From: Junio C Hamano <gitster@pobox•com>
To: Duy Nguyen <pclouds@gmail•com>
Cc: git@vger•kernel.org, Jens Lehmann <Jens.Lehmann@web•de>
Subject: Re: [PATCH 6/7] read-cache: refuse to create index referring to external objects
Date: Sun, 27 Jan 2013 22:36:53 -0800 [thread overview]
Message-ID: <7vpq0pyfsq.fsf@alter.siamese.dyndns.org> (raw)
In-Reply-To: <CACsJy8BwCCAZyMZ2w9fyMaNJsHRNp2V3Aen8g3drAkZ4y9mfBg@mail.gmail.com> (Duy Nguyen's message of "Mon, 28 Jan 2013 13:18:12 +0700")
Duy Nguyen <pclouds@gmail•com> writes:
> On Mon, Jan 28, 2013 at 12:48 PM, Duy Nguyen <pclouds@gmail•com> wrote:
>> Regardless the submodule odb issue, I think we should prefer
>> reading local loose objects over alternate packed ones.
>
> I think I went from one problem to another and did not make it clear.
> The reason behind this preference is security.
Reading from ours first would not help you at all if you are lacking
some that you do need from your local repository and the only
solution is not to borrow from untrustworthy sources, I think.
You borrow only from a trusted source in the first place, no?
next prev parent reply other threads:[~2013-01-28 6:37 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2013-01-24 8:42 [PATCH 1/7] sha1_file: keep track of where an SHA-1 object comes from Nguyễn Thái Ngọc Duy
2013-01-24 8:42 ` [PATCH 2/7] sha1_file: separate alt object db from own repos and submodules's Nguyễn Thái Ngọc Duy
2013-01-24 8:42 ` [PATCH 3/7] sha1_file: refuse to write commits referring to external objects Nguyễn Thái Ngọc Duy
2013-01-24 8:42 ` [PATCH 4/7] sha1_file: refuse to write trees " Nguyễn Thái Ngọc Duy
2013-01-24 8:42 ` [PATCH 5/7] sha1_file: refuse to write tags " Nguyễn Thái Ngọc Duy
2013-01-24 8:42 ` [PATCH 6/7] read-cache: refuse to create index " Nguyễn Thái Ngọc Duy
2013-01-24 19:15 ` Junio C Hamano
2013-01-25 2:00 ` Duy Nguyen
2013-01-25 19:00 ` Junio C Hamano
2013-01-28 5:48 ` Duy Nguyen
2013-01-28 5:54 ` Junio C Hamano
2013-01-28 5:57 ` Duy Nguyen
2013-01-28 6:06 ` Junio C Hamano
2013-01-28 6:18 ` Duy Nguyen
2013-01-28 6:36 ` Junio C Hamano [this message]
2013-01-28 6:57 ` Duy Nguyen
2013-01-24 8:42 ` [PATCH 7/7] refs: do not update ref(log) " Nguyễn Thái Ngọc Duy
2013-01-24 17:45 ` [PATCH 1/7] sha1_file: keep track of where an SHA-1 object comes from Junio C Hamano
2013-01-25 1:38 ` Duy Nguyen
2013-01-25 3:58 ` Junio C Hamano
2013-01-25 4:02 ` Duy Nguyen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=7vpq0pyfsq.fsf@alter.siamese.dyndns.org \
--to=gitster@pobox$(echo .)com \
--cc=Jens.Lehmann@web$(echo .)de \
--cc=git@vger$(echo .)kernel.org \
--cc=pclouds@gmail$(echo .)com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox