git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: CVE-2022-24765 and core.sharedRepository (was: What's cooking in git.git (Apr 2022, #03; Tue, 12))

From
Ddemerphq <demerphq@gmail.com>
Date
Apr 13, 2022, 03:10 UTC
Message-ID
<CANgJU+XU_j2Ge-c34qqKMZRjM5k4OBYMiJa4t7WJcPsdABWHiQ@mail.gmail.com>
In-Reply-To
<220412.86h76yglfe.gmgdl@evledraar.gmail.com>
On Tue, 12 Apr 2022 at 21:43, Ævar Arnfjörð Bjarmason <avarab@gmail.com> wrote:
Show 35 quoted lines
>
>
> On Tue, Apr 12 2022, Philippe Blain wrote:
>
> [A change of $subject seems in order]
>
> > Le 2022-04-12 à 13:04, Junio C Hamano a écrit :
> >>
> >>
> >> Security releases for the 2.30-2.35 maintenance tracks have been
> >> tagged to address CVE-2022-24765, which allows a user to trick other
> >> users into running a command of their choice easily on multi-user
> >> machines with a shared "mob" directory.  The fix has been also
> >> merged to Git 2.36-rc2 and to all integration branches.
> >>
> >
> > This is quite a big behaviour change for some environments [1], so I would think maybe it
> > deserves to be fully spelled out in the release notes for 2.36.0,
> > instead of just referring readers to the release notes for the maintenance
> > release, where they can read a full description only in the release notes
> > for 2.30.3 ?
>
> Yes, I think it deserves to be noted very prominently, and also that we
> had some mechanism for publishing relevant git-security@ discussions
> (possibly with some parts redacted) after the issues become public.
>
> Non knowing if others involved are OK with being quoted I'll just say
> that this issue was discussed at some length on the list, in particular
> that it'll severely hinder some core.sharedRepository workflows.
>
> Quoting (part of) my own reply from one of those exchanges (this is in
> reply to Johannes Schindelin):
>
>         But I don't understand why we need to immediately die() when we detect
>         this situation in setup.c.

Would I be right in thinking this explains new breakage we are seeing in CI jobs we (the Perl project) have hosted on GitHub:

https://github.com/Perl/perl5/runs/6000831257?check_suite_focus=true#step:5:1

Run git remote set-url origin "***github.com/$GITHUB_REPOSITORY" fatal: unsafe repository ('/__w/perl5/perl5' is owned by someone else) To add an exception for this directory, call:

git config --global --add safe.directory /__w/perl5/perl5 Process completed with exit code 128.

Cheers, Yves

Previous: Ævar Arnfjörð BjarmasonNext: Junio C Hamano
Message 4 of 10 in “What's cooking in git.git (Apr 2022, #03; Tue, 12)”
  1. Junio C HamanoApr 12, 2022
  2. Philippe BlainApr 12, 2022
  3. CVE-2022-24765 and core.sharedRepository (was: What's cooking in git.git (Apr 2022, #03; Tue, 12))Ævar Arnfjörð Bjarmason, Apr 12, 2022
  4. demerphqApr 13, 2022
  5. Junio C HamanoApr 13, 2022
  6. ab/plug-leak-in-revisions (was: What's cooking in git.git (Apr 2022, #03; Tue, 12))Ævar Arnfjörð Bjarmason, Apr 13, 2022
  7. Junio C HamanoApr 13, 2022
  8. Ævar Arnfjörð BjarmasonApr 14, 2022
  9. Junio C HamanoApr 14, 2022
  10. ab/ci-setup-simplify etc. (was: What's cooking in git.git (Apr 2022, #03; Tue, 12))Ævar Arnfjörð Bjarmason, Apr 13, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.