From: Johannes Schindelin Date: Thu, 22 Dec 2005 11:35:02 GMT Subject: Re: git /objects directory created 755 by default? Message-ID: In-Reply-To: <81b0412b0512220211o74f7f533j11b8e48311b61ec2@mail.gmail.com> Hi, On Thu, 22 Dec 2005, Alex Riesen wrote: > On 12/21/05, Johannes Schindelin wrote: > > > > > > > > [core] > > > > umask = 0002 > > So, I tend to say: use core.umask only in shared setups (in which you > > should not checkout files unless you know exactly what you are doing). > > May be "shell.umask" or "shared.umask" ? What would shell.umask do? Be set only when git-shell is called? Then you better have the policy to access that particular repository *only* via git-shell. Voila, it is the same effect as of core.umask. What would shared.umask do? Be set only when writing to GIT_DIR? This is a major task, since you have to find out which writes are to the working directory, which ones go to GIT_DIR. And you have to workout a policy (as I just answered in this thread) how to deal with a checked out HEAD where you can't write to the working directory (or at least modify the checked out files). The sanest way I can think of is either to disallow checkout, or to make the files writable to the group. Both methods do fine with core.umask. Now that I think of it: A third possibility is to disallow pushing to the checked out HEAD. Is this desirable? I think not. The user who works in the working directory exclusively would have to keep track of the pushed ref herself, instead of the user who pushed the ref. Sounds silly to me. Hth, Dscho