{"thread":{"id":"65414","subject":"[PATCH 00/17] tests: access bare repositories explicitly","startedAt":"2026-04-02T14:33:25Z","lastAt":"2026-04-06T16:00:12Z","messageCount":44,"participants":["Johannes Schindelin via GitGitGadget","Junio C Hamano","Johannes Schindelin"],"isPatch":true,"patchVersion":1,"patchTotal":17},"messages":[{"id":"540744","messageId":"pull.2076.git.1775140403.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":null,"subject":"[PATCH 00/17] tests: access bare repositories explicitly","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-02T14:33:06Z","receivedAt":"2026-04-02T14:33:25Z","isPatch":true,"body":"The safe.bareRepository configuration variable (introduced in 8d1a7448206e)\nallows restricting implicit bare repository discovery. Its default may well\nchange to \"explicit\" in Git v3.0, at which point any test that relies on\nimplicit discovery of a bare repository would break, even if the test\nsubject has nothing to do with bare repositories.\n\nThis series adjusts 16 test scripts and git-p4 so that they access bare\nrepositories explicitly. The techniques used are:\n\n * Replace git -C <bare-repo> ... with git --git-dir=<bare-repo> ...\n * Export GIT_DIR=. after cd-ing into a bare repository\n * Wrap commands in (GIT_DIR=<path> && export GIT_DIR && ...)\n * Add test_config_global safe.bareRepository all in the few tests where\n   implicit discovery is genuinely part of what is being tested\n\nEach commit is a self-contained fix to one test file (or a small related\ngroup).\n\nThis patch series is part of https://github.com/gitgitgadget/git/pull/2072.\n\nJohannes Schindelin (17):\n  t0001: allow implicit bare repo discovery for aliased-command test\n  t0001: replace `cd`+`git` with `git --git-dir` in `check_config`\n  t0003: use `--git-dir` for bare repo attribute tests\n  t0056: allow implicit bare repo discovery for `-C` work-tree tests\n  t1020: use `--git-dir` instead of subshell for bare repo\n  t1900: avoid using `-C <dir>` for a bare repository\n  t2400: explicitly specify bare repo for `git worktree add`\n  t2406: use `--git-dir=.` for bare repository worktree repair\n  t5503: avoid discovering a bare repository\n  t5505: export `GIT_DIR` after `git init --bare`\n  t5509: specify bare repository path explicitly\n  t5540/t5541: avoid accessing a bare repository via `-C <dir>`\n  t5619: wrap `test_commit_bulk` in `GIT_DIR` subshell for bare repo\n  t6020: use `-C` for worktree, `--git-dir` for bare repository\n  t9210: pass `safe.bareRepository=all` to `scalar register`\n  t9700: stop relying on implicit bare repo discovery\n  git p4 clone --bare: need to be explicit about the gitdir\n\n git-p4.py                                  |  1 +\n t/lib-httpd.sh                             | 12 ++--\n t/t0001-init.sh                            |  5 +-\n t/t0003-attributes.sh                      | 66 +++++++++-------------\n t/t0056-git-C.sh                           |  2 +\n t/t1020-subdirectory.sh                    |  5 +-\n t/t1900-repo-info.sh                       |  7 ++-\n t/t2400-worktree-add.sh                    | 21 +++----\n t/t2406-worktree-repair.sh                 |  2 +-\n t/t5503-tagfollow.sh                       | 13 ++---\n t/t5505-remote.sh                          |  4 +-\n t/t5509-fetch-push-namespaces.sh           | 12 ++--\n t/t5619-clone-local-ambiguous-transport.sh |  2 +-\n t/t6020-bundle-misc.sh                     |  4 +-\n t/t9210-scalar.sh                          |  2 +-\n t/t9700/test.pl                            |  9 ++-\n 16 files changed, 74 insertions(+), 93 deletions(-)\n\n\nbase-commit: cf2139f8e1680b076e115bc0b349e369b4b0ecc4\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-2076%2Fdscho%2Ftests-explicit-bare-repo-v1\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-2076/dscho/tests-explicit-bare-repo-v1\nPull-Request: https://github.com/gitgitgadget/git/pull/2076\n-- \ngitgitgadget\n"},{"id":"540745","messageId":"a1cdbd58f0af27be689230b7d8009d93bc34abca.1775140403.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.git.1775140403.gitgitgadget@gmail.com","subject":"[PATCH 01/17] t0001: allow implicit bare repo discovery for aliased-command test","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-02T14:33:07Z","receivedAt":"2026-04-02T14:33:27Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\n8d1a7448206e (setup.c: create `safe.bareRepository`, 2022-07-14)\nintroduced a setting to restrict implicit bare repository discovery,\nmitigating a social-engineering attack where an embedded bare repo's\nhooks get executed unknowingly. To allow for that default to change at\nsome stage in the future, the tests need to be prepared.\n\nThis commit adjusts a test accordingly that runs `git aliasedinit`\nfrom inside a bare repo to verify that aliased commands work there.\nThe test is about alias resolution, not bare repo discovery, so add\n`test_config_global safe.bareRepository all` to opt in explicitly.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t0001-init.sh | 1 +\n 1 file changed, 1 insertion(+)\n\ndiff --git a/t/t0001-init.sh b/t/t0001-init.sh\nindex e4d32bb4d2..6bd0a15dac 100755\n--- a/t/t0001-init.sh\n+++ b/t/t0001-init.sh\n@@ -77,6 +77,7 @@ test_expect_success 'plain nested through aliased command' '\n '\n \n test_expect_success 'plain nested in bare through aliased command' '\n+\ttest_config_global safe.bareRepository all &&\n \t(\n \t\tgit init --bare bare-ancestor-aliased.git &&\n \t\tcd bare-ancestor-aliased.git &&\n-- \ngitgitgadget\n\n"},{"id":"540746","messageId":"78744602fb33978a9f674f5f9860c58e7734d2e8.1775140403.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.git.1775140403.gitgitgadget@gmail.com","subject":"[PATCH 02/17] t0001: replace `cd`+`git` with `git --git-dir` in `check_config`","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-02T14:33:08Z","receivedAt":"2026-04-02T14:33:28Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nTo prepare for `safe.bareRepository` defaulting to `explicit`\n(see 8d1a7448206e), replace `cd <dir> && git config` with `git\n--git-dir=<dir> config` so the helper does not rely on implicit bare\nrepository discovery.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t0001-init.sh | 4 ++--\n 1 file changed, 2 insertions(+), 2 deletions(-)\n\ndiff --git a/t/t0001-init.sh b/t/t0001-init.sh\nindex 6bd0a15dac..db2bf1001f 100755\n--- a/t/t0001-init.sh\n+++ b/t/t0001-init.sh\n@@ -20,8 +20,8 @@ check_config () {\n \t\treturn 1\n \tfi\n \n-\tbare=$(cd \"$1\" && git config --bool core.bare)\n-\tworktree=$(cd \"$1\" && git config core.worktree) ||\n+\tbare=$(git --git-dir=\"$1\" config --bool core.bare)\n+\tworktree=$(git --git-dir=\"$1\" config core.worktree) ||\n \tworktree=unset\n \n \ttest \"$bare\" = \"$2\" && test \"$worktree\" = \"$3\" || {\n-- \ngitgitgadget\n\n"},{"id":"540747","messageId":"a4f7a6df516c848936e6952dac8ca02ccb0ac643.1775140403.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.git.1775140403.gitgitgadget@gmail.com","subject":"[PATCH 03/17] t0003: use `--git-dir` for bare repo attribute tests","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-02T14:33:09Z","receivedAt":"2026-04-02T14:33:29Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nThe bare repo tests in t0003-attributes.sh currently `cd` into the bare\nrepository inside subshells, relying on implicit discovery. Restructure\nthese tests to pass `--git-dir=bare.git` to the `attr_check` and\n`attr_check_source` helpers instead. This makes the code much easier to\nread, and also makes bare repo access explicit, i.e. compatible with an\neventual `safe.bareRepository=explicit` default.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t0003-attributes.sh | 66 ++++++++++++++++++-------------------------\n 1 file changed, 27 insertions(+), 39 deletions(-)\n\ndiff --git a/t/t0003-attributes.sh b/t/t0003-attributes.sh\nindex 582e207aa1..3a34f5dbc2 100755\n--- a/t/t0003-attributes.sh\n+++ b/t/t0003-attributes.sh\n@@ -346,17 +346,14 @@ test_expect_success 'setup bare' '\n \n test_expect_success 'bare repository: check that .gitattribute is ignored' '\n \t(\n-\t\tcd bare.git &&\n-\t\t(\n-\t\t\techo \"f\ttest=f\" &&\n-\t\t\techo \"a/i test=a/i\"\n-\t\t) >.gitattributes &&\n-\t\tattr_check f unspecified &&\n-\t\tattr_check a/f unspecified &&\n-\t\tattr_check a/c/f unspecified &&\n-\t\tattr_check a/i unspecified &&\n-\t\tattr_check subdir/a/i unspecified\n-\t)\n+\t\techo \"f\ttest=f\" &&\n+\t\techo \"a/i test=a/i\"\n+\t) >bare.git/.gitattributes &&\n+\tattr_check f unspecified --git-dir=bare.git &&\n+\tattr_check a/f unspecified --git-dir=bare.git &&\n+\tattr_check a/c/f unspecified --git-dir=bare.git &&\n+\tattr_check a/i unspecified --git-dir=bare.git &&\n+\tattr_check subdir/a/i unspecified --git-dir=bare.git\n '\n \n bad_attr_source_err=\"fatal: bad --attr-source or GIT_ATTR_SOURCE\"\n@@ -449,41 +446,32 @@ test_expect_success 'diff without repository with attr source' '\n '\n \n test_expect_success 'bare repository: with --source' '\n-\t(\n-\t\tcd bare.git &&\n-\t\tattr_check_source foo/bar/f f tag-1 &&\n-\t\tattr_check_source foo/bar/a/i n tag-1 &&\n-\t\tattr_check_source foo/bar/f unspecified tag-2 &&\n-\t\tattr_check_source foo/bar/a/i m tag-2 &&\n-\t\tattr_check_source foo/bar/g g tag-2 &&\n-\t\tattr_check_source foo/bar/g unspecified tag-1\n-\t)\n+\tattr_check_source foo/bar/f f tag-1 --git-dir=bare.git &&\n+\tattr_check_source foo/bar/a/i n tag-1 --git-dir=bare.git &&\n+\tattr_check_source foo/bar/f unspecified tag-2 --git-dir=bare.git &&\n+\tattr_check_source foo/bar/a/i m tag-2 --git-dir=bare.git &&\n+\tattr_check_source foo/bar/g g tag-2 --git-dir=bare.git &&\n+\tattr_check_source foo/bar/g unspecified tag-1 --git-dir=bare.git\n '\n \n test_expect_success 'bare repository: check that --cached honors index' '\n-\t(\n-\t\tcd bare.git &&\n-\t\tGIT_INDEX_FILE=../.git/index \\\n-\t\tgit check-attr --cached --stdin --all <../stdin-all |\n-\t\tsort >actual &&\n-\t\ttest_cmp ../specified-all actual\n-\t)\n+\tGIT_INDEX_FILE=.git/index \\\n+\tgit --git-dir=bare.git check-attr --cached --stdin --all <stdin-all |\n+\tsort >actual &&\n+\ttest_cmp specified-all actual\n '\n \n test_expect_success 'bare repository: test info/attributes' '\n+\tmkdir -p bare.git/info &&\n \t(\n-\t\tcd bare.git &&\n-\t\tmkdir info &&\n-\t\t(\n-\t\t\techo \"f\ttest=f\" &&\n-\t\t\techo \"a/i test=a/i\"\n-\t\t) >info/attributes &&\n-\t\tattr_check f f &&\n-\t\tattr_check a/f f &&\n-\t\tattr_check a/c/f f &&\n-\t\tattr_check a/i a/i &&\n-\t\tattr_check subdir/a/i unspecified\n-\t)\n+\t\techo \"f\ttest=f\" &&\n+\t\techo \"a/i test=a/i\"\n+\t) >bare.git/info/attributes &&\n+\tattr_check f f --git-dir=bare.git &&\n+\tattr_check a/f f --git-dir=bare.git &&\n+\tattr_check a/c/f f --git-dir=bare.git &&\n+\tattr_check a/i a/i --git-dir=bare.git &&\n+\tattr_check subdir/a/i unspecified --git-dir=bare.git\n '\n \n test_expect_success 'binary macro expanded by -a' '\n-- \ngitgitgadget\n\n"},{"id":"540748","messageId":"5b6bb1863227cf95700fab4934ec2e1dac9570aa.1775140403.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.git.1775140403.gitgitgadget@gmail.com","subject":"[PATCH 04/17] t0056: allow implicit bare repo discovery for `-C` work-tree tests","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-02T14:33:10Z","receivedAt":"2026-04-02T14:33:31Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nThe `git -C c/a.git --work-tree=../a` invocations in t0056-git-C.sh\nenter what is technically the `.git` directory of a repository to\ntest `-C` combined with `--work-tree`. In doing so, the code relies on\nimplicit discovery of bare repositories, which 8d1a7448206e (setup.c:\ncreate `safe.bareRepository`, 2022-07-14) prepared to be prevented by\ndefault.\n\nThese tests verify the interaction between those flags, so changing them\nto use `--git-dir` would defeat their purpose. So let's just temporarily\nforce-enable implicit discovery of bare repositories, no matter what\n`safe.bareRepository` defaults to.