Commit 2589bc3
Reject syntax-bearing git config option names
GHSA-jm78-9fvv-mhgr reports that config option names containing Git
syntax can be serialized as unintended directives. A regression test showed
that set, set_value, and add_value accepted delimiter, comment, bracket, and
whitespace characters in option names.
Restrict written option names to GitPython's established safe character set of
letters, digits, hyphens, underscores, and dots. This blocks characters that
can change config syntax while preserving option names historically supported
by the writer and SectionConstraint.
A broader audit confirmed that every public option-creating config API and
SectionConstraint delegate reaches this validator; no separate config writer
sink was found. The behavior was checked against Git cf5497b14, and the full
config test module plus dotted-option regression pass.1 parent 6e61b1d commit 2589bc3
2 files changed
Lines changed: 42 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
75 | 75 | | |
76 | 76 | | |
77 | 77 | | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
78 | 81 | | |
79 | 82 | | |
80 | 83 | | |
| |||
897 | 900 | | |
898 | 901 | | |
899 | 902 | | |
| 903 | + | |
| 904 | + | |
900 | 905 | | |
901 | 906 | | |
902 | 907 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
194 | 194 | | |
195 | 195 | | |
196 | 196 | | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
| 226 | + | |
| 227 | + | |
| 228 | + | |
| 229 | + | |
| 230 | + | |
| 231 | + | |
| 232 | + | |
| 233 | + | |
197 | 234 | | |
198 | 235 | | |
199 | 236 | | |
| |||
0 commit comments