git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git-daemon: needs /root/.config/git/config?

From
IKIan Kumlien <pomac@vapor.com>
Date
Jun 5, 2013, 11:19 UTC
Message-ID
<20130605111918.GE22308@pomac.netswarm.net>
In-Reply-To
<20130604160815.GB15953@sigill.intra.peff.net>
On Tue, Jun 04, 2013 at 12:08:15PM -0400, Jeff King wrote:
Show 15 quoted lines
> On Tue, Jun 04, 2013 at 04:13:14PM +0200, Ian Kumlien wrote:
> 
> > Due to the earlier problem I upgraded git on all machines 
> > and eneded up with a ubunut machine running in to problems.
> > 
> > I started getting errors like:
> > "fatal: protocol error: bad line length character: fata"
> > 
> > Which after some head scratching caused me to tell xinetd to directly
> > launch git-daemon, eventually it worked fine, but i did get this error
> > message:
> 
> Looks like your stderr was being redirected to your stdout; this
> particular error aside, that is likely to cause weird protocol problems
> for any error that git outputs.
Yeah =)
Show 12 quoted lines
> > Jun  4 16:12:05 xyz git-daemon[10246]: unable to access
> > '/root/.config/git/config': Permission denied
> > 
> > It's not the first time i've seen it but i've been able to ignore it
> > before. This is running as a local user (as in not root) and this user
> > shouldn't have access to /root. But i eventually had to do chown o+x
> > /root to workaround this error.
> 
> The problem is that you have presumably dropped privileges in the daemon
> instance, but your $HOME environment variable still points to /root. Git
> cannot read all of its config files (nor even find out if they exist),
> so it bails rather than continue.
Yeah, assumed =P
> Older versions of git silently ignored errors reading config files, but
> it was tightened in v1.8.1.1, as there can be quite serious implications
> to failing to read expected config (e.g., imagine transfer.fsckobjects,
> or receive.deny* is ignored).

Yes, i agree, it's suboptimal but I for one would use getpwuid to get the home directory of the executing user to avoid this - though i don't know how portable it is (or if there is any other issues)

It's a bit hard to control this with xinetd doing it behind the scenes...

Show 5 quoted lines
> However, since changing user id and leaving $HOME is so common, there is
> a patch under consideration to loosen the check only for the case of
> EACCES on files in $HOME. That commit is 4698c8f (config: allow
> inaccessible configuration under $HOME, 2013-04-12); it's not yet in any
> released version of git, though.

Ah, ok, thanks, I'll have a look - maybe i can actually contribute something for once =)

> In the meantime, the suggested workaround is to set $HOME for the
> git-daemon user, rather than loosening /root.

Well, I have no idea of how to control HOME in xinetd - access to the machine is limited and x doesn't give that much access (nothing really important is actually stored in /root)

For now, this is the workaround we have =P
> -Peff
Previous: Junio C HamanoNext: Andreas Krey
Message 8 of 12 in “git-daemon: needs /root/.config/git/config?”
  1. Ian KumlienJun 4, 2013
  2. Jeff KingJun 4, 2013
  3. Johannes SixtJun 4, 2013
  4. Jonathan NiederJun 4, 2013
  5. Junio C HamanoJun 4, 2013
  6. Jeff KingJun 4, 2013
  7. Junio C HamanoJun 4, 2013
  8. Ian KumlienJun 5, 2013
  9. Andreas KreyJun 5, 2013
  10. Jeff KingJun 5, 2013
  11. Bernhard R. LinkJun 9, 2013
  12. Ian KumlienJun 10, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.