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t0056-git-C.sh | 2 ++\n 1 file changed, 2 insertions(+)\n\ndiff --git a/t/t0056-git-C.sh b/t/t0056-git-C.sh\nindex 2630e756da..6b7122add5 100755\n--- a/t/t0056-git-C.sh\n+++ b/t/t0056-git-C.sh\n@@ -57,11 +57,13 @@ test_expect_success 'Order should not matter: \"--git-dir=a.git -C c\" is equivale\n test_expect_success 'Effect on --work-tree option: \"-C c/a.git --work-tree=../a\"  is equivalent to \"--work-tree=c/a --git-dir=c/a.git\"' '\n \trm c/a/a.txt &&\n \tgit --git-dir=c/a.git --work-tree=c/a status >expected &&\n+\ttest_config_global safe.bareRepository all &&\n \tgit -C c/a.git --work-tree=../a status >actual &&\n \ttest_cmp expected actual\n '\n \n test_expect_success 'Order should not matter: \"--work-tree=../a -C c/a.git\" is equivalent to \"-C c/a.git --work-tree=../a\"' '\n+\ttest_config_global safe.bareRepository all &&\n \tgit -C c/a.git --work-tree=../a status >expected &&\n \tgit --work-tree=../a -C c/a.git status >actual &&\n \ttest_cmp expected actual\n-- \ngitgitgadget\n\n"},{"id":"540749","messageId":"c38f0a68f10df01ee2c99f05d0f33a0a517ffb50.1775140403.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.git.1775140403.gitgitgadget@gmail.com","subject":"[PATCH 05/17] t1020: use `--git-dir` instead of subshell for bare repo","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-02T14:33:11Z","receivedAt":"2026-04-02T14:33:33Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nReplace an unnecessarily complex subshell pattern with a much simpler\n`--git-dir`-based one. The latter is not only simpler, it also no\nlonger relies on implicit bare repo discovery, which would fail with\n`safe.bareRepository=explicit`.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t1020-subdirectory.sh | 5 +----\n 1 file changed, 1 insertion(+), 4 deletions(-)\n\ndiff --git a/t/t1020-subdirectory.sh b/t/t1020-subdirectory.sh\nindex 9fdbb2af80..20d2d306fe 100755\n--- a/t/t1020-subdirectory.sh\n+++ b/t/t1020-subdirectory.sh\n@@ -177,10 +177,7 @@ test_expect_success 'no file/rev ambiguity check inside a bare repo (explicit GI\n test_expect_success 'no file/rev ambiguity check inside a bare repo' '\n \ttest_when_finished \"rm -fr foo.git\" &&\n \tgit clone -s --bare .git foo.git &&\n-\t(\n-\t\tcd foo.git &&\n-\t\tgit show -s HEAD\n-\t)\n+\tgit --git-dir=foo.git show -s HEAD\n '\n \n test_expect_success SYMLINKS 'detection should not be fooled by a symlink' '\n-- \ngitgitgadget\n\n"},{"id":"540750","messageId":"a084c39273ec9e613fe1c6c982700292f5ddb705.1775140403.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.git.1775140403.gitgitgadget@gmail.com","subject":"[PATCH 06/17] t1900: avoid using `-C <dir>` for a bare repository","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-02T14:33:12Z","receivedAt":"2026-04-02T14:33:34Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nTo prepare for `safe.bareRepository` defaulting to `explicit` (see\n8d1a7448206e), add an optional 6th parameter `repo_flag` (defaulting\nto `-C`) to the `test_repo_info` helper, and use it in the caller that\nwants to operate on a bare repository.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t1900-repo-info.sh | 7 ++++---\n 1 file changed, 4 insertions(+), 3 deletions(-)\n\ndiff --git a/t/t1900-repo-info.sh b/t/t1900-repo-info.sh\nindex 39bb77dda0..6280da1efb 100755\n--- a/t/t1900-repo-info.sh\n+++ b/t/t1900-repo-info.sh\n@@ -20,6 +20,7 @@ test_repo_info () {\n \trepo_name=$3\n \tkey=$4\n \texpected_value=$5\n+\trepo_flag=${6:--C}\n \n \ttest_expect_success \"setup: $label\" '\n \t\teval \"$init_command $repo_name\"\n@@ -27,13 +28,13 @@ test_repo_info () {\n \n \ttest_expect_success \"lines: $label\" '\n \t\techo \"$key=$expected_value\" > expect &&\n-\t\tgit -C \"$repo_name\" repo info \"$key\" >actual &&\n+\t\tgit $repo_flag \"$repo_name\" repo info \"$key\" >actual &&\n \t\ttest_cmp expect actual\n \t'\n \n \ttest_expect_success \"nul: $label\" '\n \t\tprintf \"%s\\n%s\\0\" \"$key\" \"$expected_value\" >expect &&\n-\t\tgit -C \"$repo_name\" repo info --format=nul \"$key\" >actual &&\n+\t\tgit $repo_flag \"$repo_name\" repo info --format=nul \"$key\" >actual &&\n \t\ttest_cmp_bin expect actual\n \t'\n }\n@@ -48,7 +49,7 @@ test_repo_info 'bare repository = false is retrieved correctly' \\\n \t'git init' 'nonbare' 'layout.bare' 'false'\n \n test_repo_info 'bare repository = true is retrieved correctly' \\\n-\t'git init --bare' 'bare' 'layout.bare' 'true'\n+\t'git init --bare' 'bare' 'layout.bare' 'true' '--git-dir'\n \n test_repo_info 'shallow repository = false is retrieved correctly' \\\n \t'git init' 'nonshallow' 'layout.shallow' 'false'\n-- \ngitgitgadget\n\n"},{"id":"540751","messageId":"6a7730cf57b6b5efbc8d0556e19c8117955a74de.1775140403.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.git.1775140403.gitgitgadget@gmail.com","subject":"[PATCH 07/17] t2400: explicitly specify bare repo for `git worktree add`","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-02T14:33:13Z","receivedAt":"2026-04-02T14:33:36Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nTo prepare for `safe.bareRepository` defaulting to `explicit` (see\n8d1a7448206e), specify the gitdir specifically in bare-repo `git\nworktree add` invocations via `--git-dir=.` so Git does not rely on\nimplicit bare repository discovery.\n\nWhile at it, also avoid unnecessary subshells and `cd`ing. This\nsimplifies the logic in a rather pleasant way.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t2400-worktree-add.sh | 21 +++++++--------------\n 1 file changed, 7 insertions(+), 14 deletions(-)\n\ndiff --git a/t/t2400-worktree-add.sh b/t/t2400-worktree-add.sh\nindex 023e1301c8..0f8c837647 100755\n--- a/t/t2400-worktree-add.sh\n+++ b/t/t2400-worktree-add.sh\n@@ -171,11 +171,8 @@ test_expect_success 'not die on re-checking out current branch' '\n '\n \n test_expect_success '\"add\" from a bare repo' '\n-\t(\n-\t\tgit clone --bare . bare &&\n-\t\tcd bare &&\n-\t\tgit worktree add -b bare-main ../there2 main\n-\t)\n+\tgit clone --bare . bare &&\n+\tgit -C bare --git-dir=. worktree add -b bare-main ../there2 main\n '\n \n test_expect_success 'checkout from a bare repo without \"add\"' '\n@@ -186,15 +183,11 @@ test_expect_success 'checkout from a bare repo without \"add\"' '\n '\n \n test_expect_success '\"add\" default branch of a bare repo' '\n-\t(\n-\t\tgit clone --bare . bare2 &&\n-\t\tcd bare2 &&\n-\t\tgit worktree add ../there3 main &&\n-\t\tcd ../there3 &&\n-\t\t# Simple check that a Git command does not\n-\t\t# immediately fail with the current setup\n-\t\tgit status\n-\t) &&\n+\tgit clone --bare . bare2 &&\n+\tgit -C bare2 --git-dir=. worktree add ../there3 main &&\n+\t# Simple check that a Git command does not\n+\t# immediately fail with the current setup\n+\tgit status &&\n \tcat >expect <<-EOF &&\n \tinit.t\n \tEOF\n-- \ngitgitgadget\n\n"},{"id":"540752","messageId":"2905e000c526e6fe7140bec7a7ead152b495db65.1775140403.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.git.1775140403.gitgitgadget@gmail.com","subject":"[PATCH 08/17] t2406: use `--git-dir=.` for bare repository worktree repair","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-02T14:33:14Z","receivedAt":"2026-04-02T14:33:37Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nTo prepare for `safe.bareRepository` defaulting to `explicit` (see\n8d1a7448206e), the test case t2406.10(repair .git file from bare.git)\ncannot rely on the implicit discovery of thee bare repository. Simply\nadd a `--git-dir=.` to the invocation. The `-C bare.git` argument is\nstill needed so that the `repair` command realizes works on the intended\ndirectory.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t2406-worktree-repair.sh | 2 +-\n 1 file changed, 1 insertion(+), 1 deletion(-)\n\ndiff --git a/t/t2406-worktree-repair.sh b/t/t2406-worktree-repair.sh\nindex f5f19b3169..cac448b575 100755\n--- a/t/t2406-worktree-repair.sh\n+++ b/t/t2406-worktree-repair.sh\n@@ -84,7 +84,7 @@ test_expect_success 'repair .git file from bare.git' '\n \tgit -C bare.git worktree add --detach ../corrupt &&\n \tgit -C corrupt rev-parse --absolute-git-dir >expect &&\n \trm -f corrupt/.git &&\n-\tgit -C bare.git worktree repair &&\n+\tgit -C bare.git --git-dir=. worktree repair &&\n \tgit -C corrupt rev-parse --absolute-git-dir >actual &&\n \ttest_cmp expect actual\n '\n-- \ngitgitgadget\n\n"},{"id":"540753","messageId":"9001883e152407464c83227f1e09664d0d8826b5.1775140403.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.git.1775140403.gitgitgadget@gmail.com","subject":"[PATCH 09/17] t5503: avoid discovering a bare repository","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-02T14:33:15Z","receivedAt":"2026-04-02T14:33:38Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nThe test case \"fetch specific OID with tag following\" creates a bare\nrepository and wants to operate on it by changing the working directory\nand relying on Git's implicit discovery of the bare repository.\n\nOnce the `safe.bareRepository` default is changed, this is no longer\nan option.\n\nSo let's adjust the commands to specify the bare repository explicitly,\nvia `--git-dir`, and avoid changing the working directory. As a bonus,\nthe result is arguably more readable than the original code.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t5503-tagfollow.sh | 13 +++++--------\n 1 file changed, 5 insertions(+), 8 deletions(-)\n\ndiff --git a/t/t5503-tagfollow.sh b/t/t5503-tagfollow.sh\nindex febe441041..6d178d84dd 100755\n--- a/t/t5503-tagfollow.sh\n+++ b/t/t5503-tagfollow.sh\n@@ -168,16 +168,13 @@ test_expect_success 'new clone fetch main and tags' '\n \n test_expect_success 'fetch specific OID with tag following' '\n \tgit init --bare clone3.git &&\n-\t(\n-\t\tcd clone3.git &&\n-\t\tgit remote add origin .. &&\n-\t\tgit fetch origin $B:refs/heads/main &&\n+\tgit --git-dir=clone3.git remote add origin \"$PWD\" &&\n+\tgit --git-dir=clone3.git fetch origin $B:refs/heads/main &&\n \n-\t\tgit -C .. for-each-ref >expect &&\n-\t\tgit for-each-ref >actual &&\n+\tgit for-each-ref >expect &&\n+\tgit --git-dir=clone3.git for-each-ref >actual &&\n \n-\t\ttest_cmp expect actual\n-\t)\n+\ttest_cmp expect actual\n '\n \n test_done\n-- \ngitgitgadget\n\n"},{"id":"540754","messageId":"6932658411309228d2d670d9b6c2e4be4f17f985.1775140403.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.git.1775140403.gitgitgadget@gmail.com","subject":"[PATCH 10/17] t5505: export `GIT_DIR` after `git init --bare`","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-02T14:33:16Z","receivedAt":"2026-04-02T14:33:39Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nTo prepare for `safe.bareRepository` defaulting to `explicit` (see\n8d1a7448206e), export `GIT_DIR=.` right after `git init --bare &&` so\nsubsequent commands access the bare repo explicitly.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t5505-remote.sh | 4 ++--\n 1 file changed, 2 insertions(+), 2 deletions(-)\n\ndiff --git a/t/t5505-remote.sh b/t/t5505-remote.sh\nindex e592c0bcde..6d3d8510ca 100755\n--- a/t/t5505-remote.sh\n+++ b/t/t5505-remote.sh\n@@ -561,7 +561,7 @@ test_expect_success 'add --mirror && prune' '\n \tmkdir mirror &&\n \t(\n \t\tcd mirror &&\n-\t\tgit init --bare &&\n+\t\tgit init --bare && GIT_DIR=. && export GIT_DIR &&\n \t\tgit remote add --mirror -f origin ../one\n \t) &&\n \t(\n@@ -583,7 +583,7 @@ test_expect_success 'add --mirror setting HEAD' '\n \tmkdir headmirror &&\n \t(\n \t\tcd headmirror &&\n-\t\tgit init --bare -b notmain &&\n+\t\tgit init --bare -b notmain && GIT_DIR=. && export GIT_DIR &&\n \t\tgit remote add --mirror -f origin ../one &&\n \t\ttest \"$(git symbolic-ref HEAD)\" = \"refs/heads/main\"\n \t)\n-- \ngitgitgadget\n\n"},{"id":"540755","messageId":"f6fc807af627701bf7f9ea413c7714e9bc01aea4.1775140403.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.git.1775140403.gitgitgadget@gmail.com","subject":"[PATCH 11/17] t5509: specify bare repository path explicitly","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-02T14:33:17Z","receivedAt":"2026-04-02T14:33:42Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nAfter switching from `-C pushee` to `--git-dir=pushee` as part of\nthe `safe.bareRepository` preparation, `ext::` URLs that used `.`\n(resolved relative to the `-C` target) must spell out the directory\nname explicitly.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t5509-fetch-push-namespaces.sh | 12 ++++++------\n 1 file changed, 6 insertions(+), 6 deletions(-)\n\ndiff --git a/t/t5509-fetch-push-namespaces.sh b/t/t5509-fetch-push-namespaces.sh\nindex 095df1a753..7771a3b34a 100755\n--- a/t/t5509-fetch-push-namespaces.sh\n+++ b/t/t5509-fetch-push-namespaces.sh\n@@ -88,8 +88,8 @@ test_expect_success 'mirroring a repository using a ref namespace' '\n \n test_expect_success 'hide namespaced refs with transfer.hideRefs' '\n \tGIT_NAMESPACE=namespace \\\n-\t\tgit -C pushee -c transfer.hideRefs=refs/tags \\\n-\t\tls-remote \"ext::git %s .