{"thread":{"id":"61522","subject":"How to disable safe directories?","startedAt":"2024-05-21T08:39:43Z","lastAt":"2024-05-21T14:49:51Z","messageCount":6,"participants":["Jeffrey Walton","Harald Dunkel"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"495153","messageId":"CAH8yC8mPP_2jv8HDBdMxWv6TbiLXeDnD=KmNRMbno2bHQtfH1A@mail.gmail.com","threadId":"61522","inReplyTo":null,"subject":"How to disable safe directories?","fromName":"Jeffrey Walton","fromEmail":"noloader@gmail.com","sentAt":"2024-05-21T08:39:32Z","receivedAt":"2024-05-21T08:39:43Z","isPatch":false,"sender":{"key":"noloader@gmail.com","avatar":null},"body":"Hi Everyone,\n\nI've got a big DoS on my hands since safe directories landed on\nFedora. I think this commit is the one responsible, but I may be\nmistaken: <https://github.com/git/git/commit/8959555cee7e>.\n\nAt this point I've wasted enough time on them. Now I would like to\ndisable them completely.\n\nHow do I disable the safe directory changes?\n\nThanks in advance,\n\nJeff\n"},{"id":"495157","messageId":"3e4a7071-60b0-4f7a-b347-d584d5eb076e@aixigo.com","threadId":"61522","inReplyTo":"CAH8yC8mPP_2jv8HDBdMxWv6TbiLXeDnD=KmNRMbno2bHQtfH1A@mail.gmail.com","subject":"Re: How to disable safe directories?","fromName":"Harald Dunkel","fromEmail":"harald.dunkel@aixigo.com","sentAt":"2024-05-21T10:42:07Z","receivedAt":"2024-05-21T10:42:10Z","isPatch":false,"sender":{"key":"harald.dunkel@aixigo.com","avatar":null},"body":"On 2024-05-21 10:39:32, Jeffrey Walton wrote:\n> Hi Everyone,\n> \n> I've got a big DoS on my hands since safe directories landed on\n> Fedora. I think this commit is the one responsible, but I may be\n> mistaken: <https://github.com/git/git/commit/8959555cee7e>.\n> \n> At this point I've wasted enough time on them. Now I would like to\n> disable them completely.\n> \n> How do I disable the safe directory changes?\n> \n\nThat is actually pretty easy: Kick out the commit. I would suggest\nto turn the die() into a warning(), though, giving people time to\nadopt this restriction.\n\n\nRegards\n\nHarri\n"},{"id":"495158","messageId":"CAH8yC8mNns_XiQHp3=q_tYr03Q+kR1r=2WOYha1XMp+cYs9WDQ@mail.gmail.com","threadId":"61522","inReplyTo":"3e4a7071-60b0-4f7a-b347-d584d5eb076e@aixigo.com","subject":"Re: How to disable safe directories?","fromName":"Jeffrey Walton","fromEmail":"noloader@gmail.com","sentAt":"2024-05-21T10:45:18Z","receivedAt":"2024-05-21T10:45:29Z","isPatch":false,"sender":{"key":"noloader@gmail.com","avatar":null},"body":"On Tue, May 21, 2024 at 6:42 AM Harald Dunkel <harald.dunkel@aixigo.com> wrote:\n>\n> On 2024-05-21 10:39:32, Jeffrey Walton wrote:\n> > Hi Everyone,\n> >\n> > I've got a big DoS on my hands since safe directories landed on\n> > Fedora. I think this commit is the one responsible, but I may be\n> > mistaken: <https://github.com/git/git/commit/8959555cee7e>.\n> >\n> > At this point I've wasted enough time on them. Now I would like to\n> > disable them completely.\n> >\n> > How do I disable the safe directory changes?\n> >\n>\n> That is actually pretty easy: Kick out the commit. I would suggest\n> to turn the die() into a warning(), though, giving people time to\n> adopt this restriction.\n\nThanks Harri.\n\nWould that be something like safe_directories.enabled = false? If not,\ncan you point to a setting?