[RFC] setup: fail if .git is not a file or directory
- From
Tian Yuchen <a3205153416@gmail.com>
- Date
- Feb 11, 2026, 18:21 UTC
- Message-ID
- <20260211182122.35352-1-a3205153416@gmail.com>
Currently, `setup_git_directory_gently_1()` checks if `.git` is a regular file (handling submodules/worktrees) or a directory. If it is neither (e.g., a FIFO), the code hits a NEEDSWORK comment and simply ignores the entity, continuing the discovery process in the parent directory.
This behavior can be very dangerous. If a user is inside a subdirectory containing a melformed/broken `.git` entity, the Git will traverse up, attach to a parent repository and might execute destructive commands.
I tried to resolve the NEEDSWORK by using `lstat()` to explicitly check the entity's mode. If it is neither a regular file nor a directory, we kill the discovery process.
But I still have questions: 1. Is failing hard the desired behavior here? Should skipping it and continuing discovery be an option for the user, which might seem more fault-tolerant? 2. Should we die() immediately here, or return GIT_DIR_INVALID_GITFILE and let the caller decide?
Signed-off-by: Tian Yuchen <a3205153416@gmail.com> --- setup.c | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-)
diff --git a/setup.c b/setup.c index 3a6a048620..a1b56de67a 100644 --- a/setup.c +++ b/setup.c @@ -1581,7 +1581,17 @@ static enum discovery_result setup_git_directory_gently_1(struct strbuf *dir, if (!gitdirenv) { if (die_on_error || error_code == READ_GITFILE_ERR_NOT_A_FILE) { - /* NEEDSWORK: fail if .git is not file nor dir */ + struct stat st; + if (!lstat(dir->buf, &st) && + !S_ISREG(st.st_mode) && + !S_ISDIR(st.st_mode)){ + + if (die_on_error) + die(_("Invalid %s: not a regular file or directory"), dir->buf); + else + return GIT_DIR_INVALID_GITFILE; + } + if (is_git_directory(dir->buf)) { gitdirenv = DEFAULT_GIT_DIR_ENVIRONMENT; gitdir_path = xstrdup(dir->buf);
-- 2.43.0