git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git ate my home directory :-(

From
Ddemerphq <demerphq@gmail.com>
Date
Mar 26, 2013, 19:08 UTC
Message-ID
<CANgJU+U-M9zUUzRNJ=r=Utp7BMhGO37wDQAx8et0W23P3CTegA@mail.gmail.com>
In-Reply-To
<20130326174804.GB10383@sigill.intra.peff.net>
On 26 March 2013 18:48, Jeff King <peff@peff.net> wrote:
Show 14 quoted lines
> On Tue, Mar 26, 2013 at 06:20:09PM +0100, demerphq wrote:
>
>> Seconded. At $work lots of people started asking anxious questions
>> about this. It was suggested it is a potential security hole, although
>> I am not sure I agree, but the general idea being that if you could
>> manage to set this var in someones environment then they might use git
>> to do real damage to a system. (The counterargument being that if you
>> can set that in someones environment you can do worse already... But
>> im a not a security type so I cant say)
>
> IMHO, that is just silly. Setting GIT_WORK_TREE=/ would be just as
> destructive. Or GIT_EXTERNAL_DIFF="rm -rf /" (or GIT_PAGER, etc).
> If there is a danger to the implicit-workdir behavior, it is due to
> accidental usage, not from a malicious attack.
Yeah, that was my line of reasoning too. I'm glad to hear you agree.

cheers Yves

-- 
perl -Mre=debug -e "/just|another|perl|hacker/"
Previous: Jeff KingNext: Jeff King
Message 24 of 35 in “git ate my home directory :-(”
  1. Richard WeinbergerMar 25, 2013
  2. Jonathan NiederMar 25, 2013
  3. Junio C HamanoMar 25, 2013
  4. Jonathan NiederMar 25, 2013
  5. Junio C HamanoMar 25, 2013
  6. Junio C HamanoMar 25, 2013
  7. Richard WeinbergerMar 25, 2013
  8. Jonathan NiederMar 25, 2013
  9. Junio C HamanoMar 25, 2013
  10. Richard WeinbergerMar 25, 2013
  11. Jonathan NiederMar 25, 2013
  12. Brandon CaseyMar 25, 2013
  13. Philip OakleyMar 26, 2013
  14. Duy NguyenMar 26, 2013
  15. Jeff KingMar 26, 2013
  16. Junio C HamanoMar 26, 2013
  17. Duy NguyenMar 27, 2013
  18. Philip OakleyMar 26, 2013
  19. Richard WeinbergerMar 26, 2013
  20. Jeff KingMar 26, 2013
  21. Richard WeinbergerMar 26, 2013
  22. demerphqMar 26, 2013
  23. Jeff KingMar 26, 2013
  24. demerphqMar 26, 2013
  25. Jeff KingMar 26, 2013
  26. Junio C HamanoMar 26, 2013
  27. Jeff KingMar 26, 2013
  28. 1/3 environment: set GIT_WORK_TREE when we figure out work treeJeff King, Mar 26, 2013
  29. Jonathan NiederMar 26, 2013
  30. 2/3 setup: warn about implicit worktree with $GIT_DIRJeff King, Mar 26, 2013
  31. Jonathan NiederMar 26, 2013
  32. Jeff KingMar 26, 2013
  33. Jonathan NiederMar 26, 2013
  34. Matthieu MoyMar 27, 2013
  35. 3/3 setup: treat GIT_DIR without GIT_WORK_TREE as a bare repoJeff King, Mar 26, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.