git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git log -p unexpected behaviour - security risk?

From
Tay Ray Chuan <rctay89@gmail.com>
Date
Apr 11, 2013, 15:19 UTC
Message-ID
<CALUzUxrp4+S-Nm-Scb9sT9sBw1mLEb3-CBc_P0KqL20qNmFO3w@mail.gmail.com>
In-Reply-To
<CAHQ6N+qdA5Lck1_ByOYPOG4ngsztz3HQSw8c_U_K8OnDapj4bQ@mail.gmail.com>
On Thu, Apr 11, 2013 at 6:36 PM, John Tapsell <johnflux@gmail.com> wrote:
Show 13 quoted lines
>   I noticed that code that you put in merge will not be visible by
> default.  This seems like a pretty horrible security problem, no?
>
> I made the following test tree, with just 3 commits:
>
> https://github.com/johnflux/ExampleEvilness.git
>
> Doing "git log -p"  shows all very innocent commits.  Completely
> hidden is the change to add "EVIL CODE MUWHAHAHA".
>
> This seems really dangerous!
>
> The evil code only shows up with the non-default  --cc or -m  option.

For email-based patch workflows (eg. git, linux kernel), then this is not a problem - the diff doesn't even show up, so nothing is applied when git-am is run.

For github with pull-requests, a diff is shown between trees, so this will show up.

-- Cheers, Ray Chuan

Previous: John TapsellNext: Simon Ruderich
Message 2 of 22 in “git log -p unexpected behaviour - security risk?”
  1. John TapsellApr 11, 2013
  2. Tay Ray ChuanApr 11, 2013
  3. Simon RuderichApr 20, 2013
  4. Junio C HamanoApr 21, 2013
  5. John TapsellApr 21, 2013
  6. Jonathan NiederApr 21, 2013
  7. John TapsellApr 21, 2013
  8. Thomas RastApr 21, 2013
  9. Jonathan NiederApr 21, 2013
  10. Junio C HamanoApr 21, 2013
  11. John SzakmeisterApr 30, 2013
  12. Junio C HamanoApr 30, 2013
  13. John SzakmeisterApr 30, 2013
  14. Matthieu MoyApr 30, 2013
  15. John SzakmeisterApr 30, 2013
  16. John TapsellApr 30, 2013
  17. Junio C HamanoApr 30, 2013
  18. John TapsellApr 30, 2013
  19. Junio C HamanoApr 30, 2013
  20. John TapsellMay 1, 2013
  21. shawn wilsonApr 30, 2013
  22. Junio C HamanoApr 21, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.