Skip to content

Commit 5083f8b

Browse files
committed
Windows: add support for a Windows-wide configuration
Between the libgit2 and the Git for Windows project, there has been a discussion how we could share Git configuration to avoid duplication (or worse: skew). Earlier, libgit2 was nice enough to just re-use Git for Windows' C:\Program Files (x86)\Git\etc\gitconfig but with the big changes that went into Git for Windows 2.x, there would have been more paths to search, as there now was a 64-bit version in addition to a 32-bit one, and the corresponding config files are `%PROGRAMFILES%\Git\mingw64\etc` and `...\mingw32\etc`, respectively. Worse: there are portable Git for Windows versions out there which live in totally unrelated directories, still. Therefore we came to a consensus to use `%PROGRAMDATA%\Git\config` as the location for shared Git settings that are of wider interest than just Git for Windows, read: for other Git implementations. Of course, the configuration in `%PROGRAMDATA%\Git\config` has the widest reach, therefore it must take the lowest precedence, i.e. Git for Windows can still override settings in its `etc/gitconfig` file. Git for Windows supports this since v2.5.0 (i.e. since the first v2.x), and libgit2 supports it as of v0.28.1: libgit2/libgit2@8c7c5fa585 Helped-by: Andreas Heiduk <[email protected]> Signed-off-by: Johannes Schindelin <[email protected]>
1 parent aa25c82 commit 5083f8b

File tree

7 files changed

+148
-7
lines changed

7 files changed

+148
-7
lines changed

Documentation/config.txt

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,9 @@ the Git commands' behavior. The files `.git/config` and optionally
77
repository are used to store the configuration for that repository, and
88
`$HOME/.gitconfig` is used to store a per-user configuration as
99
fallback values for the `.git/config` file. The file `/etc/gitconfig`
10-
can be used to store a system-wide default configuration.
10+
can be used to store a system-wide default configuration. On Windows,
11+
configuration can also be stored in `C:\ProgramData\Git\config`; This
12+
file will be used also by libgit2-based software.
1113

1214
The configuration variables are used by both the Git plumbing
1315
and the porcelains. The variables are divided into sections, wherein

Documentation/git-config.txt

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -272,8 +272,16 @@ FILES
272272
If not set explicitly with `--file`, there are four files where
273273
'git config' will search for configuration options:
274274

275+
$PROGRAMDATA/Git/config::
276+
(Windows-only) System-wide configuration file shared with other Git
277+
implementations. Typically `$PROGRAMDATA` points to `C:\ProgramData`.
278+
275279
$(prefix)/etc/gitconfig::
276280
System-wide configuration file.
281+
(Windows-only) This file contains only the settings which are
282+
specific for this installation of Git for Windows and which should
283+
not be shared with other Git implementations like JGit, libgit2.
284+
`--system` will select this file.
277285

278286
$XDG_CONFIG_HOME/git/config::
279287
Second user-specific configuration file. If $XDG_CONFIG_HOME is not set

Documentation/git.txt

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -566,7 +566,8 @@ for further details.
566566

567567
`GIT_CONFIG_NOSYSTEM`::
568568
Whether to skip reading settings from the system-wide
569-
`$(prefix)/etc/gitconfig` file. This environment variable can
569+
`$(prefix)/etc/gitconfig` file (and on Windows, also from the
570+
`%PROGRAMDATA%\Git\config` file). This environment variable can
570571
be used along with `$HOME` and `$XDG_CONFIG_HOME` to create a
571572
predictable environment for a picky script, or you can set it
572573
temporarily to avoid using a buggy `/etc/gitconfig` file while

compat/mingw.c

Lines changed: 119 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,8 @@
22
#include "win32.h"
33
#include <conio.h>
44
#include <wchar.h>
5+
#include <aclapi.h>
6+
#include <sddl.h>
57
#include "../strbuf.h"
68
#include "../run-command.h"
79
#include "../cache.h"
@@ -2450,3 +2452,120 @@ int uname(struct utsname *buf)
24502452
"%u", (v >> 16) & 0x7fff);
24512453
return 0;
24522454
}
2455+
2456+
/*
2457+
* Verify that the file in question is owned by an administrator or system
2458+
* account, or at least by the current user.
2459+
*
2460+
* This function returns 1 if successful, 0 if the file is not owned by any of
2461+
* these, or -1 on error.
2462+
*/
2463+
static int validate_system_file_ownership(const char *path)
2464+
{
2465+
WCHAR wpath[MAX_PATH];
2466+
PSID owner_sid = NULL;
2467+
PSECURITY_DESCRIPTOR descriptor = NULL;
2468+
HANDLE token;
2469+
TOKEN_USER* info = NULL;
2470+
DWORD err, len;
2471+
int ret;
2472+
2473+
if (xutftowcs_path(wpath, path) < 0)
2474+
return -1;
2475+
2476+
err = GetNamedSecurityInfoW(wpath, SE_FILE_OBJECT,
2477+
OWNER_SECURITY_INFORMATION |
2478+
DACL_SECURITY_INFORMATION,
2479+
&owner_sid, NULL, NULL, NULL, &descriptor);
2480+
2481+
/* if the file does not exist, it does not have a valid owner */
2482+
if (err == ERROR_FILE_NOT_FOUND || err == ERROR_PATH_NOT_FOUND) {
2483+
ret = 0;
2484+
owner_sid = NULL;
2485+
goto finish_validation;
2486+
}
2487+
2488+
if (err != ERROR_SUCCESS) {
2489+
ret = error(_("failed to validate '%s' (%ld)"), path, err);
2490+
owner_sid = NULL;
2491+
goto finish_validation;
2492+
}
2493+
2494+
if (!IsValidSid(owner_sid)) {
2495+
ret = error(_("invalid owner: '%s'"), path);
2496+
goto finish_validation;
2497+
}
2498+
2499+
if (IsWellKnownSid(owner_sid, WinBuiltinAdministratorsSid) ||
2500+
IsWellKnownSid(owner_sid, WinLocalSystemSid)) {
2501+
ret = 1;
2502+
goto finish_validation;
2503+
}
2504+
2505+
/* Obtain current user's SID */
2506+
if (OpenProcessToken(GetCurrentProcess(), TOKEN_QUERY, &token) &&
2507+
!GetTokenInformation(token, TokenUser, NULL, 0, &len)) {
2508+
info = xmalloc((size_t)len);
2509+
if (!GetTokenInformation(token, TokenUser, info, len, &len))
2510+
FREE_AND_NULL(info);
2511+
}
2512+
2513+
if (!info)
2514+
ret = 0;
2515+
else {
2516+
ret = EqualSid(owner_sid, info->User.Sid) ? 1 : 0;
2517+
free(info);
2518+
}
2519+
2520+
finish_validation:
2521+
if (!ret && owner_sid) {
2522+
#define MAX_NAME_OR_DOMAIN 256
2523+
wchar_t owner_name[MAX_NAME_OR_DOMAIN];
2524+
wchar_t owner_domain[MAX_NAME_OR_DOMAIN];
2525+
wchar_t *p = NULL;
2526+
DWORD size = MAX_NAME_OR_DOMAIN;
2527+
SID_NAME_USE type;
2528+
char name[3 * MAX_NAME_OR_DOMAIN + 1];
2529+
2530+
if (!LookupAccountSidW(NULL, owner_sid, owner_name, &size,
2531+
owner_domain, &size, &type) ||
2532+
xwcstoutf(name, owner_name, ARRAY_SIZE(name)) < 0) {
2533+
if (!ConvertSidToStringSidW(owner_sid, &p))
2534+
strlcpy(name, "(unknown)", ARRAY_SIZE(name));
2535+
else {
2536+
if (xwcstoutf(name, p, ARRAY_SIZE(name)) < 0)
2537+
strlcpy(name, "(some user)",
2538+
ARRAY_SIZE(name));
2539+
LocalFree(p);
2540+
}
2541+
}
2542+
2543+
warning(_("'%s' has a dubious owner: '%s'.\n"
2544+
"For security reasons, it is therefore ignored.\n"
2545+
"To fix this, please transfer ownership to an "
2546+
"admininstrator."),
2547+
path, name);
2548+
}
2549+
2550+
if (descriptor)
2551+
LocalFree(descriptor);
2552+
2553+
return ret;
2554+
}
2555+
2556+
const char *program_data_config(void)
2557+
{
2558+
static struct strbuf path = STRBUF_INIT;
2559+
static unsigned initialized;
2560+
2561+
if (!initialized) {
2562+
const char *env = mingw_getenv("PROGRAMDATA");
2563+
if (env) {
2564+
strbuf_addf(&path, "%s/Git/config", env);
2565+
if (validate_system_file_ownership(path.buf) != 1)
2566+
strbuf_setlen(&path, 0);
2567+
}
2568+
initialized = 1;
2569+
}
2570+
return *path.buf ? path.buf : NULL;
2571+
}

compat/mingw.h

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -443,6 +443,8 @@ static inline void convert_slashes(char *path)
443443
#define PATH_SEP ';'
444444
extern char *mingw_query_user_email(void);
445445
#define query_user_email mingw_query_user_email
446+
extern const char *program_data_config(void);
447+
#define git_program_data_config program_data_config
446448
#if !defined(__MINGW64_VERSION_MAJOR) && (!defined(_MSC_VER) || _MSC_VER < 1800)
447449
#define PRIuMAX "I64u"
448450
#define PRId64 "I64d"

config.c

Lines changed: 10 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1676,11 +1676,16 @@ static int do_git_config_sequence(const struct config_options *opts,
16761676
repo_config = NULL;
16771677

16781678
current_parsing_scope = CONFIG_SCOPE_SYSTEM;
1679-
if (git_config_system() && !access_or_die(git_etc_gitconfig(), R_OK,
1680-
opts->system_gently ?
1681-
ACCESS_EACCES_OK : 0))
1682-
ret += git_config_from_file(fn, git_etc_gitconfig(),
1683-
data);
1679+
if (git_config_system()) {
1680+
int flags = opts->system_gently ? ACCESS_EACCES_OK : 0;
1681+
const char *program_data = git_program_data_config();
1682+
const char *etc = git_etc_gitconfig();
1683+
1684+
if (program_data && !access_or_die(program_data, R_OK, flags))
1685+
ret += git_config_from_file(fn, program_data, data);
1686+
if (!access_or_die(etc, R_OK, flags))
1687+
ret += git_config_from_file(fn, etc, data);
1688+
}
16841689

16851690
current_parsing_scope = CONFIG_SCOPE_GLOBAL;
16861691
if (xdg_config && !access_or_die(xdg_config, R_OK, ACCESS_EACCES_OK))

git-compat-util.h

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -412,6 +412,10 @@ static inline char *git_find_last_dir_sep(const char *path)
412412
#endif
413413
#endif
414414

415+
#ifndef git_program_data_config
416+
#define git_program_data_config() NULL
417+
#endif
418+
415419
#if defined(__HP_cc) && (__HP_cc >= 61000)
416420
#define NORETURN __attribute__((noreturn))
417421
#define NORETURN_PTR

0 commit comments

Comments
 (0)