git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: regression: "96b9e0e3 config: treat user and xdg config permission problems as errors" busted git-daemon

From
Junio C Hamano <gitster@pobox.com>
Date
Apr 11, 2013, 19:54 UTC
Message-ID
<7vwqs8hmh1.fsf@alter.siamese.dyndns.org>
In-Reply-To
<20130411181439.GA2820@sigill.intra.peff.net>
Jeff King <peff@peff.net> writes:
Show 26 quoted lines
> On Thu, Apr 11, 2013 at 11:11:03AM -0700, Jonathan Nieder wrote:
>
>> > -- >8 --
>> > Subject: [PATCH] daemon: set HOME when we switch to --user
>> 
>> Thanks for taking care of it.  For what it's worth,
>> 
>> Acked-by: Jonathan Nieder <jrnieder@gmail.com>
>> 
>> I'm not sure whether to keep 96b9e0e (config: treat user and xdg
>> config permission problem as errors) in the long run, BTW.  There have
>> been multiple reports about dropping privileges and not being able to
>> access the old HOME, and I'm not convinced any more that the
>> predictability is worth the breakage for such people.  Though checking
>> if $HOME is inaccessible and treating that case specially would be
>> even worse...
>> 
>> Insights welcome.
>
> I could go either way. I think 96b9e0e is the right thing to do
> conceptually, but I kind of doubt it was affecting all that many people.
> And though it's _possible_ for it to be a security problem, I find it
> much more likely that the site admin tries to set some config, gets
> annoyed when it doesn't work, and debugs it. So from a practical
> perspective, 96b9e0e may be doing more harm than good, even though it's
> the right thing.
Recent reports in this thread make us think so, I guess.

But reverting 96b9e0e alone would not help these people very much though. They will have reams of warning messages in their server logs, and the way to "fix" it would be the same as the way to work around the access_or_die(), namely, to set $HOME to point at a more appropriate place before running "git daemon".

I also have a suspicion that your patch makes things worse for people who are more adept at these issues around running daemons than the people who introduced this problem in the first place (eh, that's "us"). It is plausible that they may run multiple instances of "initially root but setuid() to an unprivileged user" daemons, giving each of them a separate play area by setting $HOME to different values, just for management's ease not necessarily for security (hence sharing the same unprivileged user), which will be broken by the patch that unconditionally overrides $HOME.

A trade off to make things slightly easier for one sysadmin by making another thing impossible to do for another sysadmin does not sound like a good one.

Previous: Jonathan NiederNext: W. Trevor King
Message 11 of 39 in “regression: "96b9e0e3 config: treat user and xdg config permission problems as errors" busted git-daemon”
  1. Mike GalbraithApr 10, 2013
  2. W. Trevor KingApr 10, 2013
  3. Mike GalbraithApr 11, 2013
  4. Jeff KingApr 11, 2013
  5. Mike GalbraithApr 11, 2013
  6. Junio C HamanoApr 11, 2013
  7. Jeff KingApr 11, 2013
  8. Jonathan NiederApr 11, 2013
  9. Jeff KingApr 11, 2013
  10. Jonathan NiederApr 11, 2013
  11. Junio C HamanoApr 11, 2013
  12. W. Trevor KingApr 11, 2013
  13. Junio C HamanoApr 11, 2013
  14. Jeff KingApr 11, 2013
  15. W. Trevor KingApr 12, 2013
  16. Junio C HamanoApr 12, 2013
  17. Jeff KingApr 12, 2013
  18. Junio C HamanoApr 12, 2013
  19. Jeff KingApr 12, 2013
  20. Mike GalbraithApr 12, 2013
  21. W. Trevor KingApr 12, 2013
  22. Jeff KingApr 12, 2013
  23. Junio C HamanoApr 12, 2013
  24. Jeff KingApr 12, 2013
  25. Jeff KingApr 12, 2013
  26. Junio C HamanoApr 12, 2013
  27. Jeff KingApr 12, 2013
  28. Junio C HamanoApr 12, 2013
  29. Jeff KingApr 12, 2013
  30. Junio C HamanoApr 12, 2013
  31. config: allow inaccessible configuration under $HOMEJonathan Nieder, Apr 12, 2013
  32. Jeff KingApr 12, 2013
  33. fixup! config: allow inaccessible configuration under $HOMEJonathan Nieder, Apr 12, 2013
  34. config: allow inaccessible configuration under $HOMEJonathan Nieder, Apr 12, 2013
  35. Mike GalbraithApr 13, 2013
  36. Jason A. DonenfeldMay 25, 2013
  37. Junio C HamanoApr 12, 2013
  38. Mike GalbraithApr 12, 2013
  39. Jeff KingApr 11, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.