threads / discuss / 63216

How to get git-daemon to work in a post-CVE world?

Subject: How to get git-daemon to work in a post-CVE world?

## tl;dr

4 messages between Mar 30, 2025 and Mar 31, 2025.

replies: 3people: 2as markdown or json

MegaBrutal· Mar 30, 2025, 08:30 UTC · lore
Hi Everyone,

I'm new to the list, just thought it's the best place to talk about Git. I'm running a public read-only git server with git-daemon. I've recently noticed that my repos can't be cloned and found that particular CVE which made git to verify the owners of the git repos.

fatal: detected dubious ownership in repository at '/srv/git/mgsautils.git'

The feasible solution is to declare the directory safe in .gitconfig. Contrary to my policy of not creating a home for my services, I made a home for git-daemon and placed a .gitconfig there. It seems to have an effect, because the error message has changed to the following:

fatal: detected dubious ownership in repository at '.'

Now how to solve this? It's a relative path so I wouldn't know what it has a problem with. I obviously can't declare '.' safe in .gitconfig, because it could have unintended consequences. I understand it's a security feature, but it's starting to get too cumbersome to work around to reestablish the original intended behavior. (Earlier I found out that I also need to create a .gitconfig for my git-shell users as well.)

Best regards, MegaBrutal

Konstantin Ryabitsev· Mar 31, 2025, 14:53 UTC · re: MegaBrutal · lore

Re: How to get git-daemon to work in a post-CVE world?

On Sun, Mar 30, 2025 at 10:30:00AM +0200, MegaBrutal wrote:
Show 10 quoted lines
> Hi Everyone,
> 
> I'm new to the list, just thought it's the best place to talk about
> Git. I'm running a public read-only git server with git-daemon. I've
> recently noticed that my repos can't be cloned and found that
> particular CVE which made git to verify the owners of the git repos.
> 
> fatal: detected dubious ownership in repository at '/srv/git/mgsautils.git'
> 
> The feasible solution is to declare the directory safe in .gitconfig.
You can set global values in /etc/gitconfig, e.g.:
    [safe]
      directory = /srv/git/*
-K
MegaBrutal· Mar 31, 2025, 20:15 UTC · re: Konstantin Ryabitsev · lore

Re: How to get git-daemon to work in a post-CVE world?

Konstantin Ryabitsev <konstantin@linuxfoundation.org> ezt írta (időpont: 2025. márc. 31., H, 16:53):

Show 17 quoted lines
>
> On Sun, Mar 30, 2025 at 10:30:00AM +0200, MegaBrutal wrote:
> > Hi Everyone,
> >
> > I'm new to the list, just thought it's the best place to talk about
> > Git. I'm running a public read-only git server with git-daemon. I've
> > recently noticed that my repos can't be cloned and found that
> > particular CVE which made git to verify the owners of the git repos.
> >
> > fatal: detected dubious ownership in repository at '/srv/git/mgsautils.git'
> >
> > The feasible solution is to declare the directory safe in .gitconfig.
>
> You can set global values in /etc/gitconfig, e.g.:
>
>     [safe]
>       directory = /srv/git/*

Thanks! While it is much more convenient to set it in one global /etc/gitconfig than individual home directories, I encountered the following problems:

1. It doesn't do anything with the other error I get, when the
problematic directory is '.'. I still keep getting that error message.
2. Git daemon doesn't seem to resolve the '*' wildcard, i.e. with the
wildcard I get the original message back which complains about
'/srv/git/mgsautils.git', despite it should be covered by
'/srv/git/*'. When I supply the full path, however, the error message
is still about '.'.

I even performed a whole Ubuntu release upgrade to get a new version of Git, but 2.43.0 acts the same. Seems like git-daemon is more stricts than plain git – what might be the problem?

Konstantin Ryabitsev· Mar 31, 2025, 20:45 UTC · re: MegaBrutal · lore

Re: How to get git-daemon to work in a post-CVE world?

On Mon, Mar 31, 2025 at 10:15:00PM +0200, MegaBrutal wrote:
Show 29 quoted lines
> > > I'm new to the list, just thought it's the best place to talk about
> > > Git. I'm running a public read-only git server with git-daemon. I've
> > > recently noticed that my repos can't be cloned and found that
> > > particular CVE which made git to verify the owners of the git repos.
> > >
> > > fatal: detected dubious ownership in repository at '/srv/git/mgsautils.git'
> > >
> > > The feasible solution is to declare the directory safe in .gitconfig.
> >
> > You can set global values in /etc/gitconfig, e.g.:
> >
> >     [safe]
> >       directory = /srv/git/*
> 
> Thanks! While it is much more convenient to set it in one global
> /etc/gitconfig than individual home directories, I encountered the
> following problems:
> 
> 1. It doesn't do anything with the other error I get, when the
> problematic directory is '.'. I still keep getting that error message.
> 2. Git daemon doesn't seem to resolve the '*' wildcard, i.e. with the
> wildcard I get the original message back which complains about
> '/srv/git/mgsautils.git', despite it should be covered by
> '/srv/git/*'. When I supply the full path, however, the error message
> is still about '.'.
> 
> I even performed a whole Ubuntu release upgrade to get a new version
> of Git, but 2.43.0 acts the same. Seems like git-daemon is more
> stricts than plain git – what might be the problem?

2.43.0 is not very new. I believe in that version it only supported setting that to '*' as a wildcard, so the following should work for you, hopefully:

    [safe]
      directory = *
-K

← back to recent threads