\" >actual &&\n+\t\tgit --git-dir=pushee -c transfer.hideRefs=refs/tags \\\n+\t\tls-remote \"ext::git %s pushee\" >actual &&\n \tprintf \"$commit1\\trefs/heads/main\\n\" >expected &&\n \ttest_cmp expected actual\n '\n@@ -97,8 +97,8 @@ test_expect_success 'hide namespaced refs with transfer.hideRefs' '\n test_expect_success 'check that transfer.hideRefs does not match unstripped refs' '\n \tgit -C pushee pack-refs --all &&\n \tGIT_NAMESPACE=namespace \\\n-\t\tgit -C pushee -c transfer.hideRefs=refs/namespaces/namespace/refs/tags \\\n-\t\tls-remote \"ext::git %s .\" >actual &&\n+\t\tgit --git-dir=pushee -c transfer.hideRefs=refs/namespaces/namespace/refs/tags \\\n+\t\tls-remote \"ext::git %s pushee\" >actual &&\n \tprintf \"$commit1\\trefs/heads/main\\n\" >expected &&\n \tprintf \"$commit0\\trefs/tags/0\\n\" >>expected &&\n \tprintf \"$commit1\\trefs/tags/1\\n\" >>expected &&\n@@ -107,8 +107,8 @@ test_expect_success 'check that transfer.hideRefs does not match unstripped refs\n \n test_expect_success 'hide full refs with transfer.hideRefs' '\n \tGIT_NAMESPACE=namespace \\\n-\t\tgit -C pushee -c transfer.hideRefs=\"^refs/namespaces/namespace/refs/tags\" \\\n-\t\tls-remote \"ext::git %s .\" >actual &&\n+\t\tgit --git-dir=pushee -c transfer.hideRefs=\"^refs/namespaces/namespace/refs/tags\" \\\n+\t\tls-remote \"ext::git %s pushee\" >actual &&\n \tprintf \"$commit1\\trefs/heads/main\\n\" >expected &&\n \ttest_cmp expected actual\n '\n-- \ngitgitgadget\n\n"},{"id":"540756","messageId":"5aa3f2a225b9b22a026e0994f2eef583da9d26db.1775140403.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.git.1775140403.gitgitgadget@gmail.com","subject":"[PATCH 12/17] t5540/t5541: avoid accessing a bare repository via `-C <dir>`","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-02T14:33:18Z","receivedAt":"2026-04-02T14:33:43Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nIn the `test_http_push_nonff` function both of these test scripts\ncall, there were two Git invocations that assume that bare repositories\nwill always be discovered when the current working directory is inside\none. This is unlikely to be true forever because at some stage, the\n`safe.bareRepository` config is prone to be modified to be safe by\ndefault.\n\nSo let's be safe and specify the bare repository explicitly.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/lib-httpd.sh | 12 +++++-------\n 1 file changed, 5 insertions(+), 7 deletions(-)\n\ndiff --git a/t/lib-httpd.sh b/t/lib-httpd.sh\nindex 4c76e813e3..f15158b2c5 100644\n--- a/t/lib-httpd.sh\n+++ b/t/lib-httpd.sh\n@@ -259,7 +259,7 @@ test_http_push_nonff () {\n \n \ttest_expect_success 'non-fast-forward push fails' '\n \t\tcd \"$REMOTE_REPO\" &&\n-\t\tHEAD=$(git rev-parse --verify HEAD) &&\n+\t\tHEAD=$(git --git-dir=. rev-parse --verify HEAD) &&\n \n \t\tcd \"$LOCAL_REPO\" &&\n \t\tgit checkout $BRANCH &&\n@@ -270,7 +270,7 @@ test_http_push_nonff () {\n \t\t(\n \t\t\tcd \"$REMOTE_REPO\" &&\n \t\t\techo \"$HEAD\" >expect &&\n-\t\t\tgit rev-parse --verify HEAD >actual &&\n+\t\t\tgit --git-dir=. rev-parse --verify HEAD >actual &&\n \t\t\ttest_cmp expect actual\n \t\t)\n \t'\n@@ -284,18 +284,16 @@ test_http_push_nonff () {\n \t'\n \n \ttest_expect_${EXPECT_CAS_RESULT} 'force with lease aka cas' '\n-\t\tHEAD=$(\tcd \"$REMOTE_REPO\" && git rev-parse --verify HEAD ) &&\n+\t\tHEAD=$(git --git-dir=\"$REMOTE_REPO\" rev-parse --verify HEAD) &&\n \t\ttest_when_finished '\\''\n-\t\t\t(cd \"$REMOTE_REPO\" && git update-ref HEAD \"$HEAD\")\n+\t\t\tgit --git-dir=\"$REMOTE_REPO\" update-ref HEAD \"$HEAD\"\n \t\t'\\'' &&\n \t\t(\n \t\t\tcd \"$LOCAL_REPO\" &&\n \t\t\tgit push -v --force-with-lease=$BRANCH:$HEAD origin\n \t\t) &&\n \t\tgit rev-parse --verify \"$BRANCH\" >expect &&\n-\t\t(\n-\t\t\tcd \"$REMOTE_REPO\" && git rev-parse --verify HEAD\n-\t\t) >actual &&\n+\t\tgit --git-dir=\"$REMOTE_REPO\" rev-parse --verify HEAD >actual &&\n \t\ttest_cmp expect actual\n \t'\n }\n-- \ngitgitgadget\n\n"},{"id":"540757","messageId":"97f22f9e873afdce8b2afc9de2e3f118d24aefb2.1775140403.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.git.1775140403.gitgitgadget@gmail.com","subject":"[PATCH 13/17] t5619: wrap `test_commit_bulk` in `GIT_DIR` subshell for bare repo","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-02T14:33:19Z","receivedAt":"2026-04-02T14:33:45Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nTo prepare for `safe.bareRepository` defaulting to `explicit` (see\n8d1a7448206e), wrap the `test_commit_bulk` call in `(GIT_DIR=\"$REPO\" &&\nexport GIT_DIR && test_commit_bulk ...)` because `test_commit_bulk -C`\nrelies on implicit discovery which would fail once the default changes.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t5619-clone-local-ambiguous-transport.sh | 2 +-\n 1 file changed, 1 insertion(+), 1 deletion(-)\n\ndiff --git a/t/t5619-clone-local-ambiguous-transport.sh b/t/t5619-clone-local-ambiguous-transport.sh\nindex cce62bf78d..3e9aac9015 100755\n--- a/t/t5619-clone-local-ambiguous-transport.sh\n+++ b/t/t5619-clone-local-ambiguous-transport.sh\n@@ -21,7 +21,7 @@ test_expect_success 'setup' '\n \techo \"secret\" >sensitive/secret &&\n \n \tgit init --bare \"$REPO\" &&\n-\ttest_commit_bulk -C \"$REPO\" --ref=main 1 &&\n+\t(GIT_DIR=\"$REPO\" && export GIT_DIR && test_commit_bulk --ref=main 1) &&\n \n \tgit -C \"$REPO\" update-ref HEAD main &&\n \tgit -C \"$REPO\" update-server-info &&\n-- \ngitgitgadget\n\n"},{"id":"540758","messageId":"1ae4caf1559d23d32c72fc1bf94c5c0025baf7c4.1775140403.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.git.1775140403.gitgitgadget@gmail.com","subject":"[PATCH 14/17] t6020: use `-C` for worktree, `--git-dir` for bare repository","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-02T14:33:20Z","receivedAt":"2026-04-02T14:33:46Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nTo prepare for `safe.bareRepository` defaulting to `explicit`\n(see 8d1a7448206e), adjust a loop that iterated over both a\nbare (`cloned`) and a non-bare (`unbundled`) repository using\nthe same `-C` flag: the bare repo needs `--git-dir` to avoid\nimplicit discovery, while the non-bare one keeps `-C`.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t6020-bundle-misc.sh | 4 ++--\n 1 file changed, 2 insertions(+), 2 deletions(-)\n\ndiff --git a/t/t6020-bundle-misc.sh b/t/t6020-bundle-misc.sh\nindex 500c81b8a1..82df105b47 100755\n--- a/t/t6020-bundle-misc.sh\n+++ b/t/t6020-bundle-misc.sh\n@@ -594,9 +594,9 @@ do\n \t\treflist=$(git for-each-ref --format=\"%(objectname)\") &&\n \t\tgit rev-list --objects --filter=$filter --missing=allow-any \\\n \t\t\t$reflist >expect &&\n-\t\tfor repo in cloned unbundled\n+\t\tfor opt in \"--git-dir cloned\" \"-C unbundled\"\n \t\tdo\n-\t\t\tgit -C $repo rev-list --objects --missing=allow-any \\\n+\t\t\tgit $opt rev-list --objects --missing=allow-any \\\n \t\t\t\t$reflist >actual &&\n \t\t\ttest_cmp expect actual || return 1\n \t\tdone\n-- \ngitgitgadget\n\n"},{"id":"540759","messageId":"861a8e0940f172b2e401611efda7d42ae31373ea.1775140403.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.git.1775140403.gitgitgadget@gmail.com","subject":"[PATCH 15/17] t9210: pass `safe.bareRepository=all` to `scalar register`","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-02T14:33:21Z","receivedAt":"2026-04-02T14:33:48Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nThis test expects `scalar register` to discover a bare repo and\nreject it. Since `scalar` does not support `--git-dir` (that option\nwould not make sense in the context of that command), pass `-c\nsafe.bareRepository=all` to opt into implicit discovery of bare\nrepositories, so the test keeps working once the default changes to\n`explicit`.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t9210-scalar.sh | 2 +-\n 1 file changed, 1 insertion(+), 1 deletion(-)\n\ndiff --git a/t/t9210-scalar.sh b/t/t9210-scalar.sh\nindex 009437a5f3..54513c220b 100755\n--- a/t/t9210-scalar.sh\n+++ b/t/t9210-scalar.sh\n@@ -88,7 +88,7 @@ test_expect_success 'scalar enlistments need a worktree' '\n \ttest_when_finished rm -rf bare test &&\n \n \tgit init --bare bare/src &&\n-\t! scalar register bare/src 2>err &&\n+\t! scalar -c safe.bareRepository=all register bare/src 2>err &&\n \tgrep \"Scalar enlistments require a worktree\" err &&\n \n \tgit init test/src &&\n-- \ngitgitgadget\n\n"},{"id":"540760","messageId":"1f1668a6f4ded1647242d652929abe91a4877816.1775140403.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.git.1775140403.gitgitgadget@gmail.com","subject":"[PATCH 16/17] t9700: stop relying on implicit bare repo discovery","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-02T14:33:22Z","receivedAt":"2026-04-02T14:33:49Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nCurrently, the \"alternate bare repo\" test case relies on Git\ndiscovering non-bare and bare repositories alike. However, the automatic\ndiscovery of bare repository represents a weakness that leaves Git\nusers vulnerable. To that end, the `safe.bareRepository` config was\nintroduced, but out of backwards-compatibility concerns, the default is\nnot yet secure.\n\nTo prepare for that default to switch to the secure one, where bare\nrepositories are never discovered automatically but instead must be\nspecified explicitly, let's do exactly that in this test case: specify\nit explicitly, via setting the environment variable `GIT_DIR`.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t9700/test.pl | 9 ++++++---\n 1 file changed, 6 insertions(+), 3 deletions(-)\n\ndiff --git a/t/t9700/test.pl b/t/t9700/test.pl\nindex f83e6169e2..99b712b626 100755\n--- a/t/t9700/test.pl\n+++ b/t/t9700/test.pl\n@@ -153,9 +153,12 @@ unlink $tmpfile3;\n chdir($abs_repo_dir);\n \n # open alternate bare repo\n-my $r4 = Git->repository(Directory => \"$abs_repo_dir/bare.git\");\n-is($r4->command_oneline(qw(log --format=%s)), \"bare commit\",\n-\t\"log of bare repo works\");\n+{\n+\tlocal $ENV{GIT_DIR} = \"$abs_repo_dir/bare.git\";\n+\tmy $r4 = Git->repository(Directory => \"$abs_repo_dir/bare.git\");\n+\tis($r4->command_oneline(qw(log --format=%s)), \"bare commit\",\n+\t\t\"log of bare repo works\");\n+}\n \n # unquoting paths\n is(Git::unquote_path('abc'), 'abc', 'unquote unquoted path');\n-- \ngitgitgadget\n\n"},{"id":"540761","messageId":"c8e5bef27b4635774eb88f29c98e35e2c613d5a8.1775140403.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.git.1775140403.gitgitgadget@gmail.com","subject":"[PATCH 17/17] git p4 clone --bare: need to be explicit about the gitdir","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-02T14:33:23Z","receivedAt":"2026-04-02T14:33:51Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nWhen `safe.bareRepository` will change to be safe by default, bare\nrepositories won't be discovered by default anymore. To prepare for\nthis, `git p4` must be explicit about the gitdir when cloning into a\nbare repository, and no longer rely on that implicit discovery.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n git-p4.py | 1 +\n 1 file changed, 1 insertion(+)\n\ndiff --git a/git-p4.py b/git-p4.py\nindex c0ca7becaf..dd38dbca22 100755\n--- a/git-p4.py\n+++ b/git-p4.py\n@@ -4360,6 +4360,7 @@ class P4Clone(P4Sync):\n         init_cmd = [\"git\", \"init\"]\n         if self.cloneBare:\n             init_cmd.append(\"--bare\")\n+            os.environ[\"GIT_DIR\"] = os.getcwd()\n         retcode = subprocess.call(init_cmd)\n         if retcode:\n             raise subprocess.CalledProcessError(retcode, init_cmd)\n-- \ngitgitgadget\n"},{"id":"540782","messageId":"xmqqeckxqld8.fsf@gitster.g","threadId":"65414","inReplyTo":"pull.2076.git.1775140403.gitgitgadget@gmail.com","subject":"Re: [PATCH 00/17] tests: access bare repositories explicitly","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2026-04-02T18:15:47Z","receivedAt":"2026-04-02T18:15:49Z","isPatch":true,"body":"\"Johannes Schindelin via GitGitGadget\" <gitgitgadget@gmail.com>\nwrites:\n\n> The safe.bareRepository configuration variable (introduced in 8d1a7448206e)\n> allows restricting implicit bare repository discovery. Its default may well\n> change to \"explicit\" in Git v3.0, at which point any test that relies on\n> implicit discovery of a bare repository would break, even if the test\n> subject has nothing to do with bare repositories.\n\nI do not recall such a change for safe.bareRepository discussed in\nthe recent past, and I do not have a strong opinion yet because of\nthat, but if no such change to require \"explicit\" comes, we would be\nlosing test coverage with these patches, because these rewrite the\nones that rely on a working code in implicit cases?