git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [SECURITY PATCH] git-prompt.sh: don't put unsanitized branch names in $PS1

From
Junio C Hamano <gitster@pobox.com>
Date
Apr 22, 2014, 19:47 UTC
Message-ID
<xmqqr44p4042.fsf@gitster.dls.corp.google.com>
In-Reply-To
<5356B71A.6070500@bbn.com>
Richard Hansen <rhansen@bbn.com> writes:
Show 5 quoted lines
>> and plan for transition to forbid them
>> everywhere in a next big version bump (it is too late for 2.0).
>
> Would it be acceptable to have a config option to forbid these in a
> non-major version bump?  

Of course ;-) Because we try very hard to avoid a "flag day" change, any "plan for transition" inevitably has to include what we need to do _before_ the big version bump.

Show 10 quoted lines
> If it's OK to have a config option, then here's one possible transition
> path (probably flawed, but my intent is to bootstrap discussion):
>
>   1. Add an option to forbid dangerous characters.  The option defaults
>      to disabled for compatibility.  If the option is unset, print a
>      warning upon encountering a ref name that would be forbidden.
>   2. Later, flip the default to enabled.
>   3. Later, in the weeks/months leading up to the next major version
>      release, print the warning even if the config option is set to
>      disabled.

Sounds fairly conservative and nice. We may want to treat creating a new such ref and using an existing such ref differently, though, and that might give us a better/smoother transition (as you are, I am just thinking aloud).

For example, it might be sufficient to do these two things:
 (1) upon an attempt to use an existing such ref, warn and encourage
     renaming of the ref.
 (2) upon an attempt to create a new one, error it out.

in the first step, and in either case, tell the user about the loosening variable.

Going that route may shorten the time until the initial safety.
Previous: Richard HansenNext: Junio C Hamano
Message 7 of 11 in “git-prompt.sh: don't put unsanitized branch names in $PS1”
  1. git-prompt.sh: don't put unsanitized branch names in $PS1Richard Hansen, Apr 21, 2014
  2. Jeff KingApr 21, 2014
  3. Richard HansenApr 21, 2014
  4. Michael HaggertyApr 22, 2014
  5. Junio C HamanoApr 22, 2014
  6. Richard HansenApr 22, 2014
  7. Junio C HamanoApr 22, 2014
  8. Junio C HamanoApr 21, 2014
  9. Junio C HamanoApr 21, 2014
  10. Richard HansenApr 21, 2014
  11. git-prompt.sh: don't put unsanitized branch names in $PS1Richard Hansen, Apr 21, 2014

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.