git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 0/3] Strengthen fsck checks for submodule URLs

From
Neil Mayhew <neil@mayhew.name>
Date
Nov 13, 2024, 19:24 UTC
Message-ID
<d9f53fe7-6570-4aea-894c-942e12e012c4@mayhew.name>
In-Reply-To
<20240110102338.GA16674@coredump.intra.peff.net>
On 10 Jan 24 03:23, Jeff King wrote:
 > By making it an fsck
 > check, though, any mistakes that are embedded in history (even if
 > they are now corrected) will make it a pain to use the repository
 > with sites that enable transfer.fsckObjects.
 >
 > My gut feeling is that this is probably OK in practice. If it does
 > cause pain, we might consider loosening the fsck.gitmodulesUrl
 > severity (under the notion from above that it is no longer a
 > critical security check). But if it doesn't cause real-world pain,
 > being pickier is probably better (it may save us from a
 > vulnerability down the road).

This pain is happening in https://github.com/IntersectMBO/cardano-ledger.git, a large open-source repo. There was a bad edit to .gitmodules which was immediately corrected by another commit. However, the bad commit is still in the history. It happened 6 years ago, so there's no possibility of us changing the history. We just spent time investigating a bug report from someone who was unable to clone the repo, and eventually we discovered that they had transfer.fsckObjects enabled. Even without this option, however, we still want people to be able to run fsck successfully on the repo.

It's awkward that our repo now won't pass an fsck check and we have no way to correct that. I'd really like not to have to put a note in the README warning about this.

Is there any possibility of "loosening the fsck.gitmodulesUrl severity", as Jeff suggested?

Previous: Jeff KingNext: Neil Mayhew
Message 14 of 31 in “Strengthen fsck checks for submodule URLs”
  1. 0/3 Strengthen fsck checks for submodule URLsVictoria Dye via GitGitGadget, Jan 9, 2024
  2. 1/3 submodule-config.h: move check_submodule_urlVictoria Dye via GitGitGadget, Jan 9, 2024
  3. 2/3 t7450: test submodule urlsVictoria Dye via GitGitGadget, Jan 9, 2024
  4. Junio C HamanoJan 9, 2024
  5. Victoria DyeJan 11, 2024
  6. Jeff KingJan 10, 2024
  7. Victoria DyeJan 11, 2024
  8. Jeff KingJan 12, 2024
  9. 3/3 submodule-config.c: strengthen URL fsck checkVictoria Dye via GitGitGadget, Jan 9, 2024
  10. Junio C HamanoJan 9, 2024
  11. Patrick SteinhardtJan 10, 2024
  12. Victoria DyeJan 17, 2024
  13. Jeff KingJan 10, 2024
  14. Neil MayhewNov 13, 2024
  15. Neil MayhewNov 13, 2024
  16. Junio C HamanoNov 13, 2024
  17. Jeff KingNov 14, 2024
  18. Neil MayhewNov 14, 2024
  19. Junio C HamanoNov 14, 2024
  20. Neil MayhewNov 14, 2024
  21. Neil MayhewNov 14, 2024
  22. 0/4 Strengthen fsck checks for submodule URLsVictoria Dye via GitGitGadget, Jan 18, 2024
  23. 1/4 submodule-config.h: move check_submodule_urlVictoria Dye via GitGitGadget, Jan 18, 2024
  24. 2/4 test-submodule: remove command line handling for check-nameVictoria Dye via GitGitGadget, Jan 18, 2024
  25. Junio C HamanoJan 18, 2024
  26. 3/4 t7450: test submodule urlsVictoria Dye via GitGitGadget, Jan 18, 2024
  27. Patrick SteinhardtJan 19, 2024
  28. Junio C HamanoJan 19, 2024
  29. 4/4 submodule-config.c: strengthen URL fsck checkVictoria Dye via GitGitGadget, Jan 18, 2024
  30. Junio C HamanoJan 18, 2024
  31. Jeff KingJan 20, 2024

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.