git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] [COGITO] make cg-tag use git-check-ref-format

From
Petr Baudis <pasky@suse.cz>
Date
Dec 13, 2005, 17:00 UTC
Message-ID
<20051213170015.GD22159@pasky.or.cz>
In-Reply-To
<7vy82p9rnb.fsf@assigned-by-dhcp.cox.net>

Dear diary, on Tue, Dec 13, 2005 at 12:13:12PM CET, I got a letter where Junio C Hamano <junkio@cox.net> said that...

Show 20 quoted lines
> Martin Atukunda <matlads@dsmagic.com> writes:
> 
> > The egrep pattern used by cg-tag is too restrictive. While it will prevent
> > control characters from being specified as a tag name, it will also reject
> > nearly anything written in a non-English language, as noted by -hpa
> >...
> > -(echo $name | egrep -qv '[^a-zA-Z0-9_.@!:-]') || \
> > +git-check-ref-format $name || \
> >  	die "name contains invalid characters"
> 
> Perhaps you meant to say:
> 
> 	git-check-ref-format "$name"
> 
> instead; after all you are dealing with potentially garbage
> input from the user here.
> 
> While you are at it, you might want to also quote $_git/refs/tags
> immediately follows the part that you patched, and there is
> another.

Thank you both for the patch, but I'd be much more comfortable if at least quotes (both ' and "), backslashes, ? and * would be prohibited in the names as well. Any chance of also implementing this policy upstream? Taken to the extreme, using such a names for tags might be perceived as a possible security vulnerability wrt. the less shell-savy users. ;-)

-- 
				Petr "Pasky" Baudis
Stuff: http://pasky.or.cz/
VI has two modes: the one in which it beeps and the one in which
it doesn't.
Previous: Martin AtukundaNext: Junio C Hamano
Message 4 of 9 in “[COGITO] make cg-tag use git-check-ref-format”
  1. [COGITO] make cg-tag use git-check-ref-formatMartin Atukunda, Dec 13, 2005
  2. Junio C HamanoDec 13, 2005
  3. Martin AtukundaDec 13, 2005
  4. Petr BaudisDec 13, 2005
  5. Junio C HamanoDec 13, 2005
  6. Alex RiesenDec 15, 2005
  7. Junio C HamanoDec 15, 2005
  8. Junio C HamanoDec 16, 2005
  9. Petr BaudisDec 16, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.