{"thread":{"id":"61965","subject":"Regression bug with latest SAFE ownership patch","startedAt":"2024-08-17T03:15:42Z","lastAt":"2024-08-18T17:30:48Z","messageCount":3,"participants":["James","brian m. carlson","Colin Stagner"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"501176","messageId":"CADCaTgpcmMbLoKR-rWf_roWfbgWJL6HuURDxwovvKQA8syf=vw@mail.gmail.com","threadId":"61965","inReplyTo":null,"subject":"Regression bug with latest SAFE ownership patch","fromName":"James","fromEmail":"purpleidea@gmail.com","sentAt":"2024-08-17T03:15:05Z","receivedAt":"2024-08-17T03:15:42Z","isPatch":false,"sender":{"key":"purpleidea@gmail.com","avatar":"https://gravatar.com/avatar/161941d0314aee3803e1012aa5dedb2403ed9dcd00ec769bce81435493abe18d?d=mp&s=160"},"body":"I am not a subscriber to this mailing list, so please please CC-me on replies.\n\nI believe the recent changes for the safe ownership patch seemed to\nhave introduced a regression. I have a git repo which is on a shared\nserver that I trust and control. Adding a safe.directory does _not_\nallow me to use this repo anymore. I can't even run a `git fetch`\nwithout an error. I have renamed the repo name and directory, but\noutput is otherwise precise. Full logs and versions shown below:\n\njames@computer1:~/whatever$ git remote show server2\nfatal: detected dubious ownership in repository at\n'/home/someoneelse/whatever/.git'\nTo add an exception for this directory, call:\n\n    git config --global --add safe.directory /home/someoneelse/whatever/.git\nfatal: Could not read from remote repository.\n\nPlease make sure you have the correct access rights\nand the repository exists.\njames@computer1:~/whatever$ git config --add safe.directory\n/home/someoneelse/whatever/.git\njames@computer1:~/whatever$ git config --add safe.directory '*'\njames@computer1:~/whatever$ git fetch server2\nfatal: detected dubious ownership in repository at\n'/home/someoneelse/whatever/.git'\nTo add an exception for this directory, call:\n\n    git config --global --add safe.directory /home/someoneelse/whatever/.git\nfatal: Could not read from remote repository.\n\nPlease make sure you have the correct access rights\nand the repository exists.\njames@computer1:~/whatever$ cat .git/config\n[core]\n    repositoryformatversion = 0\n    filemode = true\n    bare = false\n    logallrefupdates = true\n[branch \"master\"]\n    remote = origin\n    merge = refs/heads/master\n[remote \"server2\"]\n    url = ssh://root@server2:/home/someoneelse/whatever/\n    fetch = +refs/heads/*:refs/remotes/server2/*\n[safe]\n    directory = /home/someoneelse/whatever/.git\n    directory = *\njames@computer1:~/whatever$ git version\ngit version 2.45.2\njames@computer1:~/whatever$ ssh root@server2 git version\ngit version 2.45.2\njames@computer1:~/whatever$\n\nThanks,\nJames\n@purpleidea\nhttps://purpleidea.com/\nhttps://github.com/purpleidea/mgmt/\n"},{"id":"501225","messageId":"ZsDC-nRxPIxQmoTj@tapette.crustytoothpaste.net","threadId":"61965","inReplyTo":"CADCaTgpcmMbLoKR-rWf_roWfbgWJL6HuURDxwovvKQA8syf=vw@mail.gmail.com","subject":"Re: Regression bug with latest SAFE ownership patch","fromName":"brian m. carlson","fromEmail":"sandals@crustytoothpaste.net","sentAt":"2024-08-17T15:34:18Z","receivedAt":"2024-08-17T15:34:21Z","isPatch":false,"sender":{"key":"sandals@crustytoothpaste.net","avatar":"https://avatars.githubusercontent.com/u/497054?v=4"},"body":"On 2024-08-17 at 03:15:05, James wrote:\n> I am not a subscriber to this mailing list, so please please CC-me on replies.\n> \n> I believe the recent changes for the safe ownership patch seemed to\n> have introduced a regression. I have a git repo which is on a shared\n> server that I trust and control. Adding a safe.directory does _not_\n> allow me to use this repo anymore. I can't even run a `git fetch`\n> without an error. I have renamed the repo name and directory, but\n> output is otherwise precise. Full logs and versions shown below:\n> \n> james@computer1:~/whatever$ git remote show server2\n> fatal: detected dubious ownership in repository at\n> '/home/someoneelse/whatever/.git'\n> To add an exception for this directory, call:\n> \n>     git config --global --add safe.directory /home/someoneelse/whatever/.git\n> fatal: Could not read from remote repository.\n> \n> Please make sure you have the correct access rights\n> and the repository exists.\n> james@computer1:~/whatever$ git config --add safe.directory\n> /home/someoneelse/whatever/.git\n> james@computer1:~/whatever$ git config --add safe.directory '*'\n\nThis adds the option to the local configuration, but it has to be in the\nglobal (`--global`) or system (`--system`) config.  A malicious user\nthat owned the repository could modify the local config, so it can't be\ntrusted for this reason.\n-- \nbrian m. carlson (they/them or he/him)\nToronto, Ontario, CA\n"},{"id":"501240","messageId":"fe20f819-5b8e-4cca-a094-24e5d4333aa6@howdoi.land","threadId":"61965","inReplyTo":"CADCaTgpcmMbLoKR-rWf_roWfbgWJL6HuURDxwovvKQA8syf=vw@mail.gmail.com","subject":"Re: Regression bug with latest SAFE ownership patch","fromName":"Colin Stagner","fromEmail":"ask+git@howdoi.land","sentAt":"2024-08-18T17:30:35Z","receivedAt":"2024-08-18T17:30:48Z","isPatch":false,"sender":{"key":"ask+git@howdoi.land","avatar":null},"body":"On 8/16/24 22:15, James wrote:\n> I have a git repo which is on a shared server that I trust and control. Adding a safe.directory does _not_ allow me to use this repo anymore.\n\n> james@computer1:~/whatever$ git remote show server2\n\n> [remote \"server2\"]\n>      url = ssh://root@server2:/home/someoneelse/whatever/\n>      fetch = +refs/heads/*:refs/remotes/server2/*\n\nI believe that safe.directory only affects repositories hosted on the \nlocal filesystem—and not on SSH or HTTP(S) remotes.\n\nI would discourage cloning a user repository with the root user, or \nrunning git as root if you can at all avoid it.\n\nSince you already have root access on this system, how difficult would \nit be to add your SSH key as an authorized_key for someoneelse? Then you \ncould use ssh://someoneelse@server2:/home/someoneelse/whatever/.git as \nyour remote.\n\nYou could also share repositories via a simple gatekeeper or forge, like \ngitolite.\n\nColin\n\n"}]}