Re: t7528-signed-commit-ssh.sh fails due to ssh-agent fails to start with ENAMETOOLONG
- From
Jeff King <peff@peff.net>
- Date
- Oct 18, 2025, 09:51 UTC
- Message-ID
- <20251018095125.GE1060824@coredump.intra.peff.net>
- In-Reply-To
- <xmqqbjm51l3a.fsf@gitster.g>
On Fri, Oct 17, 2025 at 10:42:17AM -0700, Junio C Hamano wrote:
Show 19 quoted lines
> Jeff King <peff@peff.net> writes: > > > AFAICT, ssh-agent does not quote the path in its output. So for example: > > > > d='/tmp/has spaces' > > mkdir "$d" > > HOME=$d ssh-agent > > > > will produce: > > > > SSH_AUTH_SOCK=/tmp/has spaces/.ssh/agent/s.IcPuGe26YY.agent.6PtD3uhM4O; export SSH_AUTH_SOCK; > > > > which is nonsense to eval. > > So if $d were > > d='/tmp/has rm -rf in it' > > would that produce some interesting side effect?
Yep. Somewhat terrifying, though I guess if an attacker controls your $HOME environment variable you probably have bigger worries.
-Peff