test(git): Explicitly test for git injection attacks - #17253
Conversation
|
r? @weihanglo rustbot has assigned @weihanglo. Use Why was this reviewer chosen?The reviewer was selected based on:
|
There was a problem hiding this comment.
There aren't any other user controlled parameters to git. It would be good to harden this with --end-of-options but we would then need to set a minimum git version so figured I'd pass for now as the needed versions aren't as universally available yet.
This reminds me: What is the minimal supported Git version we have?
There was a problem hiding this comment.
I'm not aware of us specifying it or what it would be.
This comment has been minimized.
This comment has been minimized.
See https://nesbitt.io/2026/07/21/end-of-options.html While Cargo does support using the git cli, we are not subject to this because - we require URLs to be used in the `Cargo.toml`, `.cargo/config.toml` parser for git sources - we always prefix branches, revs, and tags or don't use them Tests are added to demonstrate this. I wasn't exhaustive (`patch`, `tag`, more `rev` kinds) but figured this was approriate based on source code inspection. There aren't any other user controlled parameters to git. It would be good to harden this with `--end-of-options` but we would then need to set a minimum git version so figured I'd pass for now as the needed versions aren't as universally available yet.
|
This PR was rebased onto a different master commit. Here's a range-diff highlighting what actually changed. Rebasing is a normal part of keeping PRs up to date, so no action is needed—this note is just to help reviewers. |
Update cargo submodule 17 commits in 3efb1f477e99b42974b982d939fd100303cdf7db..54b61f13a4eea47ec3ee95237d4107976d7909ed 2026-07-17 23:53:19 +0000 to 2026-07-24 13:23:18 +0000 - chore: bump to `libgit2-sys@0.18.7+1.9.6` (rust-lang/cargo#17259) - Enable build-dir layout v2 on nightly by default (rust-lang/cargo#17258) - fix(path): clarify error message when path dependency has wrong package (rust-lang/cargo#16927) - fix(toml): warn on hyphenated lint names and duplicates (rust-lang/cargo#17051) - fix(test): gate trim-paths tests on split debuginfo support (rust-lang/cargo#17256) - test(git): Explicitly test for git injection attacks (rust-lang/cargo#17253) - fix(git): Suggest libgit2 if git-cli fails (rust-lang/cargo#17252) - fix(diag): bound transitive unused dependency traversal (rust-lang/cargo#17251) - fix(git): Hide git fetch output without progress (rust-lang/cargo#17243) - revert(lint): Remove `new_implicit_minimum_version_req` (rust-lang/cargo#16321) (rust-lang/cargo#17249) - fix: Add haiku's dylib path (rust-lang/cargo#17248) - Zsh completion: Add `-p` and `--package` flags for `cargo add` (rust-lang/cargo#17247) - refactor(source): Clarify the name of the remote git registry (rust-lang/cargo#17240) - fix(timings): only report units the job queue actually ran (rust-lang/cargo#17238) - Do not include proc-macro deps in rustc search path args (rust-lang/cargo#17236) - chore(deps): update cargo-semver-checks to v0.49.0 (rust-lang/cargo#17237) - rustdoc: rename the doc parts metadata params (rust-lang/cargo#17234) r? ghost
