git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: How to prevent changes to repository by root

From
PHPete Harlan <pgit@pcharlan.com>
Date
Jun 18, 2010, 20:45 UTC
Message-ID
<4C1BDAED.3030809@pcharlan.com>
In-Reply-To
<AANLkTimjIraq-qDaifACixJ4cCOYuvkf1v-hVpeaVt3u@mail.gmail.com>
On 06/16/2010 07:28 PM, Nazri Ramliy wrote:
Show 11 quoted lines
> On Thu, Jun 17, 2010 at 12:09 AM, Aneurin Price <aneurin.price@gmail.com> wrote:
>> How are they becoming root? If they are using sudo you could forbid
>> running git as root. If they are using su or logging in directly maybe
>> you can get away with some trivial thing like putting 'alias
>> git=/bin/false' in /root/.bashrc - or some wrapper which does
>> something helpful rather than silently fail :-).
> 
> Thanks for dropping the hint on wrapper.
> 
> I've implemented one that give the user a friendly reminder
> that they are running git as root and ask whether to continue.
When I needed this I wrote a hook that refused a commit by root unless the commit message said something to the effect of:
Root commit performed by <person or script name>.
It's not that I minded so much that root was doing commits, it's the anonymity that was the problem.  So automated scripts that ran as root could perform commits too, they just had to include this note in the commit message so we knew which script was doing it.  It was all the honor-system, but it did what we wanted and prevented committing as root by accident.
--Pete
Previous: Nazri Ramliy
Message 5 of 5 in “How to prevent changes to repository by root”
  1. Nazri RamliyJun 14, 2010
  2. Nicolas SebrechtJun 16, 2010
  3. Aneurin PriceJun 16, 2010
  4. Nazri RamliyJun 17, 2010
  5. Pete HarlanJun 18, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.