Repository navigation
security: strip git trace env, single-quote credential helper, harden URL parsing - #505
Merged
Merged
Conversation
… URL parsing Closes #489 (security hardening umbrella), #490 (detached HEAD fallback), #491 (fetch_and_rebase swallows symbolic-ref error). ## Security - Strip GIT_TRACE / GIT_TRACE_CURL / GIT_CURL_VERBOSE / GCM_TRACE etc. on every Command::new("git") that talks to a remote. Without this, CI that sets GIT_CURL_VERBOSE=1 (or a Datadog APM agent that injects GIT_TRACE_CURL transparently) causes git to dump the Authorization header to stderr, which ferrflow then forwarded into anyhow::Error display strings. Added a token-pattern scrubber on stderr propagation as a defense in depth (masks ghs_/ghp_/gho_/ghu_/glpat_/github_pat_). - Switch credential helper escaping from double-quote escaping to single-quoted sh literals with proper ' -> '\'' encoding. A token containing dollar, backtick, semicolon, ampersand no longer reaches sh -c as code. Added unit test with an evil token. - Hook subprocesses now env_remove GITHUB_TOKEN / FERRFLOW_TOKEN / GITLAB_TOKEN before exec. Bot mode sets these process-wide so git picks them up via credential helper, but a malicious hook can no longer exfiltrate the token by echoing the env var. - extract_host (src/forge/mod.rs) now strips userinfo (user[:pwd]@) before returning the host. Previously a remote like https://attacker.com#@github.com/owner/repo resolved host to "attacker.com#@github.com" which downstream forge construction could mis-route the token to. - TS config loader writes its wrapper into tempfile::tempdir() instead of the directory of the user .ts. Closes a symlink TOCTOU where a cohabiting process could create .ferrflow-loader.mjs as a symlink to ~/.bashrc before ferrflow fs::write follows it. ## Bug fixes - resolve_current_branch (src/git/repo.rs) no longer falls back to GITHUB_REF_NAME when the CI is in detached HEAD mode and that env var contains a tag name. Only use GITHUB_REF when it starts with refs/heads/. Same logic for CI_COMMIT_REF_NAME (skip when CI_COMMIT_TAG is set). - fetch_and_rebase (src/git/push.rs) no longer silently rewrites a branch ref when symbolic-ref fails. Previously a detached HEAD state caused .ok().unwrap_or_default() to compare empty to the target ref, dropping into a destructive update-ref plus checkout -f that could overwrite the user local state. Now hard-fails with a clear HEAD is detached error and an actionable hint. - formats/gomod.rs no longer falls through to the process CWD when file_path.parent() is the empty Path. ## Tests - 514 lib tests plus 616 bin tests pass, cargo clippy -D warnings clean - New tests: single-quote-escape an evil token, strip GIT_TRACE env
There was a problem hiding this comment.
Benchmark
Details
| Benchmark suite | Current: 577336d | Previous: 0b5fe57 | Ratio |
|---|---|---|---|
git_collect_tags/single_tag |
19778 ns/iter (± 51) |
This comment was automatically generated by workflow using github-action-benchmark.
This was referenced May 24, 2026
This was referenced Jun 11, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #489 (security hardening umbrella), #490 (detached HEAD branch resolve), #491 (fetch_and_rebase destructive checkout).
Summary
7 hardening fixes from the audit, batched as one PR because they share the test-suite + the same files (`src/git/auth.rs` is touched by 3 of them).
Security
Bug fixes
Test plan