git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: regression: "96b9e0e3 config: treat user and xdg config permission problems as errors" busted git-daemon

From
Jeff King <peff@peff.net>
Date
Apr 11, 2013, 20:08 UTC
Message-ID
<20130411200818.GE1255@sigill.intra.peff.net>
In-Reply-To
<7vwqs8hmh1.fsf@alter.siamese.dyndns.org>
On Thu, Apr 11, 2013 at 12:54:34PM -0700, Junio C Hamano wrote:
Show 15 quoted lines
> > I could go either way. I think 96b9e0e is the right thing to do
> > conceptually, but I kind of doubt it was affecting all that many people.
> > And though it's _possible_ for it to be a security problem, I find it
> > much more likely that the site admin tries to set some config, gets
> > annoyed when it doesn't work, and debugs it. So from a practical
> > perspective, 96b9e0e may be doing more harm than good, even though it's
> > the right thing.
> 
> Recent reports in this thread make us think so, I guess.
> 
> But reverting 96b9e0e alone would not help these people very much
> though.  They will have reams of warning messages in their server
> logs, and the way to "fix" it would be the same as the way to work
> around the access_or_die(), namely, to set $HOME to point at a more
> appropriate place before running "git daemon".

Yeah, if we revert 96b9e0e, it would only make sense to revert the warnings, too. Going halfway does not help anyone.

Show 9 quoted lines
> I also have a suspicion that your patch makes things worse for
> people who are more adept at these issues around running daemons
> than the people who introduced this problem in the first place (eh,
> that's "us").  It is plausible that they may run multiple instances
> of "initially root but setuid() to an unprivileged user" daemons,
> giving each of them a separate play area by setting $HOME to
> different values, just for management's ease not necessarily for
> security (hence sharing the same unprivileged user), which will be
> broken by the patch that unconditionally overrides $HOME.

Yes, we would definitely be breaking them with this patch. I don't know how common that is. As you noted, it is a bad idea security-wise (if everything runs as "nobody", then the services are not insulated from each other), but I can perhaps see a case where all git repos are owned by the "git" user, but they may be accessed by different config profiles, which are managed by $HOME.

You could still accomplish the same thing with git by setting XDG_CONFIG_HOME, though that of course requires effort from the admin. Sub-programs may not necessarily respect $XDG_CONFIG_HOME, though (e.g., anything run from a post-receive hook). On the other hand, people do not generally push through git-daemon. But that feels like a weak argument.

-Peff
Previous: Mike Galbraith
Message 39 of 39 in “regression: "96b9e0e3 config: treat user and xdg config permission problems as errors" busted git-daemon”
  1. Mike GalbraithApr 10, 2013
  2. W. Trevor KingApr 10, 2013
  3. Mike GalbraithApr 11, 2013
  4. Jeff KingApr 11, 2013
  5. Mike GalbraithApr 11, 2013
  6. Junio C HamanoApr 11, 2013
  7. Jeff KingApr 11, 2013
  8. Jonathan NiederApr 11, 2013
  9. Jeff KingApr 11, 2013
  10. Jonathan NiederApr 11, 2013
  11. Junio C HamanoApr 11, 2013
  12. W. Trevor KingApr 11, 2013
  13. Junio C HamanoApr 11, 2013
  14. Jeff KingApr 11, 2013
  15. W. Trevor KingApr 12, 2013
  16. Junio C HamanoApr 12, 2013
  17. Jeff KingApr 12, 2013
  18. Junio C HamanoApr 12, 2013
  19. Jeff KingApr 12, 2013
  20. Mike GalbraithApr 12, 2013
  21. W. Trevor KingApr 12, 2013
  22. Jeff KingApr 12, 2013
  23. Junio C HamanoApr 12, 2013
  24. Jeff KingApr 12, 2013
  25. Jeff KingApr 12, 2013
  26. Junio C HamanoApr 12, 2013
  27. Jeff KingApr 12, 2013
  28. Junio C HamanoApr 12, 2013
  29. Jeff KingApr 12, 2013
  30. Junio C HamanoApr 12, 2013
  31. config: allow inaccessible configuration under $HOMEJonathan Nieder, Apr 12, 2013
  32. Jeff KingApr 12, 2013
  33. fixup! config: allow inaccessible configuration under $HOMEJonathan Nieder, Apr 12, 2013
  34. config: allow inaccessible configuration under $HOMEJonathan Nieder, Apr 12, 2013
  35. Mike GalbraithApr 13, 2013
  36. Jason A. DonenfeldMay 25, 2013
  37. Junio C HamanoApr 12, 2013
  38. Mike GalbraithApr 12, 2013
  39. Jeff KingApr 11, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.