git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 5/5] setup: allow not marking self owned repos as safe in `ensure_safe_repository()`

From
D. Ben Knoble <ben.knoble@gmail.com>
Date
Oct 13, 2025, 11:59 UTC
Message-ID
<CALnO6CBLr2iL0r+ywM4Vjw0=J2DNFv9Nhhq_PHuxt4eK=Z95ww@mail.gmail.com>
In-Reply-To
<20251013094152.23597-6-git@lohmann.sh>
On Mon, Oct 13, 2025 at 5:43 AM Michael Lohmann <git@lohmann.sh> wrote:
Show 46 quoted lines
>
> Git considers all repositories as safe, if they are either
>  - explicitly set in "safe.directory" config, or
>  - the user owns the repo
>
> Since a user could unzip a folder they downloaded from the internet and
> unknown to them, it is a repository with malicious hooks/config, an
> attacker could easily get code execution. Even a command line prompt
> would automatically trigger this if executing `git status` after
> entering the malicious directory.
>
> Allow not to automatically treat all repos owned by the user as safe.
> This can either be done by "--assume-unsafe", the environment variable
> "GIT_ASSUME_UNSAFE" or by setting the configuration "safe.assumeUnsafe"
> in a safe context (so not the repo config, as it should not be able to
> allow list itself).
>
> Signed-off-by: Michael Lohmann <git@lohmann.sh>
> ---
> Question in setup.c: is setting the environment variable inside of
> safe_directory_cb the best way to "communicate" this result?
> Alternatively one could add a new member to the struct, but I thought
> this was not the best either...
>
>
>  Documentation/config/safe.adoc    |  9 +++++++
>  Documentation/git.adoc            | 14 ++++++++++-
>  environment.h                     |  1 +
>  git.c                             |  6 ++++-
>  setup.c                           |  9 +++++++
>  t/t0036-allow-unsafe-directory.sh | 42 +++++++++++++++++++++++++++++++
>  6 files changed, 79 insertions(+), 2 deletions(-)
>
> diff --git a/Documentation/config/safe.adoc b/Documentation/config/safe.adoc
> index 2d45c98b12..2ac5d94762 100644
> --- a/Documentation/config/safe.adoc
> +++ b/Documentation/config/safe.adoc
> @@ -60,3 +60,12 @@ which id the original user has.
>  If that is not what you would prefer and want git to only trust
>  repositories that are owned by root instead, then you can remove
>  the `SUDO_UID` variable from root's environment before invoking git.
> +
> +safe.assumeUnsafe::
> +       Boolean to indicate that the ownership of a repository should not
> +       be taken into account when checking if the repository is safe. It
> +       will prevent against accidental arbitrariy code execution
s/arbitrariy/arbitrary. (fix typo + add period)
Show 27 quoted lines
> ++
> +To temporarily allow git execution in case of an assumed unsafe repository,
> +run the command with `--allow-unsafe`. To permanently trust this path, add
> +it to the `safe.directory` config.
> diff --git a/Documentation/git.adoc b/Documentation/git.adoc
> index 7df51c38f9..162350f3db 100644
> --- a/Documentation/git.adoc
> +++ b/Documentation/git.adoc
> @@ -14,7 +14,7 @@ SYNOPSIS
>      [-p | --paginate | -P | --no-pager] [--no-replace-objects] [--no-lazy-fetch]
>      [--no-optional-locks] [--no-advice] [--bare] [--git-dir=<path>]
>      [--work-tree=<path>] [--namespace=<name>] [--config-env=<name>=<envvar>]
> -    [--allow-unsafe]
> +    [--allow-unsafe] [--assume-unsafe]
>      <command> [<args>]
>
>  DESCRIPTION
> @@ -238,6 +238,13 @@ If you just want to run git as if it was started in `<path>` then use
>         execution by hooks or configuration settings. Equivalent to setting
>         the environment variable `GIT_ALLOW_UNSAFE=1`.
>
> +--assume-unsafe::
> +       Prevent arbitrary code execution by hooks or configuration if not
> +       executed in a "safe.directory". With setting this, filesystem ownership
> +       of the repository in question no longer satisfies to mark it as safe.
> +       Equivalent to setting `GIT_ASSUME_UNSAFE=1`. This is overwritten if
> +       `--allow-unsafe` is passed as well.
Here and later, I think you mean "overridden" not "overwritten"
-- 
D. Ben Knoble
Previous: Michael LohmannNext: Michael Lohmann
Message 9 of 24 in “Allow enforcing safe.directory”
  1. 0/5 Allow enforcing safe.directoryMichael Lohmann, Oct 13, 2025
  2. 1/5 setup: rename `ensure_safe_repository()` for clarityMichael Lohmann, Oct 13, 2025
  3. 2/5 setup: rename `die_upon_assumed_unsafe_repo()` to align with checkMichael Lohmann, Oct 13, 2025
  4. Junio C HamanoOct 14, 2025
  5. 3/5 setup: refactor `ensure_safe_repository()` testing prioritiesMichael Lohmann, Oct 13, 2025
  6. Junio C HamanoOct 14, 2025
  7. 4/5 setup: allow temporary bypass of `ensure_safe_repository()` checksMichael Lohmann, Oct 13, 2025
  8. 5/5 setup: allow not marking self owned repos as safe in `ensure_safe_repository()`Michael Lohmann, Oct 13, 2025
  9. D. Ben KnobleOct 13, 2025
  10. 0/5 Apply comments of D. Ben KnobleMichael Lohmann, Oct 13, 2025
  11. 1/5 setup: rename `ensure_safe_repository()` for clarityMichael Lohmann, Oct 13, 2025
  12. 2/5 setup: rename `die_upon_assumed_unsafe_repo()` to align with checkMichael Lohmann, Oct 13, 2025
  13. 3/5 setup: refactor `ensure_safe_repository()` testing prioritiesMichael Lohmann, Oct 13, 2025
  14. 4/5 setup: allow temporary bypass of `ensure_safe_repository()` checksMichael Lohmann, Oct 13, 2025
  15. 5/5 setup: allow not marking self owned repos as safe in `ensure_safe_repository()`Michael Lohmann, Oct 13, 2025
  16. 0/5 Allow skipping ownership of repo in safety considerationMichael Lohmann, Oct 16, 2025
  17. 3/5 setup: refactor `ensure_safe_repository()` testing prioritiesMichael Lohmann, Oct 16, 2025
  18. 1/5 setup: rename `ensure_safe_repository()` for clarityMichael Lohmann, Oct 16, 2025
  19. 2/5 setup: rename `die_upon_unsafe_repo()` to align with checkMichael Lohmann, Oct 16, 2025
  20. 4/5 setup: allow temporary bypass of `ensure_safe_repository()` checksMichael Lohmann, Oct 16, 2025
  21. Junio C HamanoOct 16, 2025
  22. 5/5 setup: allow not marking self owned repos as safe in `ensure_safe_repository()`Michael Lohmann, Oct 16, 2025
  23. Junio C HamanoOct 16, 2025
  24. Junio C HamanoOct 16, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.