git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v3] setup: fail if .git is not a file or directory

From
Tian Yuchen <a3205153416@gmail.com>
Date
Feb 14, 2026, 04:52 UTC
Message-ID
<20260214045247.118013-1-a3205153416@gmail.com>
In-Reply-To
<20260212172405.48614-1-a3205153416@gmail.com>

Currently, `setup_git_directory_gently_1()` checks if `.git` is a regular file (handling submodules/worktrees) or a directory. If it is neither (e.g., a FIFO), the code hits a NEEDSWORK comment and simply ignores the entity, continuing the discovery process in the parent directory.

Failing instead of ignoring here makes it easier for the users to notice anomalies and take action, particularly if this non-file non-directory entity was created by mistake or by file system corruption.

However, strictly enforcing 'lstat()' and 'S_ISREG()' breaks valid workflows where '.git' is a symlink pointing to a real git directory (e.g. created via 'ln -s'). To ensure safety and correctness:

1. Differentiate between "missing file" and "is a directory". This
   removes the long standing NEEDSWORK comment in 'read_gitfile_gently()'.
2. Explicitly check 'st_mode' after 'stat()'. If the path resolves to a
   directory, return 'READ_GITFILE_ERR_IS_A_DIR' so the caller can try
   to handle it as a directory.
3. If the path exists but is neither a regular file nor a directory,
   return 'READ_GITFILE_ERR_NOT_A_FILE'.

Update 'setup_git_directory_gently_1()' to aborts setup immeditaely upon encountering a malicous '.git' file.

Signed-off-by: Tian Yuchen <a3205153416@gmail.com>
---
I have verified this with a test script covering:
1. Normal .git file
2. .git as a symlink to a directory
3. .git as a FIFO
4. .git as a symlink to a FIFO
5. .git with garbage content
 setup.c | 39 +++++++++++++++++++++++++++++----------
 setup.h |  3 +++
 2 files changed, 32 insertions(+), 10 deletions(-)
diff --git a/setup.c b/setup.c
index 3a6a048620..8681a8a9d1 100644
--- a/setup.c
+++ b/setup.c
@@ -911,6 +911,10 @@ void read_gitfile_error_die(int error_code, const char *path, const char *dir)
 		die(_("no path in gitfile: %s"), path);
 	case READ_GITFILE_ERR_NOT_A_REPO:
 		die(_("not a git repository: %s"), dir);
+	case READ_GITFILE_ERR_STAT_ENOENT:
+		die(_("Not a git repository: %s"), path);
+	case READ_GITFILE_ERR_IS_A_DIR:
+		die(_("Not a git file (is a directory): %s"), path);
 	default:
 		BUG("unknown error code");
 	}
@@ -939,8 +943,14 @@ const char *read_gitfile_gently(const char *path, int *return_error_code)
 	static struct strbuf realpath = STRBUF_INIT;
 
 	if (stat(path, &st)) {
-		/* NEEDSWORK: discern between ENOENT vs other errors */
-		error_code = READ_GITFILE_ERR_STAT_FAILED;
+		if (errno == ENOENT)
+			error_code = READ_GITFILE_ERR_STAT_ENOENT;
+		else
+			error_code = READ_GITFILE_ERR_STAT_FAILED;
+		goto cleanup_return;
+	}
+	if (S_ISDIR(st.st_mode)) {
+		error_code = READ_GITFILE_ERR_IS_A_DIR;
 		goto cleanup_return;
 	}
 	if (!S_ISREG(st.st_mode)) {
@@ -994,7 +1004,9 @@ const char *read_gitfile_gently(const char *path, int *return_error_code)
 cleanup_return:
 	if (return_error_code)
 		*return_error_code = error_code;
-	else if (error_code)
+	else if (error_code &&
+		error_code != READ_GITFILE_ERR_STAT_ENOENT &&
+		error_code != READ_GITFILE_ERR_IS_A_DIR)
 		read_gitfile_error_die(error_code, path, dir);
 
