Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .jules/sentinel.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
## $(date +%Y-%m-%d) - Prevent RCE via malicious .git/config core.fsmonitor
**Vulnerability:** Invoking `git` operations (like `diff` or `ls-files`) programmatically in untrusted repositories without overriding configuration can allow arbitrary command execution via a malicious `.git/config` setting `core.fsmonitor`.
**Learning:** `subprocess.run(["git", ...])` is not completely safe, even for seemingly innocuous commands like `git diff` or `git rev-parse`. A repository downloaded from an untrusted source might carry a customized configuration that points to an executable bundled with the repository.
**Prevention:** When invoking `git` via `subprocess` against potentially untrusted directories, always apply the configuration `("-c", "core.fsmonitor=false")` (typically defined as `_SAFE_GIT_CONFIG`) directly in the command arguments.
10 changes: 6 additions & 4 deletions src/wardline/core/delta.py
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,8 @@
if TYPE_CHECKING:
from wardline.scanner.index import Entity

_SAFE_GIT_CONFIG = ("-c", "core.fsmonitor=false")


def get_changed_files_since(ref: str, root: Path) -> set[str]:
"""Get the set of file paths (repo-relative, POSIX-style matching Location.path)
Expand All @@ -22,7 +24,7 @@ def get_changed_files_since(ref: str, root: Path) -> set[str]:
# 1. Get the git toplevel directory.
try:
res = subprocess.run(
["git", "rev-parse", "--show-toplevel"],
["git", *_SAFE_GIT_CONFIG, "rev-parse", "--show-toplevel"],
cwd=root,
capture_output=True,
text=True,
Expand All @@ -38,7 +40,7 @@ def get_changed_files_since(ref: str, root: Path) -> set[str]:
# 2. Resolve ref to a verified object id before passing it to git diff.
try:
res = subprocess.run(
["git", "rev-parse", "--verify", "--end-of-options", ref],
["git", *_SAFE_GIT_CONFIG, "rev-parse", "--verify", "--end-of-options", ref],
cwd=git_toplevel,
capture_output=True,
text=True,
Expand All @@ -54,7 +56,7 @@ def get_changed_files_since(ref: str, root: Path) -> set[str]:
# 3. Get changed files since ref (committed since ref, staged, unstaged).
try:
res = subprocess.run(
["git", "diff", "--name-only", verified_ref, "--"],
["git", *_SAFE_GIT_CONFIG, "diff", "--name-only", verified_ref, "--"],
cwd=git_toplevel,
capture_output=True,
text=True,
Expand All @@ -68,7 +70,7 @@ def get_changed_files_since(ref: str, root: Path) -> set[str]:
# 4. Get untracked files.
try:
res = subprocess.run(
["git", "ls-files", "--others", "--exclude-standard"],
["git", *_SAFE_GIT_CONFIG, "ls-files", "--others", "--exclude-standard"],
cwd=git_toplevel,
capture_output=True,
text=True,
Expand Down
6 changes: 4 additions & 2 deletions src/wardline/core/legis.py
Original file line number Diff line number Diff line change
Expand Up @@ -73,6 +73,8 @@
SCAN_SCOPE_FIELD = "scan_scope"
SCAN_SCOPE_SCHEMA = "wardline-legis-scan-scope-1"

_SAFE_GIT_CONFIG = ("-c", "core.fsmonitor=false")

# The one shared vocabulary β€” legis carries these 8 tiers verbatim (TRUST_TIERS in
# legis ingest.py). Sourced from the lattice so the two can never drift.
TRUST_TIERS: frozenset[str] = frozenset(t.value for t in TaintState)
Expand Down Expand Up @@ -199,7 +201,7 @@ def _git_tree_sha(root: Path) -> str | None:
"""
try:
rev = subprocess.run(
["git", "rev-parse", "HEAD^{tree}"],
["git", *_SAFE_GIT_CONFIG, "rev-parse", "HEAD^{tree}"],
cwd=root,
capture_output=True,
text=True,
Expand All @@ -215,7 +217,7 @@ def _git_repo_root(root: Path) -> Path | None:
"""The containing git repository root, or None when unavailable."""
try:
rev = subprocess.run(
["git", "rev-parse", "--show-toplevel"],
["git", *_SAFE_GIT_CONFIG, "rev-parse", "--show-toplevel"],
cwd=root,
capture_output=True,
text=True,
Expand Down
20 changes: 18 additions & 2 deletions tests/unit/core/test_delta.py
Original file line number Diff line number Diff line change
Expand Up @@ -43,8 +43,24 @@ def run_dispatch(args, **kwargs):
res = get_changed_files_since("HEAD~1", root)

assert res == {"foo.py", "bar.py", "baz.py"}
assert mock_run.call_args_list[1].args[0] == ["git", "rev-parse", "--verify", "--end-of-options", "HEAD~1"]
assert mock_run.call_args_list[2].args[0] == ["git", "diff", "--name-only", "abc123", "--"]
assert mock_run.call_args_list[1].args[0] == [
"git",
"-c",
"core.fsmonitor=false",
"rev-parse",
"--verify",
"--end-of-options",
"HEAD~1",
]
assert mock_run.call_args_list[2].args[0] == [
"git",
"-c",
"core.fsmonitor=false",
"diff",
"--name-only",
"abc123",
"--",
]


@patch("subprocess.run")
Expand Down
Loading