git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: How to get git-daemon to work in a post-CVE world?

From
MMegaBrutal <megabrutal@gmail.com>
Date
Mar 31, 2025, 20:15 UTC
Message-ID
<CAE8gLh=1bqA6UTR4wAX1u1naic2cSGiekz0jLKxWeaxBKa=xiQ@mail.gmail.com>
In-Reply-To
<20250331-devious-woodpecker-of-temperance-b18608@lemur>

Konstantin Ryabitsev <konstantin@linuxfoundation.org> ezt írta (időpont: 2025. márc. 31., H, 16:53):

Show 17 quoted lines
>
> On Sun, Mar 30, 2025 at 10:30:00AM +0200, MegaBrutal wrote:
> > Hi Everyone,
> >
> > I'm new to the list, just thought it's the best place to talk about
> > Git. I'm running a public read-only git server with git-daemon. I've
> > recently noticed that my repos can't be cloned and found that
> > particular CVE which made git to verify the owners of the git repos.
> >
> > fatal: detected dubious ownership in repository at '/srv/git/mgsautils.git'
> >
> > The feasible solution is to declare the directory safe in .gitconfig.
>
> You can set global values in /etc/gitconfig, e.g.:
>
>     [safe]
>       directory = /srv/git/*

Thanks! While it is much more convenient to set it in one global /etc/gitconfig than individual home directories, I encountered the following problems:

1. It doesn't do anything with the other error I get, when the
problematic directory is '.'. I still keep getting that error message.
2. Git daemon doesn't seem to resolve the '*' wildcard, i.e. with the
wildcard I get the original message back which complains about
'/srv/git/mgsautils.git', despite it should be covered by
'/srv/git/*'. When I supply the full path, however, the error message
is still about '.'.

I even performed a whole Ubuntu release upgrade to get a new version of Git, but 2.43.0 acts the same. Seems like git-daemon is more stricts than plain git – what might be the problem?

Previous: Konstantin RyabitsevNext: Konstantin Ryabitsev
Message 3 of 4 in “How to get git-daemon to work in a post-CVE world?”
  1. MegaBrutalMar 30, 2025
  2. Konstantin RyabitsevMar 31, 2025
  3. MegaBrutalMar 31, 2025
  4. Konstantin RyabitsevMar 31, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.