git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git /objects directory created 755 by default?

From
Junio C Hamano <junkio@cox.net>
Date
Dec 22, 2005, 20:15 UTC
Message-ID
<7v3bkkkhwb.fsf@assigned-by-dhcp.cox.net>
In-Reply-To
<Pine.LNX.4.63.0512222022510.31591@wbgn013.biozentrum.uni-wuerzburg.de>
Johannes Schindelin <Johannes.Schindelin@gmx.de> writes:
> And then somebody comes along and allows world access by chmod(0775) and 
> does not realize that *everybody* can delete packs, objects and what-nots 
> in GIT_DIR.

That somebody has to be somebody who owns .git directory not just a group member, so that is not a serious objection either, but you need to realize I was joking with 0777 -- a saner default would obviously be 0775. Otherwise you would not be able to server it from gitweb safely -- http server is typically not a group member.

> Given the complexity we are talking about, and the needs which are not at 
> all that complicated, why not just go with core.umask until somebody 
> *needs* core.repositoryumask?

I am afraid that is going backwards. Nobody *needs* core.umask either, but we are still talking about this. That is because you wanted to make things easier for people, and I agree with you that it would be nicer if we did not require people set umask to sane values suitable for group work themselves, but somehow we did that automatically for them. The longer I think about it, however, the more I feel this is a lost cause.

Earlier, I suggested git-shell one-liner, only because I thought git-shell users (or administrators that support git-shell users) may not have any way to set the umask to sane values themselves, but I think that should also be doable by telling sshd what the initial umask of the users should be. And that was where this umask discussion was started, but I think not touching umask at all is the right direction.

Your core.umask would make sure the .git/objects/ directory would be suitable for other members, but git is not the only tool the people would use in the working tree. To work well with an editor that does not overwrite an existing file but does creat/rename upon saving would require you to have a sane umask if the user adopts your "shared working tree writable by all members" workflow. Running "make" in the working tree would leave object files, worse yet in a temporary build directory make created, with permission bits masked with your umask, making it imposible to run "make clean" for other members.

Regardless of where and how people come from to work in the working tree, they need to set umask appropriately anyway.

The only possible issue is one umask might not be sufficient, but unfortunately you can have only one umask at a time. The example of "receiption branches" is not a shared repository for me in the strict sense, but allows for you to push into. I cannot work with umask 022 in such a repository even if I wanted to have files in the working tree honor tighter umask. To deal also with such cases, not mucking with umask but solving the problem in a more direct way may make more sense -- namely we should be able to say "such and such things under .git/ in this repository must be ug+rw regardless of user's umask".

Previous: Johannes SchindelinNext: Johannes Schindelin
Message 25 of 34 in “git /objects directory created 755 by default?”
  1. Martin LanghoffDec 20, 2005
  2. Junio C HamanoDec 20, 2005
  3. Junio C HamanoDec 21, 2005
  4. Martin LanghoffDec 21, 2005
  5. Junio C HamanoDec 21, 2005
  6. Martin LanghoffDec 21, 2005
  7. Junio C HamanoDec 21, 2005
  8. Martin LanghoffDec 21, 2005
  9. Junio C HamanoDec 21, 2005
  10. Martin LanghoffDec 21, 2005
  11. Ben CliffordDec 22, 2005
  12. Johannes SchindelinDec 21, 2005
  13. Junio C HamanoDec 21, 2005
  14. Johannes SchindelinDec 21, 2005
  15. Andreas EricssonDec 22, 2005
  16. Johannes SchindelinDec 22, 2005
  17. Andreas EricssonDec 22, 2005
  18. Johannes SchindelinDec 22, 2005
  19. Andreas EricssonDec 22, 2005
  20. Johannes SchindelinDec 22, 2005
  21. Andreas EricssonDec 22, 2005
  22. Johannes SchindelinDec 22, 2005
  23. Junio C HamanoDec 22, 2005
  24. Johannes SchindelinDec 22, 2005
  25. Junio C HamanoDec 22, 2005
  26. Johannes SchindelinDec 22, 2005
  27. Junio C HamanoDec 23, 2005
  28. Andreas EricssonDec 23, 2005
  29. Alex RiesenDec 22, 2005
  30. Johannes SchindelinDec 22, 2005
  31. Alex RiesenDec 22, 2005
  32. Johannes SchindelinDec 22, 2005
  33. Alex RiesenDec 22, 2005
  34. Johannes SchindelinDec 22, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.