{"thread":{"id":"64999","subject":"[RFC GSoC PATCH] environment: move core.trustctime to repo_settings","startedAt":"2026-02-15T11:24:11Z","lastAt":"2026-02-18T11:45:48Z","messageCount":5,"participants":["Ayush Jha","Junio C Hamano","Bello Olamide"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"536054","messageId":"20260215112331.22-1-kumarayushjha123@gmail.com","threadId":"64999","inReplyTo":null,"subject":"[RFC GSoC PATCH] environment: move core.trustctime to repo_settings","fromName":"Ayush Jha","fromEmail":"kumarayushjha123@gmail.com","sentAt":"2026-02-15T11:23:30Z","receivedAt":"2026-02-15T11:24:11Z","isPatch":true,"sender":{"key":"kumarayushjha123@gmail.com","avatar":null},"body":"The core.trustctime configuration variable is currently stored as a global in environment.c. This prevents it from being repository-specific, which is problematic when multiple repository instances are used within the same process.\n\nThis change continues the effort to move global configuration into struct repo_settings, as discussed in\n<20260208062949.596-1-kumarayushjha123@gmail.com>.\n\nMove trust_ctime into struct repo_settings so that it is associated with a repository instance.\n\nAdd repo_settings_get_trust_ctime() to lazily read the\ncore.trustctime configuration value, defaulting to true.\n\nUpdate statinfo.c to use the new accessor instead of the global variable.\n\nSigned-off-by: Ayush Jha <kumarayushjha123@gmail.com>\n---\n environment.c   | 5 -----\n environment.h   | 1 -\n repo-settings.c | 7 +++++++\n repo-settings.h | 8 ++++++++\n statinfo.c      | 4 ++--\n 5 files changed, 17 insertions(+), 8 deletions(-)\n\ndiff --git a/environment.c b/environment.c\nindex 8ffbf92d50..95bd0db63c 100644\n--- a/environment.c\n+++ b/environment.c\n@@ -41,7 +41,6 @@ static int pack_compression_seen;\n static int zlib_compression_seen;\n \n int trust_executable_bit = 1;\n-int trust_ctime = 1;\n int check_stat = 1;\n int has_symlinks = 1;\n int minimum_abbrev = 4, default_abbrev = -1;\n@@ -308,10 +307,6 @@ int git_default_core_config(const char *var, const char *value,\n \t\ttrust_executable_bit = git_config_bool(var, value);\n \t\treturn 0;\n \t}\n-\tif (!strcmp(var, \"core.trustctime\")) {\n-\t\ttrust_ctime = git_config_bool(var, value);\n-\t\treturn 0;\n-\t}\n \tif (!strcmp(var, \"core.checkstat\")) {\n \t\tif (!value)\n \t\t\treturn config_error_nonbool(var);\ndiff --git a/environment.h b/environment.h\nindex 27f657af04..148103ea51 100644\n--- a/environment.h\n+++ b/environment.h\n@@ -145,7 +145,6 @@ extern char *git_work_tree_cfg;\n \n /* Environment bits from configuration mechanism */\n extern int trust_executable_bit;\n-extern int trust_ctime;\n extern int check_stat;\n extern int has_symlinks;\n extern int minimum_abbrev, default_abbrev;\ndiff --git a/repo-settings.c b/repo-settings.c\nindex 208e09ff17..bb7d983023 100644\n--- a/repo-settings.c\n+++ b/repo-settings.c\n@@ -233,3 +233,10 @@ void repo_settings_reset_shared_repository(struct repository *repo)\n {\n \trepo->settings.shared_repository_initialized = 0;\n }\n+\n+int repo_settings_get_trust_ctime(struct repository *repo)\n+{\n+\tif (repo->settings.trust_ctime < 0)\n+\t\trepo_cfg_bool(repo, \"core.trustctime\", &repo->settings.trust_ctime, 1);\n+\treturn repo->settings.trust_ctime;\n+}\ndiff --git a/repo-settings.h b/repo-settings.h\nindex cad9c3f0cc..709f86108b 100644\n--- a/repo-settings.h\n+++ b/repo-settings.h\n@@ -70,6 +70,8 @@ struct repo_settings {\n \tint max_allowed_tree_depth;\n \n \tchar *hooks_path;\n+\n+\tint trust_ctime;\n };\n #define REPO_SETTINGS_INIT { \\\n \t.shared_repository = -1, \\\n@@ -81,6 +83,7 @@ struct repo_settings {\n \t.packed_git_window_size = DEFAULT_PACKED_GIT_WINDOW_SIZE, \\\n \t.packed_git_limit = DEFAULT_PACKED_GIT_LIMIT, \\\n \t.max_allowed_tree_depth = DEFAULT_MAX_ALLOWED_TREE_DEPTH, \\\n+\t.trust_ctime = -1, \\\n }\n \n void prepare_repo_settings(struct repository *r);\n@@ -90,6 +93,11 @@ void repo_settings_clear(struct repository *r);\n enum log_refs_config repo_settings_get_log_all_ref_updates(struct repository *repo);\n /* Read the value for \"core.warnAmbiguousRefs\". */\n int repo_settings_get_warn_ambiguous_refs(struct repository *repo);\n+/* Read and set the value for \"core.attributesfile\". */\n+const char *repo_settings_get_attributes_file(struct repository *repo);\n+\n+/* Read the value for \"core.trustctime\". */\n+int repo_settings_get_trust_ctime(struct repository *repo);\n /* Read the value for \"core.hooksPath\". */\n const char *repo_settings_get_hooks_path(struct repository *repo);\n \ndiff --git a/statinfo.c b/statinfo.c\nindex 30a164b0e6..ebc8faef27 100644\n--- a/statinfo.c\n+++ b/statinfo.c\n@@ -66,14 +66,14 @@ int match_stat_data(const struct stat_data *sd, struct stat *st)\n \n \tif (sd->sd_mtime.sec != (unsigned int)st->st_mtime)\n \t\tchanged |= MTIME_CHANGED;\n-\tif (trust_ctime && check_stat &&\n+\tif (repo_settings_get_trust_ctime(the_repository) && check_stat &&\n \t    sd->sd_ctime.sec != (unsigned int)st->st_ctime)\n \t\tchanged |= CTIME_CHANGED;\n \n #ifdef USE_NSEC\n \tif (check_stat && sd->sd_mtime.nsec != ST_MTIME_NSEC(*st))\n \t\tchanged |= MTIME_CHANGED;\n-\tif (trust_ctime && check_stat &&\n+\tif (repo_settings_get_trust_ctime(the_repository) && check_stat &&\n \t    sd->sd_ctime.nsec != ST_CTIME_NSEC(*st))\n \t\tchanged |= CTIME_CHANGED;\n #endif\n-- \n2.53.0.windows.1\n\n"},{"id":"536219","messageId":"xmqqpl63b2tm.fsf@gitster.g","threadId":"64999","inReplyTo":"20260215112331.22-1-kumarayushjha123@gmail.com","subject":"Re: [RFC GSoC PATCH] environment: move core.trustctime to repo_settings","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2026-02-17T19:13:57Z","receivedAt":"2026-02-17T19:14:00Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Ayush Jha <kumarayushjha123@gmail.com> writes:\n\n> The core.trustctime configuration variable is currently stored as a global in environment.c. This prevents it from being repository-specific, which is problematic when multiple repository instances are used within the same process.\n>\n> This change continues the effort to move global configuration into struct repo_settings, as discussed in\n> <20260208062949.596-1-kumarayushjha123@gmail.com>.\n>\n> Move trust_ctime into struct repo_settings so that it is associated with a repository instance.\n>\n> Add repo_settings_get_trust_ctime() to lazily read the\n> core.trustctime configuration value, defaulting to true.\n>\n> Update statinfo.c to use the new accessor instead of the global variable.\n>\n> Signed-off-by: Ayush Jha <kumarayushjha123@gmail.com>\n> ---\n>  environment.c   | 5 -----\n>  environment.h   | 1 -\n>  repo-settings.c | 7 +++++++\n>  repo-settings.h | 8 ++++++++\n>  statinfo.c      | 4 ++--\n>  5 files changed, 17 insertions(+), 8 deletions(-)\n\nDoesn't this regress end-user experience when the configuration\nvariable is misspelled, e.g. \"[core] trustctime = bad\"?  We used to\nrun git_config_bool() from git_config(git_default_condfig) fairly\nearly in the program, and would have died before doing anythihng to\ngive the user a chance to fix the configuration files before going\nforward.\n\nNow we will run deep into codepath and would not notice the\nmisconfigured core.trustctime until the code happens to ask to\ncompare the filesystem stat data and in-core index stat data.\n\nI think this is a recurring theme, e.g.\n\nhttps://lore.kernel.org/git/32fceddc-c867-4a47-bde8-c873279edbc1@gmail.com/\nhttps://lore.kernel.org/git/a881499d-e236-4f8e-a217-b6bce69e3e3c@gmail.com/\n\nThat other topic Olamide has been working on seems to have settled\n*not* to lazily load into repo_settings to avoid the problem.\nInstead it reads and parses at the same places in the code path as\nbefore, but into a repo_config_values structure that is associated\nwith the repository in question (which typically is the_repository).