git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] gitfaq: document using stash import/export to sync working tree

From
Junio C Hamano <gitster@pobox.com>
Date
Jan 10, 2026, 01:56 UTC
Message-ID
<xmqqo6n2temn.fsf@gitster.g>
In-Reply-To
<aWFg_VUZH5_ZqTix@fruit.crustytoothpaste.net>
"brian m. carlson" <sandals@crustytoothpaste.net> writes:
Show 14 quoted lines
> On 2026-01-09 at 14:32:40, Junio C Hamano wrote:
>> "brian m. carlson" <sandals@crustytoothpaste.net> writes:
>> 
>> > Git 2.51 learned how to import and export stashes.  This is a
>> > secure and robust way to transfer working tree states across machines
>> 
>> Here "secure" in "secure and robust" triggered my "huh?" sensor.  It
>> is a robust way, but is there something particularly "secure" about
>> it, other than "it is less likely to break your repository" in the
>> sense that is already covered by "robust".
>
> We know that sharing a working tree with different users is not secure
> because people can have things like hooks or config options that execute
> arbitrary code.  Transferring stashes doesn't have that downside.

Ah, I wasn't thinking about two different people transferring repositories. Using rsync may have that downside.

Previous: brian m. carlson
Message 4 of 4 in “gitfaq: document using stash import/export to sync working tree”
  1. gitfaq: document using stash import/export to sync working treebrian m. carlson, Jan 9, 2026
  2. Junio C HamanoJan 9, 2026
  3. brian m. carlsonJan 9, 2026
  4. Junio C HamanoJan 10, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.