Re: [PATCH v3 0/5] Sanitize sideband channel messages
- From
Johannes Schindelin <johannes.schindelin@gmx.de>
- Date
- Jan 16, 2026, 22:32 UTC
- Message-ID
- <fc58c8ea-88d0-d86c-30e6-0ab9fceb23cc@gmx.de>
- In-Reply-To
- <pull.1853.v3.git.1768602373.gitgitgadget@gmail.com>
Hi,
On Fri, 16 Jan 2026, Johannes Schindelin via GitGitGadget wrote:
> Note: This series applies cleanly on v2.47.3. Integrating this into newer > versions is a bit cumbersome; I pushed a version of the branch as rebased to > v2.53.0-rc0 here: > https://github.com/dscho/git/tree/refs/heads/sanitize-sideband-2.53.0-rc0
Here is the range-diff:
1: e6b71af0cad = 1: 757c859add0 sideband: mask control characters
2: 8f64d658447 ! 2: 28c9fa7e205 sideband: introduce an "escape hatch" to allow control characters
@@ Commit message
Suggested-by: brian m. carlson <sandals@crustytoothpaste.net>
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
- ## Documentation/config.txt ##
-@@ Documentation/config.txt: include::config/sequencer.txt[]
+ ## Documentation/config.adoc ##
+@@ Documentation/config.adoc: include::config/sequencer.adoc[]
- include::config/showbranch.txt[]
+ include::config/showbranch.adoc[]
-+include::config/sideband.txt[]
++include::config/sideband.adoc[]
+
- include::config/sparse.txt[]
+ include::config/sparse.adoc[]
- include::config/splitindex.txt[]
+ include::config/splitindex.adoc[]
- ## Documentation/config/sideband.txt (new) ##
+ ## Documentation/config/sideband.adoc (new) ##
@@
+sideband.allowControlCharacters::
+ By default, control characters that are delivered via the sideband
@@ sideband.c: static struct keyword_entry keywords[] = {
+static int allow_control_characters;
+
/* Returns a color setting (GIT_COLOR_NEVER, etc). */
- static int use_sideband_colors(void)
+ static enum git_colorbool use_sideband_colors(void)
{
-@@ sideband.c: static int use_sideband_colors(void)
- if (use_sideband_colors_cached >= 0)
+@@ sideband.c: static enum git_colorbool use_sideband_colors(void)
+ if (use_sideband_colors_cached != GIT_COLOR_UNKNOWN)
return use_sideband_colors_cached;
-+ git_config_get_bool("sideband.allowcontrolcharacters",
++ repo_config_get_bool(the_repository, "sideband.allowcontrolcharacters",
+ &allow_control_characters);
+
- if (!git_config_get_string_tmp(key, &value))
+ if (!repo_config_get_string_tmp(the_repository, key, &value))
use_sideband_colors_cached = git_config_colorbool(key, value);
- else if (!git_config_get_string_tmp("color.ui", &value))
+ else if (!repo_config_get_string_tmp(the_repository, "color.ui", &value))
@@ sideband.c: void list_config_color_sideband_slots(struct string_list *list, const char *pref
static void strbuf_add_sanitized(struct strbuf *dest, const char *src, int n)
3: 44838acaccc ! 3: 58a4f78783b sideband: do allow ANSI color sequences by default
@@ Commit message
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
- ## Documentation/config/sideband.txt ##
+ ## Documentation/config/sideband.adoc ##
@@
sideband.allowControlCharacters::
By default, control characters that are delivered via the sideband
@@ sideband.c: static struct keyword_entry keywords[] = {
+} allow_control_characters = ALLOW_ANSI_COLOR_SEQUENCES;
/* Returns a color setting (GIT_COLOR_NEVER, etc). */
- static int use_sideband_colors(void)
-@@ sideband.c: static int use_sideband_colors(void)
- if (use_sideband_colors_cached >= 0)
+ static enum git_colorbool use_sideband_colors(void)
+@@ sideband.c: static enum git_colorbool use_sideband_colors(void)
+ if (use_sideband_colors_cached != GIT_COLOR_UNKNOWN)
return use_sideband_colors_cached;
-- git_config_get_bool("sideband.allowcontrolcharacters",
+- repo_config_get_bool(the_repository, "sideband.allowcontrolcharacters",
- &allow_control_characters);
-+ switch (git_config_get_maybe_bool("sideband.allowcontrolcharacters", &i)) {
++ switch (repo_config_get_maybe_bool(the_repository, "sideband.allowcontrolcharacters", &i)) {
+ case 0: /* Boolean value */
+ allow_control_characters = i ? ALLOW_ALL_CONTROL_CHARACTERS :
+ ALLOW_NO_CONTROL_CHARACTERS;
+ break;
+ case -1: /* non-Boolean value */
-+ if (git_config_get_string_tmp("sideband.allowcontrolcharacters",
++ if (repo_config_get_string_tmp(the_repository, "sideband.allowcontrolcharacters",
+ &value))
+ ; /* huh? `get_maybe_bool()` returned -1 */
+ else if (!strcmp(value, "default"))
@@ sideband.c: static int use_sideband_colors(void)
+ break; /* not configured */
+ }
