Re: [PATCH v3 5/5] setup: allow not marking self owned repos as safe in `ensure_safe_repository()`
- From
Junio C Hamano <gitster@pobox.com>
- Date
- Oct 16, 2025, 19:33 UTC
- Message-ID
- <xmqqo6q63al6.fsf@gitster.g>
- In-Reply-To
- <20251016053322.44495-6-git@lohmann.sh>
Michael Lohmann <git@lohmann.sh> writes:
> +safe.assumeUnsafe:: > +--assume-unsafe:: > +`GIT_ASSUME_UNSAFE`::
I haven't thought things through thoroughly yet, but this probably is a good thing to have. I cannot say the same to [4/5], though.
Show 10 quoted lines
> @@ -1330,6 +1336,9 @@ static int ensure_safe_repository(const char *gitfile,
> if (data.is_safe)
> return 1;
>
> + if (git_env_bool("GIT_ASSUME_UNSAFE", 0))
> + return 0;
> +
> if (!git_env_bool("GIT_TEST_ASSUME_DIFFERENT_OWNER", 0) &&
> (!gitfile || is_path_owned_by_current_user(gitfile, report)) &&
> (!worktree || is_path_owned_by_current_user(worktree, report)) &&I think you didn't have to do anything in [3/5] for this, though.
It is sufficient to pretend as if GIT_TEST_ASSUME_DIFFERENT_OWNER is set when GIT_ASSUME_UNSAFE (and its config/option equivalents) is set, no? IOW, wouldn't it be equivalent to your series, if you dropped [3/5] and replace this hunk with the following?
setup.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-)
diff --git i/setup.c w/setup.c index 7086741e6c..e3c81a6fae 100644 --- i/setup.c +++ w/setup.c @@ -1307,7 +1307,8 @@ static int ensure_valid_ownership(const char *gitfile, { struct safe_directory_data data = { 0 }; - if (!git_env_bool("GIT_TEST_ASSUME_DIFFERENT_OWNER", 0) && + if (!git_env_bool("GIT_ASSUME_UNSAFE", 0) && + !git_env_bool("GIT_TEST_ASSUME_DIFFERENT_OWNER", 0) && (!gitfile || is_path_owned_by_current_user(gitfile, report)) && (!worktree || is_path_owned_by_current_user(worktree, report)) && (!gitdir || is_path_owned_by_current_user(gitdir, report)))