Code

resolve_ref(): do not follow incorrectly-formatted symbolic refs
[git.git] / refs.c
diff --git a/refs.c b/refs.c
index 473f7f6bc6b01c69d12dc3997232aa0df2a7ce16..b0555018995e5f029f3dd1d014e1ac9ef74c3672 100644 (file)
--- a/refs.c
+++ b/refs.c
@@ -581,6 +581,11 @@ const char *resolve_ref(const char *ref, unsigned char *sha1, int reading, int *
                buf = buffer + 4;
                while (isspace(*buf))
                        buf++;
+               if (check_refname_format(buf, REFNAME_ALLOW_ONELEVEL)) {
+                       warning("symbolic reference in %s is formatted incorrectly",
+                               path);
+                       return NULL;
+               }
                ref = strcpy(ref_buffer, buf);
                if (flag)
                        *flag |= REF_ISSYMREF;