- if (!git_config_get_string_tmp(key, &value))
+ if (!repo_config_get_string_tmp(the_repository, key, &value))
use_sideband_colors_cached = git_config_colorbool(key, value);
@@ sideband.c: void list_config_color_sideband_slots(struct string_list *list, const char *pref
list_config_item(list, prefix, keywords[i].keyword);
4: cc578465b9c ! 4: 24708d83075 sideband: add options to allow more control sequences to be passed through
@@ Commit message
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
- ## Documentation/config/sideband.txt ##
-@@ Documentation/config/sideband.txt: sideband.allowControlCharacters::
+ ## Documentation/config/sideband.adoc ##
+@@ Documentation/config/sideband.adoc: sideband.allowControlCharacters::
By default, control characters that are delivered via the sideband
are masked, except ANSI color sequences. This prevents potentially
unwanted ANSI escape sequences from being sent to the terminal. Use
@@ sideband.c: static struct keyword_entry keywords[] = {
+}
/* Returns a color setting (GIT_COLOR_NEVER, etc). */
- static int use_sideband_colors(void)
-@@ sideband.c: static int use_sideband_colors(void)
- if (git_config_get_string_tmp("sideband.allowcontrolcharacters",
+ static enum git_colorbool use_sideband_colors(void)
+@@ sideband.c: static enum git_colorbool use_sideband_colors(void)
+ if (repo_config_get_string_tmp(the_repository, "sideband.allowcontrolcharacters",
&value))
; /* huh? `get_maybe_bool()` returned -1 */
- else if (!strcmp(value, "default"))
5: f2eb0a758ce ! 5: 4db96901d02 sideband: offer to configure sanitizing on a per-URL basis
@@ Commit message
Suggested-by: Junio Hamano <gitster@pobox.com>
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
- ## Documentation/config/sideband.txt ##
-@@ Documentation/config/sideband.txt: sideband.allowControlCharacters::
+ ## Documentation/config/sideband.adoc ##
+@@ Documentation/config/sideband.adoc: sideband.allowControlCharacters::
`true`::
Allow all control characters to be sent to the terminal.
--
@@ sideband.c: static void parse_allow_control_characters(const char *value)
+ config.collect_fn = sideband_config_callback;
+
+ normalized_url = url_normalize(url, &config.url);
-+ git_config(urlmatch_config_entry, &config);
++ repo_config(the_repository, urlmatch_config_entry, &config);
+ free(normalized_url);
+ string_list_clear(&config.vars, 1);
+ urlmatch_config_release(&config);
}
/* Returns a color setting (GIT_COLOR_NEVER, etc). */
-@@ sideband.c: static int use_sideband_colors(void)
- if (use_sideband_colors_cached >= 0)
+@@ sideband.c: static enum git_colorbool use_sideband_colors(void)
+ if (use_sideband_colors_cached != GIT_COLOR_UNKNOWN)
return use_sideband_colors_cached;
-- switch (git_config_get_maybe_bool("sideband.allowcontrolcharacters", &i)) {
+- switch (repo_config_get_maybe_bool(the_repository, "sideband.allowcontrolcharacters", &i)) {
- case 0: /* Boolean value */
- allow_control_characters = i ? ALLOW_ALL_CONTROL_CHARACTERS :
- ALLOW_NO_CONTROL_CHARACTERS;
- break;
- case -1: /* non-Boolean value */
-- if (git_config_get_string_tmp("sideband.allowcontrolcharacters",
+- if (repo_config_get_string_tmp(the_repository, "sideband.allowcontrolcharacters",
- &value))
- ; /* huh? `get_maybe_bool()` returned -1 */
- else
@@ sideband.c: static int use_sideband_colors(void)
- default:
- break; /* not configured */
+ if (allow_control_characters == ALLOW_CONTROL_SEQUENCES_UNSET) {
-+ if (!git_config_get_value("sideband.allowcontrolcharacters", &value))
++ if (!repo_config_get_value(the_repository, "sideband.allowcontrolcharacters", &value))
+ sideband_allow_control_characters_config("sideband.allowcontrolcharacters", value);
+
+ if (allow_control_characters == ALLOW_CONTROL_SEQUENCES_UNSET)
+ allow_control_characters = ALLOW_DEFAULT_ANSI_SEQUENCES;
}
- if (!git_config_get_string_tmp(key, &value))
+ if (!repo_config_get_string_tmp(the_repository, key, &value))
## sideband.h ##
@@ sideband.h: int demultiplex_sideband(const char *me, int status,
@@ transport.c
#include "bundle-uri.h"
+#include "sideband.h"
- static int transport_use_color = -1;
+ static enum git_colorbool transport_use_color = GIT_COLOR_UNKNOWN;
static char transport_colors[][COLOR_MAXLEN] = {
@@ transport.c: struct transport *transport_get(struct remote *remote, const char *url)
- ret->hash_algo = &hash_algos[GIT_HASH_SHA1];
+ ret->hash_algo = &hash_algos[GIT_HASH_SHA1_LEGACY];
+ sideband_apply_url_config(ret->url);
+Ciao, Johannes