git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: pathspec: problems with too long command line

From
Jeff King <peff@peff.net>
Date
Nov 21, 2018, 13:21 UTC
Message-ID
<20181121132152.GA8246@sigill.intra.peff.net>
In-Reply-To
<c3be6eff-365b-96b8-16d2-0528612fc1fc@syntevo.com>
On Wed, Nov 21, 2018 at 10:23:34AM +0100, Marc Strapetz wrote:
Show 13 quoted lines
> From our GUI client we are invoking git operations on a possibly large set
> of files. This may result in pathspecs which are exceeding the maximum
> command line length, especially on Windows [1] and OSX [2]. To workaround
> this problem we are currently splitting up such operations by invoking
> multiple git commands. This works well for some commands (like add), but
> doesn't work well for others (like commit).
> 
> A possible solution could be to add another patchspec magic word which will
> read paths from a file instead of command line. A similar approach can be
> found in Mercurial with its "listfile:" pattern [3].
> 
> Does that sound reasonable? If so, we should be able to provide a
> corresponding patch.

Quite a few commands take --stdin, which can be used to send pathspecs (and often other stuff) without size limits. I don't think either "commit" or "add" does, but that might be another route.

I'm slightly nervous at a pathspec that starts reading arbitrary files, because I suspect there may be interesting ways to abuse it for services which expose Git. E.g., if I have a web service which can show the history of a file, I might take a $file parameter from the client and run "git rev-list -- $file" (handling shell quoting, of course). That's OK now, but with the proposed pathspec magic, a malicious user could ask for ":(from-file=/etc/passwd)" or whatever.

I dunno. Maybe that is overly paranoid, and certainly servers like that are a subset of users. And perhaps such servers should be specifying GIT_LITERAL_PATHSPECS=1 anyway.

-Peff
Previous: Marc StrapetzNext: Junio C Hamano
Message 2 of 4 in “pathspec: problems with too long command line”
  1. Marc StrapetzNov 21, 2018
  2. Jeff KingNov 21, 2018
  3. Junio C HamanoNov 21, 2018
  4. Marc StrapetzNov 21, 2018

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.