{"thread":{"id":"63687","subject":"bash: unescaped `>` character when switching branches","startedAt":"2025-06-24T13:00:13Z","lastAt":"2025-06-25T20:19:42Z","messageCount":5,"participants":["Ondrej Pohorelsky","Kristoffer Haugsbakk","Phillip Wood","Junio C Hamano"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"520635","messageId":"CA+B51BHEB24JNzOroTxFodxiuPJ1=Vj7KRFevrm2YatnTVuoYA@mail.gmail.com","threadId":"63687","inReplyTo":null,"subject":"bash: unescaped `>` character when switching branches","fromName":"Ondrej Pohorelsky","fromEmail":"opohorel@redhat.com","sentAt":"2025-06-24T12:59:58Z","receivedAt":"2025-06-24T13:00:13Z","isPatch":false,"sender":{"key":"opohorel@redhat.com","avatar":"https://avatars.githubusercontent.com/u/35430604?v=4"},"body":"Hi,\n\nOur customer has found a possible issue when switching branches.\nOutput redirection character `>` is not escaped properly when\nswitching/checking out to different branch.\n\nSteps to reproduce:\n1. Create a new branch and switch back to master\n```\n$ git switch -C 'issue#1234>/tmp/dangerfile'\nSwitched to a new branch 'issue#1234>/tmp/dangerfile'\n$ git switch master\n```\n\n2. Try to switch to the created branch with using auto-completion\n```\ngit switch i<TAB>\n$ git switch issue#1234>/tmp/dangerfile\nfatal: invalid reference: issue#1234\n```\n3. Verify that the /tmp/dangerfile has been created\n```\n$ ls /tmp/dangerfile\n/tmp/dangerfile\n```\n\nInternal interpretation of the created branch:\n└── refs\n    ├── heads\n    │   ├── issue#1234>\n    │   │   └── tmp\n    │   │       └── dangerfile\n\nTested on Fedora 42 with git-2.49.\n\n\nI've found out that this behavior happens only when using Bash. Zsh\nproperly escapes the characters when creating and switching to the\nbranch. Git shouldn't be tricked into creating a file when the user is\nswitching branches. I'm not entirely sure where the issue lies in the\ncode, so I'm not attaching any patch fixing this.\n\n\n-- \nOndřej Pohořelský\n\nSoftware Engineer\n\nRed Hat\n\nopohorel@redhat.com\n\n"},{"id":"520680","messageId":"8515698b-4ab7-4901-bacb-1c47180c2530@app.fastmail.com","threadId":"63687","inReplyTo":"CA+B51BHEB24JNzOroTxFodxiuPJ1=Vj7KRFevrm2YatnTVuoYA@mail.gmail.com","subject":"Re: bash: unescaped `>` character when switching branches","fromName":"Kristoffer Haugsbakk","fromEmail":"kristofferhaugsbakk@fastmail.com","sentAt":"2025-06-25T08:53:56Z","receivedAt":"2025-06-25T08:54:19Z","isPatch":false,"sender":{"key":"kristofferhaugsbakk@fastmail.com","avatar":null},"body":"On Tue, Jun 24, 2025, at 14:59, Ondrej Pohorelsky wrote:\n> Hi,\n>\n> Our customer has found a possible issue when switching branches.\n> Output redirection character `>` is not escaped properly when\n> switching/checking out to different branch.\n>\n> Steps to reproduce:\n> 1. Create a new branch and switch back to master\n> ```\n> $ git switch -C 'issue#1234>/tmp/dangerfile'\n> Switched to a new branch 'issue#1234>/tmp/dangerfile'\n> $ git switch master\n> ```\n\nIt’s too bad that git-check-ref-format(1) does not disallow `>`.\n\nIt would be nice to have an opt-in extension to the ref format check\nwhich disallows `>`.\n"},{"id":"520697","messageId":"84eccfa1-88fe-43b8-a839-61ea4fa4e4e9@gmail.com","threadId":"63687","inReplyTo":"8515698b-4ab7-4901-bacb-1c47180c2530@app.fastmail.com","subject":"Re: bash: unescaped `>` character when switching branches","fromName":"Phillip Wood","fromEmail":"phillip.wood123@gmail.com","sentAt":"2025-06-25T13:57:36Z","receivedAt":"2025-06-25T13:57:39Z","isPatch":false,"sender":{"key":"phillip.wood@dunelm.org.uk","avatar":null},"body":"On 25/06/2025 09:53, Kristoffer Haugsbakk wrote:\n> On Tue, Jun 24, 2025, at 14:59, Ondrej Pohorelsky wrote:\n>> Hi,\n>>\n>> Our customer has found a possible issue when switching branches.\n>> Output redirection character `>` is not escaped properly when\n>> switching/checking out to different branch.