\n\nShoudln't there be a patch [01/18] before everything else that\nupdates Documentation/BreakingChanges.adoc to propose the default\nchange?\n\nI've scanned the patches and assuming that there is no implicit\naccess to bare repository allowed, the strategies taken in them ...\n\n> This series adjusts 16 test scripts and git-p4 so that they access bare\n> repositories explicitly. The techniques used are:\n>\n>  * Replace git -C <bare-repo> ... with git --git-dir=<bare-repo> ...\n>  * Export GIT_DIR=. after cd-ing into a bare repository\n>  * Wrap commands in (GIT_DIR=<path> && export GIT_DIR && ...)\n>  * Add test_config_global safe.bareRepository all in the few tests where\n>    implicit discovery is genuinely part of what is being tested\n\n... which are summarized nicely above, all make sense.\n\nThanks.\n"},{"id":"540794","messageId":"xmqq341dozxc.fsf@gitster.g","threadId":"65414","inReplyTo":"f6fc807af627701bf7f9ea413c7714e9bc01aea4.1775140403.git.gitgitgadget@gmail.com","subject":"Re: [PATCH 11/17] t5509: specify bare repository path explicitly","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2026-04-02T20:44:15Z","receivedAt":"2026-04-02T20:44:17Z","isPatch":true,"body":"\"Johannes Schindelin via GitGitGadget\" <gitgitgadget@gmail.com>\nwrites:\n\n>  test_expect_success 'hide namespaced refs with transfer.hideRefs' '\n>  \tGIT_NAMESPACE=namespace \\\n> -\t\tgit -C pushee -c transfer.hideRefs=refs/tags \\\n> -\t\tls-remote \"ext::git %s .\" >actual &&\n> +\t\tgit --git-dir=pushee -c transfer.hideRefs=refs/tags \\\n> +\t\tls-remote \"ext::git %s pushee\" >actual &&\n\nHmph.  The command being ls-remote (which does not care what state\nyour working tree files are), the above may work, but rewriting \n\"-C there\" with \"--git-dir=there\" changes the semantics of the\nprogram, no?  A more conservative rewrite that would preserve what\nthe original wanted to test would be to ...\n\n\t(\n\t\tcd pushee &&\n\t\tgit --git-dir=. -c ... ls-remote ...\n\t)\n\n... do this instead, I think.\n\n>  \tprintf \"$commit1\\trefs/heads/main\\n\" >expected &&\n>  \ttest_cmp expected actual\n>  '\n> @@ -97,8 +97,8 @@ test_expect_success 'hide namespaced refs with transfer.hideRefs' '\n>  test_expect_success 'check that transfer.hideRefs does not match unstripped refs' '\n>  \tgit -C pushee pack-refs --all &&\n>  \tGIT_NAMESPACE=namespace \\\n> -\t\tgit -C pushee -c transfer.hideRefs=refs/namespaces/namespace/refs/tags \\\n> -\t\tls-remote \"ext::git %s .\" >actual &&\n> +\t\tgit --git-dir=pushee -c transfer.hideRefs=refs/namespaces/namespace/refs/tags \\\n> +\t\tls-remote \"ext::git %s pushee\" >actual &&\n>  \tprintf \"$commit1\\trefs/heads/main\\n\" >expected &&\n>  \tprintf \"$commit0\\trefs/tags/0\\n\" >>expected &&\n>  \tprintf \"$commit1\\trefs/tags/1\\n\" >>expected &&\n> @@ -107,8 +107,8 @@ test_expect_success 'check that transfer.hideRefs does not match unstripped refs\n>  \n>  test_expect_success 'hide full refs with transfer.hideRefs' '\n>  \tGIT_NAMESPACE=namespace \\\n> -\t\tgit -C pushee -c transfer.hideRefs=\"^refs/namespaces/namespace/refs/tags\" \\\n> -\t\tls-remote \"ext::git %s .\" >actual &&\n> +\t\tgit --git-dir=pushee -c transfer.hideRefs=\"^refs/namespaces/namespace/refs/tags\" \\\n> +\t\tls-remote \"ext::git %s pushee\" >actual &&\n>  \tprintf \"$commit1\\trefs/heads/main\\n\" >expected &&\n>  \ttest_cmp expected actual\n>  '\n"},{"id":"540855","messageId":"f43a7add-6a0c-2368-1b4c-655dfa6361e7@gmx.de","threadId":"65414","inReplyTo":"xmqq341dozxc.fsf@gitster.g","subject":"Re: [PATCH 11/17] t5509: specify bare repository path explicitly","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2026-04-03T14:22:37Z","receivedAt":"2026-04-03T14:22:43Z","isPatch":true,"body":"Hi Junio,\n\nOn Fri, 3 Apr 2026, Junio C Hamano wrote:\n\n> \"Johannes Schindelin via GitGitGadget\" <gitgitgadget@gmail.com>\n> writes:\n> \n> >  test_expect_success 'hide namespaced refs with transfer.hideRefs' '\n> >  \tGIT_NAMESPACE=namespace \\\n> > -\t\tgit -C pushee -c transfer.hideRefs=refs/tags \\\n> > -\t\tls-remote \"ext::git %s .\" >actual &&\n> > +\t\tgit --git-dir=pushee -c transfer.hideRefs=refs/tags \\\n> > +\t\tls-remote \"ext::git %s pushee\" >actual &&\n> \n> Hmph.  The command being ls-remote (which does not care what state\n> your working tree files are), the above may work, but rewriting \n> \"-C there\" with \"--git-dir=there\" changes the semantics of the\n> program, no?  A more conservative rewrite that would preserve what\n> the original wanted to test would be to ...\n> \n> \t(\n> \t\tcd pushee &&\n> \t\tgit --git-dir=. -c ... ls-remote ...\n> \t)\n> \n> ... do this instead, I think.\n\nIt would be indeed more conservative, and it even results in less changes\nwhen done in a more elegant fashion, by appending `--git-dir=.` after the\n`-C pushee`, as the patches \"t2400: explicitly specify bare repo for `git\nworktree add`\" and \"t2406: use `--git-dir=.` for bare repository worktree\nrepair\" already do. That will not only result in vastly less changed lines\n(and hence less cognitive load on any reviewer), but also avoid the\nproposed subshell. I'll go with `--git-dir=.`, then.\n\nCiao,\nJohannes\n\n> \n> >  \tprintf \"$commit1\\trefs/heads/main\\n\" >expected &&\n> >  \ttest_cmp expected actual\n> >  '\n> > @@ -97,8 +97,8 @@ test_expect_success 'hide namespaced refs with transfer.hideRefs' '\n> >  test_expect_success 'check that transfer.hideRefs does not match unstripped refs' '\n> >  \tgit -C pushee pack-refs --all &&\n> >  \tGIT_NAMESPACE=namespace \\\n> > -\t\tgit -C pushee -c transfer.hideRefs=refs/namespaces/namespace/refs/tags \\\n> > -\t\tls-remote \"ext::git %s .\" >actual &&\n> > +\t\tgit --git-dir=pushee -c transfer.hideRefs=refs/namespaces/namespace/refs/tags \\\n> > +\t\tls-remote \"ext::git %s pushee\" >actual &&\n> >  \tprintf \"$commit1\\trefs/heads/main\\n\" >expected &&\n> >  \tprintf \"$commit0\\trefs/tags/0\\n\" >>expected &&\n> >  \tprintf \"$commit1\\trefs/tags/1\\n\" >>expected &&\n> > @@ -107,8 +107,8 @@ test_expect_success 'check that transfer.hideRefs does not match unstripped refs\n> >  \n> >  test_expect_success 'hide full refs with transfer.hideRefs' '\n> >  \tGIT_NAMESPACE=namespace \\\n> > -\t\tgit -C pushee -c transfer.hideRefs=\"^refs/namespaces/namespace/refs/tags\" \\\n> > -\t\tls-remote \"ext::git %s .\" >actual &&\n> > +\t\tgit --git-dir=pushee -c transfer.hideRefs=\"^refs/namespaces/namespace/refs/tags\" \\\n> > +\t\tls-remote \"ext::git %s pushee\" >actual &&\n> >  \tprintf \"$commit1\\trefs/heads/main\\n\" >expected &&\n> >  \ttest_cmp expected actual\n> >  '\n> \n> \n"},{"id":"540863","messageId":"xmqqqzovnc25.fsf@gitster.g","threadId":"65414","inReplyTo":"f43a7add-6a0c-2368-1b4c-655dfa6361e7@gmx.de","subject":"Re: [PATCH 11/17] t5509: specify bare repository path explicitly","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2026-04-03T18:17:22Z","receivedAt":"2026-04-03T18:17:25Z","isPatch":true,"body":"Johannes Schindelin <Johannes.Schindelin@gmx.de> writes:\n\n> It would be indeed more conservative, and it even results in less changes\n> when done in a more elegant fashion, by appending `--git-dir=.` after the\n> `-C pushee`, as the patches \"t2400: explicitly specify bare repo for `git\n> worktree add`\" and \"t2406: use `--git-dir=.` for bare repository worktree\n> repair\" already do. That will not only result in vastly less changed lines\n> (and hence less cognitive load on any reviewer), but also avoid the\n> proposed subshell. I'll go with `--git-dir=.`, then.\n\nAh, yes, with or without -C shouldn't affect the decision to use\n\"--git-dir=$path\" in the first place, and the ones that need the\nchange to explicitly say \"--git-dir=$path\" in this series are all\nthe ones that wants to be at the level where HEAD and refs/ exists\nand access the repository contents (as if it were a bare repository\neven when it is a part of a repository with a worktree, or it may\nbe going there into a real bare repository), by definition what we\nneed to add is \"--git-dir=.\", no arbitrary $path adjusted for each\ncase is needed.\n\nMakes sense.\n\nAssuming that we want to tighten the rule and prepare for the\ntightening before it happens, that is.  I personally do not think it\nis a bad move, but I do not recall we had much discussion to gain a\ncommunity consensus to go in that direction.\n"},{"id":"540910","messageId":"67a9157c-37f5-282f-4566-0f6c55226571@gmx.de","threadId":"65414","inReplyTo":"xmqqqzovnc25.fsf@gitster.g","subject":"Re: [PATCH 11/17] t5509: specify bare repository path explicitly","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2026-04-04T19:29:20Z","receivedAt":"2026-04-04T19:29:24Z","isPatch":true,"body":"Hi Junio,\n\nOn Fri, 3 Apr 2026, Junio C Hamano wrote:\n\n> Johannes Schindelin <Johannes.Schindelin@gmx.de> writes:\n> \n> > It would be indeed more conservative, and it even results in less changes\n> > when done in a more elegant fashion, by appending `--git-dir=.` after the\n> > `-C pushee` [...]\n> \n> Makes sense.\n> \n> Assuming that we want to tighten the rule and prepare for the tightening\n> before it happens, that is.  I personally do not think it is a bad move,\n> but I do not recall we had much discussion to gain a community consensus\n> to go in that direction.\n\nWell, I wanted to contribute a patch to that extent, as a discussion\nstarter. And then the CI build broke. And then I found myself almost\noverwhelmed with the changes required to let the CI build pass. And then I\nthought I'd go through the effort of making those changes just to gauge\nhow much of a problem changing the default would be for affected parties.\nAnd then I split up the preparatory patches into multiple sub-branches so\nthat reviewers wouldn't get overwhelmed. And you're looking at the first\nsub-branch broken out from that PR.\n\nNote that this here patch series, while it would be a necessary\nprerequisite for changing the `safe.bareRepository` default in Git 3.0,\ndoes have merit on its own, and I do not intend these patches to make such\na change of default behavior more or less likely in Git 3.0.\n\nBy introducing that setting, we declared that while not necessary at the\nmoment, it is better, really, to specify the location of bare repositories\nexplcitly than to rely on the implicit discovery. And this patch series\naddresses a couple of places where Git's own test suite does not follow\nour own advice.\n\nFor that reason I consider this patch series strictly a spring cleaning.\n\nCiao,\nJohannes\n"},{"id":"540911","messageId":"dcb8c6f1-1410-9f04-c389-6f69ac4fe842@gmx.de","threadId":"65414","inReplyTo":"xmqqeckxqld8.fsf@gitster.g","subject":"Re: [PATCH 00/17] tests: access bare repositories explicitly","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2026-04-04T19:45:31Z","receivedAt":"2026-04-04T19:45:35Z","isPatch":true,"body":"Hi Junio,\n\nOn Thu, 2 Apr 2026, Junio C Hamano wrote:\n\n> \"Johannes Schindelin via GitGitGadget\" <gitgitgadget@gmail.com>\n> writes:\n> \n> > The safe.bareRepository configuration variable (introduced in\n> > 8d1a7448206e) allows restricting implicit bare repository discovery.\n> > Its default may well change to \"explicit\" in Git v3.0, at which point\n> > any test that relies on implicit discovery of a bare repository would\n> > break, even if the test subject has nothing to do with bare\n> > repositories.\n> \n> I do not recall such a change for safe.bareRepository discussed in\n> the recent past, and I do not have a strong opinion yet because of\n> that, but if no such change to require \"explicit\" comes, we would be\n> losing test coverage with these patches, because these rewrite the\n> ones that rely on a working code in implicit cases?\n\nNote that the commit message says \"may well\" not \"will\". Precisely because\nsuch a discussion has not been had in the recent past.\n\nBut yes, that discussion has not happened, and I was quite surprised about\nthat when I recently looked (I prepared some of my code for such a change,\nassuming that Git 3.0 as a natural inflection point would be the time for\n8d1a7448206e's long journey to come to a conclusion).\n\n> Shoudln't there be a patch [01/18] before everything else that\n> updates Documentation/BreakingChanges.adoc to propose the default\n> change?