From: Jeff King Date: Sat, 18 Oct 2025 09:51:25 GMT Subject: Re: t7528-signed-commit-ssh.sh fails due to ssh-agent fails to start with ENAMETOOLONG Message-ID: <20251018095125.GE1060824@coredump.intra.peff.net> In-Reply-To: On Fri, Oct 17, 2025 at 10:42:17AM -0700, Junio C Hamano wrote: > Jeff King writes: > > > AFAICT, ssh-agent does not quote the path in its output. So for example: > > > > d='/tmp/has spaces' > > mkdir "$d" > > HOME=$d ssh-agent > > > > will produce: > > > > SSH_AUTH_SOCK=/tmp/has spaces/.ssh/agent/s.IcPuGe26YY.agent.6PtD3uhM4O; export SSH_AUTH_SOCK; > > > > which is nonsense to eval. > > So if $d were > > d='/tmp/has rm -rf in it' > > would that produce some interesting side effect? Yep. Somewhat terrifying, though I guess if an attacker controls your $HOME environment variable you probably have bigger worries. -Peff