git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[RFC] archive: behavior of --prefix with absolute or parent path components

From
Pushkar Singh <pushkarkumarsingh1970@gmail.com>
Date
Apr 7, 2026, 16:21 UTC
Message-ID
<20260407162101.2285-1-pushkarkumarsingh1970@gmail.com>
Hi,

While experimenting with "git archive", I noticed some behavior around the --prefix option that might be worth clarifying.

Currently, --prefix accepts values such as absolute paths or ones with ..,
e.g.:
    git archive --prefix=/ HEAD > out.tar
    git archive --prefix=//// HEAD > out.tar
    git archive --prefix=../../ HEAD > out.tar
Upon listing the archive contents (e.g., tar -tf), you get entries like:
    /a.txt
    ////a.txt
    ../../a.txt
In such cases, tar emits warnings like:
    "Removing leading '/' from member names"
    "Removing leading '../' from member names"

This suggests that Git passes the prefix through as-is, relying on downstream tools to sanitize potentially unsafe paths.

From a user perspective, I was wondering:
  - Is this behavior intentional (i.e., leaving validation to archive
    consumers)?
  - Would it be worth documenting this explicitly?
  - Or should there be any normalization or validation at the Git level?

I understand that Git generally avoids enforcing policy decisions in such cases, but I wanted to confirm whether this behavior is intentional.

I’d appreciate any thoughts on this :-)

Thanks, Pushkar

Next: Jeff King
Message 1 of 6 in “[RFC] archive: behavior of --prefix with absolute or parent path components”
  1. Pushkar SinghApr 7, 2026
  2. Jeff KingApr 7, 2026
  3. Junio C HamanoApr 7, 2026
  4. brian m. carlsonApr 7, 2026
  5. archive: document --prefix handling of absolute and parent pathsPushkar Singh, Apr 8, 2026
  6. Jeff KingApr 8, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.