git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git log -p unexpected behaviour - security risk?

From
Jonathan Nieder <jrnieder@gmail.com>
Date
Apr 21, 2013, 10:21 UTC
Message-ID
<20130421102150.GJ10429@elie.Belkin>
In-Reply-To
<CAHQ6N+pKb-44rOM7ocYMvSDyimvAGZppX1Gc=st59aVKzJSBKw@mail.gmail.com>
John Tapsell wrote:
> I'm concerned that noone is taking this security risk seriously.

If anyone relies on "git log -p" or "git log -p --cc" output to make sure that the untrusted code they use doesn't introduce unwanted behavior, they are making a serious mistake. A merge can completely undo important changes made in a side branch and "-c" and "--cc" will not show it. The lack of "-c" cannot be a security issue here, because in normal life adding "-c" isn't a secure deployment strategy.

That's why if you want to review the code you are pulling in as a whole, it is worthwhile to do

	git diff HEAD...FETCH_HEAD

That is how you ask "What code changes does FETCH_HEAD introduce?" before putting your stamp of approval on them by merging and pushing out the result. Unfortunately that doesn't protect you from maliciously written commits that will be encountered when bisecting. At some point you have to be able to trust people.

Hope that helps, Jonathan

Previous: John TapsellNext: John Tapsell
Message 6 of 22 in “git log -p unexpected behaviour - security risk?”
  1. John TapsellApr 11, 2013
  2. Tay Ray ChuanApr 11, 2013
  3. Simon RuderichApr 20, 2013
  4. Junio C HamanoApr 21, 2013
  5. John TapsellApr 21, 2013
  6. Jonathan NiederApr 21, 2013
  7. John TapsellApr 21, 2013
  8. Thomas RastApr 21, 2013
  9. Jonathan NiederApr 21, 2013
  10. Junio C HamanoApr 21, 2013
  11. John SzakmeisterApr 30, 2013
  12. Junio C HamanoApr 30, 2013
  13. John SzakmeisterApr 30, 2013
  14. Matthieu MoyApr 30, 2013
  15. John SzakmeisterApr 30, 2013
  16. John TapsellApr 30, 2013
  17. Junio C HamanoApr 30, 2013
  18. John TapsellApr 30, 2013
  19. Junio C HamanoApr 30, 2013
  20. John TapsellMay 1, 2013
  21. shawn wilsonApr 30, 2013
  22. Junio C HamanoApr 21, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.