threads / discuss / 62427

safe.directory warnings for root-owned repositories

Subject: safe.directory warnings for root-owned repositories

## tl;dr

4 messages between Oct 31, 2024 and Oct 31, 2024.

replies: 3people: 3as markdown or json

Michael Orlitzky· Oct 31, 2024, 04:23 UTC · lore
If I create a new repository as root,
  $ sudo git init
  Initialized empty Git repository in /home/mjo/tmp/.git/
  $ ls -alh
  total 12K
  drwxr-xr-x  3 mjo  mjo  4.0K 2024-10-31 00:09 .
  drwxr-x--- 17 mjo  mjo  4.0K 2024-10-31 00:07 ..
  drwxr-xr-x  6 root root 4.0K 2024-10-31 00:09 .git
and attempt to do anything in it, I get a safe.directory warning:
  $ git status
  fatal: detected dubious ownership in repository at '/home/mjo/tmp'
  ...

Does that make sense? In terms of ownership, root:root is as safe as it gets.

I'm aware that safe.directory is only scratching the surface of these "doing things in a directory that someone else can write to" exploits, but within the limited scope of this one feature, root ownership does not strike me as particularly dubious.

Caleb White· Oct 31, 2024, 05:38 UTC · re: Michael Orlitzky · lore

Re: safe.directory warnings for root-owned repositories

On Wed Oct 30, 2024 at 11:23 PM CDT, Michael Orlitzky wrote:
Show 24 quoted lines
> If I create a new repository as root,
>
>   $ sudo git init
>   Initialized empty Git repository in /home/mjo/tmp/.git/
>
>   $ ls -alh
>   total 12K
>   drwxr-xr-x  3 mjo  mjo  4.0K 2024-10-31 00:09 .
>   drwxr-x--- 17 mjo  mjo  4.0K 2024-10-31 00:07 ..
>   drwxr-xr-x  6 root root 4.0K 2024-10-31 00:09 .git
>
> and attempt to do anything in it, I get a safe.directory warning:
>
>   $ git status
>   fatal: detected dubious ownership in repository at '/home/mjo/tmp'
>   ...
>
> Does that make sense? In terms of ownership, root:root is as safe as
> it gets.
>
> I'm aware that safe.directory is only scratching the surface of these
> "doing things in a directory that someone else can write to" exploits,
> but within the limited scope of this one feature, root ownership does
> not strike me as particularly dubious.

The dubious ownership check simply reports that the directory is owned by someone other than the user running the command, with no special handling for the root user. While the error might not make the most sense in this context, I'm not sure that it's worth special-casing the root user (really the user with id = 0 as it might not be named `root`) in the implementation.

Why would you initialize a repository as `root` in the first place?

Best, Caleb

Michael Orlitzky· Oct 31, 2024, 12:15 UTC · re: Caleb White · lore

Re: safe.directory warnings for root-owned repositories

On 2024-10-31 05:38:00, Caleb White wrote:
Show 9 quoted lines
> 
> The dubious ownership check simply reports that the directory is owned by
> someone other than the user running the command, with no special handling
> for the root user. While the error might not make the most sense in this
> context, I'm not sure that it's worth special-casing the root user
> (really the user with id = 0 as it might not be named `root`) in the
> implementation.
> 
> Why would you initialize a repository as `root` in the first place?
To avoid the dubious ownership warning, obviously :)

These are shared repositories that I and my coworkers push to over SSH. Write access is granted via ACLs, with ownership being mostly irrelevant. (This is still "unsafe," but not for the stated reason.)

I don't necessarily have a problem with adding O(m*n) safe.directory entries, but every once in a while someone will ask me about it, and I don't have a good answer for why it's not safe to push to a repository that's owned by root. I guess it's just more annoying to have to override the warning when the warning is wrong. Though if it was changed to "dubious repository writability," I wouldn't be able to complain any more.

Taylor Blau· Oct 31, 2024, 20:04 UTC · re: Michael Orlitzky · lore

Re: safe.directory warnings for root-owned repositories

On Thu, Oct 31, 2024 at 08:15:24AM -0400, Michael Orlitzky wrote:
Show 12 quoted lines
> On 2024-10-31 05:38:00, Caleb White wrote:
> >
> > The dubious ownership check simply reports that the directory is owned by
> > someone other than the user running the command, with no special handling
> > for the root user. While the error might not make the most sense in this
> > context, I'm not sure that it's worth special-casing the root user
> > (really the user with id = 0 as it might not be named `root`) in the
> > implementation.
> >
> > Why would you initialize a repository as `root` in the first place?
>
> To avoid the dubious ownership warning, obviously :)

If you want to avoid the warning entirely, you can set 'safe.directory' to "*" at the global level, and that will opt-out of the check entirely.

Of course, you should consult that portion of the git-config(1) manual page to understand the implications of doing so, but it is something that Git supports doing.

Thanks, Taylor

← back to recent threads