Re: [PATCH 0/7] Restrict the usage of config_from_gitmodules()

2018-06-22 Thread Brandon Williams
On 06/22, Antonio Ospite wrote: > On Fri, 22 Jun 2018 10:13:10 -0700 > Brandon Williams wrote: > > [...] > > Thanks for working on this. I think its a good approach and the end > > result makes it much harder for arbitrary config to sneak back in to the > > .gitmodules file. And after this

Re: [PATCH 0/7] Restrict the usage of config_from_gitmodules()

2018-06-22 Thread Antonio Ospite
On Fri, 22 Jun 2018 10:13:10 -0700 Brandon Williams wrote: [...] > Thanks for working on this. I think its a good approach and the end > result makes it much harder for arbitrary config to sneak back in to the > .gitmodules file. And after this series it looks like you should be in > a good

Re: [PATCH 0/7] Restrict the usage of config_from_gitmodules()

2018-06-22 Thread Brandon Williams
On 06/22, Antonio Ospite wrote: > Hi, > > when I tried to reuse and extend 'config_from_gitmodules' in > https://public-inbox.org/git/20180514105823.8378-2-...@ao2.it/ it was > pointed out to me that special care is needed to make sure that this > function does not get abused to bring in

[PATCH 0/7] Restrict the usage of config_from_gitmodules()

2018-06-22 Thread Antonio Ospite
Hi, when I tried to reuse and extend 'config_from_gitmodules' in https://public-inbox.org/git/20180514105823.8378-2-...@ao2.it/ it was pointed out to me that special care is needed to make sure that this function does not get abused to bring in arbitrary configuration stored in the .gitmodules