{"thread":{"id":"64684","subject":"Git destroys u+s and g+s directory modes","startedAt":"2025-12-27T02:43:48Z","lastAt":"2026-01-02T07:55:29Z","messageCount":9,"participants":["Hadmut Danisch","Michal Suchánek","rsbecker@nexbridge.com","Andreas Schwab","Gabor Gombas","Jeff King"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"532770","messageId":"eb36360d-f539-4f77-b175-57330ef05eac@danisch.de","threadId":"64684","inReplyTo":null,"subject":"Git destroys u+s and g+s directory modes","fromName":"Hadmut Danisch","fromEmail":"hadmut@danisch.de","sentAt":"2025-12-27T02:37:51Z","receivedAt":"2025-12-27T02:43:48Z","isPatch":false,"sender":{"key":"hadmut@danisch.de","avatar":null},"body":"Hi,\n\n(please respond to my e-mail as well, not just to the list, I'm not \nsubscribed),\n\n\nI do have a problem with git 2.43.0 (ubuntu server 24.04.3) and \ndirectory modes:\n\n\nI do need my git repo (owned by me) to be readable by a system user \n(running a rootless podman container).\n\nI therefore set a special group for the directory, and set the sgid bit \nof the directory ( chgrp ... and chmod 2770 ), but when doing a git \nclone onto that directory, git rewrites all file modes, including the \none of the root directory, and the  S_ISGID is lost.\n\n\nThe only setting I found about file modes is core.fileMode, but git docs \ntell that this is for file systems that do not keep permissions \ncorrectly, such as CIFS or Windows bases file systems, not for keeping \ngit from changing.\n\nThe only way I found is to define a hook to correctly set modes after \ngit pull.\n\n\nIs there a way to keep git from destroying group permission and S_ISGID?\n\n\nIf not: Proposal to set a bit mask with file mode flags git shouldn't touch?\n\n\nregards\n\nHadmut\n\n\n\n\n"},{"id":"532779","messageId":"aU_lqe2Z47STv68O@kitsune.suse.cz","threadId":"64684","inReplyTo":"eb36360d-f539-4f77-b175-57330ef05eac@danisch.de","subject":"Re: Git destroys u+s and g+s directory modes","fromName":"Michal Suchánek","fromEmail":"msuchanek@suse.de","sentAt":"2025-12-27T13:56:57Z","receivedAt":"2025-12-27T13:57:04Z","isPatch":false,"sender":{"key":"msuchanek@suse.de","avatar":"https://avatars.githubusercontent.com/u/787652?v=4"},"body":"On Sat, Dec 27, 2025 at 03:37:51AM +0100, Hadmut Danisch wrote:\n> Hi,\n> \n> (please respond to my e-mail as well, not just to the list, I'm not\n> subscribed),\n> \n> \n> I do have a problem with git 2.43.0 (ubuntu server 24.04.3) and directory\n> modes:\n> \n> \n> I do need my git repo (owned by me) to be readable by a system user (running\n> a rootless podman container).\n\nWhen you want it to be readable you do not need any special permission\nbits.\n\nYou can set the directories and files to be readable by group, and\nensure the container user is part of the group.\n\nYou are porbably looking for core.sharedRepository configuration option.\n\nIf git is particularly unhappy accessing a readonly repository and the\ncontainer is short-lived you can add an overlay over the repository when\ncreating the container.\n\nHTH\n\nMichal\n"},{"id":"532780","messageId":"008901dc773c$f05508c0$d0ff1a40$@nexbridge.com","threadId":"64684","inReplyTo":"aU_lqe2Z47STv68O@kitsune.suse.cz","subject":"RE: Git destroys u+s and g+s directory modes","fromName":"","fromEmail":"rsbecker@nexbridge.com","sentAt":"2025-12-27T14:27:26Z","receivedAt":"2025-12-27T14:30:25Z","isPatch":false,"sender":{"key":"randall.becker@nexbridge.ca","avatar":"https://avatars.githubusercontent.com/u/28956764?v=4"},"body":"On December 27, 2025 8:57 AM, Michal Suchánek wrote:\n> On Sat, Dec 27, 2025 at 03:37:51AM +0100, Hadmut Danisch wrote:\n> > Hi,\n> >\n> > (please respond to my e-mail as well, not just to the list, I'm not\n> > subscribed),\n> >\n> >\n> > I do have a problem with git 2.43.0 (ubuntu server 24.04.3) and\n> > directory\n> > modes:\n> >\n> >\n> > I do need my git repo (owned by me) to be readable by a system user\n> > (running a rootless podman container).\n> \n> When you want it to be readable you do not need any special permission\nbits.\n> \n> You can set the directories and files to be readable by group, and ensure\nthe\n> container user is part of the group.