\n\nWell, yes and no. There should be an update to BreakingChanges to propose\nthat default change, but obviously it should not only be a documentation\nchange: It should also adjust `Documentation/config/safe.adoc` to mention\nthe intended change of behavior, and it should introduce\n`WITH_BREAKING_HANGES`-specific conditional code in `setup.c`.\n\nAnd, crucially, it should pass the test suite under WITH_BREAKING_CHANGES.\n\nTo do that, a lot more needs to happen than just the 17 patches in this\nhere patch series. Most of the additional changes are quite mechanical,\nand can be validated relatively easily despite their sheer number. And\nonly at the very end of those changes can that `safe.bareRepository`\nchange even be proposed. The eventual patch that does what you ask (but\nnot as 1/18, for the reasons I outlined above), and more, is:\nhttps://github.com/gitgitgadget/git/pull/2072/changes/435e3505e7997a25f45777a6ba436899a793c59c\n\nI plan on proposing that patch in due time, to start the discussion\nwhether or not it is a good idea to change the default of\n`safe.bareRepository` in Git 3.0.\n\nCiao,\nJohannes\n"},{"id":"540912","messageId":"pull.2076.v2.git.1775332197.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.git.1775140403.gitgitgadget@gmail.com","subject":"[PATCH v2 00/17] tests: access bare repositories explicitly","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-04T19:49:40Z","receivedAt":"2026-04-04T19:49:59Z","isPatch":true,"body":"The safe.bareRepository configuration variable (introduced in 8d1a7448206e)\nallows restricting implicit bare repository discovery. Its default may well\nchange to \"explicit\" in Git v3.0, at which point any test that relies on\nimplicit discovery of a bare repository would break, even if the test\nsubject has nothing to do with bare repositories.\n\nThis series adjusts 16 test scripts and git-p4 so that they access bare\nrepositories explicitly. The techniques used are:\n\n * Replace git -C <bare-repo> ... with git --git-dir=<bare-repo> ...\n * Export GIT_DIR=. after cd-ing into a bare repository\n * Wrap commands in (GIT_DIR=<path> && export GIT_DIR && ...)\n * Add test_config_global safe.bareRepository all in the few tests where\n   implicit discovery is genuinely part of what is being tested\n\nEach commit is a self-contained fix to one test file (or a small related\ngroup).\n\nThis patch series is part of https://github.com/gitgitgadget/git/pull/2072.\n\nChanges since v1:\n\n * Dramatically simplified the patch \"t5509: specify bare repository path\n   explicitly\"\n\nJohannes Schindelin (17):\n  t0001: allow implicit bare repo discovery for aliased-command test\n  t0001: replace `cd`+`git` with `git --git-dir` in `check_config`\n  t0003: use `--git-dir` for bare repo attribute tests\n  t0056: allow implicit bare repo discovery for `-C` work-tree tests\n  t1020: use `--git-dir` instead of subshell for bare repo\n  t1900: avoid using `-C <dir>` for a bare repository\n  t2400: explicitly specify bare repo for `git worktree add`\n  t2406: use `--git-dir=.` for bare repository worktree repair\n  t5503: avoid discovering a bare repository\n  t5505: export `GIT_DIR` after `git init --bare`\n  t5509: specify bare repository path explicitly\n  t5540/t5541: avoid accessing a bare repository via `-C <dir>`\n  t5619: wrap `test_commit_bulk` in `GIT_DIR` subshell for bare repo\n  t6020: use `-C` for worktree, `--git-dir` for bare repository\n  t9210: pass `safe.bareRepository=all` to `scalar register`\n  t9700: stop relying on implicit bare repo discovery\n  git p4 clone --bare: need to be explicit about the gitdir\n\n git-p4.py                                  |  1 +\n t/lib-httpd.sh                             | 12 ++--\n t/t0001-init.sh                            |  5 +-\n t/t0003-attributes.sh                      | 66 +++++++++-------------\n t/t0056-git-C.sh                           |  2 +\n t/t1020-subdirectory.sh                    |  5 +-\n t/t1900-repo-info.sh                       |  7 ++-\n t/t2400-worktree-add.sh                    | 21 +++----\n t/t2406-worktree-repair.sh                 |  2 +-\n t/t5503-tagfollow.sh                       | 13 ++---\n t/t5505-remote.sh                          |  4 +-\n t/t5509-fetch-push-namespaces.sh           |  6 +-\n t/t5619-clone-local-ambiguous-transport.sh |  2 +-\n t/t6020-bundle-misc.sh                     |  4 +-\n t/t9210-scalar.sh                          |  2 +-\n t/t9700/test.pl                            |  9 ++-\n 16 files changed, 71 insertions(+), 90 deletions(-)\n\n\nbase-commit: cf2139f8e1680b076e115bc0b349e369b4b0ecc4\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-2076%2Fdscho%2Ftests-explicit-bare-repo-v2\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-2076/dscho/tests-explicit-bare-repo-v2\nPull-Request: https://github.com/gitgitgadget/git/pull/2076\n\nRange-diff vs v1:\n\n  1:  a1cdbd58f0 =  1:  a1cdbd58f0 t0001: allow implicit bare repo discovery for aliased-command test\n  2:  78744602fb =  2:  78744602fb t0001: replace `cd`+`git` with `git --git-dir` in `check_config`\n  3:  a4f7a6df51 =  3:  a4f7a6df51 t0003: use `--git-dir` for bare repo attribute tests\n  4:  5b6bb18632 =  4:  5b6bb18632 t0056: allow implicit bare repo discovery for `-C` work-tree tests\n  5:  c38f0a68f1 =  5:  c38f0a68f1 t1020: use `--git-dir` instead of subshell for bare repo\n  6:  a084c39273 =  6:  a084c39273 t1900: avoid using `-C <dir>` for a bare repository\n  7:  6a7730cf57 =  7:  6a7730cf57 t2400: explicitly specify bare repo for `git worktree add`\n  8:  2905e000c5 =  8:  2905e000c5 t2406: use `--git-dir=.` for bare repository worktree repair\n  9:  9001883e15 =  9:  9001883e15 t5503: avoid discovering a bare repository\n 10:  6932658411 = 10:  6932658411 t5505: export `GIT_DIR` after `git init --bare`\n 11:  f6fc807af6 ! 11:  2f1e745b55 t5509: specify bare repository path explicitly\n     @@ Metadata\n       ## Commit message ##\n          t5509: specify bare repository path explicitly\n      \n     -    After switching from `-C pushee` to `--git-dir=pushee` as part of\n     -    the `safe.bareRepository` preparation, `ext::` URLs that used `.`\n     -    (resolved relative to the `-C` target) must spell out the directory\n     -    name explicitly.\n     +    When `ls-remote` is told to switch the current working directory to the\n     +    bare repository `pushee` via `-C pushee`, as part of the\n     +    `safe.bareRepository` preparation let's append `--git-dir=.` to spell\n     +    out that this is a bare repository that does not need to be discovered\n     +    implictly.\n      \n          Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n      \n     @@ t/t5509-fetch-push-namespaces.sh: test_expect_success 'mirroring a repository us\n       test_expect_success 'hide namespaced refs with transfer.hideRefs' '\n       \tGIT_NAMESPACE=namespace \\\n      -\t\tgit -C pushee -c transfer.hideRefs=refs/tags \\\n     --\t\tls-remote \"ext::git %s .\" >actual &&\n     -+\t\tgit --git-dir=pushee -c transfer.hideRefs=refs/tags \\\n     -+\t\tls-remote \"ext::git %s pushee\" >actual &&\n     ++\t\tgit -C pushee --git-dir=. -c transfer.hideRefs=refs/tags \\\n     + \t\tls-remote \"ext::git %s .\" >actual &&\n       \tprintf \"$commit1\\trefs/heads/main\\n\" >expected &&\n       \ttest_cmp expected actual\n     - '\n      @@ t/t5509-fetch-push-namespaces.sh: test_expect_success 'hide namespaced refs with transfer.hideRefs' '\n       test_expect_success 'check that transfer.hideRefs does not match unstripped refs' '\n       \tgit -C pushee pack-refs --all &&\n       \tGIT_NAMESPACE=namespace \\\n      -\t\tgit -C pushee -c transfer.hideRefs=refs/namespaces/namespace/refs/tags \\\n     --\t\tls-remote \"ext::git %s .\" >actual &&\n     -+\t\tgit --git-dir=pushee -c transfer.hideRefs=refs/namespaces/namespace/refs/tags \\\n     -+\t\tls-remote \"ext::git %s pushee\" >actual &&\n     ++\t\tgit -C pushee --git-dir=. -c transfer.hideRefs=refs/namespaces/namespace/refs/tags \\\n     + \t\tls-remote \"ext::git %s .\" >actual &&\n       \tprintf \"$commit1\\trefs/heads/main\\n\" >expected &&\n       \tprintf \"$commit0\\trefs/tags/0\\n\" >>expected &&\n     - \tprintf \"$commit1\\trefs/tags/1\\n\" >>expected &&\n      @@ t/t5509-fetch-push-namespaces.sh: test_expect_success 'check that transfer.hideRefs does not match unstripped refs\n       \n       test_expect_success 'hide full refs with transfer.hideRefs' '\n       \tGIT_NAMESPACE=namespace \\\n      -\t\tgit -C pushee -c transfer.hideRefs=\"^refs/namespaces/namespace/refs/tags\" \\\n     --\t\tls-remote \"ext::git %s .\" >actual &&\n     -+\t\tgit --git-dir=pushee -c transfer.hideRefs=\"^refs/namespaces/namespace/refs/tags\" \\\n     -+\t\tls-remote \"ext::git %s pushee\" >actual &&\n     ++\t\tgit -C pushee --git-dir=. -c transfer.hideRefs=\"^refs/namespaces/namespace/refs/tags\" \\\n     + \t\tls-remote \"ext::git %s .\" >actual &&\n       \tprintf \"$commit1\\trefs/heads/main\\n\" >expected &&\n       \ttest_cmp expected actual\n     - '\n 12:  5aa3f2a225 = 12:  c8789bd542 t5540/t5541: avoid accessing a bare repository via `-C <dir>`\n 13:  97f22f9e87 = 13:  f09a96e55d t5619: wrap `test_commit_bulk` in `GIT_DIR` subshell for bare repo\n 14:  1ae4caf155 = 14:  01ec77c908 t6020: use `-C` for worktree, `--git-dir` for bare repository\n 15:  861a8e0940 = 15:  00eaefbf62 t9210: pass `safe.bareRepository=all` to `scalar register`\n 16:  1f1668a6f4 = 16:  890dfd024d t9700: stop relying on implicit bare repo discovery\n 17:  c8e5bef27b = 17:  139b9da946 git p4 clone --bare: need to be explicit about the gitdir\n\n-- \ngitgitgadget\n"},{"id":"540913","messageId":"a1cdbd58f0af27be689230b7d8009d93bc34abca.1775332197.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.v2.git.1775332197.gitgitgadget@gmail.com","subject":"[PATCH v2 01/17] t0001: allow implicit bare repo discovery for aliased-command test","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-04T19:49:41Z","receivedAt":"2026-04-04T19:50:00Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\n8d1a7448206e (setup.c: create `safe.bareRepository`, 2022-07-14)\nintroduced a setting to restrict implicit bare repository discovery,\nmitigating a social-engineering attack where an embedded bare repo's\nhooks get executed unknowingly. To allow for that default to change at\nsome stage in the future, the tests need to be prepared.\n\nThis commit adjusts a test accordingly that runs `git aliasedinit`\nfrom inside a bare repo to verify that aliased commands work there.\nThe test is about alias resolution, not bare repo discovery, so add\n`test_config_global safe.bareRepository all` to opt in explicitly.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t0001-init.sh | 1 +\n 1 file changed, 1 insertion(+)\n\ndiff --git a/t/t0001-init.sh b/t/t0001-init.sh\nindex e4d32bb4d2..6bd0a15dac 100755\n--- a/t/t0001-init.sh\n+++ b/t/t0001-init.sh\n@@ -77,6 +77,7 @@ test_expect_success 'plain nested through aliased command' '\n '\n \n test_expect_success 'plain nested in bare through aliased command' '\n+\ttest_config_global safe.bareRepository all &&\n \t(\n \t\tgit init --bare bare-ancestor-aliased.git &&\n \t\tcd bare-ancestor-aliased.git &&\n-- \ngitgitgadget\n\n"},{"id":"540914","messageId":"78744602fb33978a9f674f5f9860c58e7734d2e8.1775332197.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.v2.git.1775332197.gitgitgadget@gmail.com","subject":"[PATCH v2 02/17] t0001: replace `cd`+`git` with `git --git-dir` in `check_config`","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-04T19:49:42Z","receivedAt":"2026-04-04T19:50:02Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nTo prepare for `safe.bareRepository` defaulting to `explicit`\n(see 8d1a7448206e), replace `cd <dir> && git config` with `git\n--git-dir=<dir> config` so the helper does not rely on implicit bare\nrepository discovery.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t0001-init.sh | 4 ++--\n 1 file changed, 2 insertions(+), 2 deletions(-)\n\ndiff --git a/t/t0001-init.sh b/t/t0001-init.sh\nindex 6bd0a15dac..db2bf1001f 100755\n--- a/t/t0001-init.sh\n+++ b/t/t0001-init.sh\n@@ -20,8 +20,8 @@ check_config () {\n \t\treturn 1\n \tfi\n \n-\tbare=$(cd \"$1\" && git config --bool core.bare)\n-\tworktree=$(cd \"$1\" && git config core.worktree) ||\n+\tbare=$(git --git-dir=\"$1\" config --bool core.bare)\n+\tworktree=$(git --git-dir=\"$1\" config core.worktree) ||\n \tworktree=unset\n \n \ttest \"$bare\" = \"$2\" && test \"$worktree\" = \"$3\" || {\n-- \ngitgitgadget\n\n"},{"id":"540915","messageId":"a4f7a6df516c848936e6952dac8ca02ccb0ac643.1775332197.