git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied

From
Johannes Schindelin <johannes.schindelin@gmx.de>
Date
Sep 23, 2015, 11:10 UTC
Message-ID
<5f56381a3cf5a5ccf6a1e4e3ea48f516@dscho.org>
In-Reply-To
<1442955525.29498.94.camel@transmode.se>
Hi Joakim,
On 2015-09-22 22:58, Joakim Tjernlund wrote:
Show 7 quoted lines
> On Tue, 2015-09-22 at 22:00 +0200, Johannes Schindelin wrote:
>>
>> The reason should be easy to understand: Git's concept is based on the idea that you have full control over
>> your repository. Other repositories you might only have read access.
> 
> Yes and some repos I only have partial write access to(config, hooks
> etc. might be readonly)
The partial write access idea is definitely not part of the original idea of Git, and your use case is actually the first I heard of.
The original idea was really that you either own your repository, or you do not. And that includes the repositories that can be accessed publicly: you own them or you don't.
Now, I know that in particular in some corporate setups, there needs to be a permission system in place that disallows certain users from doing certain things (such as editing the config).
The Git solution is to set up a server, usually with SSH, and allow users to push and fetch from the repositories, but nothing else (i.e. no shell access), then set up hooks to implement the permission system.
This is much less error prone than partially locking down a repository on some network drive because the file system structure simply does not reflect the permission structure. That is where all your troubles come from.
Show 7 quoted lines
>> But this idea you have, to somehow introduce fine-grained levels of control, this idea would imply that all
>> of a sudden Git is no longer free to write to its files as it likes. And as far as Git is concerned,
>> everything inside .git/ *are* its files.
> 
> This does not compute for me, files inside git are git's files, I only
> think that not all users
> to a repo should have the same (write) access.
But then it is your duty to tell *Git* what it can and what it cannot do. Typically via those hooks I mentioned.
> A .git/tmp/ would make housekeeping easier, you would know that every
> file under .git
> should be there and if you find something you don't recognize you would react.
No, it would actually make it harder. I seem to recall that there was some problem with renaming a file unless it was already in the same directory as the destination. If all files were to be written to .git/tmp/ first...
Show 9 quoted lines
>> If you need to exert more control in a specific repository, you simply make it accessible only as a non-file-system remote
>> (where only `git`, `git-receive-pack` and `git-upload-pack` are allowed to be executed) and define hooks
>> that can accept or deny on a *much* finer level than file system permissions ever could, after all.
> 
> Even if I did go through this hassle, I would prefer if temporary data
> were put somewhere else
> than .git/ as I think mixing config/persistent data with temporary
> data in the same directory is something
> that should be avoided.
Sure, I understand what you ask for. It's just that Git worked in a different direction for 10 years now ;-)

Ciao, Johannes

Previous: Joakim TjernlundNext: Junio C Hamano
Message 17 of 20 in “Unable to create temporary file '/var/git/tmv3-target-overlay.git/shallow_Un8ZOR': Permission denied”
  1. Joakim TjernlundAug 21, 2015
  2. Joakim TjernlundAug 21, 2015
  3. Joakim TjernlundAug 31, 2015
  4. Duy NguyenAug 31, 2015
  5. Joakim TjernlundSep 14, 2015
  6. Duy NguyenSep 17, 2015
  7. Joakim TjernlundSep 17, 2015
  8. Duy NguyenSep 19, 2015
  9. Duy NguyenSep 19, 2015
  10. Johannes SchindelinSep 19, 2015
  11. Joakim TjernlundSep 20, 2015
  12. Joakim TjernlundSep 19, 2015
  13. Junio C HamanoSep 21, 2015
  14. Joakim TjernlundSep 21, 2015
  15. Johannes SchindelinSep 22, 2015
  16. Joakim TjernlundSep 22, 2015
  17. Johannes SchindelinSep 23, 2015
  18. Junio C HamanoSep 23, 2015
  19. Joakim TjernlundSep 23, 2015
  20. Johannes SchindelinSep 23, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.