git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v3 4/5] setup: allow temporary bypass of `ensure_safe_repository()` checks

From
Junio C Hamano <gitster@pobox.com>
Date
Oct 16, 2025, 19:26 UTC
Message-ID
<xmqqv7ke3axu.fsf@gitster.g>
In-Reply-To
<20251016053322.44495-5-git@lohmann.sh>
Michael Lohmann <git@lohmann.sh> writes:
Show 6 quoted lines
> So far, the only option to allow executing git in what it considers to
> be an "unsafe context" is to set this repository as "safe.directory". If
> a user only wants to temporarily execute one command, they would need to
> set the path as safe, execute the command and then remove the path
> again. Forgetting to do the latter would make the user vulnerable if
> this repo was changed afterwards in a malicious way.
If you want to do a one-shot thing, wouldn't ...
	$ cd $there
	$ GIT_DIR=$(pwd)/.git GIT_WORK_TREE=$(pwd) git ...

... be more or less the standard practice? If you are at the top level of the working tree (which is why the above example uses $(pwd)/.git for GIT_DIR), you do not even have to specify GIT_WORK_TREE and get away with

	$ GIT_DIR=.git git ...

In other words, the above argument does not sound like a very strong justification.

> +--allow-unsafe::
> +	Temporarily trust the repository regardless of "safe.directory"
> +	configuration or ownership, potentially resulting in arbitrary code
> +	execution by hooks or configuration settings.

As the only justification for this new feature to exist that was explained in the proposed log message was "one shot execution", this command line option does look justifiable. Even though with the current system, you do not have to muck with configuration files and only have to set the GIT_DIR environment variable, passing this command line option that does not take a value may still be slightly easier.

> + Equivalent to setting
> +	the environment variable `GIT_ALLOW_UNSAFE=1`.

But such an enviornment variable is not justified. Setting an engironment variable would last until you unset it, and it implies that it is no longer a single shot use case that this new feature targets.

Show 5 quoted lines
> +`GIT_ALLOW_UNSAFE`::
> +	This Boolean environment variable can be set to true to skip the
> +	safety checks of "safe.directory" configuration and if the user
> +	owns the repository before potentially executing arbitrary code
> +	from hooks or config.

Please don't add this. It has the same "Forgetting to unset the environment variable will make the user vulnerable" downside as temporarily editing your configuration file.

Not convinced why this feature must exist, at least not yet.
Previous: Michael LohmannNext: Michael Lohmann
Message 21 of 24 in “Allow enforcing safe.directory”
  1. 0/5 Allow enforcing safe.directoryMichael Lohmann, Oct 13, 2025
  2. 1/5 setup: rename `ensure_safe_repository()` for clarityMichael Lohmann, Oct 13, 2025
  3. 2/5 setup: rename `die_upon_assumed_unsafe_repo()` to align with checkMichael Lohmann, Oct 13, 2025
  4. Junio C HamanoOct 14, 2025
  5. 3/5 setup: refactor `ensure_safe_repository()` testing prioritiesMichael Lohmann, Oct 13, 2025
  6. Junio C HamanoOct 14, 2025
  7. 4/5 setup: allow temporary bypass of `ensure_safe_repository()` checksMichael Lohmann, Oct 13, 2025
  8. 5/5 setup: allow not marking self owned repos as safe in `ensure_safe_repository()`Michael Lohmann, Oct 13, 2025
  9. D. Ben KnobleOct 13, 2025
  10. 0/5 Apply comments of D. Ben KnobleMichael Lohmann, Oct 13, 2025
  11. 1/5 setup: rename `ensure_safe_repository()` for clarityMichael Lohmann, Oct 13, 2025
  12. 2/5 setup: rename `die_upon_assumed_unsafe_repo()` to align with checkMichael Lohmann, Oct 13, 2025
  13. 3/5 setup: refactor `ensure_safe_repository()` testing prioritiesMichael Lohmann, Oct 13, 2025
  14. 4/5 setup: allow temporary bypass of `ensure_safe_repository()` checksMichael Lohmann, Oct 13, 2025
  15. 5/5 setup: allow not marking self owned repos as safe in `ensure_safe_repository()`Michael Lohmann, Oct 13, 2025
  16. 0/5 Allow skipping ownership of repo in safety considerationMichael Lohmann, Oct 16, 2025
  17. 3/5 setup: refactor `ensure_safe_repository()` testing prioritiesMichael Lohmann, Oct 16, 2025
  18. 1/5 setup: rename `ensure_safe_repository()` for clarityMichael Lohmann, Oct 16, 2025
  19. 2/5 setup: rename `die_upon_unsafe_repo()` to align with checkMichael Lohmann, Oct 16, 2025
  20. 4/5 setup: allow temporary bypass of `ensure_safe_repository()` checksMichael Lohmann, Oct 16, 2025
  21. Junio C HamanoOct 16, 2025
  22. 5/5 setup: allow not marking self owned repos as safe in `ensure_safe_repository()`Michael Lohmann, Oct 16, 2025
  23. Junio C HamanoOct 16, 2025
  24. Junio C HamanoOct 16, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.