Update cargo submodule 17 commits in 3efb1f477e99b42974b982d939fd100303cdf7db..54b61f13a4eea47ec3ee95237d4107976d7909ed 2026-07-17 23:53:19 +0000 to 2026-07-24 13:23:18 +0000 - chore: bump to `libgit2-sys@0.18.7+1.9.6` (rust-lang/cargo#17259) - Enable build-dir layout v2 on nightly by default (rust-lang/cargo#17258) - fix(path): clarify error message when path dependency has wrong package (rust-lang/cargo#16927) - fix(toml): warn on hyphenated lint names and duplicates (rust-lang/cargo#17051) - fix(test): gate trim-paths tests on split debuginfo support (rust-lang/cargo#17256) - test(git): Explicitly test for git injection attacks (rust-lang/cargo#17253) - fix(git): Suggest libgit2 if git-cli fails (rust-lang/cargo#17252) - fix(diag): bound transitive unused dependency traversal (rust-lang/cargo#17251) - fix(git): Hide git fetch output without progress (rust-lang/cargo#17243) - revert(lint): Remove `new_implicit_minimum_version_req` (rust-lang/cargo#16321) (rust-lang/cargo#17249) - fix: Add haiku's dylib path (rust-lang/cargo#17248) - Zsh completion: Add `-p` and `--package` flags for `cargo add` (rust-lang/cargo#17247) - refactor(source): Clarify the name of the remote git registry (rust-lang/cargo#17240) - fix(timings): only report units the job queue actually ran (rust-lang/cargo#17238) - Do not include proc-macro deps in rustc search path args (rust-lang/cargo#17236) - chore(deps): update cargo-semver-checks to v0.49.0 (rust-lang/cargo#17237) - rustdoc: rename the doc parts metadata params (rust-lang/cargo#17234) r? ghost
Update cargo submodule ## src/tools/cargo 20 commits in 3efb1f477e99b42974b982d939fd100303cdf7db..a09737c688e6b643b3a2e185d076bb4a298d6965 2026-07-17 23:53:19 +0000 to 2026-07-26 15:00:33 +0000 - fix(cli): don't panic during completions when rustup is unavailable (rust-lang/cargo#17263) - docs(workspace): add recommended structure to members field (rust-lang/cargo#17166) - Update cargo-fetch.md to remove cargo-prefetch reference (rust-lang/cargo#16568) - chore: bump to `libgit2-sys@0.18.7+1.9.6` (rust-lang/cargo#17259) - Enable build-dir layout v2 on nightly by default (rust-lang/cargo#17258) - fix(path): clarify error message when path dependency has wrong package (rust-lang/cargo#16927) - fix(toml): warn on hyphenated lint names and duplicates (rust-lang/cargo#17051) - fix(test): gate trim-paths tests on split debuginfo support (rust-lang/cargo#17256) - test(git): Explicitly test for git injection attacks (rust-lang/cargo#17253) - fix(git): Suggest libgit2 if git-cli fails (rust-lang/cargo#17252) - fix(diag): bound transitive unused dependency traversal (rust-lang/cargo#17251) - fix(git): Hide git fetch output without progress (rust-lang/cargo#17243) - revert(lint): Remove `new_implicit_minimum_version_req` (rust-lang/cargo#16321) (rust-lang/cargo#17249) - fix: Add haiku's dylib path (rust-lang/cargo#17248) - Zsh completion: Add `-p` and `--package` flags for `cargo add` (rust-lang/cargo#17247) - refactor(source): Clarify the name of the remote git registry (rust-lang/cargo#17240) - fix(timings): only report units the job queue actually ran (rust-lang/cargo#17238) - Do not include proc-macro deps in rustc search path args (rust-lang/cargo#17236) - chore(deps): update cargo-semver-checks to v0.49.0 (rust-lang/cargo#17237) - rustdoc: rename the doc parts metadata params (rust-lang/cargo#17234) ## src/tools/rustc-perf 12 commits in 0508bdcd37152b28c39b6752828683cdd3f128b5..74ecbcdf88411937a6e39baf2779948565dfd388 2026-07-15 10:20:27 +0000 to 2026-07-27 15:02:48 +0000 - feat: support `@argfile` for rustc-fake (rust-lang/rustc-perf#2509) - Download Clippy when a Clippy profile is requested (rust-lang/rustc-perf#2508) - Add early check for missing rustdoc/clippy in a toolchain (rust-lang/rustc-perf#2507) - Add 2026-07-21 triage (rust-lang/rustc-perf#2506) - use