threads / discuss / 61522

How to disable safe directories?

Subject: How to disable safe directories?

## tl;dr

6 messages between May 21, 2024 and May 21, 2024.

replies: 5people: 2as markdown or json

Jeffrey Walton· May 21, 2024, 08:39 UTC · lore
Hi Everyone,

I've got a big DoS on my hands since safe directories landed on Fedora. I think this commit is the one responsible, but I may be mistaken: <https://github.com/git/git/commit/8959555cee7e>.

At this point I've wasted enough time on them. Now I would like to disable them completely.

How do I disable the safe directory changes?
Thanks in advance,
Jeff
Harald Dunkel· May 21, 2024, 10:42 UTC · re: Jeffrey Walton · lore

Re: How to disable safe directories?

On 2024-05-21 10:39:32, Jeffrey Walton wrote:
Show 11 quoted lines
> Hi Everyone,
> 
> I've got a big DoS on my hands since safe directories landed on
> Fedora. I think this commit is the one responsible, but I may be
> mistaken: <https://github.com/git/git/commit/8959555cee7e>.
> 
> At this point I've wasted enough time on them. Now I would like to
> disable them completely.
> 
> How do I disable the safe directory changes?
> 

That is actually pretty easy: Kick out the commit. I would suggest to turn the die() into a warning(), though, giving people time to adopt this restriction.

Regards
Harri
Jeffrey Walton· May 21, 2024, 10:45 UTC · re: Harald Dunkel · lore

Re: How to disable safe directories?

On Tue, May 21, 2024 at 6:42 AM Harald Dunkel <harald.dunkel@aixigo.com> wrote:
Show 17 quoted lines
>
> On 2024-05-21 10:39:32, Jeffrey Walton wrote:
> > Hi Everyone,
> >
> > I've got a big DoS on my hands since safe directories landed on
> > Fedora. I think this commit is the one responsible, but I may be
> > mistaken: <https://github.com/git/git/commit/8959555cee7e>.
> >
> > At this point I've wasted enough time on them. Now I would like to
> > disable them completely.
> >
> > How do I disable the safe directory changes?
> >
>
> That is actually pretty easy: Kick out the commit. I would suggest
> to turn the die() into a warning(), though, giving people time to
> adopt this restriction.
Thanks Harri.

Would that be something like safe_directories.enabled = false? If not, can you point to a setting?

Jeff
Harald Dunkel· May 21, 2024, 14:25 UTC · re: Jeffrey Walton · lore

Re: How to disable safe directories?

On 2024-05-21 12:45:18, Jeffrey Walton wrote:
Show 6 quoted lines
> 
> Thanks Harri.
> 
> Would that be something like safe_directories.enabled = false? If not,
> can you point to a setting?
> 

It is possible to disable this feature globally using something like

	git config --system --add safe.directory /somepath/.git
Some say even
	git config --system --add safe.directory '*'
works, but I haven't tried that.
Regards
Harri
Jeffrey Walton· May 21, 2024, 14:40 UTC · re: Harald Dunkel · lore

Re: How to disable safe directories?

On Tue, May 21, 2024 at 10:25 AM Harald Dunkel <harald.dunkel@aixigo.com> wrote:
Show 19 quoted lines
>
> On 2024-05-21 12:45:18, Jeffrey Walton wrote:
> >
> > Thanks Harri.
> >
> > Would that be something like safe_directories.enabled = false? If not,
> > can you point to a setting?
> >
>
> It is possible to disable this feature globally using something
> like
>
>         git config --system --add safe.directory /somepath/.git
>
> Some say even
>
>         git config --system --add safe.directory '*'
>
> works, but I haven't tried that.
Thanks Harri.
Yeah, that did not work for me, either.

I've been through directory permissions on the workstations and servers, and the SELinux contexts on the server. I cannot find anything wrong with them. Do you know how to have git tell us what the actual problem is? `git -v pull` is not providing more information, like what the actual problem is (it just barfs).

Thanks again.
Jeff
Harald Dunkel· May 21, 2024, 14:49 UTC · re: Harald Dunkel · lore

Re: How to disable safe directories?

On 2024-05-21 16:25:17, Harald Dunkel wrote:
Show 6 quoted lines
> 
> It is possible to disable this feature globally using something
> like
> 
> 	git config --system --add safe.directory /somepath/.git
> 
PS: Its obvious that each peer running git can verify only local
directories for dubious access bits. Working with shared remote
repositories you have to consider setting the safe.directory option
on the remote server.

Since CVE-2024-32004 assumes an attacker running its own repository, I just wonder why he should use the most recent, fixed git version?

Regards Harri

← back to recent threads