Re: [RFC] setup: fail if .git is not a file or directory
- From
brian m. carlson <sandals@crustytoothpaste.net>
- Date
- Feb 12, 2026, 22:39 UTC
- Message-ID
- <aY5Wid6eg1-LwZm8@fruit.crustytoothpaste.net>
- In-Reply-To
- <20260211182122.35352-1-a3205153416@gmail.com>
On 2026-02-11 at 18:21:22, Tian Yuchen wrote:
Show 13 quoted lines
> Currently, `setup_git_directory_gently_1()` checks if `.git` is a > regular file (handling submodules/worktrees) or a directory. If it is > neither (e.g., a FIFO), the code hits a NEEDSWORK comment and simply > ignores the entity, continuing the discovery process in the parent > directory. > > This behavior can be very dangerous. If a user is inside a subdirectory > containing a melformed/broken `.git` entity, the Git will traverse up, > attach to a parent repository and might execute destructive commands. > > I tried to resolve the NEEDSWORK by using `lstat()` to explicitly check > the entity's mode. If it is neither a regular file nor a directory, we > kill the discovery process.
We used to allow symlinks as well. That was used instead of gitfiles for submodules at one point, I believe, and there may still be some people using that. A brief test indicates that that functionality still works, so if we make a change here, we should be sure to accept symlinks as well.
In general, we should allow people to use symlinks wherever they can use a file or directory unless we can definitively prove that there's a clear security or functionality problem that cannot be avoided. Git was originally written for Unix, after all.
-- brian m. carlson (they/them) Toronto, Ontario, CA