Thread (2 messages) flat view 2 messages, 2 authors, 2016-06-16

Re: [PATCH v5 2/2] submodule: pass on http.extraheader config settings

From: Jeff King <hidden>
Date: 2016-06-16 02:19:04

On Thu, Apr 28, 2016 at 12:06:56PM -0700, Junio C Hamano wrote:
Jeff King [off-list ref] writes:
quoted
On Thu, Apr 28, 2016 at 09:09:44AM -0700, Stefan Beller wrote:
quoted
quoted
I think the key thing with a blacklist is somebody has to go to the work
to audit the existing keys.
Would it be sufficient to wait until someone screams at the mailing list
for some key to be blacklisted? (I mean in the short term that would be
of less quality, but relying on the larger community would result in a better
end result? So your going through is just a jump start this process of
listening to the community?)
Yeah, I think ultimately we will rely on the community. But I would feel
a lot more comfortable if somebody made at least a single pass.

I'll be curious what Junio says, too. I generally defer to him on how
conservative we want to be in cases like this.
Starting from an empty whitelist and waiting for people to scream
with valid use cases would automatically give us the single pass to
identify the set of essential ones that users must be able to pass,
no?
It's definitely sufficient, it's just annoying if a user shows up every
week and says "I want X.Y", and then somebody else shows up a week later
and says "I want X.Z".

Are we serving any purpose in vetting each one (and if so, what)?

-Peff
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help