Commit Graph
8 Commits
Author SHA1 Message Date
copilot-swe-agent[bot]androbbyrussell 61f12e078f fix(vcs_info): avoid undefining wrapper during load transition
Co-authored-by: robbyrussell <257+robbyrussell@users.noreply.github.com>
2026-09-06 15:56:08 +00:00
copilot-swe-agent[bot]androbbyrussell e4172614e8 fix(vcs_info): keep lazy wrapper recoverable on autoload failure
Co-authored-by: robbyrussell <257+robbyrussell@users.noreply.github.com>
2026-09-06 15:55:21 +00:00
copilot-swe-agent[bot]androbbyrussell 3fe8d6d6af fix(vcs_info): preserve preloaded VCS_INFO_formats when patching
Co-authored-by: robbyrussell <257+robbyrussell@users.noreply.github.com>
2026-09-06 15:54:56 +00:00
Robby RussellandClaude Fable 5.1 a0fa610df3 perf(vcs_info): apply the %-quoting patch on first use
lib/vcs_info.zsh loaded VCS_INFO_formats and regexp-replace and patched
the function body on every startup, although only themes that call
vcs_info ever need it. Define a VCS_INFO_formats wrapper that loads and
patches the real function the first time it's called, then replaces
itself with it. `autoload` doesn't override an existing function, so
the wrapper survives a theme's `autoload -Uz vcs_info` and vcs_info's
own autoload of VCS_INFO_*.

Verified that a branch named `evil%n%m` still renders literally after
prompt expansion, as with the eager patch (CVE-2021-45444 mitigation).
Measured on macOS arm64, zsh 5.9: 1.6 ms -> 0.1 ms per interactive
start.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-06 08:14:53 -07:00
Marc Cornellà 5cb943eea4 fix(lib): fix return code after expected non-zero exit code (#11524)
Fixes #11524
2023-02-24 17:27:23 +01:00
Marc Cornellà b00b59364a fix(vcs_info): don't patch VCS_INFO_formats if not found 2022-02-21 20:30:06 +01:00
Marc Cornellà 07b829c894 fix(vcs_info): quote % in relevant fields on all current Zsh releases 2022-02-21 18:34:28 +01:00
Marc Cornellà ef3f7c43a9 fix: apply workaround patch for vcs_info (CVE-2021-45444)
This lib function applies a patch to the VCS_INFO_formats function
in zsh versions from v5.0.3 until v5.8, which don't quote % chars
in some arguments received. Normally that just means that some
% characters in these strings (branch names, directories, etc.)
will be incorrectly parsed as formatting sequences.

With CVE-2021-45444, however, this means that one of these strings
from a malicious source (e.g. a malicious git repository) can
trigger command injection and run arbitrary code in the user's
machine when visiting such git repository.

Zsh 5.8.1 fixes this vulnerability [1], but older vcs_info setups
still need a workaround such as this one to patch the vulnerability.

[1] https://github.com/zsh-users/zsh/commit/c3ea1e5d52eff8b7b172fa8c1ccc3462b43b2790
2022-02-13 19:07:12 +01:00