guanghu-ice-heart/server-tools/lake-lamp-authz/hooks/guanghu-ice-heart-post-receive

33 lines
1.1 KiB
Shell
Executable file

#!/bin/sh
set -eu
# The code-channel service runs with UMask=0077. Keep that isolation for its
# database and other state, but make Git objects and refs readable/writable by
# the repository's dedicated shared group after an accepted public push.
repo_dir=$(CDPATH= cd -- "$(dirname -- "$0")/.." && pwd -P)
cd "$repo_dir"
owner_uid=$(id -u)
share_tree() {
find "$1" -user "$owner_uid" -type d -exec chmod g+rwx {} +
find "$1" -user "$owner_uid" -type f -exec chmod g+rw {} +
}
share_tree "$repo_dir/objects"
share_tree "$repo_dir/refs"
# receive-pack may keep new objects in a quarantine directory until hooks have
# completed. Normalize that directory before Git moves the objects into place.
if [ -n "${GIT_OBJECT_DIRECTORY:-}" ] && [ -d "$GIT_OBJECT_DIRECTORY" ]; then
case "$GIT_OBJECT_DIRECTORY/" in
"$repo_dir/"*) share_tree "$GIT_OBJECT_DIRECTORY" ;;
esac
fi
for shared_file in HEAD packed-refs; do
if [ -f "$repo_dir/$shared_file" ]; then
find "$repo_dir/$shared_file" -user "$owner_uid" -exec chmod g+rw {} +
fi
done
printf '%s\n' "post_receive_permissions_reconciled" >"$repo_dir/hooks/post-receive.last"