Untrusted hgrc files, why report them?

Martin Geisler mg at aragost.com
Fri Feb 25 03:40:42 CST 2011


Hi guys,

It's very rare that I'm working with a repository that I do not
completely own, but when I do, it's highly annoying to get the warnings
about untrusted config files.

Why do we even issue such warnings? It's not like I would expect my
Emacs to read another users's ~/.emacs file if I open a file inside his
home directory. So I would also not expect Mercurial to honor a .hg/hgrc
file belonging to another user.

I suspect that most of us core developers never see the warning because
we always own our repositories. And I also suspect that when users do
see the warning, then it's only annoying and strange to them.

Is there anybody here who are happy with the warning?

-- 
Martin Geisler

aragost Trifork
Professional Mercurial support
http://aragost.com/en/services/mercurial/blog/


More information about the Mercurial-devel mailing list