git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied

From
JTJoakim Tjernlund <joakim.tjernlund@transmode.se>
Date
Sep 23, 2015, 20:41 UTC
Message-ID
<1443040900.29498.119.camel@transmode.se>
In-Reply-To
<5f56381a3cf5a5ccf6a1e4e3ea48f516@dscho.org>
On Wed, 2015-09-23 at 13:10 +0200, Johannes Schindelin wrote:
Show 14 quoted lines
> Hi Joakim,
> 
> On 2015-09-22 22:58, Joakim Tjernlund wrote:
> > On Tue, 2015-09-22 at 22:00 +0200, Johannes Schindelin wrote:
> > > 
> > > The reason should be easy to understand: Git's concept is based on the idea that you have full control
> > > over
> > > your repository. Other repositories you might only have read access.
> > 
> > Yes and some repos I only have partial write access to(config, hooks
> > etc. might be readonly)
> 
> The partial write access idea is definitely not part of the original idea of Git, and your use case is
> actually the first I heard of.

Ouch, that cannot be so?? The first thing one would do for some level of accident protection would be to just change privs on a few selected files/dirs.

Show 6 quoted lines
> 
> The original idea was really that you either own your repository, or you do not. And that includes the
> repositories that can be accessed publicly: you own them or you don't.
> 
> Now, I know that in particular in some corporate setups, there needs to be a permission system in place that
> disallows certain users from doing certain things (such as editing the config).
Exactly! This is what we are doing.
> 
> The Git solution is to set up a server, usually with SSH, and allow users to push and fetch from the
> repositories, but nothing else (i.e. no shell access), then set up hooks to implement the permission system.

But this is too big of an ax just to get any protection at all. Dedicating a server just for this is very costly, both the physical/virtual server and to maintain it.

> 
> This is much less error prone than partially locking down a repository on some network drive because the
> file system structure simply does not reflect the permission structure. That is where all your troubles come
> from.
Sure, but here is room for improvement.
 Jocke
Previous: Junio C HamanoNext: Johannes Schindelin
Message 19 of 20 in “Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied”
  1. Joakim TjernlundAug 21, 2015
  2. Joakim TjernlundAug 21, 2015
  3. Joakim TjernlundAug 31, 2015
  4. Duy NguyenAug 31, 2015
  5. Joakim TjernlundSep 14, 2015
  6. Duy NguyenSep 17, 2015
  7. Joakim TjernlundSep 17, 2015
  8. Duy NguyenSep 19, 2015
  9. Duy NguyenSep 19, 2015
  10. Johannes SchindelinSep 19, 2015
  11. Joakim TjernlundSep 20, 2015
  12. Joakim TjernlundSep 19, 2015
  13. Junio C HamanoSep 21, 2015
  14. Joakim TjernlundSep 21, 2015
  15. Johannes SchindelinSep 22, 2015
  16. Joakim TjernlundSep 22, 2015
  17. Johannes SchindelinSep 23, 2015
  18. Junio C HamanoSep 23, 2015
  19. Joakim TjernlundSep 23, 2015
  20. Johannes SchindelinSep 23, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.