git/list[1] front-page[2] threads[3] people[4] search[5] about
 

git submodule: update=!command

From
RLRyan Lortie <desrt@desrt.ca>
Date
Mar 17, 2015, 19:28 UTC
Message-ID
<1426620537.1785877.241673949.72FB3B40@webmail.messagingengine.com>
karaj,
'man git-submodule' contains mention (in one place) that:
    Setting the key submodule.$name.update to !command
    will cause command to be run.

This is not documented in 'man gitmodules' (which documents the other possible values for the 'update' key) nor in 'man git-config' which also mentions the 'update' key (but refers readers to the two other pages).

This feature is scary. The idea that arbitrary code could be executed on my machine when I run innocent-looking git commands, based on the content of the .gitmodules file is enough to give pause to anybody.

Fortunately, it seems that (for now?) this is not really the case. 'git submodule init' will copy the values of the 'update' key from .gitmodules to your local git config, but only if they are one of "none", "checkout", "merge" or "rebase".

So, I guess I'm asking two things.

The first is a question about git's basic policy with respect to things like this. I hope that it's safe to assume that running 'git' commands on repositories downloaded from potentially-hostile places will never result in the authors of those repositories being able to run code on my machine.

If that is true then, the second request would be to spell this out more explicitly in the relevant documentation. I'm happy to write a patch to do that, if it is deemed appropriate.

Thanks in advance.
Cheers
Next: Jeff King
Message 1 of 10 in “git submodule: update=!command”
  1. Ryan LortieMar 17, 2015
  2. Jeff KingMar 17, 2015
  3. Ryan LortieMar 17, 2015
  4. Chris PackhamMar 18, 2015
  5. Junio C HamanoMar 17, 2015
  6. Ryan LortieMar 17, 2015
  7. Junio C HamanoMar 17, 2015
  8. Ryan LortieMar 17, 2015
  9. Chris PackhamMar 18, 2015
  10. Chris PackhamMar 18, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.