\n\nJeff\n"},{"id":"495164","messageId":"d71c7dff-46a7-4ac8-a8c7-ab4985458071@aixigo.com","threadId":"61522","inReplyTo":"CAH8yC8mNns_XiQHp3=q_tYr03Q+kR1r=2WOYha1XMp+cYs9WDQ@mail.gmail.com","subject":"Re: How to disable safe directories?","fromName":"Harald Dunkel","fromEmail":"harald.dunkel@aixigo.com","sentAt":"2024-05-21T14:25:17Z","receivedAt":"2024-05-21T14:25:20Z","isPatch":false,"sender":{"key":"harald.dunkel@aixigo.com","avatar":null},"body":"On 2024-05-21 12:45:18, Jeffrey Walton wrote:\n> \n> Thanks Harri.\n> \n> Would that be something like safe_directories.enabled = false? If not,\n> can you point to a setting?\n> \n\nIt is possible to disable this feature globally using something\nlike\n\n\tgit config --system --add safe.directory /somepath/.git\n\nSome say even\n\n\tgit config --system --add safe.directory '*'\n\nworks, but I haven't tried that.\n\n\nRegards\n\nHarri\n"},{"id":"495166","messageId":"CAH8yC8nqRSmxHp+9fdPNh29eLv4JZ2+NFnYtOejhf-F+n7jkCw@mail.gmail.com","threadId":"61522","inReplyTo":"d71c7dff-46a7-4ac8-a8c7-ab4985458071@aixigo.com","subject":"Re: How to disable safe directories?","fromName":"Jeffrey Walton","fromEmail":"noloader@gmail.com","sentAt":"2024-05-21T14:40:44Z","receivedAt":"2024-05-21T14:40:55Z","isPatch":false,"sender":{"key":"noloader@gmail.com","avatar":null},"body":"On Tue, May 21, 2024 at 10:25 AM Harald Dunkel <harald.dunkel@aixigo.com> wrote:\n>\n> On 2024-05-21 12:45:18, Jeffrey Walton wrote:\n> >\n> > Thanks Harri.\n> >\n> > Would that be something like safe_directories.enabled = false? If not,\n> > can you point to a setting?\n> >\n>\n> It is possible to disable this feature globally using something\n> like\n>\n>         git config --system --add safe.directory /somepath/.git\n>\n> Some say even\n>\n>         git config --system --add safe.directory '*'\n>\n> works, but I haven't tried that.\n\nThanks Harri.\n\nYeah, that did not work for me, either.\n\nI've been through directory permissions on the workstations and\nservers, and the SELinux contexts on the server. I cannot find\nanything wrong with them. Do you know how to have git tell us what the\nactual problem is? `git -v pull` is not providing more information,\nlike what the actual problem is (it just barfs).\n\nThanks again.\n\nJeff\n"},{"id":"495168","messageId":"98381fb2-5110-4e7f-a504-c5ff75dcd050@aixigo.com","threadId":"61522","inReplyTo":"d71c7dff-46a7-4ac8-a8c7-ab4985458071@aixigo.com","subject":"Re: How to disable safe directories?","fromName":"Harald Dunkel","fromEmail":"harald.dunkel@aixigo.com","sentAt":"2024-05-21T14:49:46Z","receivedAt":"2024-05-21T14:49:51Z","isPatch":false,"sender":{"key":"harald.dunkel@aixigo.com","avatar":null},"body":"On 2024-05-21 16:25:17, Harald Dunkel wrote:\n> \n> It is possible to disable this feature globally using something\n> like\n> \n> \tgit config --system --add safe.directory /somepath/.git\n> \n\nPS: Its obvious that each peer running git can verify only local\ndirectories for dubious access bits. Working with shared remote\nrepositories you have to consider setting the safe.directory option\non the remote server.\n\nSince CVE-2024-32004 assumes an attacker running its own repository,\nI just wonder why he should use the most recent, fixed git version?\n\nRegards\nHarri\n"}]}