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.v2.git.1775332197.gitgitgadget@gmail.com","subject":"[PATCH v2 03/17] t0003: use `--git-dir` for bare repo attribute tests","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-04T19:49:43Z","receivedAt":"2026-04-04T19:50:03Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nThe bare repo tests in t0003-attributes.sh currently `cd` into the bare\nrepository inside subshells, relying on implicit discovery. Restructure\nthese tests to pass `--git-dir=bare.git` to the `attr_check` and\n`attr_check_source` helpers instead. This makes the code much easier to\nread, and also makes bare repo access explicit, i.e. compatible with an\neventual `safe.bareRepository=explicit` default.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t0003-attributes.sh | 66 ++++++++++++++++++-------------------------\n 1 file changed, 27 insertions(+), 39 deletions(-)\n\ndiff --git a/t/t0003-attributes.sh b/t/t0003-attributes.sh\nindex 582e207aa1..3a34f5dbc2 100755\n--- a/t/t0003-attributes.sh\n+++ b/t/t0003-attributes.sh\n@@ -346,17 +346,14 @@ test_expect_success 'setup bare' '\n \n test_expect_success 'bare repository: check that .gitattribute is ignored' '\n \t(\n-\t\tcd bare.git &&\n-\t\t(\n-\t\t\techo \"f\ttest=f\" &&\n-\t\t\techo \"a/i test=a/i\"\n-\t\t) >.gitattributes &&\n-\t\tattr_check f unspecified &&\n-\t\tattr_check a/f unspecified &&\n-\t\tattr_check a/c/f unspecified &&\n-\t\tattr_check a/i unspecified &&\n-\t\tattr_check subdir/a/i unspecified\n-\t)\n+\t\techo \"f\ttest=f\" &&\n+\t\techo \"a/i test=a/i\"\n+\t) >bare.git/.gitattributes &&\n+\tattr_check f unspecified --git-dir=bare.git &&\n+\tattr_check a/f unspecified --git-dir=bare.git &&\n+\tattr_check a/c/f unspecified --git-dir=bare.git &&\n+\tattr_check a/i unspecified --git-dir=bare.git &&\n+\tattr_check subdir/a/i unspecified --git-dir=bare.git\n '\n \n bad_attr_source_err=\"fatal: bad --attr-source or GIT_ATTR_SOURCE\"\n@@ -449,41 +446,32 @@ test_expect_success 'diff without repository with attr source' '\n '\n \n test_expect_success 'bare repository: with --source' '\n-\t(\n-\t\tcd bare.git &&\n-\t\tattr_check_source foo/bar/f f tag-1 &&\n-\t\tattr_check_source foo/bar/a/i n tag-1 &&\n-\t\tattr_check_source foo/bar/f unspecified tag-2 &&\n-\t\tattr_check_source foo/bar/a/i m tag-2 &&\n-\t\tattr_check_source foo/bar/g g tag-2 &&\n-\t\tattr_check_source foo/bar/g unspecified tag-1\n-\t)\n+\tattr_check_source foo/bar/f f tag-1 --git-dir=bare.git &&\n+\tattr_check_source foo/bar/a/i n tag-1 --git-dir=bare.git &&\n+\tattr_check_source foo/bar/f unspecified tag-2 --git-dir=bare.git &&\n+\tattr_check_source foo/bar/a/i m tag-2 --git-dir=bare.git &&\n+\tattr_check_source foo/bar/g g tag-2 --git-dir=bare.git &&\n+\tattr_check_source foo/bar/g unspecified tag-1 --git-dir=bare.git\n '\n \n test_expect_success 'bare repository: check that --cached honors index' '\n-\t(\n-\t\tcd bare.git &&\n-\t\tGIT_INDEX_FILE=../.git/index \\\n-\t\tgit check-attr --cached --stdin --all <../stdin-all |\n-\t\tsort >actual &&\n-\t\ttest_cmp ../specified-all actual\n-\t)\n+\tGIT_INDEX_FILE=.git/index \\\n+\tgit --git-dir=bare.git check-attr --cached --stdin --all <stdin-all |\n+\tsort >actual &&\n+\ttest_cmp specified-all actual\n '\n \n test_expect_success 'bare repository: test info/attributes' '\n+\tmkdir -p bare.git/info &&\n \t(\n-\t\tcd bare.git &&\n-\t\tmkdir info &&\n-\t\t(\n-\t\t\techo \"f\ttest=f\" &&\n-\t\t\techo \"a/i test=a/i\"\n-\t\t) >info/attributes &&\n-\t\tattr_check f f &&\n-\t\tattr_check a/f f &&\n-\t\tattr_check a/c/f f &&\n-\t\tattr_check a/i a/i &&\n-\t\tattr_check subdir/a/i unspecified\n-\t)\n+\t\techo \"f\ttest=f\" &&\n+\t\techo \"a/i test=a/i\"\n+\t) >bare.git/info/attributes &&\n+\tattr_check f f --git-dir=bare.git &&\n+\tattr_check a/f f --git-dir=bare.git &&\n+\tattr_check a/c/f f --git-dir=bare.git &&\n+\tattr_check a/i a/i --git-dir=bare.git &&\n+\tattr_check subdir/a/i unspecified --git-dir=bare.git\n '\n \n test_expect_success 'binary macro expanded by -a' '\n-- \ngitgitgadget\n\n"},{"id":"540916","messageId":"5b6bb1863227cf95700fab4934ec2e1dac9570aa.1775332197.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.v2.git.1775332197.gitgitgadget@gmail.com","subject":"[PATCH v2 04/17] t0056: allow implicit bare repo discovery for `-C` work-tree tests","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-04T19:49:44Z","receivedAt":"2026-04-04T19:50:05Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nThe `git -C c/a.git --work-tree=../a` invocations in t0056-git-C.sh\nenter what is technically the `.git` directory of a repository to\ntest `-C` combined with `--work-tree`. In doing so, the code relies on\nimplicit discovery of bare repositories, which 8d1a7448206e (setup.c:\ncreate `safe.bareRepository`, 2022-07-14) prepared to be prevented by\ndefault.\n\nThese tests verify the interaction between those flags, so changing them\nto use `--git-dir` would defeat their purpose. So let's just temporarily\nforce-enable implicit discovery of bare repositories, no matter what\n`safe.bareRepository` defaults to.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t0056-git-C.sh | 2 ++\n 1 file changed, 2 insertions(+)\n\ndiff --git a/t/t0056-git-C.sh b/t/t0056-git-C.sh\nindex 2630e756da..6b7122add5 100755\n--- a/t/t0056-git-C.sh\n+++ b/t/t0056-git-C.sh\n@@ -57,11 +57,13 @@ test_expect_success 'Order should not matter: \"--git-dir=a.git -C c\" is equivale\n test_expect_success 'Effect on --work-tree option: \"-C c/a.git --work-tree=../a\"  is equivalent to \"--work-tree=c/a --git-dir=c/a.git\"' '\n \trm c/a/a.txt &&\n \tgit --git-dir=c/a.git --work-tree=c/a status >expected &&\n+\ttest_config_global safe.bareRepository all &&\n \tgit -C c/a.git --work-tree=../a status >actual &&\n \ttest_cmp expected actual\n '\n \n test_expect_success 'Order should not matter: \"--work-tree=../a -C c/a.git\" is equivalent to \"-C c/a.git --work-tree=../a\"' '\n+\ttest_config_global safe.bareRepository all &&\n \tgit -C c/a.git --work-tree=../a status >expected &&\n \tgit --work-tree=../a -C c/a.git status >actual &&\n \ttest_cmp expected actual\n-- \ngitgitgadget\n\n"},{"id":"540917","messageId":"c38f0a68f10df01ee2c99f05d0f33a0a517ffb50.1775332197.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.v2.git.1775332197.gitgitgadget@gmail.com","subject":"[PATCH v2 05/17] t1020: use `--git-dir` instead of subshell for bare repo","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-04T19:49:45Z","receivedAt":"2026-04-04T19:50:06Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nReplace an unnecessarily complex subshell pattern with a much simpler\n`--git-dir`-based one. The latter is not only simpler, it also no\nlonger relies on implicit bare repo discovery, which would fail with\n`safe.bareRepository=explicit`.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t1020-subdirectory.sh | 5 +----\n 1 file changed, 1 insertion(+), 4 deletions(-)\n\ndiff --git a/t/t1020-subdirectory.sh b/t/t1020-subdirectory.sh\nindex 9fdbb2af80..20d2d306fe 100755\n--- a/t/t1020-subdirectory.sh\n+++ b/t/t1020-subdirectory.sh\n@@ -177,10 +177,7 @@ test_expect_success 'no file/rev ambiguity check inside a bare repo (explicit GI\n test_expect_success 'no file/rev ambiguity check inside a bare repo' '\n \ttest_when_finished \"rm -fr foo.git\" &&\n \tgit clone -s --bare .git foo.git &&\n-\t(\n-\t\tcd foo.git &&\n-\t\tgit show -s HEAD\n-\t)\n+\tgit --git-dir=foo.git show -s HEAD\n '\n \n test_expect_success SYMLINKS 'detection should not be fooled by a symlink' '\n-- \ngitgitgadget\n\n"},{"id":"540918","messageId":"a084c39273ec9e613fe1c6c982700292f5ddb705.1775332197.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.v2.git.1775332197.gitgitgadget@gmail.com","subject":"[PATCH v2 06/17] t1900: avoid using `-C <dir>` for a bare repository","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-04T19:49:46Z","receivedAt":"2026-04-04T19:50:07Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nTo prepare for `safe.bareRepository` defaulting to `explicit` (see\n8d1a7448206e), add an optional 6th parameter `repo_flag` (defaulting\nto `-C`) to the `test_repo_info` helper, and use it in the caller that\nwants to operate on a bare repository.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t1900-repo-info.sh | 7 ++++---\n 1 file changed, 4 insertions(+), 3 deletions(-)\n\ndiff --git a/t/t1900-repo-info.sh b/t/t1900-repo-info.sh\nindex 39bb77dda0..6280da1efb 100755\n--- a/t/t1900-repo-info.sh\n+++ b/t/t1900-repo-info.sh\n@@ -20,6 +20,7 @@ test_repo_info () {\n \trepo_name=$3\n \tkey=$4\n \texpected_value=$5\n+\trepo_flag=${6:--C}\n \n \ttest_expect_success \"setup: $label\" '\n \t\teval \"$init_command $repo_name\"\n@@ -27,13 +28,13 @@ test_repo_info () {\n \n \ttest_expect_success \"lines: $label\" '\n \t\techo \"$key=$expected_value\" > expect &&\n-\t\tgit -C \"$repo_name\" repo info \"$key\" >actual &&\n+\t\tgit $repo_flag \"$repo_name\" repo info \"$key\" >actual &&\n \t\ttest_cmp expect actual\n \t'\n \n \ttest_expect_success \"nul: $label\" '\n \t\tprintf \"%s\\n%s\\0\" \"$key\" \"$expected_value\" >expect &&\n-\t\tgit -C \"$repo_name\" repo info --format=nul \"$key\" >actual &&\n+\t\tgit $repo_flag \"$repo_name\" repo info --format=nul \"$key\" >actual &&\n \t\ttest_cmp_bin expect actual\n \t'\n }\n@@ -48,7 +49,7 @@ test_repo_info 'bare repository = false is retrieved correctly' \\\n \t'git init' 'nonbare' 'layout.bare' 'false'\n \n test_repo_info 'bare repository = true is retrieved correctly' \\\n-\t'git init --bare' 'bare' 'layout.bare' 'true'\n+\t'git init --bare' 'bare' 'layout.bare' 'true' '--git-dir'\n \n test_repo_info 'shallow repository = false is retrieved correctly' \\\n \t'git init' 'nonshallow' 'layout.shallow' 'false'\n-- \ngitgitgadget\n\n"},{"id":"540919","messageId":"6a7730cf57b6b5efbc8d0556e19c8117955a74de.1775332197.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.v2.git.1775332197.gitgitgadget@gmail.com","subject":"[PATCH v2 07/17] t2400: explicitly specify bare repo for `git worktree add`","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-04T19:49:47Z","receivedAt":"2026-04-04T19:50:08Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nTo prepare for `safe.bareRepository` defaulting to `explicit` (see\n8d1a7448206e), specify the gitdir specifically in bare-repo `git\nworktree add` invocations via `--git-dir=.` so Git does not rely on\nimplicit bare repository discovery.\n\nWhile at it, also avoid unnecessary subshells and `cd`ing. This\nsimplifies the logic in a rather pleasant way.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t2400-worktree-add.sh | 21 +++++++--------------\n 1 file changed, 7 insertions(+), 14 deletions(-)\n\ndiff --git a/t/t2400-worktree-add.sh b/t/t2400-worktree-add.sh\nindex 023e1301c8..0f8c837647 100755\n--- a/t/t2400-worktree-add.sh\n+++ b/t/t2400-worktree-add.sh\n@@ -171,11 +171,8 @@ test_expect_success 'not die on re-checking out current branch' '\n '\n \n test_expect_success '\"add\" from a bare repo' '\n-\t(\n-\t\tgit clone --bare . bare &&\n-\t\tcd bare &&\n-\t\tgit worktree add -b bare-main ../there2 main\n-\t)\n+\tgit clone --bare . bare &&\n+\tgit -C bare --git-dir=. worktree add -b bare-main ../there2 main\n '\n \n test_expect_success 'checkout from a bare repo without \"add\"' '\n@@ -186,15 +183,11 @@ test_expect_success 'checkout from a bare repo without \"add\"' '\n '\n \n test_expect_success '\"add\" default branch of a bare repo' '\n-\t(\n-\t\tgit clone --bare . bare2 &&\n-\t\tcd bare2 &&\n-\t\tgit worktree add ../there3 main &&\n-\t\tcd ../there3 &&\n-\t\t# Simple check that a Git command does not\n-\t\t# immediately fail with the current setup\n-\t\tgit status\n-\t) &&\n+\tgit clone --bare . bare2 &&\n+\tgit -C bare2 --git-dir=. worktree add ../there3 main &&\n+\t# Simple check that a Git command does not\n+\t# immediately fail with the current setup\n+\tgit status &&\n \tcat >expect <<-EOF &&\n \tinit.t\n \tEOF\n-- \ngitgitgadget\n\n"},{"id":"540920","messageId":"2905e000c526e6fe7140bec7a7ead152b495db65.1775332197.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.v2.git.1775332197.gitgitgadget@gmail.com","subject":"[PATCH v2 08/17] t2406: use `--git-dir=.` for bare repository worktree repair","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-04T19:49:48Z","receivedAt":"2026-04-04T19:50:09Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nTo prepare for `safe.bareRepository` defaulting to `explicit` (see\n8d1a7448206e), the test case t2406.10(repair .git file from bare.git)\ncannot rely on the implicit discovery of thee bare repository. Simply\nadd a `--git-dir=.