git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: "git clone" executed as root on solaris 10 shreds UFS (it is possible to create hardlinks for directories as root under solaris)

From
TGThomas Glanzmann <thomas@glanzmann.de>
Date
Jul 16, 2007, 16:40 UTC
Message-ID
<20070716164042.GB4484@cip.informatik.uni-erlangen.de>
In-Reply-To
<20070716131537.GA26675@cip.informatik.uni-erlangen.de>
Hello,
Show 8 quoted lines
> exactly. The question is: Is it a Solaris bug or is it something that is
> supposed a user is able to do (it doesn't make sense for me)? I posted
> this problem to comp.unix.solaris and also contacted the UFS Maintainer
> of Solaris (it is not the first UFS bug I original found). If I don't
> receive feedback, I am going to open a call with Sun. Whatever is going
> on (hopefully it isn't PEBKAC - but I don't think so) and this time it
> isn't broken hardware either (like the last time I reported a serious
> git bug) because it happens on two machines.
below I quote the answer of the UFS maintainer:
Thomas,
some notes on the unlink(directory) part:

In the case of calling unlink(2) on a directory as a privilidged user, things like ".." (and the link count in the parent) would not be cleaned up.

The man page for unlink(1M) and unlink(2) is very clear about using rmdir(1/2) to remove a directory. It's also very clear that this does exactly what it's supposed to do: Remove a link to a file/directory. Cleaning up the ".." entry (which would clean up the link to the parent) could be considered "extra".

First the standards issues:
    The link(BA_OS) and unlink(BA_OS) descriptions in SVID3 both specify that
    a process with appropriate privileges is allowed to operate on a directory.
    We have claimed to conform to SVID3 since Solaris 2.0 and have not announced
    that we ever plan to EOL SVID3 conformance.
    UFS does support link(2)/unlink(2) with appropriate privilidges of
    directories while ZFS does not.
    The change that would provide ``Cleaning up the ".." entry ...'' would
    violate both SVID3 and POSIX and SUS requirements.  (The unlink(path)
    system call is supposed to remove the directory entry named by path; not
    the directory entry named by path and an arbitrary number of other
    directory entries.)
Second some history:
    Back before there were mkdir() and rmdir() system calls, applications
    wanting to create a directory invoked the setuid root mkdir utility
    which performed a series of mknod() and link() operations to create the
    directory and create dot and dot-dot entries in the new directory.
    Similarly, applications wanting to remove a directory invoked the
    setuid root rmdir uility which performed a series of unlink()
    operations to destroy the directory if it was empty.
    Not quite so far back in ancient history, there is also the point
    that before symlinks were available it was common practice to make
    hard links to directories.  Privileged applications can still do this
    today (as mandated by SVID) using the link() and unlink() system calls
    and the link and unlink commands.
UFS and ZFS are actually both correct, the standards wording permits either way kind of:

<snip> If path1 names a directory, link() shall fail unless the process has appropriate privileges and the implementation supports using link() on directories.

The path argument shall not name a directory unless the process has appropriate privileges and the implementation supports using unlink() on directories. <snip end>

This seems to implicitely allow an escape route; we can declare that no process has sufficient privileges to link(2)/unlink(2) directories or like ZFS did, have the underlaying implementation not supporting it at all.

The proper way is for the application to use the rmdir(2) system call, it's there since ages!

my bottom line: GIT should not call unlink on a directory.
        Thomas
Previous: Thomas GlanzmannNext: Thomas Glanzmann
Message 9 of 25 in “"git clone" executed as root on solaris 10 shreds UFS (it is possible to create hardlinks for directories as root under solaris)”
  1. Thomas GlanzmannJul 16, 2007
  2. Thomas GlanzmannJul 16, 2007
  3. David KastrupJul 16, 2007
  4. Thomas GlanzmannJul 16, 2007
  5. David KastrupJul 16, 2007
  6. Thomas GlanzmannJul 16, 2007
  7. David KastrupJul 16, 2007
  8. Thomas GlanzmannJul 16, 2007
  9. Thomas GlanzmannJul 16, 2007
  10. Thomas GlanzmannJul 16, 2007
  11. Thomas GlanzmannJul 16, 2007
  12. David KastrupJul 16, 2007
  13. Linus TorvaldsJul 16, 2007
  14. Linus TorvaldsJul 16, 2007
  15. Thomas GlanzmannJul 16, 2007
  16. Thomas GlanzmannJul 16, 2007
  17. Thomas GlanzmannJul 18, 2007
  18. Linus TorvaldsJul 18, 2007
  19. Thomas GlanzmannJul 18, 2007
  20. Thomas GlanzmannJul 16, 2007
  21. Johannes SixtJul 16, 2007
  22. Brian DowningJul 16, 2007
  23. Brian DowningJul 16, 2007
  24. David KastrupJul 16, 2007
  25. Thomas GlanzmannJul 16, 2007

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.