From: Junio C Hamano Date: Thu, 12 Feb 2026 22:45:05 GMT Subject: Re: [RFC] setup: fail if .git is not a file or directory Message-ID: In-Reply-To: "brian m. carlson" writes: > We used to allow symlinks as well. That was used instead of gitfiles > for submodules at one point, I believe, and there may still be some > people using that. A brief test indicates that that functionality still > works, so if we make a change here, we should be sure to accept symlinks > as well. In my review, I outlined a way to avoid this extra lstat(), and instead reuse the result of stat() used in read_gitfile_gently() already; the check in that function being stat() is exactly because we want to follow such a symbolic link. > In general, we should allow people to use symlinks wherever they can use > a file or directory unless we can definitively prove that there's a > clear security or functionality problem that cannot be avoided. Git was > originally written for Unix, after all. Is this also an obvlique reference to a separate potential security issue, I wonder. It reminds me that I need to see if I have to ping the thread again. Thanks.