4 ms·
So wait a minute. The situation here is that a directory Alice owns is a subdirectory of a directory Eve owns. I find it highly surprising that anyone would c
by csense 4y ago
So wait a minute. The situation here is that a directory Alice owns is a subdirectory of a directory Eve owns.
I find it highly surprising that anyone would configure a multi-user machine where a parent directory is owned by an untrusted user different from the current user. Usually a parent directory would be owned by the same user as the current directory, root, or possibly a system service account.
Although now that I think about it, /tmp might be an example -- if Eve is a local user, she can create /tmp/.git. Then if Alice tries to use the git command in a subdirectory of /tmp that's not already a Git repository, she might be bitten by this.
It's still a pretty far-fetched scenario, but I suppose it's possible a non-zero number of users are affected.
Are multi-user machines even that common? I was under the impression that most people don't really use OS level user accounts, and instead use VM's or containers if they want to have multiple people using the same physical box (especially if those people are untrusted). AFAIK traditional Unix shared hosting is mostly in the past.
I use Git regularly but I'm not going to lose any sleep over this one.
- nijave 4y agoMaybe (abused) jump servers or "admin" servers? (Those abused catchall servers will scripts and crons that don't have their own systems get thrown)
- remram 4y ago/tmp seems like a huge target here. I definitely run `git clone` in /tmp, sometimes on shared machines (HPC). I even run `git log` or similar in there, when I'm distracted I forget to `cd` down first.