List paths with -z so quoted paths are not skipped - #1
Open
WatchTree-19 wants to merge 1 commit into
Open
WatchTree-19 wants to merge 1 commit into
WatchTree-19 wants to merge 1 commit into
Conversation
StagedFiles, TrackedFiles, ManagedFiles and IgnoredManagedFiles read git output line by line. With core.quotePath (Git's default) any path containing a non-ASCII byte comes back quoted, e.g. "services/caf\303\251/.env", so IsManagedName saw the name `.env"` and dropped the file. verify reported "No managed .env files found" and the pre-commit guard let a plaintext .env in such a folder be committed. Use -z and split on NUL, as check-attr already does.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
StagedFiles,TrackedFiles,ManagedFilesandIgnoredManagedFilesreadgitoutput line by line. With Git's defaultcore.quotePath, a path containing any non-ASCII byte comes back quoted, e.g."services/caf\303\251/.env", soIsManagedNamesees the name.env"and drops the file.With
services/café/.envholdingSECRET=hunter2:envapor verifyprints "No managed .env files found." and exits 0. The same repo withservices/cafe/.envfails verify with "plaintext secrets found".SECRET=hunter3be committed in plaintext. Withcafeit refuses.After the change both paths behave like
cafe: verify fails and the guard blocks the commit.The fix adds a small
runPathshelper that runs the listing with-zand splits on NUL, the same waycheck-attris already called, and uses it for all four listings.Test:
TestPathListingsKeepNonASCIIPathsininternal/gitutil/git_test.go. It setscore.quotePath=trueso a global Git setting can't hide the problem, and checks bothManagedFilesandStagedFiles. It fails onmainand passes with the fix.go test ./...,go vetandgofmtare clean.