From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!.POSTED!not-for-mail From: Eli Zaretskii Newsgroups: gmane.emacs.devel Subject: Re: mark .dir-locals.el buffer or file as safe instead of variables as safe Date: Wed, 27 Jun 2018 05:33:59 +0300 Message-ID: <83fu19q7oo.fsf@gnu.org> References: NNTP-Posting-Host: blaine.gmane.org X-Trace: blaine.gmane.org 1530066766 26825 195.159.176.226 (27 Jun 2018 02:32:46 GMT) X-Complaints-To: usenet@blaine.gmane.org NNTP-Posting-Date: Wed, 27 Jun 2018 02:32:46 +0000 (UTC) Cc: emacs-devel@gnu.org To: cdelia@dc.uba.ar Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Wed Jun 27 04:32:42 2018 Return-path: Envelope-to: ged-emacs-devel@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by blaine.gmane.org with esmtp (Exim 4.84_2) (envelope-from ) id 1fY0G6-0006kz-9P for ged-emacs-devel@m.gmane.org; Wed, 27 Jun 2018 04:32:38 +0200 Original-Received: from localhost ([::1]:56178 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fY0IC-0005Q4-4F for ged-emacs-devel@m.gmane.org; Tue, 26 Jun 2018 22:34:48 -0400 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:48740) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fY0HQ-0005Nr-Tv for emacs-devel@gnu.org; Tue, 26 Jun 2018 22:34:01 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1fY0HN-0001uH-Nv for emacs-devel@gnu.org; Tue, 26 Jun 2018 22:34:00 -0400 Original-Received: from fencepost.gnu.org ([2001:4830:134:3::e]:39998) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fY0HN-0001tv-BA; Tue, 26 Jun 2018 22:33:57 -0400 Original-Received: from [176.228.60.248] (port=2803 helo=home-c4e4a596f7) by fencepost.gnu.org with esmtpsa (TLS1.2:RSA_AES_256_CBC_SHA1:256) (Exim 4.82) (envelope-from ) id 1fY0HM-0006BP-Oi; Tue, 26 Jun 2018 22:33:57 -0400 In-reply-to: (cdelia@dc.uba.ar) X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] X-Received-From: 2001:4830:134:3::e X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Original-Sender: "Emacs-devel" Xref: news.gmane.org gmane.emacs.devel:226756 Archived-At: > Date: Tue, 26 Jun 2018 21:14:52 -0300 > From: cdelia@dc.uba.ar > > https://www.gnu.org/software/emacs/manual/html_node/emacs/Safe-File-Variables.html#Safe-File-Variables > > I'm trying to wrap my head around this, and I, in my *very* humble > opinion, think, it's a bad design decision. > > and that's because: > One just *do not trust variables*, only *those who modify it*. I believe there's a possibility of someone's maliciously redirecting your "trusted" file to another one, e.g. with a symlink. IOW, we don't really know who modified the file and why.