Re: Destructive side-effect of "cg-status"
- From
Linus Torvalds <torvalds@osdl.org>
- Date
- Oct 1, 2005, 16:41 UTC
- Message-ID
- <Pine.LNX.4.64.0510010934290.3378@g5.osdl.org>
- In-Reply-To
- <20050930160353.F025C352B7B@atlas.denx.de>
On Fri, 30 Sep 2005, Wolfgang Denk wrote:
Show 5 quoted lines
> > So far I thought "cg-status" is a harmless command which just > displays some status information. It ain't so. One of our engineers > reported a corrupted repository after I ran "cg-status" in his > directory:
Well, it's not corrupted, but yes, the index file ends up unreadable.
> That means, that "cg-status" actually *rewrote* .git/index, with me > (wd) as new owner, and - ignoring my umask - with permissions that > prevent the original owner (sr) to access the file!
The umask thing looks like a bug. Fixed thus.
Also, arguably we should try to avoid writing the index file when not necessary, although the fact is, that cg-status (and "git status") _do_ need to actually keep it up-to-date in order to do the right thing. Also true of some other programs that might otherwise appear to be read-only (ie I've considered doing the same thing for "git diff").
We used to have that optimization, but it was broken. I fixed it but disabled it for fear of other bugs.
But honoring umask would seem to be a no-brainer.
Linus
----
diff --git a/index.c b/index.c --- a/index.c +++ b/index.c @@ -29,7 +29,7 @@ int hold_index_file_for_update(struct ca signal(SIGINT, remove_lock_file_on_signal); atexit(remove_lock_file); } - return open(cf->lockfile, O_RDWR | O_CREAT | O_EXCL, 0600); + return open(cf->lockfile, O_RDWR | O_CREAT | O_EXCL, 0666); } int commit_index_file(struct cache_file *cf)