# How to get git-daemon to work in a post-CVE world?

4 messages from 2025-03-30 to 2025-03-31. Participants: MegaBrutal, Konstantin Ryabitsev.
Thread: https://gitlist.dev/t/63216

## MegaBrutal, 2025-03-30 08:30

Subject: How to get git-daemon to work in a post-CVE world?
Message-ID: <CAE8gLhmKtV-Kz4jYT6r1NanmGdAyzd0CumVGsVnVpePQPAtnzQ@mail.gmail.com>
URL: https://gitlist.dev/e/CAE8gLhmKtV-Kz4jYT6r1NanmGdAyzd0CumVGsVnVpePQPAtnzQ%40mail.gmail.com

```
Hi Everyone,

I'm new to the list, just thought it's the best place to talk about
Git. I'm running a public read-only git server with git-daemon. I've
recently noticed that my repos can't be cloned and found that
particular CVE which made git to verify the owners of the git repos.

fatal: detected dubious ownership in repository at '/srv/git/mgsautils.git'

The feasible solution is to declare the directory safe in .gitconfig.
Contrary to my policy of not creating a home for my services, I made a
home for git-daemon and placed a .gitconfig there. It seems to have an
effect, because the error message has changed to the following:

fatal: detected dubious ownership in repository at '.'

Now how to solve this? It's a relative path so I wouldn't know what it
has a problem with. I obviously can't declare '.' safe in .gitconfig,
because it could have unintended consequences. I understand it's a
security feature, but it's starting to get too cumbersome to work
around to reestablish the original intended behavior. (Earlier I found
out that I also need to create a .gitconfig for my git-shell users as
well.)


Best regards,
MegaBrutal

```

## Konstantin Ryabitsev, 2025-03-31 14:53

Subject: Re: How to get git-daemon to work in a post-CVE world?
Message-ID: <20250331-devious-woodpecker-of-temperance-b18608@lemur>
URL: https://gitlist.dev/e/20250331-devious-woodpecker-of-temperance-b18608%40lemur
In-Reply-To: <CAE8gLhmKtV-Kz4jYT6r1NanmGdAyzd0CumVGsVnVpePQPAtnzQ@mail.gmail.com>

```
On Sun, Mar 30, 2025 at 10:30:00AM +0200, MegaBrutal wrote:
> Hi Everyone,
> 
> I'm new to the list, just thought it's the best place to talk about
> Git. I'm running a public read-only git server with git-daemon. I've
> recently noticed that my repos can't be cloned and found that
> particular CVE which made git to verify the owners of the git repos.
> 
> fatal: detected dubious ownership in repository at '/srv/git/mgsautils.git'
> 
> The feasible solution is to declare the directory safe in .gitconfig.

You can set global values in /etc/gitconfig, e.g.:

    [safe]
      directory = /srv/git/*

-K

```

## MegaBrutal, 2025-03-31 20:15

Subject: Re: How to get git-daemon to work in a post-CVE world?
Message-ID: <CAE8gLh=1bqA6UTR4wAX1u1naic2cSGiekz0jLKxWeaxBKa=xiQ@mail.gmail.com>
URL: https://gitlist.dev/e/CAE8gLh%3D1bqA6UTR4wAX1u1naic2cSGiekz0jLKxWeaxBKa%3DxiQ%40mail.gmail.com
In-Reply-To: <20250331-devious-woodpecker-of-temperance-b18608@lemur>

```
Konstantin Ryabitsev <konstantin@linuxfoundation.org> ezt írta
(időpont: 2025. márc. 31., H, 16:53):
>
> On Sun, Mar 30, 2025 at 10:30:00AM +0200, MegaBrutal wrote:
> > Hi Everyone,
> >
> > I'm new to the list, just thought it's the best place to talk about
> > Git. I'm running a public read-only git server with git-daemon. I've
> > recently noticed that my repos can't be cloned and found that
> > particular CVE which made git to verify the owners of the git repos.
> >
> > fatal: detected dubious ownership in repository at '/srv/git/mgsautils.git'
> >
> > The feasible solution is to declare the directory safe in .gitconfig.
>
> You can set global values in /etc/gitconfig, e.g.:
>
>     [safe]
>       directory = /srv/git/*

Thanks! While it is much more convenient to set it in one global
/etc/gitconfig than individual home directories, I encountered the
following problems:

1. It doesn't do anything with the other error I get, when the
problematic directory is '.'. I still keep getting that error message.
2. Git daemon doesn't seem to resolve the '*' wildcard, i.e. with the
wildcard I get the original message back which complains about
'/srv/git/mgsautils.git', despite it should be covered by
'/srv/git/*'. When I supply the full path, however, the error message
is still about '.'.

I even performed a whole Ubuntu release upgrade to get a new version
of Git, but 2.43.0 acts the same. Seems like git-daemon is more
stricts than plain git – what might be the problem?

```

## Konstantin Ryabitsev, 2025-03-31 20:45

Subject: Re: How to get git-daemon to work in a post-CVE world?
Message-ID: <20250331-thistle-wolverine-of-jest-b11d9b@lemur>
URL: https://gitlist.dev/e/20250331-thistle-wolverine-of-jest-b11d9b%40lemur
In-Reply-To: <CAE8gLh=1bqA6UTR4wAX1u1naic2cSGiekz0jLKxWeaxBKa=xiQ@mail.gmail.com>

```
On Mon, Mar 31, 2025 at 10:15:00PM +0200, MegaBrutal wrote:
> > > I'm new to the list, just thought it's the best place to talk about
> > > Git. I'm running a public read-only git server with git-daemon. I've
> > > recently noticed that my repos can't be cloned and found that
> > > particular CVE which made git to verify the owners of the git repos.
> > >
> > > fatal: detected dubious ownership in repository at '/srv/git/mgsautils.git'
> > >
> > > The feasible solution is to declare the directory safe in .gitconfig.
> >
> > You can set global values in /etc/gitconfig, e.g.:
> >
> >     [safe]
> >       directory = /srv/git/*
> 
> Thanks! While it is much more convenient to set it in one global
> /etc/gitconfig than individual home directories, I encountered the
> following problems:
> 
> 1. It doesn't do anything with the other error I get, when the
> problematic directory is '.'. I still keep getting that error message.
> 2. Git daemon doesn't seem to resolve the '*' wildcard, i.e. with the
> wildcard I get the original message back which complains about
> '/srv/git/mgsautils.git', despite it should be covered by
> '/srv/git/*'. When I supply the full path, however, the error message
> is still about '.'.
> 
> I even performed a whole Ubuntu release upgrade to get a new version
> of Git, but 2.43.0 acts the same. Seems like git-daemon is more
> stricts than plain git – what might be the problem?

2.43.0 is not very new. I believe in that version it only supported setting
that to '*' as a wildcard, so the following should work for you, hopefully:

    [safe]
      directory = *

-K

```
