{"thread":{"id":"58606","subject":"2.38 \"protected configuration\" ignores includes","startedAt":"2022-10-12T06:16:36Z","lastAt":"2022-10-12T17:09:12Z","messageCount":2,"participants":["Mantas Mikulėnas","Glen Choo"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"464649","messageId":"CAPWNY8W_Tr-WoD-GXBddD5Y8w5Y4w+gDNYQdOAJ1uBwVHuRrsQ@mail.gmail.com","threadId":"58606","inReplyTo":null,"subject":"2.38 \"protected configuration\" ignores includes","fromName":"Mantas Mikulėnas","fromEmail":"grawity@gmail.com","sentAt":"2022-10-12T06:16:19Z","receivedAt":"2022-10-12T06:16:36Z","isPatch":false,"sender":{"key":"grawity@gmail.com","avatar":"https://avatars.githubusercontent.com/u/31021?v=4"},"body":"After Git 2.38 (specifically after commit 6061601d9), git no longer\nhonors safe.directory settings in files that are [include]'d from the\nmain global configuration file, even though they are shown as being in\nglobal scope by `git config --show-scope --show-origin`.\n\nThe docs added by\nhttps://github.com/git/git/commit/779ea9303a7de3d618f3b0e329ebb89529ab3285\nonly talk about scopes and do not mention anything about [include]\nbeing specifically ignored.\n\n$ git config --get-all --show-scope --show-origin safe.directory\nglobal    file:/home/grawity/.config/git/config    /srv/this.works\nglobal    file:/home/grawity/.config/git/config.local    /srv/this.does.not.work\n\n# ~/.config/git/config (owned by grawity:users)\n[safe]\n    directory = /srv/this.works\n[include]\n    path = ~/.config/git/config.local\n\n# ~/.config/git/config.local (also owned by grawity:users)\n[safe]\n    directory = /srv/this.does.not.work\n\n-- \nMantas Mikulėnas\n"},{"id":"464732","messageId":"kl6lbkqh0y1a.fsf@chooglen-macbookpro.roam.corp.google.com","threadId":"58606","inReplyTo":"CAPWNY8W_Tr-WoD-GXBddD5Y8w5Y4w+gDNYQdOAJ1uBwVHuRrsQ@mail.gmail.com","subject":"Re: 2.38 \"protected configuration\" ignores includes","fromName":"Glen Choo","fromEmail":"chooglen@google.com","sentAt":"2022-10-12T17:09:05Z","receivedAt":"2022-10-12T17:09:12Z","isPatch":false,"sender":{"key":"glencbz@gmail.com","avatar":"https://avatars.githubusercontent.com/u/58092771?v=4"},"body":"Mantas Mikulėnas <grawity@gmail.com> writes:\n\n> After Git 2.38 (specifically after commit 6061601d9), git no longer\n> honors safe.directory settings in files that are [include]'d from the\n> main global configuration file, even though they are shown as being in\n> global scope by `git config --show-scope --show-origin`.\n>\n> The docs added by\n> https://github.com/git/git/commit/779ea9303a7de3d618f3b0e329ebb89529ab3285\n> only talk about scopes and do not mention anything about [include]\n> being specifically ignored.\n>\n> $ git config --get-all --show-scope --show-origin safe.directory\n> global    file:/home/grawity/.config/git/config    /srv/this.works\n> global    file:/home/grawity/.config/git/config.local    /srv/this.does.not.work\n>\n> # ~/.config/git/config (owned by grawity:users)\n> [safe]\n>     directory = /srv/this.works\n> [include]\n>     path = ~/.config/git/config.local\n>\n> # ~/.config/git/config.local (also owned by grawity:users)\n> [safe]\n>     directory = /srv/this.does.not.work\n>\n> -- \n> Mantas Mikulėnas\n\nCC-ed some folks who have interest in safe.directory and/or have looked\nat the safe.bareRepository series.\n\nThanks for the report. As the author of the series in question, this\nwasn't an intended change.\n\nProtect config, as implemented in 5b3c650777 (config: learn\n`git_protected_config()`, 2022-07-14), reads from a hardcoded set of\nfile paths without considering \"include\"s, so this bug is not surprising\nin retrospect.\n\nI believe this can be fixed by replacing this implementation with an\ninvocation to config_with_options() (which knows about \"include\"s)\nshould be adequate to fix this.\n\nI'll prioritize a test and a fix for this.\n"}]}