git/list[1] front-page[2] threads[3] people[4] search[5] about
wed 2026-10-07 18:12 UTC

Re: [PATCH v3 2/5] setup: extract path_allowlist_apply()

From
Christian Couder <christian.couder@gmail.com>
Date
Sep 28, 2026, 13:40 UTC
Message-ID
<CAP8UFD0da+K3FLVAgmds8CUr3aFrLjsmG7qO3mYX4foNLMYrMg@mail.gmail.com>
In-Reply-To
<xmqq33vjy6qz.fsf@gitster.g>
On Tue, Sep 8, 2026 at 7:48 PM Junio C Hamano <gitster@pobox.com> wrote:
Show 7 quoted lines
>
> Christian Couder <christian.couder@gmail.com> writes:
>
> > For clarity, let's change the `int is_safe` to `bool safe` in
> > `struct safe_directory_data`.
>
> I am not sure if this clarifies, though.
The change is now explained in the following way:
    +    As the new path_allowlist_apply() function reports its result through
    +    a `bool *matches` argument, let's also change the `int is_safe` member
    +    of `struct safe_directory_data` to a `bool`, so that its address can
    +    be passed as that argument.

and only the type of the variable is changed in v4. The "is_safe" original name is kept.

Show 43 quoted lines
> > diff --git a/setup.c b/setup.c
> > index dfe05d9a03..366a7dc5c0 100644
> > --- a/setup.c
> > +++ b/setup.c
> > @@ -1338,67 +1338,105 @@ static int canonicalize_ceiling_entry(struct string_list_item *item,
> >       }
> >  }
> >
> > +void path_allowlist_apply(const char *allowed, const char *target_path,
> > +                       bool *matches,
> > +                       bool (*allow_path)(const char *path, void *cbdata),
> > +                       void *allow_path_cbdata)
> > +{
> > +     char *normalized = NULL;
> > +
> > +     if (!allowed || !*allowed) {
> > +             *matches = false;
> > +             return;
> > +     }
> > +
> > +     if (!strcmp(allowed, "*")) {
> > +             *matches = true;
> > +             return;
> > +     }
> > +
> > +     if (!allow_path(allowed, allow_path_cbdata))
> > +             return;
> > +
> > +     /*
> > +      * A .gitconfig in $HOME may be shared across different
> > +      * machines and the config variable entries may or may not
> > +      * exist as paths on all of these machines.  In other words,
> > +      * it is not a warning worthy event when there is no such path
> > +      * on this machine---the entry may be useful elsewhere.
> > +      */
>
> This is inherited from the preimage and not something you would want
> to fix in this patch, but I do not think ignoring missing path like
> this is healthy.  You do not know if the path given is missing by
> design (i.e., the set of paths is union of paths that could exist)
> or if it is missing due to an error (i.e., a filesystem that should
> have been mounted is not mounted).  In the latter case, ignoring it
> may make the system behave in a way that the user did not intend to.

In dc0edbb01c (safe.directory: normalize the configured path, 2024-07-30) you say:

     - A configured safe.directory may be coming from .gitignore in the
       home directory that may be shared across machines.  The path
       meant to match with an entry may not necessarily exist on all of
       such machines, so not being able to convert them to real path on
       this machine is *not* a condition that is worthy of warning.
       Hence, we ignore a path that cannot be converted to a real path.

So I don't know what is the right thing to do. Maybe it's safer to warn by default but have a config option to not warn? Or maybe we should remember the unresolvable entries, and mention them only when the overall check fails?

Anyway I can add a NEEDSWORK here for now in a separate patch in this series or maybe in a followup series. In v4 nothing was changed regarding this.

