git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied

From
Johannes Schindelin <johannes.schindelin@gmx.de>
Date
Sep 22, 2015, 20:00 UTC
Message-ID
<37ca95b3fef79e348fb5ba68cd21c590@dscho.org>
In-Reply-To
<1442855328.29498.30.camel@transmode.se>
Hi Joakim,
On 2015-09-21 19:08, Joakim Tjernlund wrote:
Show 20 quoted lines
> On Mon, 2015-09-21 at 09:48 -0700, Junio C Hamano wrote:
>> Duy Nguyen <pclouds@gmail.com> writes:
>>
>> > Is it really necessary to remove write access in $GIT_DIR? Do we (git
>> > devs) have some guidelines about things in $GIT_DIR?
>>
>> Those who are allowed to "git push" into it should be able to write
>> there.  It is a different matter that "git" program itself may make
>> a policy decision to disallow some operations that the filesystem
>> bits alone would have allowed (e.g. you can arrange the "pusher" to
>> only come over the wire via "receive-pack" and "receive-pack" may
>> deliberately lack support for writing into $GIT_DIR/config).
>>
> 
> I view $GIT_DIR similar to "/" and "/tmp". Normally one does not let
> normal users write to "/"
> as you want to keep this level clean. It is not obvious to everybody
> what files are important
> under $GIT_DIR when mixed with tmp files etc.
> $GIT_DIR/tmp would solve this nicely.
By now it is pretty clear that you won't find many people here you share your opinion about locking down the Git directory.
The reason should be easy to understand: Git's concept is based on the idea that you have full control over your repository. Other repositories you might only have read access.
But this idea you have, to somehow introduce fine-grained levels of control, this idea would imply that all of a sudden Git is no longer free to write to its files as it likes. And as far as Git is concerned, everything inside .git/ *are* its files.
So in essence, the core concept of Git -- you clone a repository you cannot write to so that you have a local repository you can do *anything you like* to -- is pretty much incompatible with this idea of a selective lock down of files in .git/ that not only would require you to know very exactly what files Git might want to write, but also to keep yourself up-to-date with Git's development as to which files it might want to write for *every* new version. Making only .git/tmp/ a writable location further fails to acknowledge the fact that the hierarchy of to-be-written files follows the function of those files, not any write permission hierarchy. Since the idea seems so alien to Git's core concept, I called it "overzealous". If that hurt your feelings, I am sorry and would like to apologize
 .
Having said all that, I believe that reiterating this idea without pointing to any benefit will continue to fail to convince people that the idea is sound and that Git's core concept should change. If you need to exert more control in a specific repository, you simply make it accessible only as a non-file-system remote (where only `git`, `git-receive-pack` and `git-upload-pack` are allowed to be executed) and define hooks that can accept or deny on a *much* finer level than file system permissions ever could, after all.

Ciao, Johannes

Previous: Joakim TjernlundNext: Joakim Tjernlund
Message 15 of 20 in “Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied”
  1. Joakim TjernlundAug 21, 2015
  2. Joakim TjernlundAug 21, 2015
  3. Joakim TjernlundAug 31, 2015
  4. Duy NguyenAug 31, 2015
  5. Joakim TjernlundSep 14, 2015
  6. Duy NguyenSep 17, 2015
  7. Joakim TjernlundSep 17, 2015
  8. Duy NguyenSep 19, 2015
  9. Duy NguyenSep 19, 2015
  10. Johannes SchindelinSep 19, 2015
  11. Joakim TjernlundSep 20, 2015
  12. Joakim TjernlundSep 19, 2015
  13. Junio C HamanoSep 21, 2015
  14. Joakim TjernlundSep 21, 2015
  15. Johannes SchindelinSep 22, 2015
  16. Joakim TjernlundSep 22, 2015
  17. Johannes SchindelinSep 23, 2015
  18. Junio C HamanoSep 23, 2015
  19. Joakim TjernlundSep 23, 2015
  20. Johannes SchindelinSep 23, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.