git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git-am applies commit message diffs

From
MBMatthias Beyer <mail@beyermatthias.de>
Date
Feb 6, 2026, 08:18 UTC
Message-ID
<hn6q2mdjdqezzvtxfxffmatctnlf4ttvwedfk7wnw7xw75gy4g@hetctv53f7bh>
In-Reply-To
<CA+P7+xqcBcV8uySGgDfvt2ruAnFmfgaUy6aRbUC2zCzmCgPubw@mail.gmail.com>
Hi,
CCing some git-am contributors, hope that's alright for you!
On Fri, Feb 06, 2026 at 12:04:54AM -0800, Jacob Keller wrote:
Show 31 quoted lines
> On Thu, Feb 5, 2026 at 11:50 PM Matthias Beyer <mail@beyermatthias.de> wrote:
> >
> > Hi,
> >
> > I am not sure whether this was already reported, searching the lore did
> > not yield anything for me, but I might have overlooked it...
> >
> > This was just posted on mastodon[0]:
> >
> >     PSA: Did you know that it’s **unsafe** to put code diffs into your commit messages?
> >
> >     Like https://
> >     github.com/i3/i3/pull/6564 for example
> >
> >     Such diffs will be applied by patch(1) (also git-am(1)) as part of the code change!
> >
> >     This is how a sleep(1) made it into i3 4.25-2 in Debian unstable.
> >
> > TL;DR: If you put a diff in the commit message, that diff will be
> > applied by git-am.
> >
> > This looks clearly like unintended and might be an attack-vector, right?
> >
> 
> It is certainly surprising. I am not certain I would consider it an
> attack-vector since you should definitely be reading the commit
> messages before applying, but I could see the fact that its
> unintentional is a problem.
> [...]
>
> > [0]: https://mas.to/@zekjur/116022397626943871

As per the issue linked in that toot I quoted above, the issue clearly seems to be that it is not intentional that a diff embedded in the commit message will be applied. Nobody ever guessed that and that `sleep 1` that was in the commit message made it into debian unstable because people assumed it to work as intended.

I call that sheer luck, that it was only a `sleep 1` and not a "here is how I made this into a backdoor and here is a patch to fix it", ultimately getting the backdoor in which was written as a diff in the commit message, instead of the "fix" in the "patch part" of the email.

That said, I am no expert in either C or the git codebase at all, but from what I saw from reading the git-am codebase, it looks like it tries to find the patch by looking for three dashes on a line with a linebreak behind ("---\n"). From what I read, it looks for that from the first line. What I would think of here is looking for that "patchbreak" from the _end_ of the email rather than from the top, that would have prevented this issue, right?

Best, Matthias

Previous: Jacob KellerNext: Jeff King
Message 3 of 65 in “git-am applies commit message diffs”
  1. Matthias BeyerFeb 6, 2026
  2. Jacob KellerFeb 6, 2026
  3. Matthias BeyerFeb 6, 2026
  4. Jeff KingFeb 6, 2026
  5. 0/3 commit-msg.sample: reject messages that would confuse "git am"Phillip Wood, Feb 7, 2026
  6. 1/3 templates: add .gitattributes entry for sample hooksPhillip Wood, Feb 7, 2026
  7. 2/3 templates: detect commit messages containing diffsPhillip Wood, Feb 7, 2026
  8. 3/3 templates: detect messages that contain a separator linePhillip Wood, Feb 7, 2026
  9. Junio C HamanoFeb 7, 2026
  10. Kristoffer HaugsbakkFeb 7, 2026
  11. Junio C HamanoFeb 9, 2026
  12. Jeff KingFeb 9, 2026
  13. Phillip WoodFeb 9, 2026
  14. Jeff KingFeb 10, 2026
  15. Jeff KingFeb 9, 2026
  16. Phillip WoodFeb 9, 2026
  17. Matthias BeyerFeb 9, 2026
  18. Jeff KingFeb 10, 2026
  19. Patrick SteinhardtFeb 9, 2026
  20. Jacob KellerFeb 10, 2026
  21. Patrick SteinhardtFeb 10, 2026
  22. Junio C HamanoFeb 10, 2026
  23. Jacob KellerFeb 11, 2026
  24. Jacob KellerFeb 11, 2026
  25. Jeff KingFeb 11, 2026
  26. Kristoffer HaugsbakkFeb 11, 2026
  27. Junio C HamanoFeb 11, 2026
  28. Jeff KingFeb 10, 2026
  29. 0/2 commit-msg.sample: reject messages that would confuse "git am"Phillip Wood, Feb 13, 2026
  30. 1/2 templates: add .gitattributes entry for sample hooksPhillip Wood, Feb 13, 2026
  31. 2/2 templates: detect commit messages containing diffsPhillip Wood, Feb 13, 2026
  32. Kristoffer HaugsbakkFeb 13, 2026
  33. Junio C HamanoFeb 13, 2026
  34. Phillip WoodFeb 14, 2026
  35. Junio C HamanoFeb 13, 2026
  36. Phillip WoodFeb 14, 2026
  37. Junio C HamanoFeb 14, 2026
  38. Junio C HamanoFeb 13, 2026
  39. Florian WeimerFeb 6, 2026
  40. Jeff KingFeb 6, 2026
  41. Florian WeimerFeb 6, 2026
  42. Jeff KingFeb 6, 2026
  43. Kristoffer HaugsbakkFeb 6, 2026
  44. Jakob HaufeFeb 6, 2026
  45. Kristoffer HaugsbakkFeb 7, 2026
  46. Kristoffer HaugsbakkFeb 7, 2026
  47. doc: add caveat about roundtripping format-patchkristofferhaugsbakk@fastmail.com, Feb 8, 2026
  48. Junio C HamanoFeb 8, 2026
  49. Kristoffer HaugsbakkFeb 8, 2026
  50. Phillip WoodFeb 9, 2026
  51. Kristoffer HaugsbakkFeb 9, 2026
  52. Phillip WoodFeb 10, 2026
  53. Kristoffer HaugsbakkFeb 10, 2026
  54. doc: add caveat about roundtripping format-patchkristofferhaugsbakk@fastmail.com, Feb 9, 2026
  55. Junio C HamanoFeb 9, 2026
  56. Kristoffer HaugsbakkFeb 9, 2026
  57. Phillip WoodFeb 10, 2026
  58. Kristoffer HaugsbakkFeb 10, 2026
  59. doc: add caveat about round-tripping format-patchkristofferhaugsbakk@fastmail.com, Feb 12, 2026
  60. Junio C HamanoFeb 12, 2026
  61. Phillip WoodFeb 13, 2026
  62. Kristoffer HaugsbakkFeb 13, 2026
  63. Junio C HamanoFeb 13, 2026
  64. Christoph Anton MittererFeb 10, 2026
  65. Kristoffer HaugsbakkFeb 10, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.