{"thread":{"id":"65510","subject":"[PATCH] t6112: avoid tilde expansion","startedAt":"2026-04-18T16:32:45Z","lastAt":"2026-04-21T19:21:58Z","messageCount":4,"participants":["SZEDER Gábor","Elijah Newren"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"541863","messageId":"20260418163236.2382826-1-szeder.dev@gmail.com","threadId":"65510","inReplyTo":null,"subject":"[PATCH] t6112: avoid tilde expansion","fromName":"SZEDER Gábor","fromEmail":"szeder.dev@gmail.com","sentAt":"2026-04-18T16:32:36Z","receivedAt":"2026-04-18T16:32:45Z","isPatch":true,"body":"e987df5fe6 (list-objects-filter: implement composite filters,\n2019-06-27) introduced a test to \"t6112-rev-list-filters-objects.sh\"\nthat checks the output of a Git command with the following commands:\n\n  grep ~$omitted_1 actual &&\n  grep ~$omitted_2 actual &&\n  grep ~$omitted_3 actual &&\n\nSince the leading tilde in the pattern is not quoted/escaped, it is\nsubject to tilde expansion.  So if the system has a user whose\nusername happens to be equal to the content of one of those\n\"$omitted_*\" variables, then \"grep\" would look for the user's home\ndirectory.  Luckily, those variables contain object hashes, so this is\nnot very likely.\n\nFurthermore, Bash versions v5.0 and earlier seem to be buggy and don't\nhandle this particular tilde expansion very well, and either segfault\nright away or, in case of v3.2, get stuck in an endless loop and\nsegfault upon receiving ctrl-c.\n\nQuote those words starting with a tilde to avoid these issues.\n\nSigned-off-by: SZEDER Gábor <szeder.dev@gmail.com>\n---\n t/t6112-rev-list-filters-objects.sh | 6 +++---\n 1 file changed, 3 insertions(+), 3 deletions(-)\n\ndiff --git a/t/t6112-rev-list-filters-objects.sh b/t/t6112-rev-list-filters-objects.sh\nindex 39211ef989..e0a825bccf 100755\n--- a/t/t6112-rev-list-filters-objects.sh\n+++ b/t/t6112-rev-list-filters-objects.sh\n@@ -623,9 +623,9 @@ test_expect_success 'verify collecting omits in combined: filter' '\n \tomitted_2=$(echo a     | git hash-object --stdin) &&\n \tomitted_3=$(echo abcde | git hash-object --stdin) &&\n \n-\tgrep ~$omitted_1 actual &&\n-\tgrep ~$omitted_2 actual &&\n-\tgrep ~$omitted_3 actual &&\n+\tgrep \"~$omitted_1\" actual &&\n+\tgrep \"~$omitted_2\" actual &&\n+\tgrep \"~$omitted_3\" actual &&\n \ttest_line_count = 3 actual\n '\n \n-- \n2.54.0.rc2.650.gc37764ecfc\n\n"},{"id":"541878","messageId":"CABPp-BGV4DGwoSDCjjW2NWBhWXNDfeXwb-tPWSH_13mF0DCiRg@mail.gmail.com","threadId":"65510","inReplyTo":"20260418163236.2382826-1-szeder.dev@gmail.com","subject":"Re: [PATCH] t6112: avoid tilde expansion","fromName":"Elijah Newren","fromEmail":"newren@gmail.com","sentAt":"2026-04-19T01:26:00Z","receivedAt":"2026-04-19T01:26:03Z","isPatch":true,"body":"On Sat, Apr 18, 2026 at 9:33 AM SZEDER Gábor <szeder.dev@gmail.com> wrote:\n>\n> e987df5fe6 (list-objects-filter: implement composite filters,\n> 2019-06-27) introduced a test to \"t6112-rev-list-filters-objects.sh\"\n> that checks the output of a Git command with the following commands:\n>\n>   grep ~$omitted_1 actual &&\n>   grep ~$omitted_2 actual &&\n>   grep ~$omitted_3 actual &&\n>\n> Since the leading tilde in the pattern is not quoted/escaped, it is\n> subject to tilde expansion.  