Git development
 help / color / mirror / Atom feed
From: Junio C Hamano <gitster@pobox.com>
To: "Anupam Mediratta via GitGitGadget" <gitgitgadget@gmail.com>
Cc: git@vger.kernel.org,  Anupam Mediratta <mediratta@gmail.com>
Subject: Re: [PATCH] git-p4: avoid shell interpretation of commit ids in applyCommit
Date: Wed, 23 Sep 2026 12:11:06 -0700	[thread overview]
Message-ID: <xmqqv77vailx.fsf@gitster.g> (raw)
In-Reply-To: <pull.2411.git.git.1790093506966.gitgitgadget@gmail.com> (Anupam Mediratta via GitGitGadget's message of "Tue, 22 Sep 2026 16:11:46 +0000")

"Anupam Mediratta via GitGitGadget" <gitgitgadget@gmail.com> writes:

> @@ -2279,7 +2290,7 @@ class P4Submit(Command, P4UserMap):
>  
>              if fixed_rcs_keywords:
>                  print("Retrying the patch with RCS keywords cleaned up")
> -                if os.system(tryPatchCmd) == 0:
> +                if diffTreeApply(id, tryPatchArgs) == 0:
>                      patch_succeeded = True
>                      print("Patch succeesed this time with RCS keywords cleaned")

Both of these check the result of running diff|apply pipeline and
react to a failure.

> @@ -2291,7 +2302,7 @@ class P4Submit(Command, P4UserMap):
>          #
>          # Apply the patch for real, and do add/delete/+x handling.
>          #
> -        system(applyPatchCmd, shell=True)
> +        diffTreeApply(id, applyPatchArgs)

It is a bit hard to discover, but the original code catches a failed
"diff|apply" pipeline invocation, because the "system()" used here
is what git-p4.py defines for itself.  When the pipeline fails, this
system() raises subprocess.CalledProcessError().

The new one ignores the exit status from the pipeline, so even after
a failure to apply the change, the program continues.

Which may not be what you want to see.

>  
>          for f in filesToChangeType:
>              p4_edit(f, "-t", "auto")
> diff --git a/t/t9803-git-p4-shell-metachars.sh b/t/t9803-git-p4-shell-metachars.sh
> index 2913277013..ef8fd6e094 100755
> --- a/t/t9803-git-p4-shell-metachars.sh
> +++ b/t/t9803-git-p4-shell-metachars.sh
> @@ -105,4 +105,20 @@ test_expect_success 'branch with shell char' '
>  	)
>  '
>  
> +test_expect_success 'git p4 submit --commit does not execute shell metachars in commit id' '
> +	git p4 clone --dest="$git" //depot &&
> +	test_when_finished cleanup_git &&
> +	(
> +		cd "$git" &&
> +		git config git-p4.skipSubmitEditCheck true &&
> +		echo f3 >file3 &&
> +		git add file3 &&
> +		git commit -m "add file3" &&
> +		name='"'"'$(touch${IFS}injection-marker)'"'"' &&
> +		git branch "$name" HEAD &&
> +		P4EDITOR="test-tool chmtime +5" git p4 submit --commit "$name"
> +	) &&
> +	test_path_is_missing "$cli/injection-marker"
> +'
> +
>  test_done
>
> base-commit: d38352cd43ab9745686d697872408bc3249a153f

  reply	other threads:[~2026-09-23 19:11 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-22 16:11 [PATCH] git-p4: avoid shell interpretation of commit ids in applyCommit Anupam Mediratta via GitGitGadget
2026-09-23 19:11 ` Junio C Hamano [this message]
2026-09-24  8:28 ` [PATCH v2] " Anupam Mediratta via GitGitGadget

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=xmqqv77vailx.fsf@gitster.g \
    --to=gitster@pobox.com \
    --cc=git@vger.kernel.org \
    --cc=gitgitgadget@gmail.com \
    --cc=mediratta@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox