git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Submodules can't work recursively because Git implements policy?

From
KLKlas Lindberg <klas.lindberg@gmail.com>
Date
Apr 6, 2009, 13:42 UTC
Message-ID
<33f4f4d70904060642m25b2cff8nafed433eeabfb6c4@mail.gmail.com>
On Mon, Apr 6, 2009 at 3:16 PM, Finn Arne Gangstad <finnag@pvv.org> wrote:
Show 7 quoted lines
> git submodule update just does "git fetch" and hopes that the required
> commit appears. In practice this means that you (may) need to invent a
> tag or a branch for all the submodules, otherwise they are not
> fetchable.
>
> This bit us pretty hard when we tried to use submodules earlier, so we
> gave up. Maybe some day...

It "hopes" to find them? This is actually my other reason for bringing the whole SHA key fetching thing up. From what I can see, it is not possible to implement submodules sensibly without support for fetching SHA keys. I.e. I want fetch, checkout and every other command to recurse as needed in the presence of submodules. This limitation forces me to implement a whole CM tool where none should be necessary.

It appears to me that the security concern (being able to hide commits by making them unreachable from a named reference) is actually a policy decision and not a technical one. On what grounds does Git decide for me how to handle security concerns? It just seems more important to be able to have recursive submodule behaviour than to provide band aid for careless users.

Out of curiosity: Is it really possible to change the value of an already pushed tag? Can you only do the hiding trick with branches?

BR / Klas
Next: Finn Arne Gangstad
Message 1 of 5 in “Submodules can't work recursively because Git implements policy?”
  1. Klas LindbergApr 6, 2009
  2. Finn Arne GangstadApr 6, 2009
  3. Klas LindbergApr 6, 2009
  4. Shawn O. PearceApr 6, 2009
  5. Klas LindbergApr 6, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.