So if the system has a user whose\n> username happens to be equal to the content of one of those\n> \"$omitted_*\" variables, then \"grep\" would look for the user's home\n> directory.  Luckily, those variables contain object hashes, so this is\n> not very likely.\n>\n> Furthermore, Bash versions v5.0 and earlier seem to be buggy and don't\n> handle this particular tilde expansion very well, and either segfault\n> right away or, in case of v3.2, get stuck in an endless loop and\n> segfault upon receiving ctrl-c.\n\nInteresting find on the bash segfault behavior.\n\n> Quote those words starting with a tilde to avoid these issues.\n>\n> Signed-off-by: SZEDER Gábor <szeder.dev@gmail.com>\n> ---\n>  t/t6112-rev-list-filters-objects.sh | 6 +++---\n>  1 file changed, 3 insertions(+), 3 deletions(-)\n>\n> diff --git a/t/t6112-rev-list-filters-objects.sh b/t/t6112-rev-list-filters-objects.sh\n> index 39211ef989..e0a825bccf 100755\n> --- a/t/t6112-rev-list-filters-objects.sh\n> +++ b/t/t6112-rev-list-filters-objects.sh\n> @@ -623,9 +623,9 @@ test_expect_success 'verify collecting omits in combined: filter' '\n>         omitted_2=$(echo a     | git hash-object --stdin) &&\n>         omitted_3=$(echo abcde | git hash-object --stdin) &&\n>\n> -       grep ~$omitted_1 actual &&\n> -       grep ~$omitted_2 actual &&\n> -       grep ~$omitted_3 actual &&\n> +       grep \"~$omitted_1\" actual &&\n> +       grep \"~$omitted_2\" actual &&\n> +       grep \"~$omitted_3\" actual &&\n>         test_line_count = 3 actual\n>  '\n>\n> --\n> 2.54.0.rc2.650.gc37764ecfc\n\nLooks good to me.  I wasn't able to find any other unquoted ~$ uses in\nthe testsuite except mid-word (e.g. HEAD~$i), though I suspect your\nversion of bash seg-faulting is a better check than my grep-fu anyway.\n"},{"id":"541992","messageId":"aeaSAMOqg5RzfdIA@szeder.dev","threadId":"65510","inReplyTo":"CABPp-BGV4DGwoSDCjjW2NWBhWXNDfeXwb-tPWSH_13mF0DCiRg@mail.gmail.com","subject":"Re: [PATCH] t6112: avoid tilde expansion","fromName":"SZEDER Gábor","fromEmail":"szeder.dev@gmail.com","sentAt":"2026-04-20T20:52:16Z","receivedAt":"2026-04-20T20:52:42Z","isPatch":true,"body":"On Sat, Apr 18, 2026 at 06:26:00PM -0700, Elijah Newren wrote:\n> On Sat, Apr 18, 2026 at 9:33 AM SZEDER Gábor <szeder.dev@gmail.com> wrote:\n> >\n> > e987df5fe6 (list-objects-filter: implement composite filters,\n> > 2019-06-27) introduced a test to \"t6112-rev-list-filters-objects.sh\"\n> > that checks the output of a Git command with the following commands:\n> >\n> >   grep ~$omitted_1 actual &&\n> >   grep ~$omitted_2 actual &&\n> >   grep ~$omitted_3 actual &&\n> >\n> > Since the leading tilde in the pattern is not quoted/escaped, it is\n> > subject to tilde expansion.  So if the system has a user whose\n> > username happens to be equal to the content of one of those\n> > \"$omitted_*\" variables, then \"grep\" would look for the user's home\n> > directory.  Luckily, those variables contain object hashes, so this is\n> > not very likely.\n\nOn second thought, tilde expansion should happen before\nparameter/variable expansion, so the above is wrong: we are looking\nfor a user named \"$omitted_1\" and not a user named like whatever\nobject hash the \"$omitted_1\" variable holds.