Re: [PATCH 1/2] Custom low-level merge driver support.
- From
Johannes Schindelin <johannes.schindelin@gmx.de>
- Date
- Apr 18, 2007, 10:55 UTC
- Message-ID
- <Pine.LNX.4.64.0704181253350.12094@racer.site>
- In-Reply-To
- <4625F4AD.5CDDC502@eudaptics.com>
Hi,
On Wed, 18 Apr 2007, Johannes Sixt wrote:
Show 12 quoted lines
> Junio C Hamano wrote: > > + interpolate(cmdbuf, sizeof(cmdbuf), cmd, table, 3); > > + > > + memset(&child, 0, sizeof(child)); > > + child.argv = args; > > + args[0] = "sh"; > > + args[1] = "-c"; > > + args[2] = cmdbuf; > > + args[3] = NULL; > > If I read the code correctly, there does not happen any shell quoting > anywhere; hence, this shell invocation is dangerous.
AFAICT the files used are all temporary files named ".merge_file_xxxx" in the current directory, so there should not be a chance to have spaces or other weird characters in the files.
Ciao, Dscho