Re: [PATCH] symbolic-ref: check format of given reference
- From
Junio C Hamano <gitster@pobox.com>
- Date
- Jun 18, 2012, 17:10 UTC
- Message-ID
- <7vipeo4kcp.fsf@alter.siamese.dyndns.org>
- In-Reply-To
- <7vr4tc4lsc.fsf@alter.siamese.dyndns.org>
Junio C Hamano <gitster@pobox.com> writes:
Show 11 quoted lines
> From: Michael Schubert <mschub@elegosoft.com> > Date: Sun, 17 Jun 2012 22:26:37 +0200 > Subject: [PATCH] symbolic-ref: check format of given reference > > Currently, it's possible to update HEAD with a nonsense reference since > no strict validation is performed. Example: > > $ git symbolic-ref HEAD 'refs/heads/master > > > > > > '
It would be nice to add a new test or two to t1401. 1401.3 was already trying to catch a malformed reference with this test:
test_must_fail git symbolic-ref HEAD foo
and it did trigger thanks to the prefixcmp(argv[1], "refs/") test we already have. Probably something like
git symbolic-ref HEAD "refs/heads/.foo" git symbolic-ref HEAD "refs/heads/-foo"
would be a good start.
To make the latter _correctly_ work requires a bit of work, though. We should make sure all the check_refname_format() callers pass the full path to a ref, get rid of ALLOW_ONELEVEL, and redo commits like 6348624 (disallow branch names that start with a hyphen, 2010-09-14) and 4f0accd (tag: disallow '-' as tag name, 2011-05-10).
For that matter, shouldn't symbolic-ref be forbidden to point outside refs/heads/, not just restricted in refs/ like the current code does?