{"thread":{"id":"60694","subject":"Storing private config files in .git directory?","startedAt":"2024-01-07T13:03:29Z","lastAt":"2024-01-12T06:57:01Z","messageCount":7,"participants":["Stefan Haller","Junio C Hamano","Konstantin Ryabitsev","Marc Branchaud","Jeff King"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"486375","messageId":"8e344dee-f84e-4a2c-835a-406ee72d129b@haller-berlin.de","threadId":"60694","inReplyTo":null,"subject":"Storing private config files in .git directory?","fromName":"Stefan Haller","fromEmail":"lists@haller-berlin.de","sentAt":"2024-01-07T13:03:20Z","receivedAt":"2024-01-07T13:03:29Z","isPatch":false,"sender":{"key":"lists@haller-berlin.de","avatar":null},"body":"Our git client (lazygit) has a need to store per-repo config files that\noverride the global one, much like git itself. The easiest way to do\nthat is to store those in a .git/lazygit.cfg file, and I'm wondering if\nthere's any reason why this is a bad idea?\n\nAnother alternative would be to store the config values in .git/config\n(that's the path taken by git gui, for example), but since our config\nfile format is yaml, this would require translation. It would be trivial\nfor scalar values such as int or string, but I'm not sure how well this\nwould work for more complex settings like lists of objects.\n\nAny thoughts?\n"},{"id":"486404","messageId":"xmqq34v7lmb3.fsf@gitster.g","threadId":"60694","inReplyTo":"8e344dee-f84e-4a2c-835a-406ee72d129b@haller-berlin.de","subject":"Re: Storing private config files in .git directory?","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2024-01-08T18:20:00Z","receivedAt":"2024-01-08T18:20:04Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Stefan Haller <lists@haller-berlin.de> writes:\n\n> Our git client (lazygit) has a need to store per-repo config files that\n> override the global one, much like git itself. The easiest way to do\n> that is to store those in a .git/lazygit.cfg file, and I'm wondering if\n> there's any reason why this is a bad idea?\n\nAn obvious alternative is to have .lazygit directory next to .git directory\nwhich would give you a bigger separation, which can cut both ways.\n\n"},{"id":"486407","messageId":"20240108-affable-azure-goldfish-b91d1a@lemur","threadId":"60694","inReplyTo":"8e344dee-f84e-4a2c-835a-406ee72d129b@haller-berlin.de","subject":"Re: Storing private config files in .git directory?","fromName":"Konstantin Ryabitsev","fromEmail":"konstantin@linuxfoundation.org","sentAt":"2024-01-08T18:56:52Z","receivedAt":"2024-01-08T18:56:53Z","isPatch":false,"sender":{"key":"konstantin@linuxfoundation.org","avatar":"https://gravatar.com/avatar/7cb8827c6de56e1bd2dea16508c6708aa43feed3bf3813bcdacecdf96ceadd79?d=mp&s=160"},"body":"On Sun, Jan 07, 2024 at 02:03:20PM +0100, Stefan Haller wrote:\n> Our git client (lazygit) has a need to store per-repo config files that\n> override the global one, much like git itself. The easiest way to do\n> that is to store those in a .git/lazygit.cfg file, and I'm wondering if\n> there's any reason why this is a bad idea?\n\nI have considered the same question for b4 as well, but I chose to just rely\non git's config file handling instead of any other option. There's a large\nnumber of people who tend to deal with weird repository situations by blowing\naway the entire repo and then recloning it. They may remember to back up the\n.git/config file, but not really anything else.\n\nSo, that would be the only consideration against keeping anything in the .git\ndirectory.\n\n-K\n"},{"id":"486410","messageId":"3717f23b-14a9-4c00-aaa9-ebb0f46f811e@xiplink.com","threadId":"60694","inReplyTo":"8e344dee-f84e-4a2c-835a-406ee72d129b@haller-berlin.de","subject":"Re: Storing private config files in .git directory?","fromName":"Marc Branchaud","fromEmail":"marcnarc@xiplink.com","sentAt":"2024-01-08T19:48:34Z","receivedAt":"2024-01-08T19:48:37Z","isPatch":false,"sender":{"key":"marcnarc@xiplink.com","avatar":"https://avatars.githubusercontent.com/u/14980203?v=4"},"body":"\nOn 2024-01-07 08:03, Stefan Haller wrote:\n> Our git client (lazygit) has a need to store per-repo config files that\n> override the global one, much like git itself. The easiest way to do\n> that is to store those in a .git/lazygit.cfg file, and I'm wondering if\n> there's any reason why this is a bad idea?\n\nIn a worktree (created by \"git worktree\"), .git is a file not a directory.\n\nWorktrees are designed to each have their own .git directory, which you \ncan find with \"git rev-parse --git-dir\".  If you just want a single, \nrepo-wide config file, not a per-worktree config, you probably want to \ninstead use \"git rev-parse --git-common-dir\" to find the \"main\" repo's \n.git directory.\n\nThe problem of finding a worktree's .git directory goes away if you use \nGit's own config system, though.\n\n> Another alternative would be to store the config values in .git/config\n> (that's the path taken by git gui, for example), but since our config\n> file format is yaml, this would require translation. It would be trivial\n> for scalar values such as int or string, but I'm not sure how well this\n> would work for more complex settings like lists of objects.\n> \n> Any thoughts?\n\nYAML is a horrid little format (hey, you asked for \"thoughts\"!), and \nIIRC Git's config file format only supports multi-line values with \n\\-escaping and similar patterns, making it nearly impossible to directly \nembed YAML in Git's config file.  