git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git log -p unexpected behaviour - security risk?

From
John Tapsell <johnflux@gmail.com>
Date
Apr 21, 2013, 13:46 UTC
Message-ID
<CAHQ6N+rXE42NOyQPfLiDN8jYfL8w06hEE5MFLeFNxMR4ORD0aw@mail.gmail.com>
In-Reply-To
<20130421102150.GJ10429@elie.Belkin>
On 21 April 2013 11:21, Jonathan Nieder <jrnieder@gmail.com> wrote:
Show 7 quoted lines
> John Tapsell wrote:
>
>> I'm concerned that noone is taking this security risk seriously.
>
> If anyone relies on "git log -p" or "git log -p --cc" output to make
> sure that the untrusted code they use doesn't introduce unwanted
> behavior, they are making a serious mistake.
Which is exactly my problem.

Go and ask the average person using git this very question, and I bet you the vast majority will not know about -cc etc.

You can't just push all the blame on the user for bad defaults. Hiding code changes is a bad default.

> A merge can completely
> undo important changes made in a side branch and "-c" and "--cc" will
> not show it.
Wait, what?  This is getting even worse then!  Can you expand on this please?

And then how do I show all of these important changes with a git log -p ? Or is it impossible to get a sane output?

>  The lack of "-c" cannot be a security issue here,
> because in normal life adding "-c" isn't a secure deployment strategy.
So, is it impossible to make git log -p a "secure deployment strategy" ?
> That's why if you want to review the code you are pulling in as a
> whole, it is worthwhile to do
>
>         git diff HEAD...FETCH_HEAD

Which basically means that you're asking the review the same code twice. Once that way, and once using git log -p (to check for the exact reason that you said).

>  Unfortunately that doesn't protect you from
> maliciously written commits that will be encountered when bisecting.
> At some point you have to be able to trust people.

Seriously? Your reasoning for awful defaults is that you should just trust people?

This is getting worse and worse!
John
Previous: Jonathan NiederNext: Thomas Rast
Message 7 of 22 in “git log -p unexpected behaviour - security risk?”
  1. John TapsellApr 11, 2013
  2. Tay Ray ChuanApr 11, 2013
  3. Simon RuderichApr 20, 2013
  4. Junio C HamanoApr 21, 2013
  5. John TapsellApr 21, 2013
  6. Jonathan NiederApr 21, 2013
  7. John TapsellApr 21, 2013
  8. Thomas RastApr 21, 2013
  9. Jonathan NiederApr 21, 2013
  10. Junio C HamanoApr 21, 2013
  11. John SzakmeisterApr 30, 2013
  12. Junio C HamanoApr 30, 2013
  13. John SzakmeisterApr 30, 2013
  14. Matthieu MoyApr 30, 2013
  15. John SzakmeisterApr 30, 2013
  16. John TapsellApr 30, 2013
  17. Junio C HamanoApr 30, 2013
  18. John TapsellApr 30, 2013
  19. Junio C HamanoApr 30, 2013
  20. John TapsellMay 1, 2013
  21. shawn wilsonApr 30, 2013
  22. Junio C HamanoApr 21, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.