From: Petr Baudis Date: Tue, 13 Dec 2005 17:00:15 GMT Subject: Re: [PATCH] [COGITO] make cg-tag use git-check-ref-format Message-ID: <20051213170015.GD22159@pasky.or.cz> In-Reply-To: <7vy82p9rnb.fsf@assigned-by-dhcp.cox.net> Dear diary, on Tue, Dec 13, 2005 at 12:13:12PM CET, I got a letter where Junio C Hamano said that... > Martin Atukunda writes: > > > The egrep pattern used by cg-tag is too restrictive. While it will prevent > > control characters from being specified as a tag name, it will also reject > > nearly anything written in a non-English language, as noted by -hpa > >... > > -(echo $name | egrep -qv '[^a-zA-Z0-9_.@!:-]') || \ > > +git-check-ref-format $name || \ > > die "name contains invalid characters" > > Perhaps you meant to say: > > git-check-ref-format "$name" > > instead; after all you are dealing with potentially garbage > input from the user here. > > While you are at it, you might want to also quote $_git/refs/tags > immediately follows the part that you patched, and there is > another. Thank you both for the patch, but I'd be much more comfortable if at least quotes (both ' and "), backslashes, ? and * would be prohibited in the names as well. Any chance of also implementing this policy upstream? Taken to the extreme, using such a names for tags might be perceived as a possible security vulnerability wrt. the less shell-savy users. ;-) -- Petr "Pasky" Baudis Stuff: http://pasky.or.cz/ VI has two modes: the one in which it beeps and the one in which it doesn't.