{"thread":{"id":"61516","subject":"git-daemon doesn't work as expected in v2.45.1 and friends","startedAt":"2024-05-20T08:21:38Z","lastAt":"2024-05-21T20:40:49Z","messageCount":4,"participants":["Ondrej Pohorelsky","Konstantin Ryabitsev","Junio C Hamano"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"495067","messageId":"CA+B51BGonS2DDTBQ2RsipW4Cyg5pRv0U71RAN9M1pcPjACtJ4A@mail.gmail.com","threadId":"61516","inReplyTo":null,"subject":"git-daemon doesn't work as expected in v2.45.1 and friends","fromName":"Ondrej Pohorelsky","fromEmail":"opohorel@redhat.com","sentAt":"2024-05-20T08:21:23Z","receivedAt":"2024-05-20T08:21:38Z","isPatch":false,"sender":{"key":"opohorel@redhat.com","avatar":"https://avatars.githubusercontent.com/u/35430604?v=4"},"body":"Hi,\n\nduring testing the newest security releases in RHEL and in Fedora, we\nhave encountered broken git-daemon behavior. In a nutshell, git client\nrefuses to clone locally hosted repositories because of detected\ndubious ownership.\n\nI'll paste part of the Fedora report [0] here:\n\n```\nUpon clone, git-daemon logs the following:\n\n    [1482] Connection from ::1:45090\n    [1482] Extended attribute \"host\": localhost\n    [1482] Extended attribute \"protocol\": version=2\n    [1482] Request upload-pack for '/test.git'\n    fatal: detected dubious ownership in repository at '/var/lib/git/test.git'\n    To add an exception for this directory, call:\n            git config --global --add safe.directory /var/lib/git/test.git\n\n\nReproducible: Always\n\nSteps to Reproduce:\n1. Create repository under /var/lib/git/test.git\n2. Ensure git.socket systemd unit is started\n3. Run git clone git://localhost/test.git\nActual Results:\ngit server refuses to read /var/lib/git/site.git because it detects dubious\nownership\n```\n\nIs there a way to make git-daemon hosted repositories safe to clone,\nwithout specifying safe.directory in git config? AFAIK this is widely\nused feature of Git not only by the end users, but also quite a lot of\ntests rely on it.\n\n[0]https://bugzilla.redhat.com/show_bug.cgi?id=2281530\n\nCheers,\nOndřej Pohořelský\n\n"},{"id":"495160","messageId":"20240521-evasive-mindful-stoat-c58b31@meerkat","threadId":"61516","inReplyTo":"CA+B51BGonS2DDTBQ2RsipW4Cyg5pRv0U71RAN9M1pcPjACtJ4A@mail.gmail.com","subject":"Re: git-daemon doesn't work as expected in v2.45.1 and friends","fromName":"Konstantin Ryabitsev","fromEmail":"konstantin@linuxfoundation.org","sentAt":"2024-05-21T13:27:03Z","receivedAt":"2024-05-21T13:27:09Z","isPatch":false,"sender":{"key":"konstantin@linuxfoundation.org","avatar":"https://gravatar.com/avatar/7cb8827c6de56e1bd2dea16508c6708aa43feed3bf3813bcdacecdf96ceadd79?d=mp&s=160"},"body":"On Mon, May 20, 2024 at 10:21:23AM GMT, Ondrej Pohorelsky wrote:\n> Is there a way to make git-daemon hosted repositories safe to clone,\n> without specifying safe.directory in git config? AFAIK this is widely\n> used feature of Git not only by the end users, but also quite a lot of\n> tests rely on it.\n\nI would say more -- this is very broken and needs to be rolled back. Running\ngit-daemon as a different user is the recommended setup for read-only\ndeployments.\n\n-K\n"},{"id":"495169","messageId":"xmqq5xv7chud.fsf@gitster.g","threadId":"61516","inReplyTo":"20240521-evasive-mindful-stoat-c58b31@meerkat","subject":"Re: git-daemon doesn't work as expected in v2.45.1 and friends","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2024-05-21T15:20:10Z","receivedAt":"2024-05-21T15:20:17Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Konstantin Ryabitsev <konstantin@linuxfoundation.org> writes:\n\n> On Mon, May 20, 2024 at 10:21:23AM GMT, Ondrej Pohorelsky wrote:\n>> Is there a way to make git-daemon hosted repositories safe to clone,\n>> without specifying safe.directory in git config? AFAIK this is widely\n>> used feature of Git not only by the end users, but also quite a lot of\n>> tests rely on it.\n>\n> I would say more -- this is very broken and needs to be rolled back. Running\n> git-daemon as a different user is the recommended setup for read-only\n> deployments.\n\nIs this from f4aa8c8b (fetch/clone: detect dubious ownership of\nlocal repositories, 2024-04-10) where the commit sprinkled a\n\"protection\" meant only for \"local clone\" to more generic code paths\nthat are also used by \"git daemon\" serving a remote clients?  It may\nbe that the commit was a bit too aggressive and had a blast radius\nthat is much larger than intended?\n\nI think that 1204e1a8 (builtin/clone: refuse local clones of unsafe\nrepositories, 2024-04-15), which is a very pointed fix to ensure we\ndo not \"hardlink copy\" local repository owned by others for\nsecurity, was a good use of die_upon_dubious_ownership() call,\nthough.\n\nReverting f4aa8c8b may not be easy to do mechanically, as it\nintroduces the die_upon_dubious_ownership(), but 1204e1a8 uses an\nidentical copy of the same function introduced by 8c9c051b (setup.c:\nintroduce `die_upon_dubious_ownership()`, 2024-04-15), and reverting\nf4aa8c8b mechanically out of the merged result in v2.45.1 would\nlikely to remove the function that is still in use, which would need\nto be retained.\n\n"},{"id":"495225","messageId":"xmqq7cfmaofl.fsf@gitster.g","threadId":"61516","inReplyTo":"xmqq5xv7chud.fsf@gitster.g","subject":"Re: git-daemon doesn't work as expected in v2.45.1 and friends","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2024-05-21T20:40:46Z","receivedAt":"2024-05-21T20:40:49Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Junio C Hamano <gitster@pobox.com> writes:\n\n> Reverting f4aa8c8b may not be easy to do mechanically, as it\n> introduces the die_upon_dubious_ownership(), but 1204e1a8 uses an\n> identical copy of the same function introduced by 8c9c051b (setup.c:\n> introduce `die_upon_dubious_ownership()`, 2024-04-15), and reverting\n> f4aa8c8b mechanically out of the merged result in v2.45.1 would\n> likely to remove the function that is still in use, which would need\n> to be retained.\n\nWell the result can be seen at\n\n    https://lore.kernel.org/git/20240521195659.870714-1-gitster@pobox.com/\n\nbut I am inclined to say that its [12/12] (partial reversion of\nf4aa8c8b) is highly questionable, after thinking about it a bit\nmore.  It is true that you can run git-daemon as 'nobody', let it\npeek into repositories owned by real users, feeling safe that\n'nobody' would not be able to harm these repositories at all.  \n\nBut unless this is a tightly controlled hosting environment where no\nrepository owned by \"real users\" have malicious hooks and config\nfiles, a \"real user\" could attack \"nobody\", and the safe.directory\nmechanism that is over-agressive in denying things may alleviate the\nproblem.  At places like k.org where the repository data including\nits hooks and configuration files are trusted, setting up the\nconfiguration safe.directory in the ~nobody/.gitconfig to cover the\nreal user repositories would probably be a simple enough workaround.\n\n\n"}]}