git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git /objects directory created 755 by default?

From
Junio C Hamano <junkio@cox.net>
Date
Dec 22, 2005, 19:14 UTC
Message-ID
<7vwthxlzai.fsf@assigned-by-dhcp.cox.net>
In-Reply-To
<43AAD9D7.1070503@op5.se>
Andreas Ericsson <ae@op5.se> writes:
Show 7 quoted lines
> Junio said:
> "I agree the setting should not be limited to git-shell, but I do
> not think setting "umask" from git configuration is the right
> way either.  For files and directories under $GIT_DIR, maybe
> imposing the policy git configuration file has is OK, but I
> think honoring the user's umask is the right thing for working
> tree files."
I think this needs qualifying.

When we talk about "CVS-style shared repository", we know what it is -- there is no such thing as "*the* working tree associated with the repository" and there is no room for disagreement.

The workflow your shared repository implies is that there is an associated working tree with that repository, and the working tree should allow updates by participants who are allowed to create new things in .git/objects and update .git/refs/. If you assume that is the only valid use case for non-naked shared repository, then what I said above is not needed. It does not make any sense to have anything stricter than 007 as umask in such a case. But is it the only valid use case?

I could give each of the gitsters I trust an git-shell account on my private machine and prepare refs/heads/rcpt/js branch for you and refs/heads/rcpt/ae for Andreas to push into (I would use Carl's per branch push policy to make sure those "receipt branches" are the only ones you guys can push into if I did so).

Then instead of sending "I now have this public repository and have goodies for git improvement; please pull" e-mail to me, you could push into your branch. I will keep working on master (and my own topic branches), with whatever branch checked out in the working tree, and merge from those rcpt branches at my leisure. You guys are not allowed to touch my working tree, though.

In such a scenario, there is no reason to forbid me from applying umask 022 to my working tree files, even though making sure that fan-out directories of .git/objects/ *I* lazily create can be writable by you is essential.

I have a feeling that it might be good enough to modify safe_create_leading_directories() to chmod(0777) after creating a new directory under .git/ (or limit it to .git/objects/). The repository administrator can restrict things further by chmod 0770 .git/ as needed.

Previous: Johannes SchindelinNext: Johannes Schindelin
Message 23 of 34 in “git /objects directory created 755 by default?”
  1. Martin LanghoffDec 20, 2005
  2. Junio C HamanoDec 20, 2005
  3. Junio C HamanoDec 21, 2005
  4. Martin LanghoffDec 21, 2005
  5. Junio C HamanoDec 21, 2005
  6. Martin LanghoffDec 21, 2005
  7. Junio C HamanoDec 21, 2005
  8. Martin LanghoffDec 21, 2005
  9. Junio C HamanoDec 21, 2005
  10. Martin LanghoffDec 21, 2005
  11. Ben CliffordDec 22, 2005
  12. Johannes SchindelinDec 21, 2005
  13. Junio C HamanoDec 21, 2005
  14. Johannes SchindelinDec 21, 2005
  15. Andreas EricssonDec 22, 2005
  16. Johannes SchindelinDec 22, 2005
  17. Andreas EricssonDec 22, 2005
  18. Johannes SchindelinDec 22, 2005
  19. Andreas EricssonDec 22, 2005
  20. Johannes SchindelinDec 22, 2005
  21. Andreas EricssonDec 22, 2005
  22. Johannes SchindelinDec 22, 2005
  23. Junio C HamanoDec 22, 2005
  24. Johannes SchindelinDec 22, 2005
  25. Junio C HamanoDec 22, 2005
  26. Johannes SchindelinDec 22, 2005
  27. Junio C HamanoDec 23, 2005
  28. Andreas EricssonDec 23, 2005
  29. Alex RiesenDec 22, 2005
  30. Johannes SchindelinDec 22, 2005
  31. Alex RiesenDec 22, 2005
  32. Johannes SchindelinDec 22, 2005
  33. Alex RiesenDec 22, 2005
  34. Johannes SchindelinDec 22, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.