{"thread":{"id":"63216","subject":"How to get git-daemon to work in a post-CVE world?","startedAt":"2025-03-30T08:31:28Z","lastAt":"2025-03-31T20:45:04Z","messageCount":4,"participants":["MegaBrutal","Konstantin Ryabitsev"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"515292","messageId":"CAE8gLhmKtV-Kz4jYT6r1NanmGdAyzd0CumVGsVnVpePQPAtnzQ@mail.gmail.com","threadId":"63216","inReplyTo":null,"subject":"How to get git-daemon to work in a post-CVE world?","fromName":"MegaBrutal","fromEmail":"megabrutal@gmail.com","sentAt":"2025-03-30T08:30:00Z","receivedAt":"2025-03-30T08:31:28Z","isPatch":false,"sender":{"key":"megabrutal@gmail.com","avatar":null},"body":"Hi Everyone,\n\nI'm new to the list, just thought it's the best place to talk about\nGit. I'm running a public read-only git server with git-daemon. I've\nrecently noticed that my repos can't be cloned and found that\nparticular CVE which made git to verify the owners of the git repos.\n\nfatal: detected dubious ownership in repository at '/srv/git/mgsautils.git'\n\nThe feasible solution is to declare the directory safe in .gitconfig.\nContrary to my policy of not creating a home for my services, I made a\nhome for git-daemon and placed a .gitconfig there. It seems to have an\neffect, because the error message has changed to the following:\n\nfatal: detected dubious ownership in repository at '.'\n\nNow how to solve this? It's a relative path so I wouldn't know what it\nhas a problem with. I obviously can't declare '.' safe in .gitconfig,\nbecause it could have unintended consequences. I understand it's a\nsecurity feature, but it's starting to get too cumbersome to work\naround to reestablish the original intended behavior. (Earlier I found\nout that I also need to create a .gitconfig for my git-shell users as\nwell.)\n\n\nBest regards,\nMegaBrutal\n"},{"id":"515367","messageId":"20250331-devious-woodpecker-of-temperance-b18608@lemur","threadId":"63216","inReplyTo":"CAE8gLhmKtV-Kz4jYT6r1NanmGdAyzd0CumVGsVnVpePQPAtnzQ@mail.gmail.com","subject":"Re: How to get git-daemon to work in a post-CVE world?","fromName":"Konstantin Ryabitsev","fromEmail":"konstantin@linuxfoundation.org","sentAt":"2025-03-31T14:53:16Z","receivedAt":"2025-03-31T14:53:18Z","isPatch":false,"sender":{"key":"konstantin@linuxfoundation.org","avatar":"https://gravatar.com/avatar/7cb8827c6de56e1bd2dea16508c6708aa43feed3bf3813bcdacecdf96ceadd79?d=mp&s=160"},"body":"On Sun, Mar 30, 2025 at 10:30:00AM +0200, MegaBrutal wrote:\n> Hi Everyone,\n> \n> I'm new to the list, just thought it's the best place to talk about\n> Git. I'm running a public read-only git server with git-daemon. I've\n> recently noticed that my repos can't be cloned and found that\n> particular CVE which made git to verify the owners of the git repos.\n> \n> fatal: detected dubious ownership in repository at '/srv/git/mgsautils.git'\n> \n> The feasible solution is to declare the directory safe in .gitconfig.\n\nYou can set global values in /etc/gitconfig, e.g.:\n\n    [safe]\n      directory = /srv/git/*\n\n-K\n"},{"id":"515397","messageId":"CAE8gLh=1bqA6UTR4wAX1u1naic2cSGiekz0jLKxWeaxBKa=xiQ@mail.gmail.com","threadId":"63216","inReplyTo":"20250331-devious-woodpecker-of-temperance-b18608@lemur","subject":"Re: How to get git-daemon to work in a post-CVE world?","fromName":"MegaBrutal","fromEmail":"megabrutal@gmail.com","sentAt":"2025-03-31T20:15:00Z","receivedAt":"2025-03-31T20:16:57Z","isPatch":false,"sender":{"key":"megabrutal@gmail.com","avatar":null},"body":"Konstantin Ryabitsev <konstantin@linuxfoundation.org> ezt írta\n(időpont: 2025. márc. 31., H, 16:53):\n>\n> On Sun, Mar 30, 2025 at 10:30:00AM +0200, MegaBrutal wrote:\n> > Hi Everyone,\n> >\n> > I'm new to the list, just thought it's the best place to talk about\n> > Git. I'm running a public read-only git server with git-daemon. I've\n> > recently noticed that my repos can't be cloned and found that\n> > particular CVE which made git to verify the owners of the git repos.