` to the invocation. The `-C bare.git` argument is\nstill needed so that the `repair` command realizes works on the intended\ndirectory.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t2406-worktree-repair.sh | 2 +-\n 1 file changed, 1 insertion(+), 1 deletion(-)\n\ndiff --git a/t/t2406-worktree-repair.sh b/t/t2406-worktree-repair.sh\nindex f5f19b3169..cac448b575 100755\n--- a/t/t2406-worktree-repair.sh\n+++ b/t/t2406-worktree-repair.sh\n@@ -84,7 +84,7 @@ test_expect_success 'repair .git file from bare.git' '\n \tgit -C bare.git worktree add --detach ../corrupt &&\n \tgit -C corrupt rev-parse --absolute-git-dir >expect &&\n \trm -f corrupt/.git &&\n-\tgit -C bare.git worktree repair &&\n+\tgit -C bare.git --git-dir=. worktree repair &&\n \tgit -C corrupt rev-parse --absolute-git-dir >actual &&\n \ttest_cmp expect actual\n '\n-- \ngitgitgadget\n\n"},{"id":"540921","messageId":"9001883e152407464c83227f1e09664d0d8826b5.1775332197.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.v2.git.1775332197.gitgitgadget@gmail.com","subject":"[PATCH v2 09/17] t5503: avoid discovering a bare repository","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-04T19:49:49Z","receivedAt":"2026-04-04T19:50:10Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nThe test case \"fetch specific OID with tag following\" creates a bare\nrepository and wants to operate on it by changing the working directory\nand relying on Git's implicit discovery of the bare repository.\n\nOnce the `safe.bareRepository` default is changed, this is no longer\nan option.\n\nSo let's adjust the commands to specify the bare repository explicitly,\nvia `--git-dir`, and avoid changing the working directory. As a bonus,\nthe result is arguably more readable than the original code.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t5503-tagfollow.sh | 13 +++++--------\n 1 file changed, 5 insertions(+), 8 deletions(-)\n\ndiff --git a/t/t5503-tagfollow.sh b/t/t5503-tagfollow.sh\nindex febe441041..6d178d84dd 100755\n--- a/t/t5503-tagfollow.sh\n+++ b/t/t5503-tagfollow.sh\n@@ -168,16 +168,13 @@ test_expect_success 'new clone fetch main and tags' '\n \n test_expect_success 'fetch specific OID with tag following' '\n \tgit init --bare clone3.git &&\n-\t(\n-\t\tcd clone3.git &&\n-\t\tgit remote add origin .. &&\n-\t\tgit fetch origin $B:refs/heads/main &&\n+\tgit --git-dir=clone3.git remote add origin \"$PWD\" &&\n+\tgit --git-dir=clone3.git fetch origin $B:refs/heads/main &&\n \n-\t\tgit -C .. for-each-ref >expect &&\n-\t\tgit for-each-ref >actual &&\n+\tgit for-each-ref >expect &&\n+\tgit --git-dir=clone3.git for-each-ref >actual &&\n \n-\t\ttest_cmp expect actual\n-\t)\n+\ttest_cmp expect actual\n '\n \n test_done\n-- \ngitgitgadget\n\n"},{"id":"540922","messageId":"6932658411309228d2d670d9b6c2e4be4f17f985.1775332197.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.v2.git.1775332197.gitgitgadget@gmail.com","subject":"[PATCH v2 10/17] t5505: export `GIT_DIR` after `git init --bare`","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-04T19:49:50Z","receivedAt":"2026-04-04T19:50:12Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nTo prepare for `safe.bareRepository` defaulting to `explicit` (see\n8d1a7448206e), export `GIT_DIR=.` right after `git init --bare &&` so\nsubsequent commands access the bare repo explicitly.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t5505-remote.sh | 4 ++--\n 1 file changed, 2 insertions(+), 2 deletions(-)\n\ndiff --git a/t/t5505-remote.sh b/t/t5505-remote.sh\nindex e592c0bcde..6d3d8510ca 100755\n--- a/t/t5505-remote.sh\n+++ b/t/t5505-remote.sh\n@@ -561,7 +561,7 @@ test_expect_success 'add --mirror && prune' '\n \tmkdir mirror &&\n \t(\n \t\tcd mirror &&\n-\t\tgit init --bare &&\n+\t\tgit init --bare && GIT_DIR=. && export GIT_DIR &&\n \t\tgit remote add --mirror -f origin ../one\n \t) &&\n \t(\n@@ -583,7 +583,7 @@ test_expect_success 'add --mirror setting HEAD' '\n \tmkdir headmirror &&\n \t(\n \t\tcd headmirror &&\n-\t\tgit init --bare -b notmain &&\n+\t\tgit init --bare -b notmain && GIT_DIR=. && export GIT_DIR &&\n \t\tgit remote add --mirror -f origin ../one &&\n \t\ttest \"$(git symbolic-ref HEAD)\" = \"refs/heads/main\"\n \t)\n-- \ngitgitgadget\n\n"},{"id":"540923","messageId":"2f1e745b551e5cd492389bb20d1252042cde3141.1775332197.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.v2.git.1775332197.gitgitgadget@gmail.com","subject":"[PATCH v2 11/17] t5509: specify bare repository path explicitly","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-04T19:49:51Z","receivedAt":"2026-04-04T19:50:13Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nWhen `ls-remote` is told to switch the current working directory to the\nbare repository `pushee` via `-C pushee`, as part of the\n`safe.bareRepository` preparation let's append `--git-dir=.` to spell\nout that this is a bare repository that does not need to be discovered\nimplictly.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t5509-fetch-push-namespaces.sh | 6 +++---\n 1 file changed, 3 insertions(+), 3 deletions(-)\n\ndiff --git a/t/t5509-fetch-push-namespaces.sh b/t/t5509-fetch-push-namespaces.sh\nindex 095df1a753..5167c16c1f 100755\n--- a/t/t5509-fetch-push-namespaces.sh\n+++ b/t/t5509-fetch-push-namespaces.sh\n@@ -88,7 +88,7 @@ test_expect_success 'mirroring a repository using a ref namespace' '\n \n test_expect_success 'hide namespaced refs with transfer.hideRefs' '\n \tGIT_NAMESPACE=namespace \\\n-\t\tgit -C pushee -c transfer.hideRefs=refs/tags \\\n+\t\tgit -C pushee --git-dir=. -c transfer.hideRefs=refs/tags \\\n \t\tls-remote \"ext::git %s .\" >actual &&\n \tprintf \"$commit1\\trefs/heads/main\\n\" >expected &&\n \ttest_cmp expected actual\n@@ -97,7 +97,7 @@ test_expect_success 'hide namespaced refs with transfer.hideRefs' '\n test_expect_success 'check that transfer.hideRefs does not match unstripped refs' '\n \tgit -C pushee pack-refs --all &&\n \tGIT_NAMESPACE=namespace \\\n-\t\tgit -C pushee -c transfer.hideRefs=refs/namespaces/namespace/refs/tags \\\n+\t\tgit -C pushee --git-dir=. -c transfer.hideRefs=refs/namespaces/namespace/refs/tags \\\n \t\tls-remote \"ext::git %s .\" >actual &&\n \tprintf \"$commit1\\trefs/heads/main\\n\" >expected &&\n \tprintf \"$commit0\\trefs/tags/0\\n\" >>expected &&\n@@ -107,7 +107,7 @@ test_expect_success 'check that transfer.hideRefs does not match unstripped refs\n \n test_expect_success 'hide full refs with transfer.hideRefs' '\n \tGIT_NAMESPACE=namespace \\\n-\t\tgit -C pushee -c transfer.hideRefs=\"^refs/namespaces/namespace/refs/tags\" \\\n+\t\tgit -C pushee --git-dir=. -c transfer.hideRefs=\"^refs/namespaces/namespace/refs/tags\" \\\n \t\tls-remote \"ext::git %s .\" >actual &&\n \tprintf \"$commit1\\trefs/heads/main\\n\" >expected &&\n \ttest_cmp expected actual\n-- \ngitgitgadget\n\n"},{"id":"540924","messageId":"c8789bd5423cec3a52dea88b78a7ca541ab9db06.1775332197.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.v2.git.1775332197.gitgitgadget@gmail.com","subject":"[PATCH v2 12/17] t5540/t5541: avoid accessing a bare repository via `-C <dir>`","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-04T19:49:52Z","receivedAt":"2026-04-04T19:50:14Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nIn the `test_http_push_nonff` function both of these test scripts\ncall, there were two Git invocations that assume that bare repositories\nwill always be discovered when the current working directory is inside\none. This is unlikely to be true forever because at some stage, the\n`safe.bareRepository` config is prone to be modified to be safe by\ndefault.\n\nSo let's be safe and specify the bare repository explicitly.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/lib-httpd.sh | 12 +++++-------\n 1 file changed, 5 insertions(+), 7 deletions(-)\n\ndiff --git a/t/lib-httpd.sh b/t/lib-httpd.sh\nindex 4c76e813e3..f15158b2c5 100644\n--- a/t/lib-httpd.sh\n+++ b/t/lib-httpd.sh\n@@ -259,7 +259,7 @@ test_http_push_nonff () {\n \n \ttest_expect_success 'non-fast-forward push fails' '\n \t\tcd \"$REMOTE_REPO\" &&\n-\t\tHEAD=$(git rev-parse --verify HEAD) &&\n+\t\tHEAD=$(git --git-dir=. rev-parse --verify HEAD) &&\n \n \t\tcd \"$LOCAL_REPO\" &&\n \t\tgit checkout $BRANCH &&\n@@ -270,7 +270,7 @@ test_http_push_nonff () {\n \t\t(\n \t\t\tcd \"$REMOTE_REPO\" &&\n \t\t\techo \"$HEAD\" >expect &&\n-\t\t\tgit rev-parse --verify HEAD >actual &&\n+\t\t\tgit --git-dir=. rev-parse --verify HEAD >actual &&\n \t\t\ttest_cmp expect actual\n \t\t)\n \t'\n@@ -284,18 +284,16 @@ test_http_push_nonff () {\n \t'\n \n \ttest_expect_${EXPECT_CAS_RESULT} 'force with lease aka cas' '\n-\t\tHEAD=$(\tcd \"$REMOTE_REPO\" && git rev-parse --verify HEAD ) &&\n+\t\tHEAD=$(git --git-dir=\"$REMOTE_REPO\" rev-parse --verify HEAD) &&\n \t\ttest_when_finished '\\''\n-\t\t\t(cd \"$REMOTE_REPO\" && git update-ref HEAD \"$HEAD\")\n+\t\t\tgit --git-dir=\"$REMOTE_REPO\" update-ref HEAD \"$HEAD\"\n \t\t'\\'' &&\n \t\t(\n \t\t\tcd \"$LOCAL_REPO\" &&\n \t\t\tgit push -v --force-with-lease=$BRANCH:$HEAD origin\n \t\t) &&\n \t\tgit rev-parse --verify \"$BRANCH\" >expect &&\n-\t\t(\n-\t\t\tcd \"$REMOTE_REPO\" && git rev-parse --verify HEAD\n-\t\t) >actual &&\n+\t\tgit --git-dir=\"$REMOTE_REPO\" rev-parse --verify HEAD >actual &&\n \t\ttest_cmp expect actual\n \t'\n }\n-- \ngitgitgadget\n\n"},{"id":"540925","messageId":"f09a96e55ddcc95229efe37d2ec495ee40b4110e.1775332197.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.v2.git.1775332197.gitgitgadget@gmail.com","subject":"[PATCH v2 13/17] t5619: wrap `test_commit_bulk` in `GIT_DIR` subshell for bare repo","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-04T19:49:53Z","receivedAt":"2026-04-04T19:50:15Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nTo prepare for `safe.bareRepository` defaulting to `explicit` (see\n8d1a7448206e), wrap the `test_commit_bulk` call in `(GIT_DIR=\"$REPO\" &&\nexport GIT_DIR && test_commit_bulk ...)` because `test_commit_bulk -C`\nrelies on implicit discovery which would fail once the default changes.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t5619-clone-local-ambiguous-transport.sh | 2 +-\n 1 file changed, 1 insertion(+), 1 deletion(-)\n\ndiff --git a/t/t5619-clone-local-ambiguous-transport.sh b/t/t5619-clone-local-ambiguous-transport.sh\nindex cce62bf78d..3e9aac9015 100755\n--- a/t/t5619-clone-local-ambiguous-transport.sh\n+++ b/t/t5619-clone-local-ambiguous-transport.sh\n@@ -21,7 +21,7 @@ test_expect_success 'setup' '\n \techo \"secret\" >sensitive/secret &&\n \n \tgit init --bare \"$REPO\" &&\n-\ttest_commit_bulk -C \"$REPO\" --ref=main 1 &&\n+\t(GIT_DIR=\"$REPO\" && export GIT_DIR && test_commit_bulk --ref=main 1) &&\n \n \tgit -C \"$REPO\" update-ref HEAD main &&\n \tgit -C \"$REPO\" update-server-info &&\n-- \ngitgitgadget\n\n"},{"id":"540926","messageId":"01ec77c9080dab28afd3f013397abcf498db8798.1775332197.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.v2.git.1775332197.gitgitgadget@gmail.com","subject":"[PATCH v2 14/17] t6020: use `-C` for worktree, `--git-dir` for bare repository","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-04T19:49:54Z","receivedAt":"2026-04-04T19:50:16Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nTo prepare for `safe.bareRepository` defaulting to `explicit`\n(see 8d1a7448206e), adjust a loop that iterated over both a\nbare (`cloned`) and a non-bare (`unbundled`) repository using\nthe same `-C` flag: the bare repo needs `--git-dir` to avoid\nimplicit discovery, while the non-bare one keeps `-C`.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t6020-bundle-misc.sh | 4 ++--\n 1 file changed, 2 insertions(+), 2 deletions(-)\n\ndiff --git a/t/t6020-bundle-misc.sh b/t/t6020-bundle-misc.sh\nindex 500c81b8a1..82df105b47 100755\n--- a/t/t6020-bundle-misc.sh\n+++ b/t/t6020-bundle-misc.sh\n@@ -594,9 +594,9 @@ do\n \t\treflist=$(git for-each-ref --format=\"%(objectname)\") &&\n \t\tgit rev-list --objects --filter=$filter --missing=allow-any \\\n \t\t\t$reflist >expect &&\n-\t\tfor repo in cloned unbundled\n+\t\tfor opt in \"--git-dir cloned\" \"-C unbundled\"\n \t\tdo\n-\t\t\tgit -C $repo rev-list --objects --missing=allow-any \\\n+\t\t\tgit $opt rev-list --objects --missing=allow-any \\\n \t\t\t\t$reflist >actual &&\n \t\t\ttest_cmp expect actual || return 1\n \t\tdone\n-- \ngitgitgadget\n\n"},{"id":"540927","messageId":"00eaefbf621b96bd400577c4ab8e3ea96cc397f8.1775332197.