git@vger.kernel.org mailing list mirror (one of many)
 help / color / mirror / code / Atom feed
* [PATCH v2 1/3] read-cache: use shared perms when writing shared index
@ 2017-06-23 15:16 Christian Couder
  2017-06-23 15:16 ` [PATCH v2 2/3] t1301: move modebits() to test-lib-functions.sh Christian Couder
                   ` (3 more replies)
  0 siblings, 4 replies; 8+ messages in thread
From: Christian Couder @ 2017-06-23 15:16 UTC (permalink / raw)
  To: git
  Cc: Junio C Hamano, Ævar Arnfjörð Bjarmason,
	Michael Haggerty, Nguyen Thai Ngoc Duy, Ramsay Jones,
	Christian Couder

Since f6ecc62dbf (write_shared_index(): use tempfile module, 2015-08-10)
write_shared_index() has been using mks_tempfile() to create the
temporary file that will become the shared index.

But even before that, it looks like the functions used to create this
file didn't call adjust_shared_perm(), which means that the shared
index file has always been created with 600 permissions regardless
of the shared permission settings.

Because of that, on repositories created with `git init --shared=all`
and using the split index feature, one gets an error like:

fatal: .git/sharedindex.a52f910b489bc462f187ab572ba0086f7b5157de: index file open failed: Permission denied

when another user performs any operation that reads the shared index.

We could use create_tempfile() that calls adjust_shared_perm(), but
unfortunately create_tempfile() doesn't replace the XXXXXX at the end
of the path it is passed. So let's just call adjust_shared_perm() by
ourselves.

Signed-off-by: Christian Couder <chriscool@tuxfamily.org>
---
 read-cache.c | 8 ++++++++
 1 file changed, 8 insertions(+)

diff --git a/read-cache.c b/read-cache.c
index bc156a133e..66f85f8d58 100644
--- a/read-cache.c
+++ b/read-cache.c
@@ -2425,6 +2425,14 @@ static int write_shared_index(struct index_state *istate,
 		delete_tempfile(&temporary_sharedindex);
 		return ret;
 	}
+	ret = adjust_shared_perm(temporary_sharedindex.filename.buf);
+	if (ret) {
+		int save_errno = errno;
+		error("cannot fix permission bits on %s", temporary_sharedindex.filename.buf);
+		delete_tempfile(&temporary_sharedindex);
+		errno = save_errno;
+		return ret;
+	}
 	ret = rename_tempfile(&temporary_sharedindex,
 			      git_path("sharedindex.%s", sha1_to_hex(si->base->sha1)));
 	if (!ret) {
-- 
2.13.1.519.g0a0746bea4


^ permalink raw reply related	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2017-06-25  4:42 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2017-06-23 15:16 [PATCH v2 1/3] read-cache: use shared perms when writing shared index Christian Couder
2017-06-23 15:16 ` [PATCH v2 2/3] t1301: move modebits() to test-lib-functions.sh Christian Couder
2017-06-23 15:16 ` [PATCH v2 3/3] t1700: make sure split-index respects core.sharedrepository Christian Couder
2017-06-23 22:20   ` Junio C Hamano
2017-06-25  4:39     ` Christian Couder
2017-06-23 21:55 ` [PATCH v2 1/3] read-cache: use shared perms when writing shared index Junio C Hamano
2017-06-23 22:02 ` Junio C Hamano
2017-06-25  4:42   ` Christian Couder

Code repositories for project(s) associated with this public inbox

	https://80x24.org/mirrors/git.git

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).