# bash: unescaped `>` character when switching branches

5 messages from 2025-06-24 to 2025-06-25. Participants: Ondrej Pohorelsky, Kristoffer Haugsbakk, Phillip Wood, Junio C Hamano.
Thread: https://gitlist.dev/t/63687

## Ondrej Pohorelsky, 2025-06-24 12:59

Subject: bash: unescaped `>` character when switching branches
Message-ID: <CA+B51BHEB24JNzOroTxFodxiuPJ1=Vj7KRFevrm2YatnTVuoYA@mail.gmail.com>
URL: https://gitlist.dev/e/CA%2BB51BHEB24JNzOroTxFodxiuPJ1%3DVj7KRFevrm2YatnTVuoYA%40mail.gmail.com

```
Hi,

Our customer has found a possible issue when switching branches.
Output redirection character `>` is not escaped properly when
switching/checking out to different branch.

Steps to reproduce:
1. Create a new branch and switch back to master
ˋˋˋ
$ git switch -C 'issue#1234>/tmp/dangerfile'
Switched to a new branch 'issue#1234>/tmp/dangerfile'
$ git switch master
ˋˋˋ

2. Try to switch to the created branch with using auto-completion
ˋˋˋ
git switch i<TAB>
$ git switch issue#1234>/tmp/dangerfile
fatal: invalid reference: issue#1234
ˋˋˋ
3. Verify that the /tmp/dangerfile has been created
ˋˋˋ
$ ls /tmp/dangerfile
/tmp/dangerfile
ˋˋˋ

Internal interpretation of the created branch:
└── refs
    ├── heads
    │   ├── issue#1234>
    │   │   └── tmp
    │   │       └── dangerfile

Tested on Fedora 42 with git-2.49.


I've found out that this behavior happens only when using Bash. Zsh
properly escapes the characters when creating and switching to the
branch. Git shouldn't be tricked into creating a file when the user is
switching branches. I'm not entirely sure where the issue lies in the
code, so I'm not attaching any patch fixing this.


-- 
Ondřej Pohořelský

Software Engineer

Red Hat

opohorel@redhat.com


```

## Kristoffer Haugsbakk, 2025-06-25 08:53

Subject: Re: bash: unescaped `>` character when switching branches
Message-ID: <8515698b-4ab7-4901-bacb-1c47180c2530@app.fastmail.com>
URL: https://gitlist.dev/e/8515698b-4ab7-4901-bacb-1c47180c2530%40app.fastmail.com
In-Reply-To: <CA+B51BHEB24JNzOroTxFodxiuPJ1=Vj7KRFevrm2YatnTVuoYA@mail.gmail.com>

```
On Tue, Jun 24, 2025, at 14:59, Ondrej Pohorelsky wrote:
> Hi,
>
> Our customer has found a possible issue when switching branches.
> Output redirection character `>` is not escaped properly when
> switching/checking out to different branch.
>
> Steps to reproduce:
> 1. Create a new branch and switch back to master
> ˋˋˋ
> $ git switch -C 'issue#1234>/tmp/dangerfile'
> Switched to a new branch 'issue#1234>/tmp/dangerfile'
> $ git switch master
> ˋˋˋ

It’s too bad that git-check-ref-format(1) does not disallow `>`.

It would be nice to have an opt-in extension to the ref format check
which disallows `>`.

```

## Phillip Wood, 2025-06-25 13:57

Subject: Re: bash: unescaped `>` character when switching branches
Message-ID: <84eccfa1-88fe-43b8-a839-61ea4fa4e4e9@gmail.com>
URL: https://gitlist.dev/e/84eccfa1-88fe-43b8-a839-61ea4fa4e4e9%40gmail.com
In-Reply-To: <8515698b-4ab7-4901-bacb-1c47180c2530@app.fastmail.com>

```
On 25/06/2025 09:53, Kristoffer Haugsbakk wrote:
> On Tue, Jun 24, 2025, at 14:59, Ondrej Pohorelsky wrote:
>> Hi,
>>
>> Our customer has found a possible issue when switching branches.
>> Output redirection character `>` is not escaped properly when
>> switching/checking out to different branch.
>>
>> Steps to reproduce:
>> 1. Create a new branch and switch back to master
>> ˋˋˋ
>> $ git switch -C 'issue#1234>/tmp/dangerfile'
>> Switched to a new branch 'issue#1234>/tmp/dangerfile'
>> $ git switch master
>> ˋˋˋ
> 
> It’s too bad that git-check-ref-format(1) does not disallow `>`.

It also allows `<`, `$`, `&`, `;`, `(`, `)`, `#`, `"`, `'`, '`' and `|`. 
Our ref format is not designed for them to be used unquoted in the 
shell. I think the problem here is with our completion script not 
quoting the refname, not the format.

Best Wishes

Phillip
> It would be nice to have an opt-in extension to the ref format check
> which disallows `>`.
> 