Previous: Christian CouderNext: Christian Couder
Message 55 of 70 in “Introduce a 'fromAccepted' option to GIT_NO_LAZY_FETCH”
  1. 0/3 Introduce a 'fromAccepted' option to GIT_NO_LAZY_FETCHChristian Couder, Jul 10, 2026
  2. 1/3 promisor-remote: factor out lazy_fetch_objects()Christian Couder, Jul 10, 2026
  3. 2/3 promisor-remote: introduce enum allow_lazy_fetchChristian Couder, Jul 10, 2026
  4. 3/3 promisor-remote: teach 'fromAccepted' to GIT_NO_LAZY_FETCHChristian Couder, Jul 10, 2026
  5. brian m. carlsonJul 10, 2026
  6. Christian CouderJul 12, 2026
  7. 0/5 Introduce 'uploadpack.lazyFetchTrusted'Christian Couder, Aug 7, 2026
  8. 1/5 promisor-remote: factor out lazy_fetch_objects()Christian Couder, Aug 7, 2026
  9. 2/5 setup: extract path_allowlist_apply()Christian Couder, Aug 7, 2026
  10. 4/5 upload-pack: read uploadpack.lazyFetchTrustedChristian Couder, Aug 7, 2026
  11. 5/5 builtin/upload-pack: set GIT_NO_LAZY_FETCH to 0 on trusted repoChristian Couder, Aug 7, 2026
  12. 3/5 setup: add 'allow_dot' arg to path_allowlist_apply()Christian Couder, Aug 7, 2026
  13. Christian CouderAug 7, 2026
  14. Junio C HamanoAug 7, 2026
  15. Christian CouderAug 10, 2026
  16. Junio C HamanoAug 11, 2026
  17. 0/5 Introduce 'uploadpack.lazyFetchTrusted'Christian Couder, Aug 13, 2026
  18. 1/5 promisor-remote: factor out lazy_fetch_objects()Christian Couder, Aug 13, 2026
  19. 2/5 setup: extract path_allowlist_apply()Christian Couder, Aug 13, 2026
  20. 3/5 setup: add 'allow_dot' arg to path_allowlist_apply()Christian Couder, Aug 13, 2026
  21. 4/5 upload-pack: read uploadpack.lazyFetchTrustedChristian Couder, Aug 13, 2026
  22. 5/5 builtin/upload-pack: set GIT_NO_LAZY_FETCH to 0 on trusted repoChristian Couder, Aug 13, 2026
  23. Junio C HamanoAug 13, 2026
  24. Christian CouderAug 14, 2026
  25. Junio C HamanoAug 14, 2026
  26. Junio C HamanoAug 14, 2026
  27. Junio C HamanoAug 14, 2026
  28. Junio C HamanoAug 14, 2026
  29. Junio C HamanoAug 14, 2026
  30. Junio C HamanoAug 14, 2026
  31. 0/5 Introduce 'uploadpack.lazyFetchTrusted'Christian Couder, Sep 8, 2026
  32. 1/5 promisor-remote: factor out lazy_fetch_objects()Christian Couder, Sep 8, 2026
  33. 2/5 setup: extract path_allowlist_apply()Christian Couder, Sep 8, 2026
  34. 3/5 upload-pack: read uploadpack.lazyFetchTrustedChristian Couder, Sep 8, 2026
  35. 4/5 promisor-remote: prevent infinite recursion when lazy fetchingChristian Couder, Sep 8, 2026
  36. 5/5 builtin/upload-pack: set GIT_NO_LAZY_FETCH to 0 on trusted repoChristian Couder, Sep 8, 2026
  37. Christian CouderSep 8, 2026
  38. Christian CouderSep 8, 2026
  39. Christian CouderSep 8, 2026
  40. Christian CouderSep 8, 2026
  41. Junio C HamanoSep 8, 2026
  42. Junio C HamanoSep 8, 2026
  43. Junio C HamanoSep 8, 2026
  44. Junio C HamanoSep 8, 2026
  45. Junio C HamanoSep 8, 2026
  46. Christian CouderSep 9, 2026
  47. Junio C HamanoSep 9, 2026
  48. 0/5 Introduce 'uploadpack.lazyFetchTrusted'Christian Couder, Sep 28, 2026
  49. 1/5 promisor-remote: factor out lazy_fetch_objects()Christian Couder, Sep 28, 2026
  50. 2/5 setup: extract path_allowlist_apply()Christian Couder, Sep 28, 2026
  51. 3/5 upload-pack: read uploadpack.lazyFetchTrustedChristian Couder, Sep 28, 2026
  52. 4/5 promisor-remote: prevent infinite recursion when lazy fetchingChristian Couder, Sep 28, 2026
  53. 5/5 builtin/upload-pack: don't disable lazy fetching on trusted repoChristian Couder, Sep 28, 2026
  54. Christian CouderSep 28, 2026
  55. Christian CouderSep 28, 2026
  56. Christian CouderSep 28, 2026
  57. Christian CouderSep 28, 2026
  58. Junio C HamanoSep 29, 2026
  59. Junio C HamanoSep 29, 2026
  60. 0/5 Introduce 'uploadpack.lazyFetchTrusted'Christian Couder, Oct 2, 2026
  61. 1/5 promisor-remote: factor out lazy_fetch_objects()Christian Couder, Oct 2, 2026
  62. 2/5 setup: extract path_allowlist_apply()Christian Couder, Oct 2, 2026
  63. 3/5 upload-pack: read uploadpack.lazyFetchTrustedChristian Couder, Oct 2, 2026
  64. 4/5 promisor-remote: prevent infinite recursion when lazy fetchingChristian Couder, Oct 2, 2026
  65. 5/5 builtin/upload-pack: don't disable lazy fetching on trusted repoChristian Couder, Oct 2, 2026
  66. Christian CouderOct 2, 2026
  67. Christian CouderOct 2, 2026
  68. Christian CouderOct 2, 2026
  69. Junio C HamanoOct 5, 2026
  70. Christian CouderOct 6, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.