git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v3 2/5] setup: rename `die_upon_unsafe_repo()` to align with check

From
Michael Lohmann <git@lohmann.sh>
Date
Oct 16, 2025, 05:33 UTC
Message-ID
<20251016053322.44495-3-git@lohmann.sh>
In-Reply-To
<20251016053322.44495-1-git@lohmann.sh>

This function dies if the repo in question is deemed to be unsafe and the ownership is only part of the verification. In addition it already checks for "safe.directory" config, making the name `die_upon_dubious_ownership()` not expressive. When additional options to check if a repository is considered to be safe are added, this name is more indicative of the content.

Helped-by: Junio C Hamano <gitster@pobox.com>
Signed-off-by: Michael Lohmann <git@lohmann.sh>
---
 builtin/clone.c | 2 +-
 path.c          | 4 ++--
 setup.c         | 2 +-
 setup.h         | 2 +-
 4 files changed, 5 insertions(+), 5 deletions(-)
diff --git a/builtin/clone.c b/builtin/clone.c
index c990f398ef..08b04f5cf2 100644
--- a/builtin/clone.c
+++ b/builtin/clone.c
@@ -263,7 +263,7 @@ static void copy_or_link_directory(struct strbuf *src, struct strbuf *dest,
 	 * operation as the hardlinked files can be rewritten at will by the
 	 * potentially-untrusted user. We thus refuse to do so by default.
 	 */
-	die_upon_dubious_ownership(NULL, NULL, src_repo);
+	die_upon_unsafe_repo(NULL, NULL, src_repo);
 
 	mkdir_if_missing(dest->buf, 0777);
 
diff --git a/path.c b/path.c
index 7f56eaf993..c2ea450304 100644
--- a/path.c
+++ b/path.c
@@ -810,7 +810,7 @@ const char *enter_repo(const char *path, unsigned flags)
 			return NULL;
 		gitfile = read_gitfile(used_path.buf);
 		if (!(flags & ENTER_REPO_ANY_OWNER_OK))
-			die_upon_dubious_ownership(gitfile, NULL, used_path.buf);
+			die_upon_unsafe_repo(gitfile, NULL, used_path.buf);
 		if (gitfile) {
 			strbuf_reset(&used_path);
 			strbuf_addstr(&used_path, gitfile);
@@ -822,7 +822,7 @@ const char *enter_repo(const char *path, unsigned flags)
 	else {
 		const char *gitfile = read_gitfile(path);
 		if (!(flags & ENTER_REPO_ANY_OWNER_OK))
-			die_upon_dubious_ownership(gitfile, NULL, path);
+			die_upon_unsafe_repo(gitfile, NULL, path);
 		if (gitfile)
 			path = gitfile;
 		if (chdir(path))
diff --git a/setup.c b/setup.c
index 2c41874774..c6e1204c05 100644
--- a/setup.c
+++ b/setup.c
@@ -1333,7 +1333,7 @@ static int ensure_safe_repository(const char *gitfile,
 	return data.is_safe;
 }
 
-void die_upon_dubious_ownership(const char *gitfile, const char *worktree,
+void die_upon_unsafe_repo(const char *gitfile, const char *worktree,
 				const char *gitdir)
 {
 	struct strbuf report = STRBUF_INIT, quoted = STRBUF_INIT;
diff --git a/setup.h b/setup.h
index 8522fa8575..3f7ef03bf9 100644
--- a/setup.h
+++ b/setup.h
@@ -51,7 +51,7 @@ const char *resolve_gitdir_gently(const char *suspect, int *return_error_code);
  * config settings; for non-bare repositories, their worktree needs to be
  * added, for bare ones their git directory.
  */
-void die_upon_dubious_ownership(const char *gitfile, const char *worktree,
+void die_upon_unsafe_repo(const char *gitfile, const char *worktree,
 				const char *gitdir);
 
 void setup_work_tree(void);
-- 
2.51.1.476.g147428281d
Previous: Michael LohmannNext: Michael Lohmann
Message 19 of 24 in “Allow enforcing safe.directory”
  1. 0/5 Allow enforcing safe.directoryMichael Lohmann, Oct 13, 2025
  2. 1/5 setup: rename `ensure_safe_repository()` for clarityMichael Lohmann, Oct 13, 2025
  3. 2/5 setup: rename `die_upon_assumed_unsafe_repo()` to align with checkMichael Lohmann, Oct 13, 2025
  4. Junio C HamanoOct 14, 2025
  5. 3/5 setup: refactor `ensure_safe_repository()` testing prioritiesMichael Lohmann, Oct 13, 2025
  6. Junio C HamanoOct 14, 2025
  7. 4/5 setup: allow temporary bypass of `ensure_safe_repository()` checksMichael Lohmann, Oct 13, 2025
  8. 5/5 setup: allow not marking self owned repos as safe in `ensure_safe_repository()`Michael Lohmann, Oct 13, 2025
  9. D. Ben KnobleOct 13, 2025
  10. 0/5 Apply comments of D. Ben KnobleMichael Lohmann, Oct 13, 2025
  11. 1/5 setup: rename `ensure_safe_repository()` for clarityMichael Lohmann, Oct 13, 2025
  12. 2/5 setup: rename `die_upon_assumed_unsafe_repo()` to align with checkMichael Lohmann, Oct 13, 2025
  13. 3/5 setup: refactor `ensure_safe_repository()` testing prioritiesMichael Lohmann, Oct 13, 2025
  14. 4/5 setup: allow temporary bypass of `ensure_safe_repository()` checksMichael Lohmann, Oct 13, 2025
  15. 5/5 setup: allow not marking self owned repos as safe in `ensure_safe_repository()`Michael Lohmann, Oct 13, 2025
  16. 0/5 Allow skipping ownership of repo in safety considerationMichael Lohmann, Oct 16, 2025
  17. 3/5 setup: refactor `ensure_safe_repository()` testing prioritiesMichael Lohmann, Oct 16, 2025
  18. 1/5 setup: rename `ensure_safe_repository()` for clarityMichael Lohmann, Oct 16, 2025
  19. 2/5 setup: rename `die_upon_unsafe_repo()` to align with checkMichael Lohmann, Oct 16, 2025
  20. 4/5 setup: allow temporary bypass of `ensure_safe_repository()` checksMichael Lohmann, Oct 16, 2025
  21. Junio C HamanoOct 16, 2025
  22. 5/5 setup: allow not marking self owned repos as safe in `ensure_safe_repository()`Michael Lohmann, Oct 16, 2025
  23. Junio C HamanoOct 16, 2025
  24. Junio C HamanoOct 16, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.