From: Karthik Nayak Date: Tue, 17 Feb 2026 17:59:44 GMT Subject: Re: [PATCH v4] setup: allow cwd/.git to be a symlink to a directory Message-ID: In-Reply-To: <20260217084124.150366-1-a3205153416@gmail.com> Tian Yuchen writes: > Strictly enforcing 'lstat()' and 'S_ISREG()' on '.git' prevents valid > workflows where '.git' is a symbolic link pointing to a real git > directory (e.g. created via 'ln -s'). > > Refactor 'setup_git_directory_gently_1()' to use 'stat()' instead of > 'lstat()'. This allows the filesystem to automatically resolve symbolic > links. > > To ensure safety and correctness, the logic flow is updated to: > > 1. Ignore 'ENOENT' (file missing). > 2. Check 'IS_A_DIR' cases via 'is_git_directory()'. > 3. Explicitly reject 'NOT_A_FILE' cases (FIFOs or sockets). > > Add a new test script t/t0009-setup-security.sh which verifies: > > - Valid .git symlinks to real directories are accepted. > - .git as a named pipe (FIFO) is rejected. > - .git as a symlink to a named pipe is rejected. > - .git with garbage content is rejected. > - Empty .git directories are ignored. > > Signed-off-by: Tian Yuchen > --- > setup.c | 39 ++++++++++++++------- > setup.h | 2 ++ > t/t0009-setup-security.sh | 72 +++++++++++++++++++++++++++++++++++++++ > 3 files changed, 101 insertions(+), 12 deletions(-) > create mode 100755 t/t0009-setup-security.sh > I also missed this in my review, but the test needs to be added to 'meson.build', without which meson would fail. This is caught by our CI too, if you run the CI on GitLab/GitHub you should see the issue. Karthik