git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Bug: git config does not respect read-only .gitconfig file

From
Jonathan Word <argoday@argoday.com>
Date
Nov 8, 2016, 15:22 UTC
Message-ID
<CAD9aWChH14eviop=0_Ma_2Pa-2OyWJp9KjimH8dyqy-XDn9Rhw@mail.gmail.com>
All,
I recently discovered that `git config` does not respect read-only files.

This caused unexpected difficulty in managing the global .gitconfig for a system account shared by a large team. A team member was able to execute a `git config --global` command without any notice or warning that the underlying config file had been marked read-only in an attempt to prevent unintentional changes. If instead git had raised a warning saying that the "gitconfig is read-only" this would have prevented that team member from accidentally breaking our git config.

Bug detail:

Due to the implementation strategy of config::git_config_set_multivar_in_file_gently ( https://github.com/git/git/blob/5b33cb1fd733f581da07ae8afa7e9547eafd248e/config.c#L2074 ) the file permissions of the target .gitconfig file are not respected.

Proposal:

Part 1) Add a .gitconfig variable to respect a read-only gitconfig file and optional "--force" override option for the `git config` command

Such a gitconfig variable could be defined as: config.respectFileMode: [ "never", "allow-override", "always" ]

Where:
* never - read-only file mode of config files are ignored (aka:
existing behavior)
* allow-override - read-only file mode of config files is respected
unless the user provides a "--force" option to `git config`
* always - read-only file mode of config files is respected (and the
"--force" option does not work)

Part 2) Change config::git_config_set_multivar_in_file_gently ( https://github.com/git/git/blob/5b33cb1fd733f581da07ae8afa7e9547eafd248e/config.c#L2077 ) to verify write permissions on the destination depending on the specified config.respectFileMode variable and "--force" option.

I think that this is a reasonably sized change that enables users to opt-in to a 'strict mode' while preserving current behavior.

Thoughts?
Tested with:
OS: Linux
Version: 2.9.0 (issue exists in current master branch)
Next: Markus Hitter
Message 1 of 7 in “Bug: git config does not respect read-only .gitconfig file”
  1. Jonathan WordNov 8, 2016
  2. Markus HitterNov 8, 2016
  3. Jonathan WordNov 8, 2016
  4. Jeff KingNov 8, 2016
  5. Junio C HamanoNov 9, 2016
  6. Jeff KingNov 9, 2016
  7. Jonathan WordNov 9, 2016

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.