git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [3/4] What's not in 1.5.2 (new topics)

From
Junio C Hamano <junkio@cox.net>
Date
May 19, 2007, 19:56 UTC
Message-ID
<7vejlcwpry.fsf@assigned-by-dhcp.cox.net>
In-Reply-To
<20070519181228.GP4708@mellanox.co.il>
"Michael S. Tsirkin" <mst@dev.mellanox.co.il> writes:
Show 7 quoted lines
>> Fetching from a new URL (not just "different from what is
>> defined in .gitmodules") is a major deal from security point of
>> view (you should not fetch from stranger you do not trust).
>
> I'm sorry, I'm confused. I thought the "URL" in .gitmodules
> is just a unique project key/name? So how come you are now
> speaking about fetching from it?

Sorry for confusing you. The point was by default that we should not blindly follow URL given from upstream -- the statement you quoted is one justification why my strawman uses the URL in .gitmodules as a mere hint and look-up key.

Having said that, I'd ask not to take minor details in the strawman too literally and seriously. I am 100% sure that we would be in a serious trouble if what we end up doing matches literally what my handwaving strawman suggested. The strawman was thrown out to the open primarily so that (smarter and more beautiful) people who thought the issues longer and harder to express their opinions easier by having something to compare their unique ideas against, nothing more.

I am slightly more than 50% sure that we would not want to tie subproject fetch/clone into superproject fetch/clone, and _if_ we would tie it to anything, it would be to the checkout, but that is only my gut feeling. Maybe we end up not tying subproject fetch/clone to anything that happens in the superproject; we may even do it in a completely different way than the strawman said it _might_ work. That's perfectly fine.

The expectation from me sending out that handwaving strawman was to help encouraging others to present their ideas, with justifications. And having something to compare against, even if it is just a handwaving strawman, is often much easier when presenting your ideas and showing which part of your design is important. You can say something like "the strawman fails in this scenario, which is important in real life for such and such reasons, and my design handles it this way" -- and everybody can discuss if it is an important design consideration, and what the best design to solve that problem if it is.

So don't take that strawman, especially the details in it, too seriously, but take it as what it was: a firestarter.

Previous: Michael S. TsirkinNext: Michael S. Tsirkin
Message 45 of 55 in “[0/4] What's not in 1.5.2 (overview)”
  1. Junio C HamanoMay 16, 2007
  2. 1/4 What's not in 1.5.2 (have been cooking in next)Junio C Hamano, May 16, 2007
  3. 2/4 What's not in 1.5.2 (will cook in next)Junio C Hamano, May 16, 2007
  4. 3/4 What's not in 1.5.2 (new topics)Junio C Hamano, May 16, 2007
  5. Andy ParkinsMay 17, 2007
  6. Junio C HamanoMay 17, 2007
  7. Andy ParkinsMay 17, 2007
  8. Alex RiesenMay 17, 2007
  9. Petr BaudisMay 17, 2007
  10. Jeff KingMay 17, 2007
  11. Petr BaudisMay 17, 2007
  12. Jeff KingMay 17, 2007
  13. Petr BaudisMay 17, 2007
  14. Jeff KingMay 17, 2007
  15. Junio C HamanoMay 17, 2007
  16. Jeff KingMay 18, 2007
  17. Junio C HamanoMay 17, 2007
  18. Nicolas PitreMay 17, 2007
  19. Michael S. TsirkinMay 17, 2007
  20. Josef WeidendorferMay 17, 2007
  21. Steven GrimmMay 18, 2007
  22. Petr BaudisMay 18, 2007
  23. Josef WeidendorferMay 18, 2007
  24. Torgil SvenssonMay 19, 2007
  25. Jakub NarebskiMay 18, 2007
  26. Petr BaudisMay 18, 2007
  27. Jakub NarebskiMay 19, 2007
  28. Junio C HamanoMay 18, 2007
  29. Julian PhillipsMay 18, 2007
  30. Junio C HamanoMay 18, 2007
  31. Petr BaudisMay 20, 2007
  32. News reader woes (was: Re: [3/4] What's not in 1.5.2 (new topics))Jakub Narebski, May 25, 2007
  33. Andy ParkinsMay 18, 2007
  34. Josef WeidendorferMay 18, 2007
  35. Andy ParkinsMay 18, 2007
  36. Michael S. TsirkinMay 18, 2007
  37. Josef WeidendorferMay 18, 2007
  38. Michael S. TsirkinMay 18, 2007
  39. Aidan Van DykMay 18, 2007
  40. Michael S. TsirkinMay 18, 2007
  41. Sven VerdoolaegeMay 19, 2007
  42. Jakub NarebskiMay 21, 2007
  43. Junio C HamanoMay 18, 2007
  44. Michael S. TsirkinMay 19, 2007
  45. Junio C HamanoMay 19, 2007
  46. Michael S. TsirkinMay 18, 2007
  47. Andy ParkinsMay 18, 2007
  48. Johannes SixtMay 18, 2007
  49. Michael S. TsirkinMay 18, 2007
  50. Andy ParkinsMay 18, 2007
  51. Steven GrimmMay 19, 2007
  52. Josef WeidendorferMay 19, 2007
  53. 4/4 What's not in 1.5.2 (other bits and pieces)Junio C Hamano, May 16, 2007
  54. Petr BaudisMay 18, 2007
  55. Michael S. TsirkinMay 18, 2007

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.