stable extract_if: since 1.87 (rust-lang/rustc-perf#2191) - Update GitHub Actions (rust-lang/rustc-perf#2460) - Update dependency @types/msgpack-lite to v0.1.12 (rust-lang/rustc-perf#2439) - Add 30 day history link to artifact size tab on the compare page (rust-lang/rustc-perf#2505) - Fix selecting color for the bootstrap chart on the toolchain page (rust-lang/rustc-perf#2504) - Add artifact size history chart to toolchain page (rust-lang/rustc-perf#2501) - Parallel frontend compiler support (perf backend only) (rust-lang/rustc-perf#2491) - Run benchmark smoke test for all profiles on Windows on CI (rust-lang/rustc-perf#2503)
Update cargo submodule ## src/tools/cargo 20 commits in 3efb1f477e99b42974b982d939fd100303cdf7db..a09737c688e6b643b3a2e185d076bb4a298d6965 2026-07-17 23:53:19 +0000 to 2026-07-26 15:00:33 +0000 - fix(cli): don't panic during completions when rustup is unavailable (rust-lang/cargo#17263) - docs(workspace): add recommended structure to members field (rust-lang/cargo#17166) - Update cargo-fetch.md to remove cargo-prefetch reference (rust-lang/cargo#16568) - chore: bump to `libgit2-sys@0.18.7+1.9.6` (rust-lang/cargo#17259) - Enable build-dir layout v2 on nightly by default (rust-lang/cargo#17258) - fix(path): clarify error message when path dependency has wrong package (rust-lang/cargo#16927) - fix(toml): warn on hyphenated lint names and duplicates (rust-lang/cargo#17051) - fix(test): gate trim-paths tests on split debuginfo support (rust-lang/cargo#17256) - test(git): Explicitly test for git injection attacks (rust-lang/cargo#17253) - fix(git): Suggest libgit2 if git-cli fails (rust-lang/cargo#17252) - fix(diag): bound transitive unused dependency traversal (rust-lang/cargo#17251) - fix(git): Hide git fetch output without progress (rust-lang/cargo#17243) - revert(lint): Remove `new_implicit_minimum_version_req` (rust-lang/cargo#16321) (rust-lang/cargo#17249) - fix: Add haiku's dylib path (rust-lang/cargo#17248) - Zsh completion: Add `-p` and `--package` flags for `cargo add` (rust-lang/cargo#17247) - refactor(source): Clarify the name of the remote git registry (rust-lang/cargo#17240) - fix(timings): only report units the job queue actually ran (rust-lang/cargo#17238) - Do not include proc-macro deps in rustc search path args (rust-lang/cargo#17236) - chore(deps): update cargo-semver-checks to v0.49.0 (rust-lang/cargo#17237) - rustdoc: rename the doc parts metadata params (rust-lang/cargo#17234) ## src/tools/rustc-perf 12 commits in 0508bdcd37152b28c39b6752828683cdd3f128b5..74ecbcdf88411937a6e39baf2779948565dfd388 2026-07-15 10:20:27 +0000 to 2026-07-27 15:02:48 +0000 - feat: support `@argfile` for rustc-fake (rust-lang/rustc-perf#2509) - Download Clippy when a Clippy profile is requested (rust-lang/rustc-perf#2508) - Add early check for missing rustdoc/clippy in a toolchain (rust-lang/rustc-perf#2507) - Add 2026-07-21 triage (rust-lang/rustc-perf#2506) - use stable extract_if: since 1.87 (rust-lang/rustc-perf#2191) - Update GitHub Actions (rust-lang/rustc-perf#2460) - Update dependency @types/msgpack-lite to v0.1.12 (rust-lang/rustc-perf#2439) - Add 30 day history link to artifact size tab on the compare page (rust-lang/rustc-perf#2505) - Fix selecting color for the bootstrap chart on the toolchain page (rust-lang/rustc-perf#2504) - Add artifact size history chart to toolchain page (rust-lang/rustc-perf#2501) - Parallel frontend compiler support (perf backend only) (rust-lang/rustc-perf#2491) - Run benchmark smoke test for all profiles on Windows on CI (rust-lang/rustc-perf#2503)
