadId":"4322","inReplyTo":"447ADAEF.3030806@Intel.com","subject":"Re: [PATCH] git-receive-pack needs to set umask(2)","fromName":"Shawn Pearce","fromEmail":"spearce@spearce.org","sentAt":"2006-05-29T11:33:18Z","receivedAt":"2006-05-29T11:33:18Z","isPatch":true,"sender":{"key":"spearce@spearce.org","avatar":"https://avatars.githubusercontent.com/u/34844?v=4"},"body":"Salikh Zakirov <Salikh.Zakirov@Intel.com> wrote:\n> Johannes Schindelin wrote:\n> > See also\n> > \n> > http://thread.gmane.org/gmane.comp.version-control.git/13856/focus=13876\n> \n> I've read the thread, but couldn't find a practical solution there.\n>  \n> > The essence of the thread: If you want to do anything useful in a non-bare \n> > repository, you are likely using other tools than git, which do not \n> > interpret core.umask or $GIT_DIR/umask.\n> > \n> > If you use a bare repository, just make it shared. No need for an umask.\n> \n> Could you please elaborate on what does it mean \"make it shared\"?\n> \n> My setup: I have a bare GIT repository on a machine, where everybody can\n> SSH into (with full shell access). I've assigned the repo to a special group\n> where everybody belongs, and done a 'find repo.git -type d | xargs chmod 2775'\n> \n> The problem: After someone pushed to the repository, the object directories \n> (i.e repo.git/objects/??)\n> get created with 755 access rights, and effectively prevent everyone else from pushing\n> objects starting with the same prefix.\n> \n> The obvious solution to use umask 002 is not applicable, because\n> 1) It does not seem practical to enforce umask 002 in everyone's rc files, \n> because just one forgetful or careless person can break access for all others\n> 2) I have 'umask 002' in my ~/.profile. Somehow, it does not help,\n> because ~/.profile is not read on non-interactive SSH sessions\n> (to verify that, just try to do 'ssh somehost umask')\n> \n> The current workaround for the problem is a cron script, which\n> makes 'find | xargs chmod 2775' every 5 minutes. It works, but is ugly.\n> \n> Is there any better way to keep correct access rights in a shared repository?\n\nTry setting 'core.sharedRepository' to true:\n\n\tgit repo-config core.sharedRepository true\n\nand running your chmod script one last time.  See\nDocumentation/config.txt for some details on this switch.\n\n-- \nShawn.\n"},{"id":"20894","messageId":"Pine.LNX.4.64.0605290956190.5623@g5.osdl.org","threadId":"4322","inReplyTo":"447ADAEF.3030806@Intel.com","subject":"Re: [PATCH] git-receive-pack needs to set umask(2)","fromName":"Linus Torvalds","fromEmail":"torvalds@osdl.org","sentAt":"2006-05-29T17:00:42Z","receivedAt":"2006-05-29T17:00:42Z","isPatch":true,"sender":{"key":"torvalds@linux-foundation.org","avatar":"https://avatars.githubusercontent.com/u/1024025?v=4"},"body":"\nI realize that you already found the solution (Core.SharedRepository), \nbut:\n\nOn Mon, 29 May 2006, Salikh Zakirov wrote:\n> \n> 2) I have 'umask 002' in my ~/.profile. Somehow, it does not help,\n> because ~/.profile is not read on non-interactive SSH sessions\n> (to verify that, just try to do 'ssh somehost umask')\n\nThe \".profile\" thing is indeed read only for interactive tasks.\n\nSo use \".bashrc\" instead.\n\nThe reason I mention that is that this has come up before: if you need to \ndo things like setting PATH to point to your ~/bin directory (to use your \nown version of git rather than the system one), or if you want to set \nenvironment variables like GIT_COMMITTER_NAME etc, you should always use \n.bashrc, so that you get the same answers whether you log in \ninteractively, or whether you just do \"ssh host git-cmd\".\n\n\t\tLinus\n"},{"id":"20917","messageId":"20060529212830.GA4074@limbo.home","threadId":"4322","inReplyTo":"Pine.LNX.4.64.0605290956190.5623@g5.osdl.org","subject":"Re: [PATCH] git-receive-pack needs to set umask(2)","fromName":"Alex Riesen","fromEmail":"fork0@t-online.de","sentAt":"2006-05-29T21:28:30Z","receivedAt":"2006-05-29T21:28:30Z","isPatch":true,"sender":{"key":"raa.lkml@gmail.com","avatar":"https://avatars.githubusercontent.com/u/324101?v=4"},"body":"Linus Torvalds, Mon, May 29, 2006 19:00:42 +0200:\n> \n> I realize that you already found the solution (Core.SharedRepository), \n> but:\n> \n> On Mon, 29 May 2006, Salikh Zakirov wrote:\n> > \n> > 2) I have 'umask 002' in my ~/.profile. Somehow, it does not help,\n> > because ~/.profile is not read on non-interactive SSH sessions\n> > (to verify that, just try to do 'ssh somehost umask')\n> \n> The \".profile\" thing is indeed read only for interactive tasks.\n> \n> So use \".bashrc\" instead.\n> \n\nWill not work:\n\n$ man bash\n...\n       When  an  interactive  shell  that is not a login shell is\n       started, bash reads and executes commands from  ~/.bashrc,\n       if  that  file exists. ...\n\nBesides, not everyone has bash as their login shell.\n\nReading man sshd:\n\n     $HOME/.ssh/rc\n             If this file exists, it is run with /bin/sh after reading the\n             environment files but before starting the user's shell or com­\n             mand.  It must not produce any output on stdout; stderr must be\n             used instead.  If X11 forwarding is in use, it will receive the\n             \"proto cookie\" pair in its standard input (and DISPLAY in its\n             environment).  The script must call xauth(1) because sshd will\n             not run xauth automatically to add X11 cookies.\nand\n\n     /etc/ssh/sshrc\n             Like $HOME/.ssh/rc.  This can be used to specify machine-specific\n             login-time initializations globally.  This file should be\n             writable only by root, and should be world-readable.\n\n\nThis guaranteed to work (at least for ssh).\n"},{"id":"20921","messageId":"Pine.LNX.4.63.0605292349510.18299@wbgn013.biozentrum.uni-wuerzburg.de","threadId":"4322","inReplyTo":"20060529212830.GA4074@limbo.home","subject":"Re: [PATCH] git-receive-pack needs to set umask(2)","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2006-05-29T21:50:35Z","receivedAt":"2006-05-29T21:50:35Z","isPatch":true,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi,\n\nOn Mon, 29 May 2006, Alex Riesen wrote:\n\n> [...]\n> Reading man sshd:\n> \n>      $HOME/.ssh/rc\n>              If this file exists, it is run with /bin/sh after reading the\n>              environment files but before starting the user's shell or com­\n>              mand.  It must not produce any output on stdout; stderr must be\n>              used instead.  If X11 forwarding is in use, it will receive the\n>              \"proto cookie\" pair in its standard input (and DISPLAY in its\n>              environment).  The script must call xauth(1) because sshd will\n>              not run xauth automatically to add X11 cookies.\n> and\n> \n>      /etc/ssh/sshrc\n>              Like $HOME/.ssh/rc.  This can be used to specify machine-specific\n>              login-time initializations globally.  This file should be\n>              writable only by root, and should be world-readable.\n> \n> \n> This guaranteed to work (at least for ssh).\n\nBut not for bash. Back to square 1.\n\nCiao,\nDscho\n"}]}