git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git 2.2.x: Unexpected, overstrict file permissions after "git update-server-info"

From
Torsten Bögershausen <tboegi@web.de>
Date
Jan 5, 2015, 22:23 UTC
Message-ID
<54AB0ED0.3000400@web.de>
In-Reply-To
<20150105210724.032e9718@x230>
On 2015-01-05 20.07, Paul Sokolovsky wrote:
Show 31 quoted lines
> Hello,
> 
> We recently upgraded to git 2.2.1 from 2.1.x and faced issue with
> accessing repositories over dump HTTP protocol. In our setting,
> repositories are managed by Gerrit, so owned by Gerrit daemon user,
> but we also offer anon access via smart and dumb HTTP protocols. For the
> latter, we of course rely on "git update-server-info" being run.
> 
> So, after the upgrade, users started to report that accessing
> info/refs file of a repo, as required for HTTP dump protocol, leads to
> 403 Forbidden HTTP error. We traced that to 0600 filesystem permissions
> for such files (for objects/info/packs too) (owner is gerrit user, to
> remind). After resetting permissions to 0644, they get back to 0600
> after some time (we have a cronjob in addition to a hook to run "git
> update-server-info"). umask is permissive when running cronjob (0002).
> 
> 
> I traced the issue to:
> https://github.com/git/git/commit/d38379ece9216735ecc0ffd76c4c4e3da217daec
> 
> It says: "Let's instead switch to using a unique tempfile via mkstemp."
> Reading man mkstemp: "The  file  is  created  with permissions 0600".
> So, that's it. The patch above contains call to adjust_shared_perm(),
> but apparently it doesn't promote restrictive msktemp permissions to
> something more accessible.
> 
> Hope this issue can be addressed.
> 
> 
> Thanks,
> Paul

Does git config core.sharedRepository 0644 help?

Unless the the repo is configured as shared, adjust_shared_perm() will not widen the access bits:

http://git-htmldocs.googlecode.com/git/git-config.html
Previous: Paul SokolovskyNext: Jeff King
Message 2 of 14 in “git 2.2.x: Unexpected, overstrict file permissions after "git update-server-info"”
  1. Paul SokolovskyJan 5, 2015
  2. Torsten BögershausenJan 5, 2015
  3. Jeff KingJan 6, 2015
  4. 1/2 t1301: set umask in reflog sharedrepository=group testJeff King, Jan 6, 2015
  5. 2/2 update-server-info: create info/* with mode 0666Jeff King, Jan 6, 2015
  6. Junio C HamanoJan 6, 2015
  7. Jeff KingJan 6, 2015
  8. Junio C HamanoJan 6, 2015
  9. Jeff KingJan 6, 2015
  10. Junio C HamanoJan 6, 2015
  11. Paul SokolovskyJan 6, 2015
  12. Junio C HamanoJan 6, 2015
  13. Jeff KingJan 6, 2015
  14. Paul SokolovskyJan 6, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.