threads / discuss / 63687

bash: unescaped `>` character when switching branches

Subject: bash: unescaped `>` character when switching branches

## tl;dr

5 messages between Jun 24, 2025 and Jun 25, 2025.

replies: 4people: 4as markdown or json

Ondrej Pohorelsky· Jun 24, 2025, 12:59 UTC · lore
Hi,

Our customer has found a possible issue when switching branches. Output redirection character `>` is not escaped properly when switching/checking out to different branch.

Steps to reproduce:
1. Create a new branch and switch back to master
```
$ git switch -C 'issue#1234>/tmp/dangerfile'
Switched to a new branch 'issue#1234>/tmp/dangerfile'
$ git switch master
```
2. Try to switch to the created branch with using auto-completion
```
git switch i<TAB>
$ git switch issue#1234>/tmp/dangerfile
fatal: invalid reference: issue#1234
```
3. Verify that the /tmp/dangerfile has been created
```
$ ls /tmp/dangerfile
/tmp/dangerfile
```
Internal interpretation of the created branch:
└── refs
    ├── heads
    │   ├── issue#1234>
    │   │   └── tmp
    │   │       └── dangerfile
Tested on Fedora 42 with git-2.49.

I've found out that this behavior happens only when using Bash. Zsh properly escapes the characters when creating and switching to the branch. Git shouldn't be tricked into creating a file when the user is switching branches. I'm not entirely sure where the issue lies in the code, so I'm not attaching any patch fixing this.

-- 
Ondřej Pohořelský

Software Engineer

Red Hat

opohorel@redhat.com
Kristoffer Haugsbakk· Jun 25, 2025, 08:53 UTC · re: Ondrej Pohorelsky · lore

Re: bash: unescaped `>` character when switching branches

On Tue, Jun 24, 2025, at 14:59, Ondrej Pohorelsky wrote:
Show 13 quoted lines
> Hi,
>
> Our customer has found a possible issue when switching branches.
> Output redirection character `>` is not escaped properly when
> switching/checking out to different branch.
>
> Steps to reproduce:
> 1. Create a new branch and switch back to master
> ```
> $ git switch -C 'issue#1234>/tmp/dangerfile'
> Switched to a new branch 'issue#1234>/tmp/dangerfile'
> $ git switch master
> ```
It’s too bad that git-check-ref-format(1) does not disallow `>`.

It would be nice to have an opt-in extension to the ref format check which disallows `>`.

Phillip Wood· Jun 25, 2025, 13:57 UTC · re: Kristoffer Haugsbakk · lore

Re: bash: unescaped `>` character when switching branches

On 25/06/2025 09:53, Kristoffer Haugsbakk wrote:
Show 16 quoted lines
> On Tue, Jun 24, 2025, at 14:59, Ondrej Pohorelsky wrote:
>> Hi,
>>
>> Our customer has found a possible issue when switching branches.
>> Output redirection character `>` is not escaped properly when
>> switching/checking out to different branch.
>>
>> Steps to reproduce:
>> 1. Create a new branch and switch back to master
>> ```
>> $ git switch -C 'issue#1234>/tmp/dangerfile'
>> Switched to a new branch 'issue#1234>/tmp/dangerfile'
>> $ git switch master
>> ```
> 
> It’s too bad that git-check-ref-format(1) does not disallow `>`.

It also allows `<`, `$`, `&`, `;`, `(`, `)`, `#`, `"`, `'`, '`' and `|`. Our ref format is not designed for them to be used unquoted in the shell. I think the problem here is with our completion script not quoting the refname, not the format.

Best Wishes
Phillip
> It would be nice to have an opt-in extension to the ref format check
> which disallows `>`.
> 
Kristoffer Haugsbakk· Jun 25, 2025, 20:19 UTC · re: Phillip Wood · lore

Re: bash: unescaped `>` character when switching branches

On Wed, Jun 25, 2025, at 15:57, Phillip Wood wrote:
Show 22 quoted lines
> On 25/06/2025 09:53, Kristoffer Haugsbakk wrote:
>> On Tue, Jun 24, 2025, at 14:59, Ondrej Pohorelsky wrote:
>>> Hi,
>>>
>>> Our customer has found a possible issue when switching branches.
>>> Output redirection character `>` is not escaped properly when
>>> switching/checking out to different branch.
>>>
>>> Steps to reproduce:
>>> 1. Create a new branch and switch back to master
>>> ```
>>> $ git switch -C 'issue#1234>/tmp/dangerfile'
>>> Switched to a new branch 'issue#1234>/tmp/dangerfile'
>>> $ git switch master
>>> ```
>> 
>> It’s too bad that git-check-ref-format(1) does not disallow `>`.
>
> It also allows `<`, `$`, `&`, `;`, `(`, `)`, `#`, `"`, `'`, '`' and `|`. 
> Our ref format is not designed for them to be used unquoted in the 
> shell. I think the problem here is with our completion script not 
> quoting the refname, not the format.
On Wed, Jun 25, 2025, at 18:38, Junio C Hamano wrote:
Show 21 quoted lines
> "Kristoffer Haugsbakk" <kristofferhaugsbakk@fastmail.com> writes:
>
>> On Tue, Jun 24, 2025, at 14:59, Ondrej Pohorelsky wrote:
>>> Hi,
>>>
>>> Our customer has found a possible issue when switching branches.
>>> Output redirection character `>` is not escaped properly when
>>> switching/checking out to different branch.
>>>
>>> Steps to reproduce:
>>> 1. Create a new branch and switch back to master
>>> ```
>>> $ git switch -C 'issue#1234>/tmp/dangerfile'
>>> Switched to a new branch 'issue#1234>/tmp/dangerfile'
>>> $ git switch master
>>> ```
>>
>> It’s too bad that git-check-ref-format(1) does not disallow `>`.
>
> Is it?  It looks like an outright bug in the completion code,
> nothing more, to me.
That was an aside.
Junio C Hamano· Jun 25, 2025, 16:38 UTC · re: Kristoffer Haugsbakk · lore

Re: bash: unescaped `>` character when switching branches

"Kristoffer Haugsbakk" <kristofferhaugsbakk@fastmail.com> writes:
Show 16 quoted lines
> On Tue, Jun 24, 2025, at 14:59, Ondrej Pohorelsky wrote:
>> Hi,
>>
>> Our customer has found a possible issue when switching branches.
>> Output redirection character `>` is not escaped properly when
>> switching/checking out to different branch.
>>
>> Steps to reproduce:
>> 1. Create a new branch and switch back to master
>> ```
>> $ git switch -C 'issue#1234>/tmp/dangerfile'
>> Switched to a new branch 'issue#1234>/tmp/dangerfile'
>> $ git switch master
>> ```
>
> It’s too bad that git-check-ref-format(1) does not disallow `>`.

Is it? It looks like an outright bug in the completion code, nothing more, to me.

← back to recent threads