Re: [PATCH v3] merge-ll: expose revision names to custom drivers
- From
Junio C Hamano <gitster@pobox.com>
- Date
- Jan 20, 2024, 17:37 UTC
- Message-ID
- <xmqqsf2rgb39.fsf@gitster.g>
- In-Reply-To
- <82624802-aa7f-4856-b819-9a2990b25a69@gmail.com>
Phillip Wood <phillip.wood123@gmail.com> writes:
> Not part of this patch but I noticed that we're passing the filenames > for '%A' etc. unquoted which is a bit scary.
May be scary but safe, as long as create_temp() gives a reasonable temporary filename. We pass ".merge_file_XXXXXX" to xmkstemp(), which calls into mkstemp(), which should give us a shell safe name?
It also should be a safe conversion to change strbuf_addstr() used for these three to sq_quote_buf(), as the string with these %[OAB] placeholders are passed to the shell that eats the quoting before invoking the end-user supplied external merge driver, which means the merge driver would not notice any difference.
Thanks for being careful ;-)