Update cargo submodule ## src/tools/cargo 23 commits in 3efb1f477e99b42974b982d939fd100303cdf7db..7c83d4cc0953b81d823e47d640c64da9b8bd4fac 2026-07-17 23:53:19 +0000 to 2026-07-29 21:34:53 +0000 - fix: Pass rustdoc flags to final CCI merge step (rust-lang/cargo#17269) - Reworked how we enable the new build-dir layout on nightly (rust-lang/cargo#17272) - Allow setting `-Zembed-metadata` value from the config (rust-lang/cargo#17266) - fix(cli): don't panic during completions when rustup is unavailable (rust-lang/cargo#17263) - docs(workspace): add recommended structure to members field (rust-lang/cargo#17166) - Update cargo-fetch.md to remove cargo-prefetch reference (rust-lang/cargo#16568) - chore: bump to `libgit2-sys@0.18.7+1.9.6` (rust-lang/cargo#17259) - Enable build-dir layout v2 on nightly by default (rust-lang/cargo#17258) - fix(path): clarify error message when path dependency has wrong package (rust-lang/cargo#16927) - fix(toml): warn on hyphenated lint names and duplicates (rust-lang/cargo#17051) - fix(test): gate trim-paths tests on split debuginfo support (rust-lang/cargo#17256) - test(git): Explicitly test for git injection attacks (rust-lang/cargo#17253) - fix(git): Suggest libgit2 if git-cli fails (rust-lang/cargo#17252) - fix(diag): bound transitive unused dependency traversal (rust-lang/cargo#17251) - fix(git): Hide git fetch output without progress (rust-lang/cargo#17243) - revert(lint): Remove `new_implicit_minimum_version_req` (rust-lang/cargo#16321) (rust-lang/cargo#17249) - fix: Add haiku's dylib path (rust-lang/cargo#17248) - Zsh completion: Add `-p` and `--package` flags for `cargo add` (rust-lang/cargo#17247) - refactor(source): Clarify the name of the remote git registry (rust-lang/cargo#17240) - fix(timings): only report units the job queue actually ran (rust-lang/cargo#17238) - Do not include proc-macro deps in rustc search path args (rust-lang/cargo#17236) - chore(deps): update cargo-semver-checks to v0.49.0 (rust-lang/cargo#17237) - rustdoc: rename the doc parts metadata params (rust-lang/cargo#17234) ## src/tools/rustc-perf 12 commits in 0508bdcd37152b28c39b6752828683cdd3f128b5..74ecbcdf88411937a6e39baf2779948565dfd388 2026-07-15 10:20:27 +0000 to 2026-07-27 15:02:48 +0000 - feat: support `@argfile` for rustc-fake (rust-lang/rustc-perf#2509) - Download Clippy when a Clippy profile is requested (rust-lang/rustc-perf#2508) - Add early check for missing rustdoc/clippy in a toolchain (rust-lang/rustc-perf#2507) - Add 2026-07-21 triage (rust-lang/rustc-perf#2506) - use stable extract_if: since 1.87 (rust-lang/rustc-perf#2191) - Update GitHub Actions (rust-lang/rustc-perf#2460) - Update dependency @types/msgpack-lite to v0.1.12 (rust-lang/rustc-perf#2439) - Add 30 day history link to artifact size tab on the compare page (rust-lang/rustc-perf#2505) - Fix selecting color for the bootstrap chart on the toolchain page (rust-lang/rustc-perf#2504) - Add artifact size history chart to toolchain page (rust-lang/rustc-perf#2501) - Parallel frontend compiler support (perf backend only) (rust-lang/rustc-perf#2491) - Run benchmark smoke test for all profiles on Windows on CI (rust-lang/rustc-perf#2503)
