git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [SECURITY PATCH] git-prompt.sh: don't put unsanitized branch names in $PS1

From
RHRichard Hansen <rhansen@bbn.com>
Date
Apr 21, 2014, 22:58 UTC
Message-ID
<5355A280.6020409@bbn.com>
In-Reply-To
<xmqq1twq8g91.fsf@gitster.dls.corp.google.com>
On 2014-04-21 18:33, Junio C Hamano wrote:
Show 26 quoted lines
> Junio C Hamano <gitster@pobox.com> writes:
> 
>> Richard Hansen <rhansen@bbn.com> writes:
>>
>>> Both bash and zsh subject the value of PS1 to parameter expansion,
>>> command substitution, and arithmetic expansion.  Rather than include
>>> the raw, unescaped branch name in PS1 when running in two- or
>>> three-argument mode, construct PS1 to reference a variable that holds
>>> the branch name.  Because the shells do not recursively expand, this
>>> avoids arbitrary code execution by specially-crafted branch names such
>>> as '$(IFS=_;cmd=sudo_rm_-rf_/;$cmd)'.
>>>
>>> Signed-off-by: Richard Hansen <rhansen@bbn.com>
>>
>> I'd like to see this patch eyeballed by those who have been involved
>> in the script (shortlog and blame tells me they are SZEDER and
>> Simon, CC'ed), so that we can hopefully merge it by the time -rc1 is
>> tagged.
>>
>> Will queue so that I won't lose it in the meantime.
>>
>> Thanks.
> 
> Sadly, this does not seem to pass t9903.41 for me.
> 
>     $ bash t9903-*.sh -i -v

Oops! Because git-prompt.sh is in contrib I didn't realize there was a test for it.

The test will have to change. I'll think about the best way to adjust the test and send a reroll.

Thanks, Richard

Previous: Junio C HamanoNext: Richard Hansen
Message 10 of 11 in “git-prompt.sh: don't put unsanitized branch names in $PS1”
  1. git-prompt.sh: don't put unsanitized branch names in $PS1Richard Hansen, Apr 21, 2014
  2. Jeff KingApr 21, 2014
  3. Richard HansenApr 21, 2014
  4. Michael HaggertyApr 22, 2014
  5. Junio C HamanoApr 22, 2014
  6. Richard HansenApr 22, 2014
  7. Junio C HamanoApr 22, 2014
  8. Junio C HamanoApr 21, 2014
  9. Junio C HamanoApr 21, 2014
  10. Richard HansenApr 21, 2014
  11. git-prompt.sh: don't put unsanitized branch names in $PS1Richard Hansen, Apr 21, 2014

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.