# Upgrading git: push fails due to changed security policy: safe.directory

**URL:** <https://forum.gitea.com/t/upgrading-git-push-fails-due-to-changed-security-policy-safe-directory/5185>\
**Category:** Install/Maintain/Configure\
**Created:** [May 8, 2022, 12:34pm UTC](https://forum.gitea.com/t/upgrading-git-push-fails-due-to-changed-security-policy-safe-directory/5185 "2022-05-08T12:34:51Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![dachary](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/dachary/32/4990_2.png) [@dachary](https://forum.gitea.com/u/dachary)\
**Post date:** [May 8, 2022, 12:34pm UTC](https://forum.gitea.com/t/upgrading-git-push-fails-due-to-changed-security-policy-safe-directory/5185/1 "2022-05-08T12:34:51Z")

</div>

Bonjour,

April 12, 2022 version [git v2.35.2](https://lore.kernel.org/git/xmqqv8veb5i6.fsf@gitster.g/) was released and addresses a security issue [CVE-2022-24765](https://github.com/git-for-windows/git/security/advisories/GHSA-vw2c-22j4-2fh2). It was backported to 2.30.3, v2.31.2, v2.32.1, v2.33.2, and v2.34.2 and published by distributions such as [Debian GNU/Linux](https://security-tracker.debian.org/tracker/CVE-2022-24765), [Alpine](https://www.alpinelinux.org/releases/).

**If Gitea runs as user `foo`, calls a patched Git version and a parent directory of the git repositories is owned by a user other than `foo`, it will fail** with a message such as:

```auto
Failed to open repository: Git/Data Error: exit status 128 - fatal: unsafe repository ('/data/git/repositories/git/data.git' is owned by someone else)

```

This started to show in the past two weeks to [users running the Gitea binary on Windows](https://github.com/go-gitea/gitea/issues/19455) who also independently installed git v2.36. And then to people running [Gitea from snap](https://github.com/go-gitea/gitea/issues/19455#issuecomment-1106331149), on [a Synology NAS](https://github.com/go-gitea/gitea/issues/19455#issuecomment-1106312061) and then people running from [Gitea docker images](https://github.com/go-gitea/gitea/blob/main/Dockerfile#L2) which is based on [Alpine](https://www.alpinelinux.org/releases/).

### Fixing the problem

Since the root cause of the problem does not come from Gitea, it requires manual intervention to:

- Change the ownership of all repository directories to belong to the same user as Gitea
- Ensure Gitea does not run as root

Below are specific instructions depending on how Gitea was installed.

#### [Gitea was installed from docker images](https://hub.docker.com/r/gitea/gitea) greater or equal to 1.16.6

If you installed Gitea using [Docker Basic](https://docs.gitea.io/en-us/install-with-docker/#basics) or manually via the Docker CLI, you can modify the permissions of all files with:

```auto
docker exec gitea chown -R 1000 /data/git/repositories

```

[Gitea docker images](https://hub.docker.com/r/gitea/gitea) greater or equal to 1.16.6 contain git version greater or equal to 2.30.3 which include the security patch. Previous docker images for Gitea have a lower version of git (for instance 1.16.5 has 2.30.2) and are not impacted.

### Workarounds

If it is not possible for some reasons, there are workarounds. Be advised that **applying these workarounds exposes the host to security risks as described in [CVE-2022-24765](https://github.com/git-for-windows/git/security/advisories/GHSA-vw2c-22j4-2fh2)**:

- If using [Gitea docker images](https://hub.docker.com/r/gitea/gitea):
  - do not upgrade to 1.16.6 or above
  - downgrade from 1.16.6 or 1.16.7 to 1.16.5 (do **not** downgrade from 1.17.x, it may corrupt your the Gitea database)

- If the Gitea binary was installed independently of git, upgrade git to a version that is [greater or equal to 2.36](https://git-scm.com/docs/git-config#Documentation/git-config.txt-safedirectory) and disable the security check entirely with:
  - `git config --system --replace-all safe.directory '*'`

Cheers

---

<div class="post-metadata">

**Author:** ![singuliere](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/singuliere/32/5017_2.png) [@singuliere](https://forum.gitea.com/u/singuliere)\
**Post date:** [May 9, 2022, 6:15pm UTC](https://forum.gitea.com/t/upgrading-git-push-fails-due-to-changed-security-policy-safe-directory/5185/2 "2022-05-09T18:15:48Z")

</div>

Here are [instructions to change the permissions on Windows](https://github.com/go-gitea/gitea/issues/19455#issuecomment-1121209917):

> properties → security → advance → change owner  
> And ticking the replace all child object permission entries with inheritable permission entries from this object

---

<div class="post-metadata">

**Author:** ![singuliere](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/singuliere/32/5017_2.png) [@singuliere](https://forum.gitea.com/u/singuliere)\
**Post date:** [May 14, 2022, 12:14pm UTC](https://forum.gitea.com/t/upgrading-git-push-fails-due-to-changed-security-policy-safe-directory/5185/3 "2022-05-14T12:14:56Z")

</div>

Note that **`safe.directory`** is not documented to support **\*** in [git 2.35.2](https://git-scm.com/docs/git-config/2.35.2#Documentation/git-config.txt-safedirectory) which [is confirmed by at least one user](https://github.com/go-gitea/gitea/issues/19455#issuecomment-1125618123) but only in [git 2.36+](https://git-scm.com/docs/git-config#Documentation/git-config.txt-safedirectory).