\n> \n> You are porbably looking for core.sharedRepository configuration option.\n> \n> If git is particularly unhappy accessing a readonly repository and the\ncontainer is\n> short-lived you can add an overlay over the repository when creating the\n> container.\n\nThere is an option with ubuntu: Access Control Lists (ACLs). These provide\noverride security for directories that might assist in your process without\nhaving to worry about git security settings. It might be worth looking into\nthis option.\n\nRandall\n\n\n"},{"id":"532781","messageId":"74793560-49ae-494e-afff-9b833dd25d1c@danisch.de","threadId":"64684","inReplyTo":"008901dc773c$f05508c0$d0ff1a40$@nexbridge.com","subject":"Re: Git destroys u+s and g+s directory modes","fromName":"Hadmut Danisch","fromEmail":"hadmut@danisch.de","sentAt":"2025-12-27T14:40:11Z","receivedAt":"2025-12-27T14:40:15Z","isPatch":false,"sender":{"key":"hadmut@danisch.de","avatar":null},"body":"\nAm 27.12.25 um 15:27 schrieb rsbecker@nexbridge.com:\n> There is an option with ubuntu: Access Control Lists (ACLs). These provide\n> override security for directories that might assist in your process without\n> having to worry about git security settings. It might be worth looking into\n> this option.\n\n\nThis does not solve the problem, since ACLs do not propagate into newly \ncreated subdirectories, as group ownership with S_ISGID flag does.\n\n\nPlease try to understand the problem before trying to solve it.\n\n\nregards\n\nHadmut\n\n\n\n\n"},{"id":"532782","messageId":"aU/wuT23Ybllu/1q@danisch.de","threadId":"64684","inReplyTo":"aU_lqe2Z47STv68O@kitsune.suse.cz","subject":"Re: Git destroys u+s and g+s directory modes","fromName":"Hadmut Danisch","fromEmail":"hadmut@danisch.de","sentAt":"2025-12-27T14:44:09Z","receivedAt":"2025-12-27T14:44:11Z","isPatch":false,"sender":{"key":"hadmut@danisch.de","avatar":null},"body":"On Sat, Dec 27, 2025 at 02:56:57PM +0100, Michal Suchánek wrote:\n> \n> When you want it to be readable you do not need any special permission\n> bits.\n> \n> You can set the directories and files to be readable by group, and\n> ensure the container user is part of the group.\n\n\nAnd that's the problem: \n\n\"ensure the container user is part of the group\" is what the S_ISGID flag on directories is good for: It ensures that newly created directories inherit their parent's group. Unix administration basics. \n\nAnd this is the bit git clears and breaks this mechanism. \n\n\nregards\n\nHadmut\n\n\n"},{"id":"532783","messageId":"009101dc7744$3ead0480$bc070d80$@nexbridge.com","threadId":"64684","inReplyTo":"74793560-49ae-494e-afff-9b833dd25d1c@danisch.de","subject":"RE: Git destroys u+s and g+s directory modes","fromName":"","fromEmail":"rsbecker@nexbridge.com","sentAt":"2025-12-27T15:19:44Z","receivedAt":"2025-12-27T15:20:28Z","isPatch":false,"sender":{"key":"randall.becker@nexbridge.ca","avatar":"https://avatars.githubusercontent.com/u/28956764?v=4"},"body":"On December 27, 2025 9:40 AM, Hadmut Danisch wrote:\n> Am 27.12.25 um 15:27 schrieb rsbecker@nexbridge.com:\n> > There is an option with ubuntu: Access Control Lists (ACLs). These\n> > provide override security for directories that might assist in your\n> > process without having to worry about git security settings. It might\n> > be worth looking into this option.\n> \n> \n> This does not solve the problem, since ACLs do not propagate into newly created\n> subdirectories, as group ownership with S_ISGID flag does.\n> \n> \n> Please try to understand the problem before trying to solve it.\n\nWithout trying to be critical, the POSIX ACLs I have seen provide an option\nthat provides inheritance, so nothing in the repository will block those. That\nis why I mentioned it. However, perhaps ubuntu does not support that\ncapability.