git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git log -p unexpected behaviour - security risk?

From
Thomas Rast <trast@inf.ethz.ch>
Date
Apr 21, 2013, 15:56 UTC
Message-ID
<8738ujubbs.fsf@hexa.v.cablecom.net>
In-Reply-To
<CAHQ6N+rXE42NOyQPfLiDN8jYfL8w06hEE5MFLeFNxMR4ORD0aw@mail.gmail.com>
John Tapsell <johnflux@gmail.com> writes:
Show 10 quoted lines
> On 21 April 2013 11:21, Jonathan Nieder <jrnieder@gmail.com> wrote:
>
>> A merge can completely
>> undo important changes made in a side branch and "-c" and "--cc" will
>> not show it.
>
> Wait, what?  This is getting even worse then!  Can you expand on this please?
>
> And then how do I show all of these important changes with a git log -p ?
> Or is it impossible to get a sane output?

It pretty much by definition does not show changes if the merge picks one side unchanged:

 -c
     [...] lists only files which were modified from all parents.
 --cc
     This flag implies the -c option and further compresses the patch
     output [...]

On top of that, the default history simplification when you specify a pathspec will only walk the (or any one) unchanged side of such a merge, so if you filter for a file you wouldn't even find the offending commit further back in history.

I don't think this can be improved easily with the current one-pass[1] history/diff generation. To know what the merge *should* have done, you'd need to somehow get an idea what parts of the resulting files should be affected, which AFAICS boils down to redoing the merge. And to do that, you need to scan history so far that you can compute the merge-bases. Not to mention that redoing all merges while walking history is somewhat expensive.

You could hack up a script that does the verification manually, by actually running a merge and comparing the result with what the merge gave you. But it's not something that you would want to run by default.

[1] some things like --simplify-merges are actually another pass, but the default is to generate everything -- including diffs -- as we go.

-- 
Thomas Rast
trast@{inf,student}.ethz.ch
Previous: John TapsellNext: Jonathan Nieder
Message 8 of 22 in “git log -p unexpected behaviour - security risk?”
  1. John TapsellApr 11, 2013
  2. Tay Ray ChuanApr 11, 2013
  3. Simon RuderichApr 20, 2013
  4. Junio C HamanoApr 21, 2013
  5. John TapsellApr 21, 2013
  6. Jonathan NiederApr 21, 2013
  7. John TapsellApr 21, 2013
  8. Thomas RastApr 21, 2013
  9. Jonathan NiederApr 21, 2013
  10. Junio C HamanoApr 21, 2013
  11. John SzakmeisterApr 30, 2013
  12. Junio C HamanoApr 30, 2013
  13. John SzakmeisterApr 30, 2013
  14. Matthieu MoyApr 30, 2013
  15. John SzakmeisterApr 30, 2013
  16. John TapsellApr 30, 2013
  17. Junio C HamanoApr 30, 2013
  18. John TapsellApr 30, 2013
  19. Junio C HamanoApr 30, 2013
  20. John TapsellMay 1, 2013
  21. shawn wilsonApr 30, 2013
  22. Junio C HamanoApr 21, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.