Re: [PATCH v2 2/4] sideband: introduce an "escape hatch" to allow control characters
- From
Patrick Steinhardt <ps@pks.im>
- Date
- Jan 9, 2026, 12:38 UTC
- Message-ID
- <aWD2vOwzmuiWdd_m@pks.im>
- In-Reply-To
- <2615abd8c5d5c55486cf5885c47e09e52fad61b8.1765981422.git.gitgitgadget@gmail.com>
On Wed, Dec 17, 2025 at 02:23:40PM +0000, Johannes Schindelin via GitGitGadget wrote:
Show 12 quoted lines
> From: Johannes Schindelin <johannes.schindelin@gmx.de> > > The preceding commit fixed the vulnerability whereas sideband messages > (that are under the control of the remote server) could contain ANSI > escape sequences that would be sent to the terminal verbatim. > > However, this fix may not be desirable under all circumstances, e.g. > when remote servers deliberately add coloring to their messages to > increase their urgency. > > To help with those use cases, give users a way to opt-out of the > protections: `sideband.allowControlCharacters`.
I wonder whether this is a bit too broad. The only escape sequences that I can see a valid use case for are color codes. So wouldn't it make sense to discern color escape sequences from all other escape sequences and allow users to only enable colors without also enabling all the other, potentially more dangerous ones?
Edit: aha, you address this concern in the next commit. Nice :)
Patrick