\n> >\n> > fatal: detected dubious ownership in repository at '/srv/git/mgsautils.git'\n> >\n> > The feasible solution is to declare the directory safe in .gitconfig.\n>\n> You can set global values in /etc/gitconfig, e.g.:\n>\n>     [safe]\n>       directory = /srv/git/*\n\nThanks! While it is much more convenient to set it in one global\n/etc/gitconfig than individual home directories, I encountered the\nfollowing problems:\n\n1. It doesn't do anything with the other error I get, when the\nproblematic directory is '.'. I still keep getting that error message.\n2. Git daemon doesn't seem to resolve the '*' wildcard, i.e. with the\nwildcard I get the original message back which complains about\n'/srv/git/mgsautils.git', despite it should be covered by\n'/srv/git/*'. When I supply the full path, however, the error message\nis still about '.'.\n\nI even performed a whole Ubuntu release upgrade to get a new version\nof Git, but 2.43.0 acts the same. Seems like git-daemon is more\nstricts than plain git – what might be the problem?\n"},{"id":"515400","messageId":"20250331-thistle-wolverine-of-jest-b11d9b@lemur","threadId":"63216","inReplyTo":"CAE8gLh=1bqA6UTR4wAX1u1naic2cSGiekz0jLKxWeaxBKa=xiQ@mail.gmail.com","subject":"Re: How to get git-daemon to work in a post-CVE world?","fromName":"Konstantin Ryabitsev","fromEmail":"konstantin@linuxfoundation.org","sentAt":"2025-03-31T20:45:03Z","receivedAt":"2025-03-31T20:45:04Z","isPatch":false,"sender":{"key":"konstantin@linuxfoundation.org","avatar":"https://gravatar.com/avatar/7cb8827c6de56e1bd2dea16508c6708aa43feed3bf3813bcdacecdf96ceadd79?d=mp&s=160"},"body":"On Mon, Mar 31, 2025 at 10:15:00PM +0200, MegaBrutal wrote:\n> > > I'm new to the list, just thought it's the best place to talk about\n> > > Git. I'm running a public read-only git server with git-daemon. I've\n> > > recently noticed that my repos can't be cloned and found that\n> > > particular CVE which made git to verify the owners of the git repos.\n> > >\n> > > fatal: detected dubious ownership in repository at '/srv/git/mgsautils.git'\n> > >\n> > > The feasible solution is to declare the directory safe in .gitconfig.\n> >\n> > You can set global values in /etc/gitconfig, e.g.:\n> >\n> >     [safe]\n> >       directory = /srv/git/*\n> \n> Thanks! While it is much more convenient to set it in one global\n> /etc/gitconfig than individual home directories, I encountered the\n> following problems:\n> \n> 1. It doesn't do anything with the other error I get, when the\n> problematic directory is '.'. I still keep getting that error message.\n> 2. Git daemon doesn't seem to resolve the '*' wildcard, i.e. with the\n> wildcard I get the original message back which complains about\n> '/srv/git/mgsautils.git', despite it should be covered by\n> '/srv/git/*'. When I supply the full path, however, the error message\n> is still about '.'.\n> \n> I even performed a whole Ubuntu release upgrade to get a new version\n> of Git, but 2.43.0 acts the same. Seems like git-daemon is more\n> stricts than plain git – what might be the problem?\n\n2.43.0 is not very new. I believe in that version it only supported setting\nthat to '*' as a wildcard, so the following should work for you, hopefully:\n\n    [safe]\n      directory = *\n\n-K\n"}]}