Skip to content

test(git): Explicitly test for git injection attacks#17253

Merged
weihanglo merged 1 commit into
rust-lang:masterfrom
epage:cli-injection
Jul 22, 2026
Merged

test(git): Explicitly test for git injection attacks#17253
weihanglo merged 1 commit into
rust-lang:masterfrom
epage:cli-injection

Conversation

@epage

@epage epage commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

What does this PR try to resolve?

See https://nesbitt.io/2026/07/21/end-of-options.html

While Cargo does support using the git cli, we are not subject to this because

  • we require URLs to be used in the Cargo.toml, .cargo/config.toml parser for git sources
  • we always prefix branches, revs, and tags or don't use them

Tests are added to demonstrate this.
I wasn't exhaustive (patch, tag, more rev kinds) but figured this was approriate based on source code inspection.

There aren't any other user controlled parameters to git. It would be good to harden this with --end-of-options but we would then need to set a minimum git version so figured I'd pass for now as the needed versions aren't as universally available yet.

How to test and review this PR?

@rustbot rustbot added the S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. label Jul 21, 2026
@rustbot

rustbot commented Jul 21, 2026

Copy link
Copy Markdown
Collaborator

r? @weihanglo

rustbot has assigned @weihanglo.
They will have a look at your PR within the next two weeks and either review your PR or reassign to another reviewer.

Use r? to explicitly pick a reviewer

Why was this reviewer chosen?

The reviewer was selected based on:

  • Owners of files modified in this PR: @epage, @weihanglo
  • @epage, @weihanglo expanded to epage, weihanglo

@weihanglo weihanglo left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a good read. Thanks.

View changes since this review

Comment thread tests/testsuite/git.rs

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There aren't any other user controlled parameters to git. It would be good to harden this with --end-of-options but we would then need to set a minimum git version so figured I'd pass for now as the needed versions aren't as universally available yet.

This reminds me: What is the minimal supported Git version we have?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not aware of us specifying it or what it would be.

@weihanglo
weihanglo enabled auto-merge July 22, 2026 02:40
@rustbot

This comment has been minimized.

See https://nesbitt.io/2026/07/21/end-of-options.html

While Cargo does support using the git cli, we are not subject to this
because
- we require URLs to be used in the `Cargo.toml`, `.cargo/config.toml`
  parser for git sources
- we always prefix branches, revs, and tags or don't use them

Tests are added to demonstrate this.
I wasn't exhaustive (`patch`, `tag`, more `rev` kinds) but figured this
was approriate based on source code inspection.

There aren't any other user controlled parameters to git.
It would be good to harden this with `--end-of-options` but we would
then need to set a minimum git version so figured I'd pass for now as
the needed versions aren't as universally available yet.
@rustbot

rustbot commented Jul 22, 2026

Copy link
Copy Markdown
Collaborator

This PR was rebased onto a different master commit. Here's a range-diff highlighting what actually changed.

Rebasing is a normal part of keeping PRs up to date, so no action is needed—this note is just to help reviewers.

@weihanglo
weihanglo disabled auto-merge July 22, 2026 13:53
@weihanglo
weihanglo enabled auto-merge July 22, 2026 13:53
@weihanglo
weihanglo added this pull request to the merge queue Jul 22, 2026
Merged via the queue into rust-lang:master with commit 2b63a6a Jul 22, 2026
29 checks passed
@rustbot rustbot removed the S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. label Jul 22, 2026
@epage
epage deleted the cli-injection branch July 22, 2026 15:11
rust-bors Bot pushed a commit to rust-lang/rust that referenced this pull request Jul 25, 2026
Update cargo submodule

17 commits in 3efb1f477e99b42974b982d939fd100303cdf7db..54b61f13a4eea47ec3ee95237d4107976d7909ed
2026-07-17 23:53:19 +0000 to 2026-07-24 13:23:18 +0000
- chore: bump to `libgit2-sys@0.18.7+1.9.6` (rust-lang/cargo#17259)
- Enable build-dir layout v2 on nightly by default (rust-lang/cargo#17258)
- fix(path): clarify error message when path dependency has wrong package (rust-lang/cargo#16927)
- fix(toml): warn on hyphenated lint names and duplicates (rust-lang/cargo#17051)
- fix(test): gate trim-paths tests on split debuginfo support (rust-lang/cargo#17256)
- test(git): Explicitly test for git injection attacks (rust-lang/cargo#17253)
- fix(git): Suggest libgit2 if git-cli fails (rust-lang/cargo#17252)
- fix(diag): bound transitive unused dependency traversal (rust-lang/cargo#17251)
- fix(git): Hide git fetch output without progress  (rust-lang/cargo#17243)
- revert(lint): Remove `new_implicit_minimum_version_req` (rust-lang/cargo#16321) (rust-lang/cargo#17249)
- fix: Add haiku's dylib path (rust-lang/cargo#17248)
- Zsh completion: Add `-p` and `--package` flags for `cargo add` (rust-lang/cargo#17247)
- refactor(source): Clarify the name of the remote git registry (rust-lang/cargo#17240)
- fix(timings): only report units the job queue actually ran (rust-lang/cargo#17238)
- Do not include proc-macro deps in rustc search path args (rust-lang/cargo#17236)
- chore(deps): update cargo-semver-checks to v0.49.0 (rust-lang/cargo#17237)
- rustdoc: rename the doc parts metadata params (rust-lang/cargo#17234)

r? ghost
rust-bors Bot pushed a commit to rust-lang/rust that referenced this pull request Jul 25, 2026
Update cargo submodule



17 commits in 3efb1f477e99b42974b982d939fd100303cdf7db..54b61f13a4eea47ec3ee95237d4107976d7909ed
2026-07-17 23:53:19 +0000 to 2026-07-24 13:23:18 +0000
- chore: bump to `libgit2-sys@0.18.7+1.9.6` (rust-lang/cargo#17259)
- Enable build-dir layout v2 on nightly by default (rust-lang/cargo#17258)
- fix(path): clarify error message when path dependency has wrong package (rust-lang/cargo#16927)
- fix(toml): warn on hyphenated lint names and duplicates (rust-lang/cargo#17051)
- fix(test): gate trim-paths tests on split debuginfo support (rust-lang/cargo#17256)
- test(git): Explicitly test for git injection attacks (rust-lang/cargo#17253)
- fix(git): Suggest libgit2 if git-cli fails (rust-lang/cargo#17252)
- fix(diag): bound transitive unused dependency traversal (rust-lang/cargo#17251)
- fix(git): Hide git fetch output without progress  (rust-lang/cargo#17243)
- revert(lint): Remove `new_implicit_minimum_version_req` (rust-lang/cargo#16321) (rust-lang/cargo#17249)
- fix: Add haiku's dylib path (rust-lang/cargo#17248)
- Zsh completion: Add `-p` and `--package` flags for `cargo add` (rust-lang/cargo#17247)
- refactor(source): Clarify the name of the remote git registry (rust-lang/cargo#17240)
- fix(timings): only report units the job queue actually ran (rust-lang/cargo#17238)
- Do not include proc-macro deps in rustc search path args (rust-lang/cargo#17236)
- chore(deps): update cargo-semver-checks to v0.49.0 (rust-lang/cargo#17237)
- rustdoc: rename the doc parts metadata params (rust-lang/cargo#17234)

r? ghost
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants