git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[BUG] Destructive access to an "objects/info/alternates" repository

From
SMStefan Monnier <monnier@iro.umontreal.ca>
Date
Dec 28, 2020, 18:50 UTC
Message-ID
<jwvpn2tdb0r.fsf-monnier+gmane.comp.version-control.git@gnu.org>
[ Resending with a subject that clarifies that it's a bug report.  ]
> Thank you for filling out a Git bug report!
> Please answer the following questions to help us understand your issue.
> What did you do before the bug happened? (Steps to reproduce your
> issue)
I did basically:
    git clone --reference ~otheruser/nongnu
    [ Days passed and I did various things.  ]
    cd nongnu; git gc

Note that `otheruser` is [..wait for it..] another user, so I only have read access to the referenced repository.

> What did you expect to happen? (Expected behavior)

That it would GC the local part of the repository and that it wouldn't try to modify the referenced repository.

> What happened instead? (Actual behavior)

I got warnings indicating that Git was trying to delete files from the referenced repository:

    Enumerating objects: 35095, done.
    Nothing new to pack.
    warning: unable to unlink
'/home/otheruser/nongnu/.git/objects/pack/pack-0d85e74ac2f7e51ce26f281e64eb738e8182fa95.idx':
Permission denied
    warning: unable to unlink
'/home/otheruser/nongnu/.git/objects/pack/pack-5fe14feff49ccdee5469af9dc94f6784e8464a6b.idx':
Permission denied
> What's different between what you expected and what actually happened?
The warnings.
> Anything else you want to add:

The warnings make me wonder if I should worry about other possible misbehaviors when using such a setup.

> Please review the rest of the bug report below.
> You can delete any lines you don't wish to share.

This is on a Debian stable system but with Git from Debian testing (because the version from Debian stable crashed in a `git log` command I was using in my scripts).

[System Info] git version: git version 2.29.2 cpu: x86_64 no commit associated with this build sizeof-long: 8 sizeof-size_t: 8 shell-path: /bin/sh uname: Linux 4.19.0-9-amd64 #1 SMP Debian 4.19.118-2 (2020-04-29) x86_64 compiler info: gnuc: 10.2 libc info: glibc: 2.28 $SHELL (typically, interactive shell): /bin/bash

[Enabled Hooks]
Next: Konstantin Ryabitsev
Message 1 of 9 in “[BUG] Destructive access to an "objects/info/alternates" repository”
  1. Stefan MonnierDec 28, 2020
  2. Konstantin RyabitsevDec 28, 2020
  3. Stefan MonnierDec 28, 2020
  4. Stefan MonnierDec 28, 2020
  5. Konstantin RyabitsevDec 29, 2020
  6. Stefan MonnierJan 3, 2021
  7. Konstantin RyabitsevJan 4, 2021
  8. Stefan MonnierJan 4, 2021
  9. Konstantin RyabitsevJan 4, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.