git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 0/3] Strengthen fsck checks for submodule URLs

From
Junio C Hamano <gitster@pobox.com>
Date
Nov 13, 2024, 22:40 UTC
Message-ID
<xmqq5xoqahbx.fsf@gitster.g>
In-Reply-To
<d9f53fe7-6570-4aea-894c-942e12e012c4@mayhew.name>
Neil Mayhew <neil@mayhew.name> writes:
> ... immediately corrected by another commit. However, the bad commit is
> still in the history. It happened 6 years ago, so there's no
> possibility of us changing the history.

I think fsck.skipList was meant to cover such a case. The idea is that the blob object name of the bad .gitmodules file can be placed on the list, and the rest of the "bad commit" and the whole history can still be checked for consistency, without triggering the warning (or error) resulting from the offending .gitmodules file.

> Is there any possibility of "loosening the fsck.gitmodulesUrl
> severity", as Jeff suggested?

Isn't the suggestion not about butchering the rest of the world but by locally configuring fsck.gitmodulesUrl down from error to warning? I personally think excluding a single known-offending blob without doing such loosening is a much better idea in that it prevents *new* offending instances from getting into the repository, while allowing an existing benign and honest mistake to stay in your history. Loosening the severity of a class of check means you will accept *new* offending instances, which may very well be malicious, unlike the existing benign one you know about.

Previous: Neil MayhewNext: Jeff King
Message 16 of 31 in “Strengthen fsck checks for submodule URLs”
  1. 0/3 Strengthen fsck checks for submodule URLsVictoria Dye via GitGitGadget, Jan 9, 2024
  2. 1/3 submodule-config.h: move check_submodule_urlVictoria Dye via GitGitGadget, Jan 9, 2024
  3. 2/3 t7450: test submodule urlsVictoria Dye via GitGitGadget, Jan 9, 2024
  4. Junio C HamanoJan 9, 2024
  5. Victoria DyeJan 11, 2024
  6. Jeff KingJan 10, 2024
  7. Victoria DyeJan 11, 2024
  8. Jeff KingJan 12, 2024
  9. 3/3 submodule-config.c: strengthen URL fsck checkVictoria Dye via GitGitGadget, Jan 9, 2024
  10. Junio C HamanoJan 9, 2024
  11. Patrick SteinhardtJan 10, 2024
  12. Victoria DyeJan 17, 2024
  13. Jeff KingJan 10, 2024
  14. Neil MayhewNov 13, 2024
  15. Neil MayhewNov 13, 2024
  16. Junio C HamanoNov 13, 2024
  17. Jeff KingNov 14, 2024
  18. Neil MayhewNov 14, 2024
  19. Junio C HamanoNov 14, 2024
  20. Neil MayhewNov 14, 2024
  21. Neil MayhewNov 14, 2024
  22. 0/4 Strengthen fsck checks for submodule URLsVictoria Dye via GitGitGadget, Jan 18, 2024
  23. 1/4 submodule-config.h: move check_submodule_urlVictoria Dye via GitGitGadget, Jan 18, 2024
  24. 2/4 test-submodule: remove command line handling for check-nameVictoria Dye via GitGitGadget, Jan 18, 2024
  25. Junio C HamanoJan 18, 2024
  26. 3/4 t7450: test submodule urlsVictoria Dye via GitGitGadget, Jan 18, 2024
  27. Patrick SteinhardtJan 19, 2024
  28. Junio C HamanoJan 19, 2024
  29. 4/4 submodule-config.c: strengthen URL fsck checkVictoria Dye via GitGitGadget, Jan 18, 2024
  30. Junio C HamanoJan 18, 2024
  31. Jeff KingJan 20, 2024

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.