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.v2.git.1775332197.gitgitgadget@gmail.com","subject":"[PATCH v2 15/17] t9210: pass `safe.bareRepository=all` to `scalar register`","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-04T19:49:55Z","receivedAt":"2026-04-04T19:50:17Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nThis test expects `scalar register` to discover a bare repo and\nreject it. Since `scalar` does not support `--git-dir` (that option\nwould not make sense in the context of that command), pass `-c\nsafe.bareRepository=all` to opt into implicit discovery of bare\nrepositories, so the test keeps working once the default changes to\n`explicit`.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t9210-scalar.sh | 2 +-\n 1 file changed, 1 insertion(+), 1 deletion(-)\n\ndiff --git a/t/t9210-scalar.sh b/t/t9210-scalar.sh\nindex 009437a5f3..54513c220b 100755\n--- a/t/t9210-scalar.sh\n+++ b/t/t9210-scalar.sh\n@@ -88,7 +88,7 @@ test_expect_success 'scalar enlistments need a worktree' '\n \ttest_when_finished rm -rf bare test &&\n \n \tgit init --bare bare/src &&\n-\t! scalar register bare/src 2>err &&\n+\t! scalar -c safe.bareRepository=all register bare/src 2>err &&\n \tgrep \"Scalar enlistments require a worktree\" err &&\n \n \tgit init test/src &&\n-- \ngitgitgadget\n\n"},{"id":"540928","messageId":"890dfd024dcecf9b006c7ffd3ef9c42b17743640.1775332197.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.v2.git.1775332197.gitgitgadget@gmail.com","subject":"[PATCH v2 16/17] t9700: stop relying on implicit bare repo discovery","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-04T19:49:56Z","receivedAt":"2026-04-04T19:50:18Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nCurrently, the \"alternate bare repo\" test case relies on Git\ndiscovering non-bare and bare repositories alike. However, the automatic\ndiscovery of bare repository represents a weakness that leaves Git\nusers vulnerable. To that end, the `safe.bareRepository` config was\nintroduced, but out of backwards-compatibility concerns, the default is\nnot yet secure.\n\nTo prepare for that default to switch to the secure one, where bare\nrepositories are never discovered automatically but instead must be\nspecified explicitly, let's do exactly that in this test case: specify\nit explicitly, via setting the environment variable `GIT_DIR`.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n t/t9700/test.pl | 9 ++++++---\n 1 file changed, 6 insertions(+), 3 deletions(-)\n\ndiff --git a/t/t9700/test.pl b/t/t9700/test.pl\nindex f83e6169e2..99b712b626 100755\n--- a/t/t9700/test.pl\n+++ b/t/t9700/test.pl\n@@ -153,9 +153,12 @@ unlink $tmpfile3;\n chdir($abs_repo_dir);\n \n # open alternate bare repo\n-my $r4 = Git->repository(Directory => \"$abs_repo_dir/bare.git\");\n-is($r4->command_oneline(qw(log --format=%s)), \"bare commit\",\n-\t\"log of bare repo works\");\n+{\n+\tlocal $ENV{GIT_DIR} = \"$abs_repo_dir/bare.git\";\n+\tmy $r4 = Git->repository(Directory => \"$abs_repo_dir/bare.git\");\n+\tis($r4->command_oneline(qw(log --format=%s)), \"bare commit\",\n+\t\t\"log of bare repo works\");\n+}\n \n # unquoting paths\n is(Git::unquote_path('abc'), 'abc', 'unquote unquoted path');\n-- \ngitgitgadget\n\n"},{"id":"540929","messageId":"139b9da946e7adb1e4331bb5005e6481b2c2de20.1775332197.git.gitgitgadget@gmail.com","threadId":"65414","inReplyTo":"pull.2076.v2.git.1775332197.gitgitgadget@gmail.com","subject":"[PATCH v2 17/17] git p4 clone --bare: need to be explicit about the gitdir","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-04T19:49:57Z","receivedAt":"2026-04-04T19:50:19Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nWhen `safe.bareRepository` will change to be safe by default, bare\nrepositories won't be discovered by default anymore. To prepare for\nthis, `git p4` must be explicit about the gitdir when cloning into a\nbare repository, and no longer rely on that implicit discovery.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n git-p4.py | 1 +\n 1 file changed, 1 insertion(+)\n\ndiff --git a/git-p4.py b/git-p4.py\nindex c0ca7becaf..dd38dbca22 100755\n--- a/git-p4.py\n+++ b/git-p4.py\n@@ -4360,6 +4360,7 @@ class P4Clone(P4Sync):\n         init_cmd = [\"git\", \"init\"]\n         if self.cloneBare:\n             init_cmd.append(\"--bare\")\n+            os.environ[\"GIT_DIR\"] = os.getcwd()\n         retcode = subprocess.call(init_cmd)\n         if retcode:\n             raise subprocess.CalledProcessError(retcode, init_cmd)\n-- \ngitgitgadget\n"},{"id":"540977","messageId":"xmqq1pgsdrdw.fsf@gitster.g","threadId":"65414","inReplyTo":"dcb8c6f1-1410-9f04-c389-6f69ac4fe842@gmx.de","subject":"Re: [PATCH 00/17] tests: access bare repositories explicitly","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2026-04-06T15:45:31Z","receivedAt":"2026-04-06T15:45:34Z","isPatch":true,"body":"Johannes Schindelin <Johannes.Schindelin@gmx.de> writes:\n\n>> Shoudln't there be a patch [01/18] before everything else that\n>> updates Documentation/BreakingChanges.adoc to propose the default\n>> change?\n>\n> Well, yes and no. There should be an update to BreakingChanges to propose\n> that default change, but obviously it should not only be a documentation\n> change: It should also adjust `Documentation/config/safe.adoc` to mention\n> the intended change of behavior, and it should introduce\n> `WITH_BREAKING_HANGES`-specific conditional code in `setup.c`.\n\nAh, very true.\n\nAnd of course we'd need some tests conditional to breaking-changes\nprerequisite in the meantime, to make sure that the default is to\nallow \"all\" before breaking changes, and with the prereq the test\nchecks the new behaviour is to deny by default.\n\nAs to the changes to existing tests (i.e., this patch series started\ndoing), they have a bit of balancing act.\n\n * Most importantly, they need to make sure their indivial\n   operations, when working on a bare repository is allowed in any\n   unspecified means, continue to behave sensibly.  \"git log -p\" in\n   a bare repository should still produce patches, \"git bisect\" in a\n   bare repository should work and assume --no-checkout, etc.\n\n * Then all of them would need to be somehow told that working on a\n   bare repository is allowed in suitable way.  For most of then it\n   should be done by setting safe.bareRepository in the global\n   scope, just like many tests specify the default branch name\n   upfront just once (this is a tangent, but we should find a way to\n   get rid of GIT_TEST_DEFAULT_INITIAL_BRANCH_NAME variable support\n   in our binary and instead set it up in the test environment's\n   ~/.gitconfig), some may add --git-dir=., etc.  But the primary\n   focus with this change is to preserve what individual operation\n   each test wants to validate (see above).\n\n * There may need to be some tests behind the WITH_BREAKING_CHANGES\n   prerequisite that makes sure that the access to the repository is\n   blocked without the configuration loosening the condition, but\n   they hopefully would be minimum---unlike \"how this particular\n   command should operate in a bare repository?\" that vary per\n   command, \"no command should work in a bare repository unless ...\"\n   that is enforced in the setup phase do not have to validate each\n   and every command.\n\n> And, crucially, it should pass the test suite under WITH_BREAKING_CHANGES.\n>\n> To do that, a lot more needs to happen than just the 17 patches in this\n> here patch series. Most of the additional changes are quite mechanical,\n> and can be validated relatively easily despite their sheer number. And\n> only at the very end of those changes can that `safe.bareRepository`\n> change even be proposed.\n\nI agree with all the flow you propose here.  And for that process, I\nthink the early parts of the effort (i.e., there ~20 patches) that\nprepare existing tests that make sure the operations of individual\ncommands in bare repositories should be kept to bare minimum by\nfreezing the world to allow bare repositories, just like initial\nbranch names are frozen to either 'master' or 'main' in many test\nscripts.  Adding \"--git-dir=.\" (regardless of the \"-C there\") you\nproposed in the other thread is a valid way (but it may be tedious\nto do and verify); doing \"git config --global safe.bareRepository\nall\" upfront, if it works, might be simpler.  Any approach that\nwould achieve what we want is fine.\n\n> I plan on proposing that patch in due time, to start the discussion\n> whether or not it is a good idea to change the default of\n> `safe.bareRepository` in Git 3.0.\n\nYup, I do not think it is a bad thing in the longer term, even\nthough I suspect it might be a bit more disruptive than others\nwe have in the breaking changes document.\n\n\nThanks for working on this.\n\n"},{"id":"540978","messageId":"xmqqse98cc51.fsf@gitster.g","threadId":"65414","inReplyTo":"a1cdbd58f0af27be689230b7d8009d93bc34abca.1775332197.git.gitgitgadget@gmail.com","subject":"Re: [PATCH v2 01/17] t0001: allow implicit bare repo discovery for aliased-command test","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2026-04-06T16:00:10Z","receivedAt":"2026-04-06T16:00:12Z","isPatch":true,"body":"\"Johannes Schindelin via GitGitGadget\" <gitgitgadget@gmail.com>\nwrites:\n\n> From: Johannes Schindelin <johannes.schindelin@gmx.de>\n>\n> 8d1a7448206e (setup.c: create `safe.bareRepository`, 2022-07-14)\n> introduced a setting to restrict implicit bare repository discovery,\n> mitigating a social-engineering attack where an embedded bare repo's\n> hooks get executed unknowingly. To allow for that default to change at\n> some stage in the future, the tests need to be prepared.\n>\n> This commit adjusts a test accordingly that runs `git aliasedinit`\n> from inside a bare repo to verify that aliased commands work there.\n> The test is about alias resolution, not bare repo discovery, so add\n> `test_config_global safe.bareRepository all` to opt in explicitly.\n\nYes, I think most of the tests we run things in a bare repository is\nnot about bare repository discovery but how individual commands\nbehave in a bare repository, and these commands must be kept working\neven after a future version of Git starts to tighten the rules.\n\n> Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n> ---\n>  t/t0001-init.sh | 1 +\n>  1 file changed, 1 insertion(+)\n>\n> diff --git a/t/t0001-init.sh b/t/t0001-init.sh\n> index e4d32bb4d2..6bd0a15dac 100755\n> --- a/t/t0001-init.sh\n> +++ b/t/t0001-init.sh\n> @@ -77,6 +77,7 @@ test_expect_success 'plain nested through aliased command' '\n>  '\n>  \n>  test_expect_success 'plain nested in bare through aliased command' '\n> +\ttest_config_global safe.bareRepository all &&\n>  \t(\n>  \t\tgit init --bare bare-ancestor-aliased.git &&\n>  \t\tcd bare-ancestor-aliased.git &&\n\nSo I very much recommend the use of \"safe.bareRepository all\" in\nthese tests, not in individual test but upfront, just like many\ntests freeze use of 'main' as the default initial branch name.\n\nI also have to wonder if this alternative patch shouldn't be a\nbetter starting point?  The idea is that most of the tests that\nvalidates how individual operations work in a bare repository are\n*not* interested in the fact that bare repository access will become\nopt-in in future version of Git, but they are interested in ensuring\nthat the commands they are testing will keep working as expected\nwhen accesses to bare repositories are allowed.  So we'll run all\nexisting tests with this in the global config after we set up $HOME\nfor testing.  We'll need to write a very few *new* tests to prepare\nfor the default change, and I expect them to explicitly remove the\nsetting from the global config, and checks if the default truly\nallows or forbids access to a bare repositories.  But I am hoping\nthat most of the existing tests shouldn't need changes sprinkled all\nover.\n\nThanks.\n\n t/test-lib.sh | 5 +++++\n 1 file changed, 5 insertions(+)\n\ndiff --git c/t/test-lib.sh w/t/test-lib.sh\nindex 70fd3e9baf..fe85a0bf89 100644\n--- c/t/test-lib.sh\n+++ w/t/test-lib.sh\n@@ -1563,6 +1563,11 @@ HOME=\"$TRASH_DIRECTORY\"\n GNUPGHOME=\"$HOME/gnupg-home-not-used\"\n export HOME GNUPGHOME USER_HOME\n \n+if test -n \"$WITH_BREAKING_CHANGES\"\n+then\n+\tgit config --global safe.bareRepository all\n+fi\n+\n # \"rm -rf\" existing trash directory, even if a previous run left it\n # with bad permissions.\n remove_trash_directory () {\n"}]}