From: Junio C Hamano Date: Thu, 16 Oct 2025 19:33:57 GMT Subject: Re: [PATCH v3 5/5] setup: allow not marking self owned repos as safe in `ensure_safe_repository()` Message-ID: In-Reply-To: <20251016053322.44495-6-git@lohmann.sh> Michael Lohmann writes: > +safe.assumeUnsafe:: > +--assume-unsafe:: > +`GIT_ASSUME_UNSAFE`:: I haven't thought things through thoroughly yet, but this probably is a good thing to have. I cannot say the same to [4/5], though. > @@ -1330,6 +1336,9 @@ static int ensure_safe_repository(const char *gitfile, > if (data.is_safe) > return 1; > > + if (git_env_bool("GIT_ASSUME_UNSAFE", 0)) > + return 0; > + > if (!git_env_bool("GIT_TEST_ASSUME_DIFFERENT_OWNER", 0) && > (!gitfile || is_path_owned_by_current_user(gitfile, report)) && > (!worktree || is_path_owned_by_current_user(worktree, report)) && I think you didn't have to do anything in [3/5] for this, though. It is sufficient to pretend as if GIT_TEST_ASSUME_DIFFERENT_OWNER is set when GIT_ASSUME_UNSAFE (and its config/option equivalents) is set, no? IOW, wouldn't it be equivalent to your series, if you dropped [3/5] and replace this hunk with the following? setup.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git i/setup.c w/setup.c index 7086741e6c..e3c81a6fae 100644 --- i/setup.c +++ w/setup.c @@ -1307,7 +1307,8 @@ static int ensure_valid_ownership(const char *gitfile, { struct safe_directory_data data = { 0 }; - if (!git_env_bool("GIT_TEST_ASSUME_DIFFERENT_OWNER", 0) && + if (!git_env_bool("GIT_ASSUME_UNSAFE", 0) && + !git_env_bool("GIT_TEST_ASSUME_DIFFERENT_OWNER", 0) && (!gitfile || is_path_owned_by_current_user(gitfile, report)) && (!worktree || is_path_owned_by_current_user(worktree, report)) && (!gitdir || is_path_owned_by_current_user(gitdir, report)))