\n\n"},{"id":"536269","messageId":"CAFNBzOdqOLKFbDFCp99GvXYWs_Af3PdeXQMjE92y+s92j78GYA@mail.gmail.com","threadId":"64999","inReplyTo":"xmqqpl63b2tm.fsf@gitster.g","subject":"Re: [RFC GSoC PATCH] environment: move core.trustctime to repo_settings","fromName":"Ayush Jha","fromEmail":"kumarayushjha123@gmail.com","sentAt":"2026-02-18T11:04:34Z","receivedAt":"2026-02-18T11:04:49Z","isPatch":true,"sender":{"key":"kumarayushjha123@gmail.com","avatar":null},"body":"Hi Junio,\n\nThank you for the feedback. You are absolutely right that the\nlazy-loading approach regresses the user experience by delaying\ndetection of configuration errors.\n\nTo address this, I propose parsing core.trustctime in\nprepare_repo_settings() in repo-settings.c. This would ensure the\nconfiguration is read eagerly during repository initialization,\npreserving the historical “fail fast” behavior where invalid boolean\nvalues cause an immediate fatal error.\n\nThe repo_settings_get_trust_ctime() accessor would then simply return\nthe pre-parsed value from r->settings.trust_ctime.\n\nDoes this approach sound reasonable?\n\nThanks,\nAyush\n\nOn Wed, Feb 18, 2026 at 12:44 AM Junio C Hamano <gitster@pobox.com> wrote:\n>\n> Ayush Jha <kumarayushjha123@gmail.com> writes:\n>\n> > The core.trustctime configuration variable is currently stored as a global in environment.c. This prevents it from being repository-specific, which is problematic when multiple repository instances are used within the same process.\n> >\n> > This change continues the effort to move global configuration into struct repo_settings, as discussed in\n> > <20260208062949.596-1-kumarayushjha123@gmail.com>.\n> >\n> > Move trust_ctime into struct repo_settings so that it is associated with a repository instance.\n> >\n> > Add repo_settings_get_trust_ctime() to lazily read the\n> > core.trustctime configuration value, defaulting to true.\n> >\n> > Update statinfo.c to use the new accessor instead of the global variable.\n> >\n> > Signed-off-by: Ayush Jha <kumarayushjha123@gmail.com>\n> > ---\n> >  environment.c   | 5 -----\n> >  environment.h   | 1 -\n> >  repo-settings.c | 7 +++++++\n> >  repo-settings.h | 8 ++++++++\n> >  statinfo.c      | 4 ++--\n> >  5 files changed, 17 insertions(+), 8 deletions(-)\n>\n> Doesn't this regress end-user experience when the configuration\n> variable is misspelled, e.g. \"[core] trustctime = bad\"?  We used to\n> run git_config_bool() from git_config(git_default_condfig) fairly\n> early in the program, and would have died before doing anythihng to\n> give the user a chance to fix the configuration files before going\n> forward.\n>\n> Now we will run deep into codepath and would not notice the\n> misconfigured core.trustctime until the code happens to ask to\n> compare the filesystem stat data and in-core index stat data.\n>\n> I think this is a recurring theme, e.g.\n>\n> https://lore.kernel.org/git/32fceddc-c867-4a47-bde8-c873279edbc1@gmail.com/\n> https://lore.kernel.org/git/a881499d-e236-4f8e-a217-b6bce69e3e3c@gmail.com/\n>\n> That other topic Olamide has been working on seems to have settled\n> *not* to lazily load into repo_settings to avoid the problem.\n> Instead it reads and parses at the same places in the code path as\n> before, but into a repo_config_values structure that is associated\n> with the repository in question (which typically is the_repository).\n>\n"},{"id":"536272","messageId":"CAD=f0L-nUS1N-P2cWM9AwOFv+G7dOBgGjWwEZYP3qSDMxyhGgA@mail.gmail.com","threadId":"64999","inReplyTo":"CAFNBzOdqOLKFbDFCp99GvXYWs_Af3PdeXQMjE92y+s92j78GYA@mail.gmail.com","subject":"Re: [RFC GSoC PATCH] environment: move core.trustctime to repo_settings","fromName":"Bello Olamide","fromEmail":"belkid98@gmail.com","sentAt":"2026-02-18T11:22:50Z","receivedAt":"2026-02-18T11:22:50Z","isPatch":true,"sender":{"key":"belkid98@gmail.com","avatar":"https://avatars.githubusercontent.com/u/73387291?v=4"},"body":"On Wed, 18 Feb 2026 at 12:04, Ayush Jha <kumarayushjha123@gmail.com> wrote:\n>\n> Hi Junio,\n>\n> Thank you for the feedback. You are absolutely right that the\n> lazy-loading approach regresses the user experience by delaying\n> detection of configuration errors.