git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] Makefile: do not set setgid bit on directories on GNU/kFreeBSD

From
GTGreg Troxel <gdt@ir.bbn.com>
Date
Oct 24, 2011, 23:07 UTC
Message-ID
<rmibot6aszb.fsf@fnord.ir.bbn.com>
In-Reply-To
<20111022111107.GA12130@elie.domain.sunraytvi.com>
   * On some BSD systems, adding +s bit on directories is detrimental
     (it is not necessary on BSD to begin with). The installation
     procedure has been updated to take this into account.

I looked at the NetBSD 5 sources, and as expected files are created (unconditionally) with the gid of the parent directory.

Setting the setgid flag is only allowed if the inode's gid is in the process gid set. This is really about files that might be executed, but the check is independent of regular file/directory.

"git init --shared" creates a repository, mode 2775, and that normally seems fine. It seems good to have the sgid bit on, in case the repository is transferred to another machine with different semantics, and it's a clue to humans about the intended behavior, even if it's non-optional on BSD.

I created a directory, mode 755, owned by me, and with group that I *do not* belong to. Then, "git init --shared" produced:

  fatal: Could not make /home/gdt/FOO/.git/refs writable by group
but really the issue was setting the sgid bit:

# all with git version 1.7.6.3 13 $ l -d .git/refs/ drwxr-xr-x 2 gdt kmem 512 Oct 24 18:53 .git/refs/ 14 $ chmod g+w .git/refs/ 15 $ l -d .git/refs/ drwxrwxr-x 2 gdt kmem 512 Oct 24 18:53 .git/refs/ 16 $ chmod g+s .git/refs/ chmod: .git/refs/: Operation not permitted

However, this is a pathological situation, because I've created a shared repository that I can write to because I own it, and group kmem people can write to because they're in the group, but I couldn't write to other group kmem resources.

Is this not-allowed-to-set-setgid issue the problem the patch is trying to avoid? Or something else?

I did run the regression tests at one point and don't remember this failing.

So all in all I am agnostic as to whether DIR_HAS_BSD_GROUP_SEMANTICS should be defined on NetBSD; personally I prefer to see the setgid bits.

Previous: Jonathan Nieder
Message 7 of 7 in “Makefile: do not set setgid bit on directories on GNU/kFreeBSD”
  1. Makefile: do not set setgid bit on directories on GNU/kFreeBSDJonathan Nieder, Oct 3, 2011
  2. Jonathan NiederOct 3, 2011
  3. Junio C HamanoOct 3, 2011
  4. Sverre RabbelierOct 3, 2011
  5. Jonathan NiederOct 3, 2011
  6. Jonathan NiederOct 22, 2011
  7. Greg TroxelOct 24, 2011

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.