git/list[1] front-page[2] threads[3] people[4] search[5] about
 

git-daemon doesn't work as expected in v2.45.1 and friends

From
Ondrej Pohorelsky <opohorel@redhat.com>
Date
May 20, 2024, 08:21 UTC
Message-ID
<CA+B51BGonS2DDTBQ2RsipW4Cyg5pRv0U71RAN9M1pcPjACtJ4A@mail.gmail.com>
Hi,

during testing the newest security releases in RHEL and in Fedora, we have encountered broken git-daemon behavior. In a nutshell, git client refuses to clone locally hosted repositories because of detected dubious ownership.

I'll paste part of the Fedora report [0] here:

``` Upon clone, git-daemon logs the following:

    [1482] Connection from ::1:45090
    [1482] Extended attribute "host": localhost
    [1482] Extended attribute "protocol": version=2
    [1482] Request upload-pack for '/test.git'
    fatal: detected dubious ownership in repository at '/var/lib/git/test.git'
    To add an exception for this directory, call:
            git config --global --add safe.directory /var/lib/git/test.git
Reproducible: Always
Steps to Reproduce:
1. Create repository under /var/lib/git/test.git
2. Ensure git.socket systemd unit is started
3. Run git clone git://localhost/test.git
Actual Results:
git server refuses to read /var/lib/git/site.git because it detects dubious
ownership
```

Is there a way to make git-daemon hosted repositories safe to clone, without specifying safe.directory in git config? AFAIK this is widely used feature of Git not only by the end users, but also quite a lot of tests rely on it.

[0]https://bugzilla.redhat.com/show_bug.cgi?id=2281530

Cheers, Ondřej Pohořelský

Next: Konstantin Ryabitsev
Message 1 of 4 in “git-daemon doesn't work as expected in v2.45.1 and friends”
  1. Ondrej PohorelskyMay 20, 2024
  2. Konstantin RyabitsevMay 21, 2024
  3. Junio C HamanoMay 21, 2024
  4. Junio C HamanoMay 21, 2024

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.