Git: fatal: Detected Dubous Ownership (Safe Directory)

Since CVE-2022-24765, git refuses to operate when the repo owner differs from the current user — classic in containers, WSL, and shared mounts. The fix declares the directory safe, scoped to exactly that path.

What you'll see

Root causes

Repo directory owned by a different uid/gid

A bind-mounted volume, a container user mismatched to the host, or files chown-ed by root: git's ownership check fires. ls -ld /path shows the owner git is complaining about.

Same checkout accessed from multiple environments

Windows host + WSL + Docker all seeing one directory: three different uid mappings, one of which trips the check every time.

Fix it

  1. Confirm the ownership mismatch
    ls -ld /path/to/repo ; id   # compare repo owner with current uid/gid
  2. Declare the repo safe (scoped, per-repo)
    git config --global --add safe.directory /path/to/repo
  3. Or fix the ownership outright when you control the mount
    sudo chown -R $(id -u):$(id -g) /path/to/repo   # container: match the user in the image, or run as the right uid
  4. CI images: bake the safe.directory in
    # git config --system --add safe.directory /workspace   (in the Dockerfile) — system scope, no per-user surprises

Field note

safe.directory is an allowlist of paths git may operate on despite the ownership mismatch — it does not disable the check globally (that was deliberately made impossible). The CVE context: a malicious repo in a shared directory could execute as another user. The annoyance you see is git refusing that attack — the scoped allowlist keeps the protection for everything else.

Common questions

Can I just disable the check entirely?

git removed the global off switch deliberately. safe.directory accepts exact paths (or the * wildcard for all, strongly discouraged). Scope it to the mounts you actually control.

Why does it only fail in Docker/WSL?

Bind mounts preserve host uid/gid numbers, but the container/WSL user maps them differently — git sees an owner that is not you. Native checkouts never mismatch.

Ship it right the first time

Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.

Browse the template store →

One-time. Yours to modify. Instant download from the NinjaOps template store.