Update cargo submodule ## src/tools/cargo 23 commits in 3efb1f477e99b42974b982d939fd100303cdf7db..7c83d4cc0953b81d823e47d640c64da9b8bd4fac 2026-07-17 23:53:19 +0000 to 2026-07-29 21:34:53 +0000 - fix: Pass rustdoc flags to final CCI merge step (rust-lang/cargo#17269) - Reworked how we enable the new build-dir layout on nightly (rust-lang/cargo#17272) - Allow setting `-Zembed-metadata` value from the config (rust-lang/cargo#17266) - fix(cli): don't panic during completions when rustup is unavailable (rust-lang/cargo#17263) - docs(workspace): add recommended structure to members field (rust-lang/cargo#17166) - Update cargo-fetch.md to remove cargo-prefetch reference (rust-lang/cargo#16568) - chore: bump to `libgit2-sys@0.18.7+1.9.6` (rust-lang/cargo#17259) - Enable build-dir layout v2 on nightly by default (rust-lang/cargo#17258) - fix(path): clarify error message when path dependency has wrong package (rust-lang/cargo#16927) - fix(toml): warn on hyphenated lint names and duplicates (rust-lang/cargo#17051) - fix(test): gate trim-paths tests on split debuginfo support (rust-lang/cargo#17256) - test(git): Explicitly test for git injection attacks (rust-lang/cargo#17253) - fix(git): Suggest libgit2 if git-cli fails (rust-lang/cargo#17252) - fix(diag): bound transitive unused dependency traversal (rust-lang/cargo#17251) - fix(git): Hide git fetch output without progress (rust-lang/cargo#17243) - revert(lint): Remove `new_implicit_minimum_version_req` (rust-lang/cargo#16321) (rust-lang/cargo#17249) - fix: Add haiku's dylib path (rust-lang/cargo#17248) - Zsh completion: Add `-p` and `--package` flags for `cargo add` (rust-lang/cargo#17247) - refactor(source): Clarify the name of the remote git registry (rust-lang/cargo#17240) - fix(timings): only report units the job queue actually ran (rust-lang/cargo#17238) - Do not include proc-macro deps in rustc search path args (rust-lang/cargo#17236) - chore(deps): update cargo-semver-checks to v0.49.0 (rust-lang/cargo#17237) - rustdoc: rename the doc parts metadata params (rust-lang/cargo#17234) ## src/tools/rustc-perf 12 commits in 0508bdcd37152b28c39b6752828683cdd3f128b5..74ecbcdf88411937a6e39baf2779948565dfd388 2026-07-15 10:20:27 +0000 to 2026-07-27 15:02:48 +0000 - feat: support `@argfile` for rustc-fake (rust-lang/rustc-perf#2509) - Download Clippy when a Clippy profile is requested (rust-lang/rustc-perf#2508) - Add early check for missing rustdoc/clippy in a toolchain (rust-lang/rustc-perf#2507) - Add 2026-07-21 triage (rust-lang/rustc-perf#2506) - use stable extract_if: since 1.87 (rust-lang/rustc-perf#2191) - Update GitHub Actions (rust-lang/rustc-perf#2460) - Update dependency @types/msgpack-lite to v0.1.12 (rust-lang/rustc-perf#2439) - Add 30 day history link to artifact size tab on the compare page (rust-lang/rustc-perf#2505) - Fix selecting color for the bootstrap chart on the toolchain page (rust-lang/rustc-perf#2504) - Add artifact size history chart to toolchain page (rust-lang/rustc-perf#2501) - Parallel frontend compiler support (perf backend only) (rust-lang/rustc-perf#2491) - Run benchmark smoke test for all profiles on Windows on CI (rust-lang/rustc-perf#2503)
What does this PR try to resolve?
See https://nesbitt.io/2026/07/21/end-of-options.html
While Cargo does support using the git cli, we are not subject to this because
Cargo.toml,.cargo/config.tomlparser for git sourcesTests are added to demonstrate this.
I wasn't exhaustive (
patch,tag, morerevkinds) but figured this was approriate based on source code inspection.There aren't any other user controlled parameters to git. It would be good to harden this with
--end-of-optionsbut we would then need to set a minimum git version so figured I'd pass for now as the needed versions aren't as universally available yet.How to test and review this PR?