git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Using GIT to store /etc (Or: How to make GIT store all file permission bits)

From
Jakub Narebski <jnareb@gmail.com>
Date
Dec 10, 2006, 18:18 UTC
Message-ID
<elhit4$tr3$2@sea.gmane.org>
In-Reply-To
<A52817B6-0265-4164-8E5D-334AF92DC267@mac.com>
Kyle Moffett wrote:
Show 22 quoted lines
> On Dec 10, 2006, at 10:30:00, Jakub Narebski wrote:
>> Jeff Garzik wrote:
>>>
>>> I actively use git to version, store and distribute an exim mail  
>>> configuration across six servers.  So far my solution has been a  
>>> 'fix perms' script, or using the file perm checking capabilities  
>>> of cfengine.
>>
>> Fix perms' script used on a checkout hook is a best idea I think.
> 
> Hmm, unfortunately that has problems with security-related race  
> conditions when used directly for /etc.  Think about what happens  
> with "/etc/shadow" in that case, for example.  (/etc/.git is of  
> course 0700)  I'm sure there are others where non-root daemons get  
> unhappy when they get an inotify event and their config files have  
> suddenly become root:root:0600.  I also want to be able to "cd /etc  
> && git status" to see what changed after running "apt-get update" or  
> maybe fiddling in SWAT or webmin, so a makefile which installs into / 
> etc won't quite solve it either.  It would also be nice to see when  
> things change the permissions on files in /etc, or even bind-mount an  
> append-only volume over /etc/.git/objects to provide additional data  
> security.

The idea is to not store /etc in git directly, but use import/export scripts, which for example saves permissions and ownership in some file also tracked by git on import, and restores correct permissions on export. That is what I remember from this discussion. This of course means that you would have to write your own porcelain...

What about mentioned in other email IsiSetup?
-- 
Jakub Narebski
Warsaw, Poland
ShadeHawk on #git
Previous: Kyle MoffettNext: Jakub Narebski
Message 5 of 34 in “Using GIT to store /etc (Or: How to make GIT store all file permission bits)”
  1. Kyle MoffettDec 10, 2006
  2. Jeff GarzikDec 10, 2006
  3. Jakub NarebskiDec 10, 2006
  4. Kyle MoffettDec 10, 2006
  5. Jakub NarebskiDec 10, 2006
  6. Jakub NarebskiDec 10, 2006
  7. Kyle MoffettDec 10, 2006
  8. Andreas EricssonDec 11, 2006
  9. Jeff GarzikDec 11, 2006
  10. Josef WeidendorferDec 11, 2006
  11. Johannes SchindelinDec 11, 2006
  12. Josef WeidendorferDec 11, 2006
  13. Santi BéjarDec 10, 2006
  14. Kyle MoffettDec 10, 2006
  15. Jakub NarebskiDec 10, 2006
  16. David LangJan 10, 2007
  17. Shawn O. PearceJan 10, 2007
  18. David LangJan 10, 2007
  19. Shawn O. PearceJan 12, 2007
  20. Nikolai WeibullDec 11, 2006
  21. Daniel BarkalowDec 12, 2006
  22. Kyle MoffettDec 12, 2006
  23. Andy ParkinsDec 12, 2006
  24. Using git as a general backup mechanism (was Re: Using GIT to store /etc)Steven Grimm, Dec 12, 2006
  25. Johannes SchindelinDec 12, 2006
  26. Steven GrimmDec 12, 2006
  27. Johannes SchindelinDec 13, 2006
  28. Martin LanghoffDec 12, 2006
  29. Martin LanghoffDec 12, 2006
  30. Junio C HamanoDec 12, 2006
  31. Steven GrimmDec 14, 2006
  32. Junio C HamanoDec 15, 2006
  33. Daniel BarkalowDec 13, 2006
  34. Chris RiddochDec 14, 2006

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.