\n>>\n>> Steps to reproduce:\n>> 1. Create a new branch and switch back to master\n>> ```\n>> $ git switch -C 'issue#1234>/tmp/dangerfile'\n>> Switched to a new branch 'issue#1234>/tmp/dangerfile'\n>> $ git switch master\n>> ```\n> \n> It’s too bad that git-check-ref-format(1) does not disallow `>`.\n\nIt also allows `<`, `$`, `&`, `;`, `(`, `)`, `#`, `\"`, `'`, '`' and `|`. \nOur ref format is not designed for them to be used unquoted in the \nshell. I think the problem here is with our completion script not \nquoting the refname, not the format.\n\nBest Wishes\n\nPhillip\n> It would be nice to have an opt-in extension to the ref format check\n> which disallows `>`.\n> \n\n"},{"id":"520715","messageId":"xmqq5xgjwzbx.fsf@gitster.g","threadId":"63687","inReplyTo":"8515698b-4ab7-4901-bacb-1c47180c2530@app.fastmail.com","subject":"Re: bash: unescaped `>` character when switching branches","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2025-06-25T16:38:58Z","receivedAt":"2025-06-25T16:39:00Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"\"Kristoffer Haugsbakk\" <kristofferhaugsbakk@fastmail.com> writes:\n\n> On Tue, Jun 24, 2025, at 14:59, Ondrej Pohorelsky wrote:\n>> Hi,\n>>\n>> Our customer has found a possible issue when switching branches.\n>> Output redirection character `>` is not escaped properly when\n>> switching/checking out to different branch.\n>>\n>> Steps to reproduce:\n>> 1. Create a new branch and switch back to master\n>> ```\n>> $ git switch -C 'issue#1234>/tmp/dangerfile'\n>> Switched to a new branch 'issue#1234>/tmp/dangerfile'\n>> $ git switch master\n>> ```\n>\n> It’s too bad that git-check-ref-format(1) does not disallow `>`.\n\nIs it?  It looks like an outright bug in the completion code,\nnothing more, to me.\n"},{"id":"520729","messageId":"71204f81-3281-4089-9e9e-1a81a73c8d41@app.fastmail.com","threadId":"63687","inReplyTo":"84eccfa1-88fe-43b8-a839-61ea4fa4e4e9@gmail.com","subject":"Re: bash: unescaped `>` character when switching branches","fromName":"Kristoffer Haugsbakk","fromEmail":"kristofferhaugsbakk@fastmail.com","sentAt":"2025-06-25T20:19:20Z","receivedAt":"2025-06-25T20:19:42Z","isPatch":false,"sender":{"key":"kristofferhaugsbakk@fastmail.com","avatar":null},"body":"On Wed, Jun 25, 2025, at 15:57, Phillip Wood wrote:\n> On 25/06/2025 09:53, Kristoffer Haugsbakk wrote:\n>> On Tue, Jun 24, 2025, at 14:59, Ondrej Pohorelsky wrote:\n>>> Hi,\n>>>\n>>> Our customer has found a possible issue when switching branches.\n>>> Output redirection character `>` is not escaped properly when\n>>> switching/checking out to different branch.\n>>>\n>>> Steps to reproduce:\n>>> 1. Create a new branch and switch back to master\n>>> ```\n>>> $ git switch -C 'issue#1234>/tmp/dangerfile'\n>>> Switched to a new branch 'issue#1234>/tmp/dangerfile'\n>>> $ git switch master\n>>> ```\n>> \n>> It’s too bad that git-check-ref-format(1) does not disallow `>`.\n>\n> It also allows `<`, `$`, `&`, `;`, `(`, `)`, `#`, `\"`, `'`, '`' and `|`. \n> Our ref format is not designed for them to be used unquoted in the \n> shell. I think the problem here is with our completion script not \n> quoting the refname, not the format.\n\nOn Wed, Jun 25, 2025, at 18:38, Junio C Hamano wrote:\n> \"Kristoffer Haugsbakk\" <kristofferhaugsbakk@fastmail.com> writes:\n>\n>> On Tue, Jun 24, 2025, at 14:59, Ondrej Pohorelsky wrote:\n>>> Hi,\n>>>\n>>> Our customer has found a possible issue when switching branches.\n>>> Output redirection character `>` is not escaped properly when\n>>> switching/checking out to different branch.\n>>>\n>>> Steps to reproduce:\n>>> 1. Create a new branch and switch back to master\n>>> ```\n>>> $ git switch -C 'issue#1234>/tmp/dangerfile'\n>>> Switched to a new branch 'issue#1234>/tmp/dangerfile'\n>>> $ git switch master\n>>> ```\n>>\n>> It’s too bad that git-check-ref-format(1) does not disallow `>`.\n>\n> Is it?  It looks like an outright bug in the completion code,\n> nothing more, to me.\n\nThat was an aside.\n"}]}