lib/vcs_info.zsh loaded VCS_INFO_formats and regexp-replace and patched
the function body on every startup, although only themes that call
vcs_info ever need it. Define a VCS_INFO_formats wrapper that loads and
patches the real function the first time it's called, then replaces
itself with it. `autoload` doesn't override an existing function, so
the wrapper survives a theme's `autoload -Uz vcs_info` and vcs_info's
own autoload of VCS_INFO_*.
Verified that a branch named `evil%n%m` still renders literally after
prompt expansion, as with the eager patch (CVE-2021-45444 mitigation).
Measured on macOS arm64, zsh 5.9: 1.6 ms -> 0.1 ms per interactive
start.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This lib function applies a patch to the VCS_INFO_formats function
in zsh versions from v5.0.3 until v5.8, which don't quote % chars
in some arguments received. Normally that just means that some
% characters in these strings (branch names, directories, etc.)
will be incorrectly parsed as formatting sequences.
With CVE-2021-45444, however, this means that one of these strings
from a malicious source (e.g. a malicious git repository) can
trigger command injection and run arbitrary code in the user's
machine when visiting such git repository.
Zsh 5.8.1 fixes this vulnerability [1], but older vcs_info setups
still need a workaround such as this one to patch the vulnerability.
[1] https://github.com/zsh-users/zsh/commit/c3ea1e5d52eff8b7b172fa8c1ccc3462b43b2790