```

## Junio C Hamano, 2025-06-25 16:38

Subject: Re: bash: unescaped `>` character when switching branches
Message-ID: <xmqq5xgjwzbx.fsf@gitster.g>
URL: https://gitlist.dev/e/xmqq5xgjwzbx.fsf%40gitster.g
In-Reply-To: <8515698b-4ab7-4901-bacb-1c47180c2530@app.fastmail.com>

```
"Kristoffer Haugsbakk" <kristofferhaugsbakk@fastmail.com> writes:

> On Tue, Jun 24, 2025, at 14:59, Ondrej Pohorelsky wrote:
>> Hi,
>>
>> Our customer has found a possible issue when switching branches.
>> Output redirection character `>` is not escaped properly when
>> switching/checking out to different branch.
>>
>> Steps to reproduce:
>> 1. Create a new branch and switch back to master
>> ˋˋˋ
>> $ git switch -C 'issue#1234>/tmp/dangerfile'
>> Switched to a new branch 'issue#1234>/tmp/dangerfile'
>> $ git switch master
>> ˋˋˋ
>
> It’s too bad that git-check-ref-format(1) does not disallow `>`.

Is it?  It looks like an outright bug in the completion code,
nothing more, to me.

```

## Kristoffer Haugsbakk, 2025-06-25 20:19

Subject: Re: bash: unescaped `>` character when switching branches
Message-ID: <71204f81-3281-4089-9e9e-1a81a73c8d41@app.fastmail.com>
URL: https://gitlist.dev/e/71204f81-3281-4089-9e9e-1a81a73c8d41%40app.fastmail.com
In-Reply-To: <84eccfa1-88fe-43b8-a839-61ea4fa4e4e9@gmail.com>

```
On Wed, Jun 25, 2025, at 15:57, Phillip Wood wrote:
> On 25/06/2025 09:53, Kristoffer Haugsbakk wrote:
>> On Tue, Jun 24, 2025, at 14:59, Ondrej Pohorelsky wrote:
>>> Hi,
>>>
>>> Our customer has found a possible issue when switching branches.
>>> Output redirection character `>` is not escaped properly when
>>> switching/checking out to different branch.
>>>
>>> Steps to reproduce:
>>> 1. Create a new branch and switch back to master
>>> ˋˋˋ
>>> $ git switch -C 'issue#1234>/tmp/dangerfile'
>>> Switched to a new branch 'issue#1234>/tmp/dangerfile'
>>> $ git switch master
>>> ˋˋˋ
>> 
>> It’s too bad that git-check-ref-format(1) does not disallow `>`.
>
> It also allows `<`, `$`, `&`, `;`, `(`, `)`, `#`, `"`, `'`, '`' and `|`. 
> Our ref format is not designed for them to be used unquoted in the 
> shell. I think the problem here is with our completion script not 
> quoting the refname, not the format.

On Wed, Jun 25, 2025, at 18:38, Junio C Hamano wrote:
> "Kristoffer Haugsbakk" <kristofferhaugsbakk@fastmail.com> writes:
>
>> On Tue, Jun 24, 2025, at 14:59, Ondrej Pohorelsky wrote:
>>> Hi,
>>>
>>> Our customer has found a possible issue when switching branches.
>>> Output redirection character `>` is not escaped properly when
>>> switching/checking out to different branch.
>>>
>>> Steps to reproduce:
>>> 1. Create a new branch and switch back to master
>>> ˋˋˋ
>>> $ git switch -C 'issue#1234>/tmp/dangerfile'
>>> Switched to a new branch 'issue#1234>/tmp/dangerfile'
>>> $ git switch master
>>> ˋˋˋ
>>
>> It’s too bad that git-check-ref-format(1) does not disallow `>`.
>
> Is it?  It looks like an outright bug in the completion code,
> nothing more, to me.

That was an aside.

```