 	free(buf);
@@ -1576,18 +1588,25 @@ static enum discovery_result setup_git_directory_gently_1(struct strbuf *dir,
 		if (offset > min_offset)
 			strbuf_addch(dir, '/');
 		strbuf_addstr(dir, DEFAULT_GIT_DIR_ENVIRONMENT);
-		gitdirenv = read_gitfile_gently(dir->buf, die_on_error ?
-						NULL : &error_code);
+		gitdirenv = read_gitfile_gently(dir->buf, &error_code);
 		if (!gitdirenv) {
-			if (die_on_error ||
-			    error_code == READ_GITFILE_ERR_NOT_A_FILE) {
-				/* NEEDSWORK: fail if .git is not file nor dir */
+			if (error_code == READ_GITFILE_ERR_STAT_ENOENT ||
+				error_code == READ_GITFILE_ERR_IS_A_DIR) {
 				if (is_git_directory(dir->buf)) {
 					gitdirenv = DEFAULT_GIT_DIR_ENVIRONMENT;
 					gitdir_path = xstrdup(dir->buf);
 				}
-			} else if (error_code != READ_GITFILE_ERR_STAT_FAILED)
-				return GIT_DIR_INVALID_GITFILE;
+			} else if (error_code == READ_GITFILE_ERR_NOT_A_FILE) {
+				if (die_on_error)
+					die(_("Invalid %s: not a regular file or directory"), dir->buf);
+				else
+					return GIT_DIR_INVALID_GITFILE;
+			} else if (error_code != READ_GITFILE_ERR_STAT_FAILED) {
+				if (die_on_error)
+					read_gitfile_error_die(error_code, dir->buf, NULL);
+				else
+					return GIT_DIR_INVALID_GITFILE;
+			}
 		} else
 			gitfile = xstrdup(dir->buf);
 		/*
diff --git a/setup.h b/setup.h
index d55dcc6608..0271cc8f93 100644
--- a/setup.h
+++ b/setup.h
@@ -36,6 +36,9 @@ int is_nonbare_repository_dir(struct strbuf *path);
 #define READ_GITFILE_ERR_NO_PATH 6
 #define READ_GITFILE_ERR_NOT_A_REPO 7
 #define READ_GITFILE_ERR_TOO_LARGE 8
+#define READ_GITFILE_ERR_STAT_ENOENT 9
+#define READ_GITFILE_ERR_IS_A_DIR 10
+
 void read_gitfile_error_die(int error_code, const char *path, const char *dir);
 const char *read_gitfile_gently(const char *path, int *return_error_code);
 #define read_gitfile(path) read_gitfile_gently((path), NULL)
-- 
2.43.0
Previous: Tian YuchenNext: Junio C Hamano
Message 7 of 35 in “[RFC] setup: fail if .git is not a file or directory”
  1. Tian YuchenFeb 11, 2026
  2. Junio C HamanoFeb 11, 2026
  3. Tian YuchenFeb 12, 2026
  4. setup: fail if .git is not a file or directoryTian Yuchen, Feb 12, 2026
  5. Junio C HamanoFeb 12, 2026
  6. Tian YuchenFeb 13, 2026
  7. setup: fail if .git is not a file or directoryTian Yuchen, Feb 14, 2026
  8. Junio C HamanoFeb 15, 2026
  9. Tian YuchenFeb 15, 2026
  10. Junio C HamanoFeb 16, 2026
  11. Tian YuchenFeb 16, 2026
  12. setup: allow cwd/.git to be a symlink to a directoryTian Yuchen, Feb 17, 2026
  13. Karthik NayakFeb 17, 2026
  14. Tian YuchenFeb 17, 2026
  15. Karthik NayakFeb 17, 2026
  16. Junio C HamanoFeb 17, 2026
  17. Junio C HamanoFeb 17, 2026
  18. Karthik NayakFeb 17, 2026
  19. Tian YuchenFeb 18, 2026
  20. Karthik NayakFeb 17, 2026
  21. 0/2 setup.c: v5 rerollTian Yuchen, Feb 18, 2026
  22. 1/2 setup: distingush ENOENT from other stat errorsTian Yuchen, Feb 18, 2026
  23. Karthik NayakFeb 18, 2026
  24. Tian YuchenFeb 18, 2026
  25. Junio C HamanoFeb 18, 2026
  26. Junio C HamanoFeb 18, 2026
  27. 2/2 setup: allow cwd/.git to be a symlink to a directoryTian Yuchen, Feb 18, 2026
  28. Karthik NayakFeb 18, 2026
  29. Tian YuchenFeb 18, 2026
  30. Junio C HamanoFeb 18, 2026
  31. Tian YuchenFeb 19, 2026
  32. Tian YuchenFeb 15, 2026
  33. brian m. carlsonFeb 12, 2026
  34. Junio C HamanoFeb 12, 2026
  35. brian m. carlsonFeb 12, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.