\n\nStill unlikely, but we should still avoid it.\n\n> > Furthermore, Bash versions v5.0 and earlier seem to be buggy and don't\n> > handle this particular tilde expansion very well, and either segfault\n> > right away or, in case of v3.2, get stuck in an endless loop and\n> > segfault upon receiving ctrl-c.\n> \n> Interesting find on the bash segfault behavior.\n\nActually, I'm going to take back that statement about the Bash\nsegfault.\n\nI tested older Bash versions with binaries that I compiled myself from\nthe sources at git://git.savannah.gnu.org/bash.git, and those\nexhibited the segfault in v5.0 and below.  Bisect shows that v5.1 is\nnot just the first release but the first commit that doesn't segfault\non t6112.\n\nHowever.\n\nBash v5.1 was released on 2020-12-06, about a year and a half after\nthose unintended tilde expansions were added.  I find it hard to\nbelieve that noone stumbled upon this issue during that time...\nSuspicious, I booted my old laptop running an outdated Debian\nderivative with distro shipped Bash 5.0.17, and, lo and behold, t6112\npassed just fine.\n\nSo I'm inclined to think that something is wrong here...  No idea\nwhat, though.  I can reproduce the segfault with something as simple\nas \"./bash-v5.0 -c 'v=~a'\", and the segfault doesn't even come from\nBash but from within getpwnam() called during tilde expansion.\nOh, well.\n\nWill send a patch with updated log message some time later.\n\n"},{"id":"542053","messageId":"20260421192132.51172-1-szeder.dev@gmail.com","threadId":"65510","inReplyTo":"20260418163236.2382826-1-szeder.dev@gmail.com","subject":"[PATCH v2] t6112: avoid tilde expansion","fromName":"SZEDER Gábor","fromEmail":"szeder.dev@gmail.com","sentAt":"2026-04-21T19:21:32Z","receivedAt":"2026-04-21T19:21:58Z","isPatch":true,"body":"e987df5fe6 (list-objects-filter: implement composite filters,\n2019-06-27) introduced a test to \"t6112-rev-list-filters-objects.sh\"\nthat checks the output of a Git command with the following commands:\n\n  grep ~$omitted_1 actual &&\n  grep ~$omitted_2 actual &&\n  grep ~$omitted_3 actual &&\n\nSince the leading tilde in the pattern is not quoted/escaped, it is\nsubject to tilde expansion.  So if the system has a user whose\nusername happens to be \"$omitted_1\", then \"grep\" would look for that\nuser's home directory.\n\nQuote those words starting with a tilde to avoid this.\n\nSigned-off-by: SZEDER Gábor <szeder.dev@gmail.com>\n---\nSame diff, updated commit message.\n\n t/t6112-rev-list-filters-objects.sh | 6 +++---\n 1 file changed, 3 insertions(+), 3 deletions(-)\n\ndiff --git a/t/t6112-rev-list-filters-objects.sh b/t/t6112-rev-list-filters-objects.sh\nindex 39211ef989..e0a825bccf 100755\n--- a/t/t6112-rev-list-filters-objects.sh\n+++ b/t/t6112-rev-list-filters-objects.sh\n@@ -623,9 +623,9 @@ test_expect_success 'verify collecting omits in combined: filter' '\n \tomitted_2=$(echo a     | git hash-object --stdin) &&\n \tomitted_3=$(echo abcde | git hash-object --stdin) &&\n \n-\tgrep ~$omitted_1 actual &&\n-\tgrep ~$omitted_2 actual &&\n-\tgrep ~$omitted_3 actual &&\n+\tgrep \"~$omitted_1\" actual &&\n+\tgrep \"~$omitted_2\" actual &&\n+\tgrep \"~$omitted_3\" actual &&\n \ttest_line_count = 3 actual\n '\n \n-- \n2.54.0.655.g69726bb9dc\n\n"}]}