git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git log -p unexpected behaviour - security risk?

From
John Tapsell <johnflux@gmail.com>
Date
Apr 21, 2013, 08:56 UTC
Message-ID
<CAHQ6N+pKb-44rOM7ocYMvSDyimvAGZppX1Gc=st59aVKzJSBKw@mail.gmail.com>
In-Reply-To
<7vd2towdiq.fsf@alter.siamese.dyndns.org>
On 21 April 2013 08:26, Junio C Hamano <gitster@pobox.com> wrote:
Show 21 quoted lines
> Simon Ruderich <simon@ruderich.org> writes:
>
>> diff --git a/Documentation/diff-options.txt b/Documentation/diff-options.txt
>> index 104579d..cd35ec7 100644
>> --- a/Documentation/diff-options.txt
>> +++ b/Documentation/diff-options.txt
>> @@ -24,6 +24,10 @@ ifndef::git-format-patch[]
>>  --patch::
>>       Generate patch (see section on generating patches).
>>       {git-diff? This is the default.}
>> +ifdef::git-log[]
>> +     Changes introduced in merge commits are not displayed. Use `-c`,
>> +     `--cc` or `-m` to include them.
>> +endif::git-log[]
>
> It probably is a better change to drop "Use `-c`..." and refer to
> the "Diff formatting" section.
>
> And then add '-p' and the fact that by default it will not show
> pairwise diff for merge commits to the "Diff Formatting" section.
> That is where -c/--cc/-m are already described.
Why not have it in both places?  This is really important.

I'm concerned that noone is taking this security risk seriously. Just because it doesn't show up in certain workflows doesn't make the risk go away.

What about all the people who use git internally? They aren't using github and almost certainly aren't using a mail based system.

It's bad that we can't even set the right behaviour as a default.
John
Previous: Junio C HamanoNext: Jonathan Nieder
Message 5 of 22 in “git log -p unexpected behaviour - security risk?”
  1. John TapsellApr 11, 2013
  2. Tay Ray ChuanApr 11, 2013
  3. Simon RuderichApr 20, 2013
  4. Junio C HamanoApr 21, 2013
  5. John TapsellApr 21, 2013
  6. Jonathan NiederApr 21, 2013
  7. John TapsellApr 21, 2013
  8. Thomas RastApr 21, 2013
  9. Jonathan NiederApr 21, 2013
  10. Junio C HamanoApr 21, 2013
  11. John SzakmeisterApr 30, 2013
  12. Junio C HamanoApr 30, 2013
  13. John SzakmeisterApr 30, 2013
  14. Matthieu MoyApr 30, 2013
  15. John SzakmeisterApr 30, 2013
  16. John TapsellApr 30, 2013
  17. Junio C HamanoApr 30, 2013
  18. John TapsellApr 30, 2013
  19. Junio C HamanoApr 30, 2013
  20. John TapsellMay 1, 2013
  21. shawn wilsonApr 30, 2013
  22. Junio C HamanoApr 21, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.