{"thread":{"id":"62427","subject":"safe.directory warnings for root-owned repositories","startedAt":"2024-10-31T04:31:07Z","lastAt":"2024-10-31T20:04:54Z","messageCount":4,"participants":["Michael Orlitzky","Caleb White","Taylor Blau"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"506347","messageId":"ZyMGKHTnZDQ5JVuo@mertle","threadId":"62427","inReplyTo":null,"subject":"safe.directory warnings for root-owned repositories","fromName":"Michael Orlitzky","fromEmail":"michael@orlitzky.com","sentAt":"2024-10-31T04:23:04Z","receivedAt":"2024-10-31T04:31:07Z","isPatch":false,"sender":{"key":"michael@orlitzky.com","avatar":null},"body":"If I create a new repository as root,\n\n  $ sudo git init\n  Initialized empty Git repository in /home/mjo/tmp/.git/\n\n  $ ls -alh\n  total 12K\n  drwxr-xr-x  3 mjo  mjo  4.0K 2024-10-31 00:09 .\n  drwxr-x--- 17 mjo  mjo  4.0K 2024-10-31 00:07 ..\n  drwxr-xr-x  6 root root 4.0K 2024-10-31 00:09 .git\n\nand attempt to do anything in it, I get a safe.directory warning:\n\n  $ git status\n  fatal: detected dubious ownership in repository at '/home/mjo/tmp'\n  ...\n\nDoes that make sense? In terms of ownership, root:root is as safe as\nit gets.\n\nI'm aware that safe.directory is only scratching the surface of these\n\"doing things in a directory that someone else can write to\" exploits,\nbut within the limited scope of this one feature, root ownership does\nnot strike me as particularly dubious.\n"},{"id":"506357","messageId":"D59QZ1P3KSNB.ZXDHUA5HGC97@pm.me","threadId":"62427","inReplyTo":"ZyMGKHTnZDQ5JVuo@mertle","subject":"Re: safe.directory warnings for root-owned repositories","fromName":"Caleb White","fromEmail":"cdwhite3@pm.me","sentAt":"2024-10-31T05:38:00Z","receivedAt":"2024-10-31T05:38:05Z","isPatch":false,"sender":{"key":"cdwhite3@pm.me","avatar":"https://avatars.githubusercontent.com/u/4176520?v=4"},"body":"On Wed Oct 30, 2024 at 11:23 PM CDT, Michael Orlitzky wrote:\n> If I create a new repository as root,\n>\n>   $ sudo git init\n>   Initialized empty Git repository in /home/mjo/tmp/.git/\n>\n>   $ ls -alh\n>   total 12K\n>   drwxr-xr-x  3 mjo  mjo  4.0K 2024-10-31 00:09 .\n>   drwxr-x--- 17 mjo  mjo  4.0K 2024-10-31 00:07 ..\n>   drwxr-xr-x  6 root root 4.0K 2024-10-31 00:09 .git\n>\n> and attempt to do anything in it, I get a safe.directory warning:\n>\n>   $ git status\n>   fatal: detected dubious ownership in repository at '/home/mjo/tmp'\n>   ...\n>\n> Does that make sense? In terms of ownership, root:root is as safe as\n> it gets.\n>\n> I'm aware that safe.directory is only scratching the surface of these\n> \"doing things in a directory that someone else can write to\" exploits,\n> but within the limited scope of this one feature, root ownership does\n> not strike me as particularly dubious.\n\nThe dubious ownership check simply reports that the directory is owned by\nsomeone other than the user running the command, with no special handling\nfor the root user. While the error might not make the most sense in this\ncontext, I'm not sure that it's worth special-casing the root user\n(really the user with id = 0 as it might not be named `root`) in the\nimplementation.\n\nWhy would you initialize a repository as `root` in the first place?\n\nBest,\nCaleb\n\n"},{"id":"506385","messageId":"ZyN03D8os53XJGDo@mertle","threadId":"62427","inReplyTo":"D59QZ1P3KSNB.ZXDHUA5HGC97@pm.me","subject":"Re: safe.directory warnings for root-owned repositories","fromName":"Michael Orlitzky","fromEmail":"michael@orlitzky.com","sentAt":"2024-10-31T12:15:24Z","receivedAt":"2024-10-31T12:15:26Z","isPatch":false,"sender":{"key":"michael@orlitzky.com","avatar":null},"body":"On 2024-10-31 05:38:00, Caleb White wrote:\n> \n> The dubious ownership check simply reports that the directory is owned by\n> someone other than the user running the command, with no special handling\n> for the root user. While the error might not make the most sense in this\n> context, I'm not sure that it's worth special-casing the root user\n> (really the user with id = 0 as it might not be named `root`) in the\n> implementation.\n> \n> Why would you initialize a repository as `root` in the first place?\n\nTo avoid the dubious ownership warning, obviously :)\n\nThese are shared repositories that I and my coworkers push to over\nSSH. Write access is granted via ACLs, with ownership being mostly\nirrelevant. (This is still \"unsafe,\" but not for the stated reason.)\n\nI don't necessarily have a problem with adding O(m*n) safe.directory\nentries, but every once in a while someone will ask me about it, and I\ndon't have a good answer for why it's not safe to push to a repository\nthat's owned by root. I guess it's just more annoying to have to\noverride the warning when the warning is wrong. Though if it was\nchanged to \"dubious repository writability,\" I wouldn't be able to\ncomplain any more.\n"},{"id":"506403","messageId":"ZyPi4xdGPwfa9+ez@nand.local","threadId":"62427","inReplyTo":"ZyN03D8os53XJGDo@mertle","subject":"Re: safe.directory warnings for root-owned repositories","fromName":"Taylor Blau","fromEmail":"me@ttaylorr.com","sentAt":"2024-10-31T20:04:51Z","receivedAt":"2024-10-31T20:04:54Z","isPatch":false,"sender":{"key":"me@ttaylorr.com","avatar":"https://avatars.githubusercontent.com/u/301000140?v=4"},"body":"On Thu, Oct 31, 2024 at 08:15:24AM -0400, Michael Orlitzky wrote:\n> On 2024-10-31 05:38:00, Caleb White wrote:\n> >\n> > The dubious ownership check simply reports that the directory is owned by\n> > someone other than the user running the command, with no special handling\n> > for the root user. While the error might not make the most sense in this\n> > context, I'm not sure that it's worth special-casing the root user\n> > (really the user with id = 0 as it might not be named `root`) in the\n> > implementation.\n> >\n> > Why would you initialize a repository as `root` in the first place?\n>\n> To avoid the dubious ownership warning, obviously :)\n\nIf you want to avoid the warning entirely, you can set 'safe.directory'\nto \"*\" at the global level, and that will opt-out of the check entirely.\n\nOf course, you should consult that portion of the git-config(1) manual\npage to understand the implications of doing so, but it is something\nthat Git supports doing.\n\nThanks,\nTaylor\n"}]}