Thread (3 messages) flat view 3 messages, 2 authors, 2016-06-15

Re: [PATCH] symbolic-ref: check format of given reference

From: Junio C Hamano <hidden>
Date: 2016-06-15 22:54:07

Junio C Hamano [off-list ref] writes:
From: Michael Schubert <redacted>
Date: Sun, 17 Jun 2012 22:26:37 +0200
Subject: [PATCH] symbolic-ref: check format of given reference

Currently, it's possible to update HEAD with a nonsense reference since
no strict validation is performed. Example:

	$ git symbolic-ref HEAD 'refs/heads/master
    >
    >
    > '
It would be nice to add a new test or two to t1401.  1401.3 was
already trying to catch a malformed reference with this test:

	test_must_fail git symbolic-ref HEAD foo

and it did trigger thanks to the prefixcmp(argv[1], "refs/") test we
already have.  Probably something like

	git symbolic-ref HEAD "refs/heads/.foo"
	git symbolic-ref HEAD "refs/heads/-foo"

would be a good start.

To make the latter _correctly_ work requires a bit of work, though.
We should make sure all the check_refname_format() callers pass the
full path to a ref, get rid of ALLOW_ONELEVEL, and redo commits like
6348624 (disallow branch names that start with a hyphen, 2010-09-14)
and 4f0accd (tag: disallow '-' as tag name, 2011-05-10).

For that matter, shouldn't symbolic-ref be forbidden to point
outside refs/heads/, not just restricted in refs/ like the current
code does?
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help