git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH 2/2] update-server-info: create info/* with mode 0666

From
Jeff King <peff@peff.net>
Date
Jan 6, 2015, 03:50 UTC
Message-ID
<20150106035048.GB20087@peff.net>
In-Reply-To
<20150106034702.GA11503@peff.net>

Prior to d38379e (make update-server-info more robust, 2014-09-13), we used a straight "fopen" to create the info/refs and objects/info/packs files, which creates the file using mode 0666 (less the default umask).

In d38379e, we switched to creating the file with mkstemp to get a unique filename. But mkstemp also uses the more restrictive 0600 mode to create the file. This was an unintended side effect that we did not want, and causes problems when the repository is served by a different user than the one running update-server-info (it is no longer readable by a dumb http server running as `www`, for example).

We can fix this by using git_mkstemp_mode and specifying
0666.  Note that we could also say "just use
core.sharedrepository", as we do call adjust_shared_perm
on the result before renaming it into place.  But that is
not very friendly. The shared-repo config is usually about
making things _writable_ for other users. Until d38379e,
there was no explicit config needed to serve an otherwise
readable repository, and we should consider it a
regression.
Signed-off-by: Jeff King <peff@peff.net>
---
 server-info.c          |  2 +-
 t/t1301-shared-repo.sh | 10 ++++++++++
 2 files changed, 11 insertions(+), 1 deletion(-)
diff --git a/server-info.c b/server-info.c
index 31f4a74..34b0253 100644
--- a/server-info.c
+++ b/server-info.c
@@ -17,7 +17,7 @@ static int update_info_file(char *path, int (*generate)(FILE *))
 	FILE *fp = NULL;
 
 	safe_create_leading_directories(path);
-	fd = mkstemp(tmp);
+	fd = git_mkstemp_mode(tmp, 0666);
 	if (fd < 0)
 		goto out;
 	fp = fdopen(fd, "w");
diff --git a/t/t1301-shared-repo.sh b/t/t1301-shared-repo.sh
index 86ed901..feff55e 100755
--- a/t/t1301-shared-repo.sh
+++ b/t/t1301-shared-repo.sh
@@ -111,6 +111,16 @@ do
 
 done
 
+test_expect_success POSIXPERM 'info/refs is readable in unshared repo' '
+	rm -f .git/info/refs &&
+	test_unconfig core.sharedrepository &&
+	umask 002 &&
+	git update-server-info &&
+	echo "-rw-rw-r--" >expect &&
+	modebits .git/info/refs >actual &&
+	test_cmp expect actual
+'
+
 test_expect_success POSIXPERM 'git reflog expire honors core.sharedRepository' '
 	umask 077 &&
 	git config core.sharedRepository group &&
-- 
2.2.1.425.g441bb3c
Previous: Jeff KingNext: Junio C Hamano
Message 5 of 14 in “git 2.2.x: Unexpected, overstrict file permissions after "git update-server-info"”
  1. Paul SokolovskyJan 5, 2015
  2. Torsten BögershausenJan 5, 2015
  3. Jeff KingJan 6, 2015
  4. 1/2 t1301: set umask in reflog sharedrepository=group testJeff King, Jan 6, 2015
  5. 2/2 update-server-info: create info/* with mode 0666Jeff King, Jan 6, 2015
  6. Junio C HamanoJan 6, 2015
  7. Jeff KingJan 6, 2015
  8. Junio C HamanoJan 6, 2015
  9. Jeff KingJan 6, 2015
  10. Junio C HamanoJan 6, 2015
  11. Paul SokolovskyJan 6, 2015
  12. Junio C HamanoJan 6, 2015
  13. Jeff KingJan 6, 2015
  14. Paul SokolovskyJan 6, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.