git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git format-patch escaping issues in the patch format

From
Christoph Anton Mitterer <calestyo@scientia.org>
Date
Nov 5, 2024, 01:01 UTC
Message-ID
<b856a94969b7065e84dce60d35ae3ce72b5d0f91.camel@scientia.org>
In-Reply-To
<xmqqttcmv8a6.fsf@gitster.g>
Hey.
On Mon, 2024-11-04 at 16:22 -0800, Junio C Hamano wrote:
> ... this falls squarely into "if it hurts, don't do it" category.

I rather thought it would be the category "if it's a bug, that is completely non-obvious and not really to expect, with not even a warning in place,... it should better be fixed" ;-)

There is not reason for any commit author to assume that these strings are not valid, or possibly cause later breakage.

Even if so, it seems not really feasible to know any possible strings, especially when people might just copy&paste output from others into their commit message.

To the least there should be an error when format-patch creates a one that cannot be parsed afterwards. And a proper solution would employ some form of escaping.

And if one's on the other side, and wants to write a parser, one has no real chance of assuring that only "valid" input is used by users in a commit message.

One can easily imagine hat this could accidentally (or intentionally) be used apply undesired patches.

Cheers, Chris.

Previous: Junio C Hamano
Message 10 of 10 in “git format-patch escaping issues in the patch format”
  1. Christoph Anton MittererNov 4, 2024
  2. Kristoffer HaugsbakkNov 4, 2024
  3. Christoph Anton MittererNov 5, 2024
  4. Kristoffer HaugsbakkNov 5, 2024
  5. Christoph Anton MittererNov 5, 2024
  6. Jeff KingNov 4, 2024
  7. Christoph Anton MittererNov 5, 2024
  8. Jeff KingNov 5, 2024
  9. Junio C HamanoNov 5, 2024
  10. Christoph Anton MittererNov 5, 2024

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.