git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [SECURITY PATCH] git-prompt.sh: don't put unsanitized branch names in $PS1

From
Junio C Hamano <gitster@pobox.com>
Date
Apr 22, 2014, 17:38 UTC
Message-ID
<xmqqy4yx5knw.fsf@gitster.dls.corp.google.com>
In-Reply-To
<53562A96.6000002@alum.mit.edu>
Michael Haggerty <mhagger@alum.mit.edu> writes:
Show 7 quoted lines
> While we're at it, I think it would be prudent to ban '-' at the
> beginning of reference name segments.  For example, reference names like
>
>     refs/heads/--cmd=/sbin/halt
>     refs/tags/--exec=forkbomb(){forkbomb|forkbomb&};forkbomb
>
> are currently both legal, but I think they shouldn't be.

I think we forbid these at the Porcelain level ("git branch", "git checkout -b" and "git tag" should not let you create "-aBranch"), while leaving the plumbing lax to allow people experimenting with their repositories.

It may be sensible to discuss and agree on what exactly should be forbidden (we saw "leading dash", "semicolon and dollar anywhere" so far in the discussion) and plan for transition to forbid them everywhere in a next big version bump (it is too late for 2.0).

Previous: Michael HaggertyNext: Richard Hansen
Message 5 of 11 in “git-prompt.sh: don't put unsanitized branch names in $PS1”
  1. git-prompt.sh: don't put unsanitized branch names in $PS1Richard Hansen, Apr 21, 2014
  2. Jeff KingApr 21, 2014
  3. Richard HansenApr 21, 2014
  4. Michael HaggertyApr 22, 2014
  5. Junio C HamanoApr 22, 2014
  6. Richard HansenApr 22, 2014
  7. Junio C HamanoApr 22, 2014
  8. Junio C HamanoApr 21, 2014
  9. Junio C HamanoApr 21, 2014
  10. Richard HansenApr 21, 2014
  11. git-prompt.sh: don't put unsanitized branch names in $PS1Richard Hansen, Apr 21, 2014

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.