git/list[1] front-page[2] threads[3] people[4] search[5] about
 

bash: unescaped `>` character when switching branches

From
Ondrej Pohorelsky <opohorel@redhat.com>
Date
Jun 24, 2025, 12:59 UTC
Message-ID
<CA+B51BHEB24JNzOroTxFodxiuPJ1=Vj7KRFevrm2YatnTVuoYA@mail.gmail.com>
Hi,

Our customer has found a possible issue when switching branches. Output redirection character `>` is not escaped properly when switching/checking out to different branch.

Steps to reproduce:
1. Create a new branch and switch back to master
```
$ git switch -C 'issue#1234>/tmp/dangerfile'
Switched to a new branch 'issue#1234>/tmp/dangerfile'
$ git switch master
```
2. Try to switch to the created branch with using auto-completion
```
git switch i<TAB>
$ git switch issue#1234>/tmp/dangerfile
fatal: invalid reference: issue#1234
```
3. Verify that the /tmp/dangerfile has been created
```
$ ls /tmp/dangerfile
/tmp/dangerfile
```
Internal interpretation of the created branch:
└── refs
    ├── heads
    │   ├── issue#1234>
    │   │   └── tmp
    │   │       └── dangerfile
Tested on Fedora 42 with git-2.49.

I've found out that this behavior happens only when using Bash. Zsh properly escapes the characters when creating and switching to the branch. Git shouldn't be tricked into creating a file when the user is switching branches. I'm not entirely sure where the issue lies in the code, so I'm not attaching any patch fixing this.

-- 
Ondřej Pohořelský

Software Engineer

Red Hat

opohorel@redhat.com
Next: Kristoffer Haugsbakk
Message 1 of 5 in “bash: unescaped `>` character when switching branches”
  1. Ondrej PohorelskyJun 24, 2025
  2. Kristoffer HaugsbakkJun 25, 2025
  3. Phillip WoodJun 25, 2025
  4. Kristoffer HaugsbakkJun 25, 2025
  5. Junio C HamanoJun 25, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.