git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] Add project-wide .vimrc configuration

From
brian m. carlson <sandals@crustytoothpaste.net>
Date
Dec 9, 2020, 02:23 UTC
Message-ID
<X9A1On3v35nEjL7i@camp.crustytoothpaste.net>
In-Reply-To
<20201209002619.25468-1-felipe.contreras@gmail.com>
On 2020-12-09 at 00:26:19, Felipe Contreras wrote:
Show 8 quoted lines
> It's not efficient that everyone must set specific configurations in all
> their ~/.vimrc files; we can have a project-wide .vimrc that everyone
> can use.
> 
> By default it's ignored, you need the following in your ~/.vimrc
> 
>   set exrc
>   set secure

I would strongly recommend against advising users to use this configuration. Vim has been known to have repeated security problems with what options are allowed in restricted environments, and even with the secure option, it's still easy to do something like this:

  func Foo()
    !echo >/tmp/foo
  endfunction
  nmap i :call Foo()<CR>

When the user hits "i" to enter insert mode, they'll execute the attacker's arbitrary code.

> We could add the vim modelines at the bottom of every file, like other
> projects do, but this seems more sensible.

We have an .editorconfig file[0], which is a cross-editor file that can be used to specify these settings. It is supported by many editors out of the box, although Vim requires a plugin. Since we don't want to support configuration for every editor under the sun, it makes sense to use a single file for multiple editors and let people configure their editor accordingly.

Since Vim would require configuration either way and .editorconfig files don't have any known security issues, the .editorconfig file seems like a better option.

[0] https://editorconfig.org/
-- 
brian m. carlson (he/him or they/them)
Houston, Texas, US
Previous: Felipe ContrerasNext: Felipe Contreras
Message 9 of 15 in “Add project-wide .vimrc configuration”
  1. Add project-wide .vimrc configurationFelipe Contreras, Dec 9, 2020
  2. Junio C HamanoDec 9, 2020
  3. Felipe ContrerasDec 9, 2020
  4. Aaron SchrabDec 9, 2020
  5. Junio C HamanoDec 9, 2020
  6. Felipe ContrerasDec 9, 2020
  7. Denton LiuDec 9, 2020
  8. Felipe ContrerasDec 9, 2020
  9. brian m. carlsonDec 9, 2020
  10. Felipe ContrerasDec 9, 2020
  11. Junio C HamanoDec 9, 2020
  12. Felipe ContrerasDec 9, 2020
  13. Junio C HamanoDec 9, 2020
  14. Felipe ContrerasDec 9, 2020
  15. Randall S. BeckerDec 9, 2020

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.