\n>\n> To address this, I propose parsing core.trustctime in\n> prepare_repo_settings() in repo-settings.c. This would ensure the\n> configuration is read eagerly during repository initialization,\n> preserving the historical “fail fast” behavior where invalid boolean\n> values cause an immediate fatal error.\n>\n> The repo_settings_get_trust_ctime() accessor would then simply return\n> the pre-parsed value from r->settings.trust_ctime.\n>\n> Does this approach sound reasonable?\n>\n> Thanks,\n> Ayush\n>\n> On Wed, Feb 18, 2026 at 12:44 AM Junio C Hamano <gitster@pobox.com> wrote:\n> >\n> > Ayush Jha <kumarayushjha123@gmail.com> writes:\n> >\n> > > The core.trustctime configuration variable is currently stored as a global in environment.c. This prevents it from being repository-specific, which is problematic when multiple repository instances are used within the same process.\n> > >\n> > > This change continues the effort to move global configuration into struct repo_settings, as discussed in\n> > > <20260208062949.596-1-kumarayushjha123@gmail.com>.\n> > >\n> > > Move trust_ctime into struct repo_settings so that it is associated with a repository instance.\n> > >\n> > > Add repo_settings_get_trust_ctime() to lazily read the\n> > > core.trustctime configuration value, defaulting to true.\n> > >\n> > > Update statinfo.c to use the new accessor instead of the global variable.\n> > >\n> > > Signed-off-by: Ayush Jha <kumarayushjha123@gmail.com>\n> > > ---\n> > >  environment.c   | 5 -----\n> > >  environment.h   | 1 -\n> > >  repo-settings.c | 7 +++++++\n> > >  repo-settings.h | 8 ++++++++\n> > >  statinfo.c      | 4 ++--\n> > >  5 files changed, 17 insertions(+), 8 deletions(-)\n> >\n> > Doesn't this regress end-user experience when the configuration\n> > variable is misspelled, e.g. \"[core] trustctime = bad\"?  We used to\n> > run git_config_bool() from git_config(git_default_condfig) fairly\n> > early in the program, and would have died before doing anythihng to\n> > give the user a chance to fix the configuration files before going\n> > forward.\n> >\n> > Now we will run deep into codepath and would not notice the\n> > misconfigured core.trustctime until the code happens to ask to\n> > compare the filesystem stat data and in-core index stat data.\n> >\n> > I think this is a recurring theme, e.g.\n> >\n> > https://lore.kernel.org/git/32fceddc-c867-4a47-bde8-c873279edbc1@gmail.com/\n> > https://lore.kernel.org/git/a881499d-e236-4f8e-a217-b6bce69e3e3c@gmail.com/\n> >\n> > That other topic Olamide has been working on seems to have settled\n> > *not* to lazily load into repo_settings to avoid the problem.\n> > Instead it reads and parses at the same places in the code path as\n> > before, but into a repo_config_values structure that is associated\n> > with the repository in question (which typically is the_repository).\n> >\n\nHello Ayush\nThank you for your interest in this topic.\n\nAs Junio pointed out in his response to you, I have submitted patches that\nsettle not to lazily load into repo_settings. but instead to read and parse into\nthe struct repo_config_values structure associated with the repository.\n\nI will continue working to move other repo specific configuration variables\nin environment.c into this struct once these patches have been accepted.\nThanks\n\nOlamide\n"},{"id":"536274","messageId":"CAFNBzOebt6iz2_X1kCpSa+6JXG-OTh=FAqcQ84rAZ-4x4YQVCw@mail.gmail.com","threadId":"64999","inReplyTo":"CAD=f0L-nUS1N-P2cWM9AwOFv+G7dOBgGjWwEZYP3qSDMxyhGgA@mail.gmail.com","subject":"Re: [RFC GSoC PATCH] environment: move core.trustctime to repo_settings","fromName":"Ayush Jha","fromEmail":"kumarayushjha123@gmail.com","sentAt":"2026-02-18T11:45:33Z","receivedAt":"2026-02-18T11:45:48Z","isPatch":true,"sender":{"key":"kumarayushjha123@gmail.com","avatar":null},"body":"Hello Olamide,\n\nThank you for the update. Since you are already working on a more\nrobust pattern (repo_config_values) for this, I will drop my patch to\navoid conflicts and duplicated effort.