git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] [COGITO] make cg-tag use git-check-ref-format

From
Junio C Hamano <junkio@cox.net>
Date
Dec 15, 2005, 23:38 UTC
Message-ID
<7vacf2lyn4.fsf@assigned-by-dhcp.cox.net>
In-Reply-To
<20051215222424.GA3094@steel.home>
Alex Riesen <raa.lkml@gmail.com> writes:
Show 10 quoted lines
> Junio C Hamano, Tue, Dec 13, 2005 19:41:27 +0100:
>> 
>> > Thank you both for the patch, but I'd be much more comfortable if at
>> > least quotes (both ' and "), backslashes, ? and * would be prohibited in
>> > the names as well.
>> 
>> I second that, and thanks for pointing it out.  Any objections?
>
> Just as a warning, perhaps? It's not like git is anywhere limited in
> this respect...
Yeah, after thinking about it a bit more, I changed my mind.

The wildcard letters like ? and * I understand and sympathetic about somewhat. Something like this:

        name="*.sh" ;# this also comes from the end user
        echo $name

ends up showing every shell script in the current directory, and not literal '*.sh'.

However, I do not think covering five characters '"\?* gives us anything, and sends a strong message that we do not know our shell programming to whoever is reading our code. For one thing, the user can still say "foo[a-z]bar" to confuse you, so you also need to forbid [].

The thing is, if you start to care about single and double quotes, then what you are doing carelessly is not something simple like this:

	name='frotz'\''nitfol"filfre\xyzzy' ;# this comes from the end user.
	echo $name ;# and this prints just fine.

For quotes to matter, you must be doing an "eval" carelessly, and "eval" and careless should never go together.

        # do not try this in your repository without echo
	name="foo; echo rm -fr ."
        eval "git-rev-parse $name" 

You end up needing to forbid a lot more than the quoting and wildcard, if you want to keep your shell scripts loose and lazy; which may be a worthy goal in itself but pretty much defeats the initial discussion of "why do we allow only these characters in tags".

So in short, I am somewhat negative about the idea of adding more "forbidden letters". Let's make sure our scripts are careful where safety matters.

Note that this does not forbid Porcelains to enforce additional restrictions on their own.

Previous: Alex RiesenNext: Junio C Hamano
Message 7 of 9 in “[COGITO] make cg-tag use git-check-ref-format”
  1. [COGITO] make cg-tag use git-check-ref-formatMartin Atukunda, Dec 13, 2005
  2. Junio C HamanoDec 13, 2005
  3. Martin AtukundaDec 13, 2005
  4. Petr BaudisDec 13, 2005
  5. Junio C HamanoDec 13, 2005
  6. Alex RiesenDec 15, 2005
  7. Junio C HamanoDec 15, 2005
  8. Junio C HamanoDec 16, 2005
  9. Petr BaudisDec 16, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.