\n\n"},{"id":"532784","messageId":"87ldiovtz9.fsf@igel.home","threadId":"64684","inReplyTo":"74793560-49ae-494e-afff-9b833dd25d1c@danisch.de","subject":"Re: Git destroys u+s and g+s directory modes","fromName":"Andreas Schwab","fromEmail":"schwab@linux-m68k.org","sentAt":"2025-12-27T15:12:58Z","receivedAt":"2025-12-27T15:22:05Z","isPatch":false,"sender":{"key":"schwab@linux-m68k.org","avatar":"https://avatars.githubusercontent.com/u/2175493?v=4"},"body":"On Dez 27 2025, Hadmut Danisch wrote:\n\n> Am 27.12.25 um 15:27 schrieb rsbecker@nexbridge.com:\n>> There is an option with ubuntu: Access Control Lists (ACLs). These provide\n>> override security for directories that might assist in your process without\n>> having to worry about git security settings. It might be worth looking into\n>> this option.\n>\n>\n> This does not solve the problem, since ACLs do not propagate into newly\n> created subdirectories, as group ownership with S_ISGID flag does.\n\nYou can set the default ACL on a directory, which is then inherited by\nall newly created files.\n\n-- \nAndreas Schwab, schwab@linux-m68k.org\nGPG Key fingerprint = 7578 EB47 D4E5 4D69 2510  2552 DF73 E780 A9DA AEC1\n\"And now for something completely different.\"\n"},{"id":"532787","messageId":"aVBUg289AKC0HIVx@lan","threadId":"64684","inReplyTo":"74793560-49ae-494e-afff-9b833dd25d1c@danisch.de","subject":"Re: Git destroys u+s and g+s directory modes","fromName":"Gabor Gombas","fromEmail":"gombasgg@gmail.com","sentAt":"2025-12-27T21:49:55Z","receivedAt":"2025-12-27T21:49:59Z","isPatch":false,"sender":{"key":"gombasgg@gmail.com","avatar":null},"body":"On Sat, Dec 27, 2025 at 03:40:11PM +0100, Hadmut Danisch wrote:\n\n> This does not solve the problem, since ACLs do not propagate into newly\n> created subdirectories, as group ownership with S_ISGID flag does.\n> \n> \n> Please try to understand the problem before trying to solve it.\n\nWell, default ACLs may very well be the solution to your problem,\nbecause git does not understand ACLs, so it would leave them alone. Of\ncoure, managing ACLs at scale have their fair share of problems, so\nYMMV. The problem with the permission bits is git trying to be clever\nand thinking it can manage them - but as often, trying to be clever ends\nup not being clever at all. Unfortunately, there does not seem to be a\nconfiguration option to tell git to leave permission bits alone.\ncore.filemode is the closest one, but what you want is the opposite\nbehavior - what you want is not ignoring the executable bit, but\nignoring everything _except_ the executable bit. Maybe you can try to\nmake a patch...\n\nRegards,\nGabor\n"},{"id":"532905","messageId":"20260102075528.GE2581074@coredump.intra.peff.net","threadId":"64684","inReplyTo":"eb36360d-f539-4f77-b175-57330ef05eac@danisch.de","subject":"Re: Git destroys u+s and g+s directory modes","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2026-01-02T07:55:28Z","receivedAt":"2026-01-02T07:55:29Z","isPatch":false,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Sat, Dec 27, 2025 at 03:37:51AM +0100, Hadmut Danisch wrote:\n\n> I do have a problem with git 2.43.0 (ubuntu server 24.04.3) and directory\n> modes:\n> \n> \n> I do need my git repo (owned by me) to be readable by a system user (running\n> a rootless podman container).\n> \n> I therefore set a special group for the directory, and set the sgid bit of\n> the directory ( chgrp ... and chmod 2770 ), but when doing a git clone onto\n> that directory, git rewrites all file modes, including the one of the root\n> directory, and the  S_ISGID is lost.\n\nCan you show more exactly what commands you're running? From your\ndescription, it sounds like this:\n\n  mkdir clone\n\n  # just a convenient group that I happen to be in but which is not the\n  # default\n  chgrp audio clone\n  chmod 2770 clone\n\n  ls -ld clone\n  git clone $SOME_URL clone\n  ls -ld clone clone/* clone/*/* clone/.git\n\nBefore the clone, I have:\n\n  drwxrws--- 2 peff audio 4096 Jan  2 02:53 clone\n\nand after:\n\n  drwxrws--- 4 peff audio 4096 Jan  2 02:53 clone\n  drwxrwsr-x 8 peff audio 4096 Jan  2 02:53 clone/.git\n  drwxrwsr-x 2 peff audio 4096 Jan  2 02:53 clone/sub\n  -rw-rw-r-- 1 peff audio    8 Jan  2 02:53 clone/sub/file\n\nSo the sgid bits were preserved and propagated to subdirectories, and\neverything was added to the correct group. Do you get different results?\nOr does my recipe not match what you're trying to do?\n\n-Peff\n"}]}