Re: [SECURITY PATCH] git-prompt.sh: don't put unsanitized branch names in $PS1
- From
Junio C Hamano <gitster@pobox.com>
- Date
- Apr 22, 2014, 17:38 UTC
- Message-ID
- <xmqqy4yx5knw.fsf@gitster.dls.corp.google.com>
- In-Reply-To
- <53562A96.6000002@alum.mit.edu>
Michael Haggerty <mhagger@alum.mit.edu> writes:
Show 7 quoted lines
> While we're at it, I think it would be prudent to ban '-' at the
> beginning of reference name segments. For example, reference names like
>
> refs/heads/--cmd=/sbin/halt
> refs/tags/--exec=forkbomb(){forkbomb|forkbomb&};forkbomb
>
> are currently both legal, but I think they shouldn't be.I think we forbid these at the Porcelain level ("git branch", "git checkout -b" and "git tag" should not let you create "-aBranch"), while leaving the plumbing lax to allow people experimenting with their repositories.
It may be sensible to discuss and agree on what exactly should be forbidden (we saw "leading dash", "semicolon and dollar anywhere" so far in the discussion) and plan for transition to forbid them everywhere in a next big version bump (it is too late for 2.0).