Ideally, if you do use Git's own \nconfig then you really should just drop YAML altogether.\n\nBut you have a couple of options without going so far as translating all \nthe YAML constructs you use into git-config ones.  For example, you \ncould replace all the newlines in a YAML blob with \\n to make a \nsingle-line value that you could store in Git's config file.  That \ncomplicates hand-editing the YAML though, if that's a use case you care \nabout.\n\nBut even if you replace all the newlines with \\n, in my experience there \nare always corner-case clashes when mixing file syntaxes (e.g. quoted \nstrings are often problematic, and maybe some of your YAML values are \nthemselves multi-line).  If you want to use Git's own config file but \nstick with YAML, and you really don't care about directly editing the \nYAML, I suggest you encode the entire YAML blob in a robust single-line \nformat, like base64, and store/retrieve that using \"git config\".\n\nYou could still support hand-editing the YAML with a command like \n\"lazygit editconfig\", too.\n\n\t\tM.\n"},{"id":"486517","messageId":"20240110110842.GD16674@coredump.intra.peff.net","threadId":"60694","inReplyTo":"xmqq34v7lmb3.fsf@gitster.g","subject":"Re: Storing private config files in .git directory?","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2024-01-10T11:08:42Z","receivedAt":"2024-01-10T11:08:43Z","isPatch":false,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Mon, Jan 08, 2024 at 10:20:00AM -0800, Junio C Hamano wrote:\n\n> Stefan Haller <lists@haller-berlin.de> writes:\n> \n> > Our git client (lazygit) has a need to store per-repo config files that\n> > override the global one, much like git itself. The easiest way to do\n> > that is to store those in a .git/lazygit.cfg file, and I'm wondering if\n> > there's any reason why this is a bad idea?\n> \n> An obvious alternative is to have .lazygit directory next to .git directory\n> which would give you a bigger separation, which can cut both ways.\n\nJust to spell out one of those ways: unlike \".git\", we will happily\ncheck out \".lazygit\" from an untrusted remote repository. That may be a\nfeature if you want to be able to share project-specific config, or it\nmight be a terrible security vulnerability if lazygit config files can\ntrigger arbitrary code execution.\n\n-Peff\n"},{"id":"486627","messageId":"c8ad96bc-0180-42f4-b559-20b475098eca@haller-berlin.de","threadId":"60694","inReplyTo":"20240110110842.GD16674@coredump.intra.peff.net","subject":"Re: Storing private config files in .git directory?","fromName":"Stefan Haller","fromEmail":"lists@haller-berlin.de","sentAt":"2024-01-11T13:28:51Z","receivedAt":"2024-01-11T13:29:01Z","isPatch":false,"sender":{"key":"lists@haller-berlin.de","avatar":null},"body":"On 10.01.24 12:08, Jeff King wrote:\n> On Mon, Jan 08, 2024 at 10:20:00AM -0800, Junio C Hamano wrote:\n> \n>> An obvious alternative is to have .lazygit directory next to .git directory\n>> which would give you a bigger separation, which can cut both ways.\n> \n> Just to spell out one of those ways: unlike \".git\", we will happily\n> check out \".lazygit\" from an untrusted remote repository. That may be a\n> feature if you want to be able to share project-specific config, or it\n> might be a terrible security vulnerability if lazygit config files can\n> trigger arbitrary code execution.\n\nUnless you don't version it and add it to .gitignore instead, which (I\nsuppose) is what most people do with their .vscode/settings.json, for\nexample.\n\n-Stefan\n"},{"id":"486685","messageId":"20240112065654.GB618729@coredump.intra.peff.net","threadId":"60694","inReplyTo":"c8ad96bc-0180-42f4-b559-20b475098eca@haller-berlin.de","subject":"Re: Storing private config files in .git directory?","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2024-01-12T06:56:54Z","receivedAt":"2024-01-12T06:57:01Z","isPatch":false,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Thu, Jan 11, 2024 at 02:28:51PM +0100, Stefan Haller wrote:\n\n> On 10.01.24 12:08, Jeff King wrote:\n> > On Mon, Jan 08, 2024 at 10:20:00AM -0800, Junio C Hamano wrote:\n> > \n> >> An obvious alternative is to have .lazygit directory next to .git directory\n> >> which would give you a bigger separation, which can cut both ways.\n> > \n> > Just to spell out one of those ways: unlike \".git\", we will happily\n> > check out \".lazygit\" from an untrusted remote repository. That may be a\n> > feature if you want to be able to share project-specific config, or it\n> > might be a terrible security vulnerability if lazygit config files can\n> > trigger arbitrary code execution.\n> \n> Unless you don't version it and add it to .gitignore instead, which (I\n> suppose) is what most people do with their .vscode/settings.json, for\n> example.\n\nA .gitignore will help with people accidentally adding their .lazygit\ndirectory. What I meant, though, was somebody _intentionally_ creating a\nmalicious repository that would then execute arbitrary code when the\nvictim cloned it. We prevent that from happening with .git/config\nbecause there's special handling that refuses to check out the name\n\".git\" (or other filesystem-equivalent names). But \".lazygit\" would not\nhave that same protection.\n\n-Peff\n"}]}