Re: [RFC] setup: fail if .git is not a file or directory
- From
Junio C Hamano <gitster@pobox.com>
- Date
- Feb 12, 2026, 22:45 UTC
- Message-ID
- <xmqqy0kxlgy6.fsf@gitster.g>
- In-Reply-To
- <aY5Wid6eg1-LwZm8@fruit.crustytoothpaste.net>
"brian m. carlson" <sandals@crustytoothpaste.net> writes:
Show 5 quoted lines
> We used to allow symlinks as well. That was used instead of gitfiles > for submodules at one point, I believe, and there may still be some > people using that. A brief test indicates that that functionality still > works, so if we make a change here, we should be sure to accept symlinks > as well.
In my review, I outlined a way to avoid this extra lstat(), and instead reuse the result of stat() used in read_gitfile_gently() already; the check in that function being stat() is exactly because we want to follow such a symbolic link.
> In general, we should allow people to use symlinks wherever they can use > a file or directory unless we can definitively prove that there's a > clear security or functionality problem that cannot be avoided. Git was > originally written for Unix, after all.
Is this also an obvlique reference to a separate potential security issue, I wonder. It reminds me that I need to see if I have to ping the thread again.
Thanks.