# safe.directory warnings for root-owned repositories

4 messages from 2024-10-31 to 2024-10-31. Participants: Michael Orlitzky, Caleb White, Taylor Blau.
Thread: https://gitlist.dev/t/62427

## Michael Orlitzky, 2024-10-31 04:23

Subject: safe.directory warnings for root-owned repositories
Message-ID: <ZyMGKHTnZDQ5JVuo@mertle>
URL: https://gitlist.dev/e/ZyMGKHTnZDQ5JVuo%40mertle

```
If I create a new repository as root,

  $ sudo git init
  Initialized empty Git repository in /home/mjo/tmp/.git/

  $ ls -alh
  total 12K
  drwxr-xr-x  3 mjo  mjo  4.0K 2024-10-31 00:09 .
  drwxr-x--- 17 mjo  mjo  4.0K 2024-10-31 00:07 ..
  drwxr-xr-x  6 root root 4.0K 2024-10-31 00:09 .git

and attempt to do anything in it, I get a safe.directory warning:

  $ git status
  fatal: detected dubious ownership in repository at '/home/mjo/tmp'
  ...

Does that make sense? In terms of ownership, root:root is as safe as
it gets.

I'm aware that safe.directory is only scratching the surface of these
"doing things in a directory that someone else can write to" exploits,
but within the limited scope of this one feature, root ownership does
not strike me as particularly dubious.

```

## Caleb White, 2024-10-31 05:38

Subject: Re: safe.directory warnings for root-owned repositories
Message-ID: <D59QZ1P3KSNB.ZXDHUA5HGC97@pm.me>
URL: https://gitlist.dev/e/D59QZ1P3KSNB.ZXDHUA5HGC97%40pm.me
In-Reply-To: <ZyMGKHTnZDQ5JVuo@mertle>

```
On Wed Oct 30, 2024 at 11:23 PM CDT, Michael Orlitzky wrote:
> If I create a new repository as root,
>
>   $ sudo git init
>   Initialized empty Git repository in /home/mjo/tmp/.git/
>
>   $ ls -alh
>   total 12K
>   drwxr-xr-x  3 mjo  mjo  4.0K 2024-10-31 00:09 .
>   drwxr-x--- 17 mjo  mjo  4.0K 2024-10-31 00:07 ..
>   drwxr-xr-x  6 root root 4.0K 2024-10-31 00:09 .git
>
> and attempt to do anything in it, I get a safe.directory warning:
>
>   $ git status
>   fatal: detected dubious ownership in repository at '/home/mjo/tmp'
>   ...
>
> Does that make sense? In terms of ownership, root:root is as safe as
> it gets.
>
> I'm aware that safe.directory is only scratching the surface of these
> "doing things in a directory that someone else can write to" exploits,
> but within the limited scope of this one feature, root ownership does
> not strike me as particularly dubious.

The dubious ownership check simply reports that the directory is owned by
someone other than the user running the command, with no special handling
for the root user. While the error might not make the most sense in this
context, I'm not sure that it's worth special-casing the root user
(really the user with id = 0 as it might not be named `root`) in the
implementation.

Why would you initialize a repository as `root` in the first place?

Best,
Caleb


```

## Michael Orlitzky, 2024-10-31 12:15

Subject: Re: safe.directory warnings for root-owned repositories
Message-ID: <ZyN03D8os53XJGDo@mertle>
URL: https://gitlist.dev/e/ZyN03D8os53XJGDo%40mertle
In-Reply-To: <D59QZ1P3KSNB.ZXDHUA5HGC97@pm.me>

```
On 2024-10-31 05:38:00, Caleb White wrote:
> 
> The dubious ownership check simply reports that the directory is owned by
> someone other than the user running the command, with no special handling
> for the root user. While the error might not make the most sense in this
> context, I'm not sure that it's worth special-casing the root user
> (really the user with id = 0 as it might not be named `root`) in the
> implementation.
> 
> Why would you initialize a repository as `root` in the first place?

To avoid the dubious ownership warning, obviously :)

These are shared repositories that I and my coworkers push to over
SSH. Write access is granted via ACLs, with ownership being mostly
irrelevant. (This is still "unsafe," but not for the stated reason.)

I don't necessarily have a problem with adding O(m*n) safe.directory
entries, but every once in a while someone will ask me about it, and I
don't have a good answer for why it's not safe to push to a repository
that's owned by root. I guess it's just more annoying to have to
override the warning when the warning is wrong. Though if it was
changed to "dubious repository writability," I wouldn't be able to
complain any more.

```

## Taylor Blau, 2024-10-31 20:04

Subject: Re: safe.directory warnings for root-owned repositories
Message-ID: <ZyPi4xdGPwfa9+ez@nand.local>
URL: https://gitlist.dev/e/ZyPi4xdGPwfa9%2Bez%40nand.local
In-Reply-To: <ZyN03D8os53XJGDo@mertle>

```
On Thu, Oct 31, 2024 at 08:15:24AM -0400, Michael Orlitzky wrote:
> On 2024-10-31 05:38:00, Caleb White wrote:
> >
> > The dubious ownership check simply reports that the directory is owned by
> > someone other than the user running the command, with no special handling
> > for the root user. While the error might not make the most sense in this
> > context, I'm not sure that it's worth special-casing the root user
> > (really the user with id = 0 as it might not be named `root`) in the
> > implementation.
> >
> > Why would you initialize a repository as `root` in the first place?
>
> To avoid the dubious ownership warning, obviously :)

If you want to avoid the warning entirely, you can set 'safe.directory'
to "*" at the global level, and that will opt-out of the check entirely.

Of course, you should consult that portion of the git-config(1) manual
page to understand the implications of doing so, but it is something
that Git supports doing.

Thanks,
Taylor

```
