gitutil: end option parsing before every ref !195

merged merged by cmc on 2026-09-03 18:47 UTC · krz/gitbay:git-end-of-options into main

Discussion

cmc

Refs reaching gitutil come from URL segments and command arguments, and the call sites passed them as bare arguments after a subcommand's options. A leading-dash ref was only harmless because every caller happened to glue it to :path or ^{commit} or resolve it first; a future handler passing a raw ref to an option-taking subcommand would have been injectable.

Every invocation now passes --end-of-options before the ref (rev-parse with --verify as well, since it otherwise echoes the flag through), and blame, which has no such flag, resolves the ref to a sha first. 26 call sites across seven files; no behaviour change for valid refs.

TestRefsAreNotOptions calls every ref-taking helper with --output=<file> as the ref and asserts no file appears and the ref does not resolve. The gitutil, control and store unit tests pass; the full e2e suite runs here in CI (a local full run stalled under load from other instances on this machine, and the test it stalled in passes alone).

Closes #135