git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH 6/9] Validate @recipients before using it for sendmail and Net::SMTP.

From
Robin H. Johnson <robbat2@gentoo.org>
Date
Apr 26, 2007, 02:37 UTC
Message-ID
<11775550433329-git-send-email-robbat2@gentoo.org>
In-Reply-To
<11775550432746-git-send-email-robbat2@gentoo.org>
From: Robin H. Johnson <robbat2@gentoo.org>

Ensure that @recipients is only raw addresses when it is handed to the sendmail binary OR Net::SMTP, otherwise BCC cases might get an extra <, or wierd stuff might be passed to the exec.

Signed-off-by: Robin H. Johnson <robbat2@gentoo.org>
---
 git-send-email.perl |    3 ++-
 1 files changed, 2 insertions(+), 1 deletions(-)
diff --git a/git-send-email.perl b/git-send-email.perl
index c052760..0e1cc16 100755
--- a/git-send-email.perl
+++ b/git-send-email.perl
@@ -449,6 +449,7 @@ sub send_message
 	@cc = (map { sanitize_address_rfc822($_) } @cc);
 	my $to = join (",\n\t", @recipients);
 	@recipients = unique_email_list(@recipients,@cc,@bcclist);
+	@recipients = (map { extract_valid_address($_) } @recipients);
 	my $date = format_2822_time($time++);
 	my $gitversion = '@@GIT_VERSION@@';
 	if ($gitversion =~ m/..GIT_VERSION../) {
@@ -477,7 +478,7 @@ X-Mailer: git-send-email $gitversion
 		$header .= join("\n", @xh) . "\n";
 	}
 
-	my @sendmail_parameters = ('-i', map { extract_valid_address($_) } @recipients);
+	my @sendmail_parameters = ('-i', @recipients);
 
 	if ($dry_run) {
 		# We don't want to send the email.
-- 
1.5.2.rc0.43.g2f4c7
Previous: Robin H. JohnsonNext: Robin H. Johnson
Message 7 of 13 in “git-send-email fixes, cleanups and improvements”
  1. Robin H. JohnsonApr 26, 2007
  2. 1/9 Document --dry-run parameter to send-email.Robin H. Johnson, Apr 26, 2007
  3. 2/9 Prefix Dry- to the message status to denote dry-runs.Robin H. Johnson, Apr 26, 2007
  4. 3/9 Debugging cleanup improvementsRobin H. Johnson, Apr 26, 2007
  5. 4/9 Change the scope of the $cc variable as it is not needed outside of send_message.Robin H. Johnson, Apr 26, 2007
  6. 5/9 Perform correct quoting of recipient names.Robin H. Johnson, Apr 26, 2007
  7. 6/9 Validate @recipients before using it for sendmail and Net::SMTP.Robin H. Johnson, Apr 26, 2007
  8. 7/9 Ensure clean addresses are always used with Net::SMTPRobin H. Johnson, Apr 26, 2007
  9. 8/9 Allow users to optionally specify their envelope sender.Robin H. Johnson, Apr 26, 2007
  10. 9/9 Document --dry-run and envelope-sender for git-send-email.Robin H. Johnson, Apr 26, 2007
  11. Junio C HamanoApr 26, 2007
  12. Robin H. JohnsonApr 26, 2007
  13. 10/9 Sanitize @to recipients.Robin H. Johnson, Apr 26, 2007

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.