git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 1/2] Custom low-level merge driver support.

From
Johannes Sixt <j.sixt@eudaptics.com>
Date
Apr 18, 2007, 10:36 UTC
Message-ID
<4625F4AD.5CDDC502@eudaptics.com>
In-Reply-To
<1176888062865-git-send-email-junkio@cox.net>
Junio C Hamano wrote:
Show 8 quoted lines
> +       interpolate(cmdbuf, sizeof(cmdbuf), cmd, table, 3);
> +
> +       memset(&child, 0, sizeof(child));
> +       child.argv = args;
> +       args[0] = "sh";
> +       args[1] = "-c";
> +       args[2] = cmdbuf;
> +       args[3] = NULL;

If I read the code correctly, there does not happen any shell quoting anywhere; hence, this shell invocation is dangerous.

-- Hannes
Previous: Junio C HamanoNext: Johannes Schindelin
Message 3 of 23 in “Custom low-level merge driver support.”
  1. 0/2 Custom low-level merge driver support.Junio C Hamano, Apr 18, 2007
  2. 1/2 Custom low-level merge driver support.Junio C Hamano, Apr 18, 2007
  3. Johannes SixtApr 18, 2007
  4. Johannes SchindelinApr 18, 2007
  5. 2/2 Allow the default low-level merge driver to be configured.Junio C Hamano, Apr 18, 2007
  6. Johannes SchindelinApr 18, 2007
  7. Martin WaitzApr 18, 2007
  8. Junio C HamanoApr 18, 2007
  9. Martin WaitzApr 18, 2007
  10. Linus TorvaldsApr 18, 2007
  11. Junio C HamanoApr 18, 2007
  12. Linus TorvaldsApr 18, 2007
  13. Junio C HamanoApr 18, 2007
  14. Junio C HamanoApr 18, 2007
  15. Linus TorvaldsApr 18, 2007
  16. Linus TorvaldsApr 18, 2007
  17. Junio C HamanoApr 18, 2007
  18. Linus TorvaldsApr 18, 2007
  19. David LangApr 18, 2007
  20. Junio C HamanoApr 18, 2007
  21. Martin WaitzApr 19, 2007
  22. Junio C HamanoApr 19, 2007
  23. Custom low-level merge driver: change the configuration scheme.Junio C Hamano, Apr 18, 2007

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.