Re: [PATCH v3 2/5] setup: extract path_allowlist_apply()
From: Junio C Hamano <hidden>
Date: 2026-09-08 17:48:06
Christian Couder [off-list ref] writes:
For clarity, let's change the `int is_safe` to `bool safe` in `struct safe_directory_data`.
I am not sure if this clarifies, though.
quoted hunk ↗ jump to hunk
diff --git a/setup.c b/setup.c index dfe05d9a03..366a7dc5c0 100644 --- a/setup.c +++ b/setup.c@@ -1338,67 +1338,105 @@ static int canonicalize_ceiling_entry(struct string_list_item *item, } } +void path_allowlist_apply(const char *allowed, const char *target_path, + bool *matches, + bool (*allow_path)(const char *path, void *cbdata), + void *allow_path_cbdata) +{ + char *normalized = NULL; + + if (!allowed || !*allowed) { + *matches = false; + return; + } + + if (!strcmp(allowed, "*")) { + *matches = true; + return; + } + + if (!allow_path(allowed, allow_path_cbdata)) + return; + + /* + * A .gitconfig in $HOME may be shared across different + * machines and the config variable entries may or may not + * exist as paths on all of these machines. In other words, + * it is not a warning worthy event when there is no such path + * on this machine---the entry may be useful elsewhere. + */
This is inherited from the preimage and not something you would want to fix in this patch, but I do not think ignoring missing path like this is healthy. You do not know if the path given is missing by design (i.e., the set of paths is union of paths that could exist) or if it is missing due to an error (i.e., a filesystem that should have been mounted is not mounted). In the latter case, ignoring it may make the system behave in a way that the user did not intend to.
quoted hunk ↗ jump to hunk
+ normalized = real_pathdup(allowed, 0); + if (!normalized) + return; + + if (ends_with(normalized, "/*")) { + size_t len = strlen(normalized); + if (!fspathncmp(normalized, target_path, len - 1)) + *matches = true; + } else if (!fspathcmp(target_path, normalized)) { + *matches = true; + } + + free(normalized); +}