On Do, 02 Apr 2026, David A. Wheeler wrote:
> I think it's best to disable this functionality for now. > Perhaps it should be disabled by default until it has a better > self-protection mechanism. The default should only allow specific fields > with specific permitted value ranges, so that attackers can't mess with > people. > A 'textwidth' of 5, set without user approval, sounds like a bad idea. > Tabs are pretty much only a few valid values; I doubt "250" is a reasonable > one. > > If someone really wants the existing modeline behavior, an "insecure > modeline" option > would make sense, but I bet most users would not enable it. It seems the community prefers a whitelist approach however. So this is probably what it will be soon. Thanks, Christian -- F: Was ist golden und fliegt durch die Luft? A: Maikäfer mit Goldzahn.
