From: Junio C Hamano <gitster@pobox.com>
To: "Anupam Mediratta via GitGitGadget" <gitgitgadget@gmail.com>
Cc: git@vger.kernel.org, Anupam Mediratta <mediratta@gmail.com>
Subject: Re: [PATCH] git-p4: avoid shell interpretation of commit ids in applyCommit
Date: Wed, 23 Sep 2026 12:11:06 -0700 [thread overview]
Message-ID: <xmqqv77vailx.fsf@gitster.g> (raw)
In-Reply-To: <pull.2411.git.git.1790093506966.gitgitgadget@gmail.com> (Anupam Mediratta via GitGitGadget's message of "Tue, 22 Sep 2026 16:11:46 +0000")
"Anupam Mediratta via GitGitGadget" <gitgitgadget@gmail.com> writes:
> @@ -2279,7 +2290,7 @@ class P4Submit(Command, P4UserMap):
>
> if fixed_rcs_keywords:
> print("Retrying the patch with RCS keywords cleaned up")
> - if os.system(tryPatchCmd) == 0:
> + if diffTreeApply(id, tryPatchArgs) == 0:
> patch_succeeded = True
> print("Patch succeesed this time with RCS keywords cleaned")
Both of these check the result of running diff|apply pipeline and
react to a failure.
> @@ -2291,7 +2302,7 @@ class P4Submit(Command, P4UserMap):
> #
> # Apply the patch for real, and do add/delete/+x handling.
> #
> - system(applyPatchCmd, shell=True)
> + diffTreeApply(id, applyPatchArgs)
It is a bit hard to discover, but the original code catches a failed
"diff|apply" pipeline invocation, because the "system()" used here
is what git-p4.py defines for itself. When the pipeline fails, this
system() raises subprocess.CalledProcessError().
The new one ignores the exit status from the pipeline, so even after
a failure to apply the change, the program continues.
Which may not be what you want to see.
>
> for f in filesToChangeType:
> p4_edit(f, "-t", "auto")
> diff --git a/t/t9803-git-p4-shell-metachars.sh b/t/t9803-git-p4-shell-metachars.sh
> index 2913277013..ef8fd6e094 100755
> --- a/t/t9803-git-p4-shell-metachars.sh
> +++ b/t/t9803-git-p4-shell-metachars.sh
> @@ -105,4 +105,20 @@ test_expect_success 'branch with shell char' '
> )
> '
>
> +test_expect_success 'git p4 submit --commit does not execute shell metachars in commit id' '
> + git p4 clone --dest="$git" //depot &&
> + test_when_finished cleanup_git &&
> + (
> + cd "$git" &&
> + git config git-p4.skipSubmitEditCheck true &&
> + echo f3 >file3 &&
> + git add file3 &&
> + git commit -m "add file3" &&
> + name='"'"'$(touch${IFS}injection-marker)'"'"' &&
> + git branch "$name" HEAD &&
> + P4EDITOR="test-tool chmtime +5" git p4 submit --commit "$name"
> + ) &&
> + test_path_is_missing "$cli/injection-marker"
> +'
> +
> test_done
>
> base-commit: d38352cd43ab9745686d697872408bc3249a153f
next prev parent reply other threads:[~2026-09-23 19:11 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-22 16:11 [PATCH] git-p4: avoid shell interpretation of commit ids in applyCommit Anupam Mediratta via GitGitGadget
2026-09-23 19:11 ` Junio C Hamano [this message]
2026-09-24 8:28 ` [PATCH v2] " Anupam Mediratta via GitGitGadget
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=xmqqv77vailx.fsf@gitster.g \
--to=gitster@pobox.com \
--cc=git@vger.kernel.org \
--cc=gitgitgadget@gmail.com \
--cc=mediratta@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox