René's URL Explorer Experiment


Title: Effect of refreshing with a relative path is not obvious · Issue #1831 · gitpython-developers/GitPython · GitHub

Open Graph Title: Effect of refreshing with a relative path is not obvious · Issue #1831 · gitpython-developers/GitPython

X Title: Effect of refreshing with a relative path is not obvious · Issue #1831 · gitpython-developers/GitPython

Description: When git.refresh or git.cmd.Git.refresh (which git.refresh calls) is passed a relative path as an explicit path argument, it is taken relative to the current working directory of the process GitPython is running in at the time the refres...

Open Graph Description: When git.refresh or git.cmd.Git.refresh (which git.refresh calls) is passed a relative path as an explicit path argument, it is taken relative to the current working directory of the process GitPyt...

X Description: When git.refresh or git.cmd.Git.refresh (which git.refresh calls) is passed a relative path as an explicit path argument, it is taken relative to the current working directory of the process GitPyt...

Opengraph URL: https://github.com/gitpython-developers/GitPython/issues/1831

X: @github

direct link

Domain: togithub.com


Hey, it has json ld scripts:
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"Effect of refreshing with a relative path is not obvious","articleBody":"When `git.refresh` or `git.cmd.Git.refresh` (which `git.refresh` calls) is passed a relative path as an explicit `path` argument, it is taken relative to the current working directory of the process GitPython is running in at the time the refresh occurs. However, if instead one of those `refresh` functions is called with no argument and the value of the [`GIT_PYTHON_GIT_EXECUTABLE`](https://github.com/gitpython-developers/GitPython/blob/afa575454f85b34800460881cc9c3cd7fe78c8e3/git/cmd.py#L352) environment variable is a relative path, that value is *not* resolved, but is instead looked up every time it is run. ([The default of `git`](https://github.com/gitpython-developers/GitPython/blob/afa575454f85b34800460881cc9c3cd7fe78c8e3/git/cmd.py#L327-L328) is likewise not resolved.)\r\n\r\nhttps://github.com/gitpython-developers/GitPython/blob/afa575454f85b34800460881cc9c3cd7fe78c8e3/git/cmd.py#L365-L370\r\n\r\nThis appears intentional, and in 8dc8eb9 (#1815) I added tests that assert this behavior. **But this should also be clarified for users**, by documenting it explicitly in the docstring of at least one of the `refresh` functions. I am unsure how best to do this, because ideally the difference should be *explained*, and I don't know if there is any good reason for the two cases to work differently, other than avoiding a breaking change within the same major version of the library.\r\n\r\nIf this is only for compatibility, then it might make sense to have `git.refresh` and `git.cmd.Git.refresh` accept a second optional `resolve` argument to indicate if the first argument is supposed to be eagerly resolved, and issue a `DeprecationWarning` when the `resolve` argument is not passed (i.e., one-argument `git.refresh` calls would be deprecated). This would not substitute for adding an explanation to the docstring.\r\n\r\n#### Security implications\r\n\r\nA user who is confused about this behavior may write code like `git.refresh(\"git\")`, perhaps with the intention of undoing the effect of a previous refresh. If this is done when the current working directory is the working tree of an untrusted repository that contains a malicious `git` executable (or a malicious executable otherwise named the same as the command passed to `refresh`), then GitPython will use that command as `git`, which would be a situation like CVE-2023-40590 or CVE-2024-22190.\r\n\r\nHowever, I am inclined to consider improving how this is documented to be a security enhancement, but not a fix for an existing security vulnerability in GitPython. I think this is not really a vulnerability in GitPython for three reasons. In decreasing order of significance:\r\n\r\n- Such code would typically be identified readily, because a `git` or other such executable inside a repository would not ordinarily occur in testing or normal usage, and an unexpected `GitCommandNotFound` would be raised and observed. In particular, for the typical case of calling `git.refresh` early on, such a mistake would be identified immediately. This differs from those vulnerabilities, where the current directory was searched but then the expected places were searched, and also differs in that this is about a small likelihood of software that uses GitPython introducing its own vulnerability, rather than GitPython itself having inherently vulnerable behavior.\r\n- The behavior of GitPython need not change to fix this, since it is mainly a matter of documentation.\r\n- Searching for uses of `git.refresh` suggests this is not often used at all, and didn't turn up any incorrect uses of relative paths (though this does not guarantee there are no such incorrect uses).\r\n\r\n#### Integration considerations\r\n\r\nWith #1791, the case for documenting this inconsistency becomes stronger, because that will add another refresh-related function, `refresh_bash`, which never resolves the path. Unlike `git`, GitPython often does not need `bash` or does not need it until a hook is needed to run on Windows, so it is more likely that a wrong call to `refresh_bash` would go undetected. Therefore, I very much agree with the decision there not to resolve the path, on security grounds:\r\n\r\nhttps://github.com/gitpython-developers/GitPython/blob/8200ad10463d6df34e9b21c977e0d9092b908611/git/cmd.py#L439-L446\r\n\r\nBecause after #1791 this will be a behavioral difference between the `refresh` functions and `refresh_bash`, this will be a further reason to document the subtlety.\r\n\r\nThis could possibly be included in the docstring modifications there, which would avoid a conflict, but I am somewhat inclined not to request unnecessary enhancements there.","author":{"url":"https://github.com/EliahKagan","@type":"Person","name":"EliahKagan"},"datePublished":"2024-02-19T05:19:59.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":4},"url":"https://github.com/1831/GitPython/issues/1831"}

route-pattern/_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format)
route-controllervoltron_issues_fragments
route-actionissue_layout
fetch-noncev2:e4d76f3d-77d3-892d-d5be-5f8ac1a1af0b
current-catalog-service-hash81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114
request-idC5E4:3CC0B:30449E4:43C38EA:696936A8
html-safe-nonce51235c981640d4268a2c1b268fff7d38949b0a8f0211d43435145dfd5f4b1cf0
visitor-payloadeyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJDNUU0OjNDQzBCOjMwNDQ5RTQ6NDNDMzhFQTo2OTY5MzZBOCIsInZpc2l0b3JfaWQiOiI3OTkyNzk1NDI4MDk3MzY4NzIiLCJyZWdpb25fZWRnZSI6ImlhZCIsInJlZ2lvbl9yZW5kZXIiOiJpYWQifQ==
visitor-hmac30e0b5d94fe107371cb92d4f09d3d7181d65a995a7a0827b2a447ac3277fcf8a
hovercard-subject-tagissue:2141530005
github-keyboard-shortcutsrepository,issues,copilot
google-site-verificationApib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I
octolytics-urlhttps://collector.github.com/github/collect
analytics-location///voltron/issues_fragments/issue_layout
fb:app_id1401488693436528
apple-itunes-appapp-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/gitpython-developers/GitPython/1831/issue_layout
twitter:imagehttps://opengraph.githubassets.com/6bc5b17ef1642046cc7d1eac0dec2b72c7db459af8ecabc501dc60e79106c0ef/gitpython-developers/GitPython/issues/1831
twitter:cardsummary_large_image
og:imagehttps://opengraph.githubassets.com/6bc5b17ef1642046cc7d1eac0dec2b72c7db459af8ecabc501dc60e79106c0ef/gitpython-developers/GitPython/issues/1831
og:image:altWhen git.refresh or git.cmd.Git.refresh (which git.refresh calls) is passed a relative path as an explicit path argument, it is taken relative to the current working directory of the process GitPyt...
og:image:width1200
og:image:height600
og:site_nameGitHub
og:typeobject
og:author:usernameEliahKagan
hostnamegithub.com
expected-hostnamegithub.com
None54182691a21263b584d2e600b758e081b0ff1d10ffc0d2eefa51cf754b43b51d
turbo-cache-controlno-preview
go-importgithub.com/gitpython-developers/GitPython git https://github.com/gitpython-developers/GitPython.git
octolytics-dimension-user_id503709
octolytics-dimension-user_logingitpython-developers
octolytics-dimension-repository_id1126087
octolytics-dimension-repository_nwogitpython-developers/GitPython
octolytics-dimension-repository_publictrue
octolytics-dimension-repository_is_forkfalse
octolytics-dimension-repository_network_root_id1126087
octolytics-dimension-repository_network_root_nwogitpython-developers/GitPython
turbo-body-classeslogged-out env-production page-responsive
disable-turbofalse
browser-stats-urlhttps://api.github.com/_private/browser/stats
browser-errors-urlhttps://api.github.com/_private/browser/errors
released69ac0477df0f87da03b8b06cebd187012d7a930
ui-targetfull
theme-color#1e2327
color-schemelight dark

Links:

Skip to contenthttps://togithub.com/gitpython-developers/GitPython/issues/1831#start-of-content
https://togithub.com/
Sign in https://togithub.com/login?return_to=https%3A%2F%2Fgithub.com%2Fgitpython-developers%2FGitPython%2Fissues%2F1831
GitHub CopilotWrite better code with AIhttps://github.com/features/copilot
GitHub SparkBuild and deploy intelligent appshttps://github.com/features/spark
GitHub ModelsManage and compare promptshttps://github.com/features/models
MCP RegistryNewIntegrate external toolshttps://github.com/mcp
ActionsAutomate any workflowhttps://github.com/features/actions
CodespacesInstant dev environmentshttps://github.com/features/codespaces
IssuesPlan and track workhttps://github.com/features/issues
Code ReviewManage code changeshttps://github.com/features/code-review
GitHub Advanced SecurityFind and fix vulnerabilitieshttps://github.com/security/advanced-security
Code securitySecure your code as you buildhttps://github.com/security/advanced-security/code-security
Secret protectionStop leaks before they starthttps://github.com/security/advanced-security/secret-protection
Why GitHubhttps://github.com/why-github
Documentationhttps://docs.github.com
Bloghttps://github.blog
Changeloghttps://github.blog/changelog
Marketplacehttps://github.com/marketplace
View all featureshttps://github.com/features
Enterpriseshttps://github.com/enterprise
Small and medium teamshttps://github.com/team
Startupshttps://github.com/enterprise/startups
Nonprofitshttps://github.com/solutions/industry/nonprofits
App Modernizationhttps://github.com/solutions/use-case/app-modernization
DevSecOpshttps://github.com/solutions/use-case/devsecops
DevOpshttps://github.com/solutions/use-case/devops
CI/CDhttps://github.com/solutions/use-case/ci-cd
View all use caseshttps://github.com/solutions/use-case
Healthcarehttps://github.com/solutions/industry/healthcare
Financial serviceshttps://github.com/solutions/industry/financial-services
Manufacturinghttps://github.com/solutions/industry/manufacturing
Governmenthttps://github.com/solutions/industry/government
View all industrieshttps://github.com/solutions/industry
View all solutionshttps://github.com/solutions
AIhttps://github.com/resources/articles?topic=ai
Software Developmenthttps://github.com/resources/articles?topic=software-development
DevOpshttps://github.com/resources/articles?topic=devops
Securityhttps://github.com/resources/articles?topic=security
View all topicshttps://github.com/resources/articles
Customer storieshttps://github.com/customer-stories
Events & webinarshttps://github.com/resources/events
Ebooks & reportshttps://github.com/resources/whitepapers
Business insightshttps://github.com/solutions/executive-insights
GitHub Skillshttps://skills.github.com
Documentationhttps://docs.github.com
Customer supporthttps://support.github.com
Community forumhttps://github.com/orgs/community/discussions
Trust centerhttps://github.com/trust-center
Partnershttps://github.com/partners
GitHub SponsorsFund open source developershttps://github.com/sponsors
Security Labhttps://securitylab.github.com
Maintainer Communityhttps://maintainers.github.com
Acceleratorhttps://github.com/accelerator
Archive Programhttps://archiveprogram.github.com
Topicshttps://github.com/topics
Trendinghttps://github.com/trending
Collectionshttps://github.com/collections
Enterprise platformAI-powered developer platformhttps://github.com/enterprise
GitHub Advanced SecurityEnterprise-grade security featureshttps://github.com/security/advanced-security
Copilot for BusinessEnterprise-grade AI featureshttps://github.com/features/copilot/copilot-business
Premium SupportEnterprise-grade 24/7 supporthttps://github.com/premium-support
Pricinghttps://github.com/pricing
Search syntax tipshttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
documentationhttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
Sign in https://togithub.com/login?return_to=https%3A%2F%2Fgithub.com%2Fgitpython-developers%2FGitPython%2Fissues%2F1831
Sign up https://togithub.com/signup?ref_cta=Sign+up&ref_loc=header+logged+out&ref_page=%2F%3Cuser-name%3E%2F%3Crepo-name%3E%2Fvoltron%2Fissues_fragments%2Fissue_layout&source=header-repo&source_repo=gitpython-developers%2FGitPython
Reloadhttps://togithub.com/gitpython-developers/GitPython/issues/1831
Reloadhttps://togithub.com/gitpython-developers/GitPython/issues/1831
Reloadhttps://togithub.com/gitpython-developers/GitPython/issues/1831
gitpython-developers https://togithub.com/gitpython-developers
GitPythonhttps://togithub.com/gitpython-developers/GitPython
Please reload this pagehttps://togithub.com/gitpython-developers/GitPython/issues/1831
Notifications https://togithub.com/login?return_to=%2Fgitpython-developers%2FGitPython
Fork 964 https://togithub.com/login?return_to=%2Fgitpython-developers%2FGitPython
Star 5k https://togithub.com/login?return_to=%2Fgitpython-developers%2FGitPython
Code https://togithub.com/gitpython-developers/GitPython
Issues 169 https://togithub.com/gitpython-developers/GitPython/issues
Pull requests 8 https://togithub.com/gitpython-developers/GitPython/pulls
Discussions https://togithub.com/gitpython-developers/GitPython/discussions
Actions https://togithub.com/gitpython-developers/GitPython/actions
Security Uh oh! There was an error while loading. Please reload this page. https://togithub.com/gitpython-developers/GitPython/security
Please reload this pagehttps://togithub.com/gitpython-developers/GitPython/issues/1831
Insights https://togithub.com/gitpython-developers/GitPython/pulse
Code https://togithub.com/gitpython-developers/GitPython
Issues https://togithub.com/gitpython-developers/GitPython/issues
Pull requests https://togithub.com/gitpython-developers/GitPython/pulls
Discussions https://togithub.com/gitpython-developers/GitPython/discussions
Actions https://togithub.com/gitpython-developers/GitPython/actions
Security https://togithub.com/gitpython-developers/GitPython/security
Insights https://togithub.com/gitpython-developers/GitPython/pulse
New issuehttps://togithub.com/login?return_to=https://github.com/gitpython-developers/GitPython/issues/1831
New issuehttps://togithub.com/login?return_to=https://github.com/gitpython-developers/GitPython/issues/1831
#1839https://github.com/gitpython-developers/GitPython/pull/1839
Effect of refreshing with a relative path is not obvioushttps://togithub.com/gitpython-developers/GitPython/issues/1831#top
#1839https://github.com/gitpython-developers/GitPython/pull/1839
acknowledgedhttps://github.com/gitpython-developers/GitPython/issues?q=state%3Aopen%20label%3A%22acknowledged%22
help wantedhttps://github.com/gitpython-developers/GitPython/issues?q=state%3Aopen%20label%3A%22help%20wanted%22
https://github.com/EliahKagan
https://github.com/EliahKagan
EliahKaganhttps://github.com/EliahKagan
on Feb 19, 2024https://github.com/gitpython-developers/GitPython/issues/1831#issue-2141530005
GIT_PYTHON_GIT_EXECUTABLEhttps://github.com/gitpython-developers/GitPython/blob/afa575454f85b34800460881cc9c3cd7fe78c8e3/git/cmd.py#L352
The default of githttps://github.com/gitpython-developers/GitPython/blob/afa575454f85b34800460881cc9c3cd7fe78c8e3/git/cmd.py#L327-L328
GitPython/git/cmd.pyhttps://github.com/gitpython-developers/GitPython/blob/afa575454f85b34800460881cc9c3cd7fe78c8e3/git/cmd.py#L365-L370
afa5754https://togithub.com/gitpython-developers/GitPython/commit/afa575454f85b34800460881cc9c3cd7fe78c8e3
8dc8eb9https://github.com/gitpython-developers/GitPython/commit/8dc8eb9e76a3162636856fa31b71ba10b33705eb
#1815https://github.com/gitpython-developers/GitPython/pull/1815
CVE-2023-40590https://github.com/advisories/GHSA-wfm5-v35h-vwf4
CVE-2024-22190https://github.com/advisories/GHSA-2mqj-m65w-jghx
#1791https://github.com/gitpython-developers/GitPython/pull/1791
GitPython/git/cmd.pyhttps://github.com/gitpython-developers/GitPython/blob/8200ad10463d6df34e9b21c977e0d9092b908611/git/cmd.py#L439-L446
8200ad1https://togithub.com/gitpython-developers/GitPython/commit/8200ad10463d6df34e9b21c977e0d9092b908611
#1791https://github.com/gitpython-developers/GitPython/pull/1791
acknowledgedhttps://github.com/gitpython-developers/GitPython/issues?q=state%3Aopen%20label%3A%22acknowledged%22
help wantedhttps://github.com/gitpython-developers/GitPython/issues?q=state%3Aopen%20label%3A%22help%20wanted%22
https://github.com
Termshttps://docs.github.com/site-policy/github-terms/github-terms-of-service
Privacyhttps://docs.github.com/site-policy/privacy-policies/github-privacy-statement
Securityhttps://github.com/security
Statushttps://www.githubstatus.com/
Communityhttps://github.community/
Docshttps://docs.github.com/
Contacthttps://support.github.com?tags=dotcom-footer

Viewport: width=device-width


URLs of crawlers that visited me.