---

<div class="post-metadata">

**Author:** ![dachary](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/dachary/32/4990_2.png) [@dachary](https://forum.gitea.com/u/dachary)\
**Post date:** [May 14, 2022, 9:26pm UTC](https://forum.gitea.com/t/upgrading-git-push-fails-due-to-changed-security-policy-safe-directory/5185/4 "2022-05-14T21:26:52Z")

</div>

I think there is a simpler way to deal with this problem, here is the rationale:

* * *

It is safe to [disable the security check in Gitea](https://lab.forgefriends.org/forgefriends/forgefriends/-/merge_requests/50/diffs). It is not vulnerable to **[CVE-2022-24765](https://github.com/git-for-windows/git/security/advisories/GHSA-vw2c-22j4-2fh2)** because it calls the git CLI [after changing its working directory](https://github.com/go-gitea/gitea/blob/main/modules/git/command.go#L160) to be the git repository targeted by the command (for instance [diff](https://github.com/go-gitea/gitea/blob/main/modules/git/diff.go#L38-L45)). Therefore **it will not explore the parent directories looking for a git configuration file**.

The security check is triggered because the repository is owned by an unexpected user (root instead of git typically) and **not because a parent directory is owned by an unexpected user**. This, in itself, is a problem worth investigating but it is unrelated and was revealed by the newer security check of git even though it does not match the threat described in **[CVE-2022-24765](https://github.com/git-for-windows/git/security/advisories/GHSA-vw2c-22j4-2fh2)**.

It appears non trivial to enforce a consistent ownership of files and directories, either within docker or outside docker when network file systems are involved. The Gitea server was not troubled by this inconsistency so far because the permissions allow it to write and read where expected, regardless of the owner. Again, that does not mean it is not worth looking into, just that the problem is ancient and unrelated.

Gitea runs under a dedicated user, either when installed [from binary](https://docs.gitea.io/en-us/install-from-binary/#recommended-server-configuration) or from [docker](https://docs.gitea.io/en-us/install-with-docker/) and [modifies the global git configuration](https://github.com/go-gitea/gitea/blob/main/modules/git/git.go#L196-L207) depending on the git version at initialization time. Fixing the problem can therefore be done by [disabling the security check in the global git config file at initialization time](https://lab.forgefriends.org/forgefriends/forgefriends/-/merge_requests/50/diffs#bcd72ff867cbd1ddd5b6518c3a05b5f1a6021286_209_209). It also requires a minimum version of git 2.36 to be installed [in the Gitea docker image](https://lab.forgefriends.org/forgefriends/forgefriends/-/merge_requests/50/diffs#6651ddff6eb82c840ced7c1dddee15c6e1913dd4_44_49).

* * *

Does that sound sensible?

---

<div class="post-metadata">

**Author:** ![dachary](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/dachary/32/4990_2.png) [@dachary](https://forum.gitea.com/u/dachary)\
**Post date:** [June 2, 2022, 10:40am UTC](https://forum.gitea.com/t/upgrading-git-push-fails-due-to-changed-security-policy-safe-directory/5185/5 "2022-06-02T10:40:39Z")

</div>

This blog post explains how to workaround the problem. It also links to the pending bug fixes addressing the problem in Gitea.

> **[\[solved\] Gitea 1.16.\[678\] error: fatal: unsafe repository is owned by someone...](https://hostea.org/blog/unsafe-repository-is-owned-by-someone-else/)**
>
> If Gitea runs as user git, calls a patched Git version and a parent directory of the git repositories is owned by a user other than git, it will fail.

---

<div class="post-metadata">

**Author:** ![dachary](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/dachary/32/4990_2.png) [@dachary](https://forum.gitea.com/u/dachary)\
**Post date:** [June 23, 2022, 4:35am UTC](https://forum.gitea.com/t/upgrading-git-push-fails-due-to-changed-security-policy-safe-directory/5185/6 "2022-06-23T04:35:24Z")

</div>

For the record, here is another instance of the problem on 1.16.8. It does not give more information but it would be worth asking the person more details about their setup. They may be willing to investigate and make a reproducer.

> <https://github.com/go-gitea/gitea/issues/20095#issuecomment-1163880069>
>
> \### Description
> 
> I can not find the reason of 500 error. and do not know how to …resolve it.The account page and administrator page is normal except the Repository page. how can I resolve it . thanks a lot.
> system :windows
> version:gitea 16.6/16.8
> 
> 
> \### Gitea Version
> 
> gitea 16.6/gitea 16.8
> 
> \### Can you reproduce the bug on the Gitea demo site?
> 
> No
> 
> \### Log Gist
> 
> I can not find the log file.
> 
> \### Screenshots
> 
> !\[image\](https://user-images.githubusercontent.com/26760292/175187788-f54ae88e-0719-4750-8c15-61b082b78f8c.png)
> 
> 
> \### Git Version
> 
> 2.35.3
> 
> \### Operating System
> 
> windows
> 
> \### How are you running Gitea?
> 
> I download gitea exe from the official website.
> 
> \### Database
> 
> SQLite

```auto
2022/06/23 11:18:07 ...ules/context/repo.go:592:RepoAssignment() [E] RepoAssignment Invalid repo C:\Gitea\data\gitea-repositories\skymaper\tmcplugin.git: exit status 128 - fatal: unsafe repository ('C:/Gitea/data/gitea-repositories/skymaper/tmcplugin.git' is owned by someone else)
To add an exception for this directory, call:

```

```
git config --global --add safe.directory C:/Gitea/data/gitea-repositories/skymaper/tmcplugin.git

```

```auto

2022/06/23 11:18:07 ...s/context/context.go:204:HTML() [D] Template: status/500

```
