git/list[1] front-page[2] threads[3] people[4] search[5] about
 

git 2.2.x: Unexpected, overstrict file permissions after "git update-server-info"

From
PSPaul Sokolovsky <paul.sokolovsky@linaro.org>
Date
Jan 5, 2015, 19:07 UTC
Message-ID
<20150105210724.032e9718@x230>
Hello,

We recently upgraded to git 2.2.1 from 2.1.x and faced issue with accessing repositories over dump HTTP protocol. In our setting, repositories are managed by Gerrit, so owned by Gerrit daemon user, but we also offer anon access via smart and dumb HTTP protocols. For the latter, we of course rely on "git update-server-info" being run.

So, after the upgrade, users started to report that accessing info/refs file of a repo, as required for HTTP dump protocol, leads to 403 Forbidden HTTP error. We traced that to 0600 filesystem permissions for such files (for objects/info/packs too) (owner is gerrit user, to remind). After resetting permissions to 0644, they get back to 0600 after some time (we have a cronjob in addition to a hook to run "git update-server-info"). umask is permissive when running cronjob (0002).

I traced the issue to: https://github.com/git/git/commit/d38379ece9216735ecc0ffd76c4c4e3da217daec

It says: "Let's instead switch to using a unique tempfile via mkstemp." Reading man mkstemp: "The file is created with permissions 0600". So, that's it. The patch above contains call to adjust_shared_perm(), but apparently it doesn't promote restrictive msktemp permissions to something more accessible.

Hope this issue can be addressed.

Thanks, Paul

Linaro.org | Open source software for ARM SoCs Follow Linaro: http://www.facebook.com/pages/Linaro http://twitter.com/#!/linaroorg - http://www.linaro.org/linaro-blog

Next: Torsten Bögershausen
Message 1 of 14 in “git 2.2.x: Unexpected, overstrict file permissions after "git update-server-info"”
  1. Paul SokolovskyJan 5, 2015
  2. Torsten BögershausenJan 5, 2015
  3. Jeff KingJan 6, 2015
  4. 1/2 t1301: set umask in reflog sharedrepository=group testJeff King, Jan 6, 2015
  5. 2/2 update-server-info: create info/* with mode 0666Jeff King, Jan 6, 2015
  6. Junio C HamanoJan 6, 2015
  7. Jeff KingJan 6, 2015
  8. Junio C HamanoJan 6, 2015
  9. Jeff KingJan 6, 2015
  10. Junio C HamanoJan 6, 2015
  11. Paul SokolovskyJan 6, 2015
  12. Junio C HamanoJan 6, 2015
  13. Jeff KingJan 6, 2015
  14. Paul SokolovskyJan 6, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.