git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Regression bug with latest SAFE ownership patch

From
brian m. carlson <sandals@crustytoothpaste.net>
Date
Aug 17, 2024, 15:34 UTC
Message-ID
<ZsDC-nRxPIxQmoTj@tapette.crustytoothpaste.net>
In-Reply-To
<CADCaTgpcmMbLoKR-rWf_roWfbgWJL6HuURDxwovvKQA8syf=vw@mail.gmail.com>
On 2024-08-17 at 03:15:05, James wrote:
Show 22 quoted lines
> I am not a subscriber to this mailing list, so please please CC-me on replies.
> 
> I believe the recent changes for the safe ownership patch seemed to
> have introduced a regression. I have a git repo which is on a shared
> server that I trust and control. Adding a safe.directory does _not_
> allow me to use this repo anymore. I can't even run a `git fetch`
> without an error. I have renamed the repo name and directory, but
> output is otherwise precise. Full logs and versions shown below:
> 
> james@computer1:~/whatever$ git remote show server2
> fatal: detected dubious ownership in repository at
> '/home/someoneelse/whatever/.git'
> To add an exception for this directory, call:
> 
>     git config --global --add safe.directory /home/someoneelse/whatever/.git
> fatal: Could not read from remote repository.
> 
> Please make sure you have the correct access rights
> and the repository exists.
> james@computer1:~/whatever$ git config --add safe.directory
> /home/someoneelse/whatever/.git
> james@computer1:~/whatever$ git config --add safe.directory '*'

This adds the option to the local configuration, but it has to be in the global (`--global`) or system (`--system`) config. A malicious user that owned the repository could modify the local config, so it can't be trusted for this reason.

-- 
brian m. carlson (they/them or he/him)
Toronto, Ontario, CA
Previous: JamesNext: Colin Stagner
Message 2 of 3 in “Regression bug with latest SAFE ownership patch”
  1. JamesAug 17, 2024
  2. brian m. carlsonAug 17, 2024
  3. Colin StagnerAug 18, 2024

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.