\n\nBest regards,\nAyush\n\nOn Wed, Feb 18, 2026 at 4:52 PM Bello Olamide <belkid98@gmail.com> wrote:\n>\n> On Wed, 18 Feb 2026 at 12:04, Ayush Jha <kumarayushjha123@gmail.com> wrote:\n> >\n> > Hi Junio,\n> >\n> > Thank you for the feedback. You are absolutely right that the\n> > lazy-loading approach regresses the user experience by delaying\n> > detection of configuration errors.\n> >\n> > To address this, I propose parsing core.trustctime in\n> > prepare_repo_settings() in repo-settings.c. This would ensure the\n> > configuration is read eagerly during repository initialization,\n> > preserving the historical “fail fast” behavior where invalid boolean\n> > values cause an immediate fatal error.\n> >\n> > The repo_settings_get_trust_ctime() accessor would then simply return\n> > the pre-parsed value from r->settings.trust_ctime.\n> >\n> > Does this approach sound reasonable?\n> >\n> > Thanks,\n> > Ayush\n> >\n> > On Wed, Feb 18, 2026 at 12:44 AM Junio C Hamano <gitster@pobox.com> wrote:\n> > >\n> > > Ayush Jha <kumarayushjha123@gmail.com> writes:\n> > >\n> > > > The core.trustctime configuration variable is currently stored as a global in environment.c. This prevents it from being repository-specific, which is problematic when multiple repository instances are used within the same process.\n> > > >\n> > > > This change continues the effort to move global configuration into struct repo_settings, as discussed in\n> > > > <20260208062949.596-1-kumarayushjha123@gmail.com>.\n> > > >\n> > > > Move trust_ctime into struct repo_settings so that it is associated with a repository instance.\n> > > >\n> > > > Add repo_settings_get_trust_ctime() to lazily read the\n> > > > core.trustctime configuration value, defaulting to true.\n> > > >\n> > > > Update statinfo.c to use the new accessor instead of the global variable.\n> > > >\n> > > > Signed-off-by: Ayush Jha <kumarayushjha123@gmail.com>\n> > > > ---\n> > > >  environment.c   | 5 -----\n> > > >  environment.h   | 1 -\n> > > >  repo-settings.c | 7 +++++++\n> > > >  repo-settings.h | 8 ++++++++\n> > > >  statinfo.c      | 4 ++--\n> > > >  5 files changed, 17 insertions(+), 8 deletions(-)\n> > >\n> > > Doesn't this regress end-user experience when the configuration\n> > > variable is misspelled, e.g. \"[core] trustctime = bad\"?  We used to\n> > > run git_config_bool() from git_config(git_default_condfig) fairly\n> > > early in the program, and would have died before doing anythihng to\n> > > give the user a chance to fix the configuration files before going\n> > > forward.\n> > >\n> > > Now we will run deep into codepath and would not notice the\n> > > misconfigured core.trustctime until the code happens to ask to\n> > > compare the filesystem stat data and in-core index stat data.\n> > >\n> > > I think this is a recurring theme, e.g.\n> > >\n> > > https://lore.kernel.org/git/32fceddc-c867-4a47-bde8-c873279edbc1@gmail.com/\n> > > https://lore.kernel.org/git/a881499d-e236-4f8e-a217-b6bce69e3e3c@gmail.com/\n> > >\n> > > That other topic Olamide has been working on seems to have settled\n> > > *not* to lazily load into repo_settings to avoid the problem.\n> > > Instead it reads and parses at the same places in the code path as\n> > > before, but into a repo_config_values structure that is associated\n> > > with the repository in question (which typically is the_repository).\n> > >\n>\n> Hello Ayush\n> Thank you for your interest in this topic.\n>\n> As Junio pointed out in his response to you, I have submitted patches that\n> settle not to lazily load into repo_settings. but instead to read and parse into\n> the struct repo_config_values structure associated with the repository.\n>\n> I will continue working to move other repo specific configuration variables\n> in environment.c into this struct once these patches have been accepted.\n> Thanks\n>\n> Olamide\n"}]}