git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [BUG] fatal: transport 'file' not allowed during submodule add

From
Jonathan Nieder <jrnieder@gmail.com>
Date
Dec 28, 2022, 22:10 UTC
Message-ID
<Y6y+zkUsPhknTYH/@google.com>
In-Reply-To
<011201d91aca$a5db7800$f1926800$@nexbridge.com>
Hi Randall,
rsbecker@nexbridge.com wrote:
> Junio C Hamano wrote:
Show 6 quoted lines
>> This suspiciously sounds like what a1d4f67c (transport: make `protocol.file.allow`
>> be "user" by default, 2022-07-29) is doing deliberately.
>
> I have tried using 'git config --local protocol.file.allow always' and/or
> 'git config --local protocol.allow always' to get past this, without
> success.
Does `git config --global protocol.file.allow always` do the trick?
>>                                                           Taylor, does this look like a
>> corner case the 2.30.6 updates forgot to consider?

I think it's the intended effect (preventing file:// submodules), but I wonder if this hints that we'd want that protection to be more targeted. A file:// submodule (as opposed to a bare path without URL scheme) wouldn't trigger the "git clone --local" behavior that that commit mentions wanting to protect against, so at first glance it would appear to be no more or less dangerous than cloning from a remote repository.

One thing I'd be curious about is whether --local happening automatically is actually worth it nowadays. "git worktree" does a better job of sharing with an existing local repository, since the sharing continues even after the worktree has been created, after any "git gc" operations, and so on. Meanwhile, the distinction between file:// and bare paths is subtle enough that I regularly encounter people not being aware of it (for example when wanting a way to test protocol code locally and not understanding why a bare-path clone doesn't do that). Would it be more in the spirit of secure defaults to require --local when someone wants to request the hardlinking trick of local clone?

Thanks, Jonathan

Previous: rsbecker@nexbridge.comNext: rsbecker@nexbridge.com
Message 4 of 12 in “[BUG] fatal: transport 'file' not allowed during submodule add”
  1. rsbecker@nexbridge.comDec 27, 2022
  2. Junio C HamanoDec 28, 2022
  3. rsbecker@nexbridge.comDec 28, 2022
  4. Jonathan NiederDec 28, 2022
  5. rsbecker@nexbridge.comDec 28, 2022
  6. Taylor BlauDec 30, 2022
  7. rsbecker@nexbridge.comDec 30, 2022
  8. Jeff KingJan 3, 2023
  9. Taylor BlauDec 30, 2022
  10. rsbecker@nexbridge.comDec 30, 2022
  11. rsbecker@nexbridge.comDec 30, 2022
  12. rsbecker@nexbridge.comDec 30, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.