Coverage for /pythoncovmergedfiles/medio/medio/usr/local/lib/python3.11/site-packages/git/cmd.py: 60%

Shortcuts on this page

r m x   toggle line displays

j k   next/prev highlighted chunk

0   (zero) top of page

1   (one) first highlighted chunk

681 statements  

1# Copyright (C) 2008, 2009 Michael Trier (mtrier@gmail.com) and contributors 

2# 

3# This module is part of GitPython and is released under the 

4# 3-Clause BSD License: https://opensource.org/license/bsd-3-clause/ 

5 

6from __future__ import annotations 

7 

8__all__ = ["GitMeta", "Git"] 

9 

10import contextlib 

11import io 

12import itertools 

13import logging 

14import os 

15import re 

16import signal 

17import subprocess 

18from subprocess import DEVNULL, PIPE, Popen 

19import sys 

20from textwrap import dedent 

21import threading 

22import warnings 

23 

24from git.compat import defenc, force_bytes, safe_decode 

25from git.exc import ( 

26 CommandError, 

27 GitCommandError, 

28 GitCommandNotFound, 

29 UnsafeOptionError, 

30 UnsafeProtocolError, 

31) 

32from git.util import ( 

33 cygpath, 

34 expand_path, 

35 is_cygwin_git, 

36 patch_env, 

37 remove_password_if_present, 

38 stream_copy, 

39) 

40 

41# typing --------------------------------------------------------------------------- 

42 

43from typing import ( 

44 Any, 

45 AnyStr, 

46 BinaryIO, 

47 Callable, 

48 Dict, 

49 IO, 

50 Iterator, 

51 List, 

52 Mapping, 

53 Optional, 

54 Sequence, 

55 TYPE_CHECKING, 

56 TextIO, 

57 Tuple, 

58 Union, 

59 cast, 

60 overload, 

61) 

62 

63if sys.version_info >= (3, 10): 

64 from typing import TypeAlias 

65else: 

66 from typing_extensions import TypeAlias 

67 

68from git.types import Literal, PathLike, TBD 

69 

70if TYPE_CHECKING: 

71 from git.diff import DiffIndex 

72 from git.repo.base import Repo 

73 

74# --------------------------------------------------------------------------------- 

75 

76execute_kwargs = { 

77 "istream", 

78 "with_extended_output", 

79 "with_exceptions", 

80 "as_process", 

81 "output_stream", 

82 "stdout_as_string", 

83 "kill_after_timeout", 

84 "with_stdout", 

85 "universal_newlines", 

86 "shell", 

87 "env", 

88 "max_chunk_size", 

89 "strip_newline_in_stdout", 

90} 

91 

92_logger = logging.getLogger(__name__) 

93 

94 

95# ============================================================================== 

96## @name Utilities 

97# ------------------------------------------------------------------------------ 

98# Documentation 

99## @{ 

100 

101 

102def handle_process_output( 

103 process: "Git.AutoInterrupt" | Popen, 

104 stdout_handler: Union[ 

105 None, 

106 Callable[[AnyStr], None], 

107 Callable[[List[AnyStr]], None], 

108 Callable[[bytes, "Repo", "DiffIndex"], None], 

109 ], 

110 stderr_handler: Union[None, Callable[[AnyStr], None], Callable[[List[AnyStr]], None]], 

111 finalizer: Union[None, Callable[[Union[Popen, "Git.AutoInterrupt"]], None]] = None, 

112 decode_streams: bool = True, 

113 kill_after_timeout: Union[None, float] = None, 

114) -> None: 

115 R"""Register for notifications to learn that process output is ready to read, and 

116 dispatch lines to the respective line handlers. 

117 

118 This function returns once the finalizer returns. 

119 

120 :param process: 

121 :class:`subprocess.Popen` instance. 

122 

123 :param stdout_handler: 

124 f(stdout_line_string), or ``None``. 

125 

126 :param stderr_handler: 

127 f(stderr_line_string), or ``None``. 

128 

129 :param finalizer: 

130 f(proc) - wait for proc to finish. 

131 

132 :param decode_streams: 

133 Assume stdout/stderr streams are binary and decode them before pushing their 

134 contents to handlers. 

135 

136 This defaults to ``True``. Set it to ``False`` if: 

137 

138 - ``universal_newlines == True``, as then streams are in text mode, or 

139 - decoding must happen later, such as for :class:`~git.diff.Diff`\s. 

140 

141 :param kill_after_timeout: 

142 :class:`float` or ``None``, Default = ``None`` 

143 

144 To specify a timeout in seconds for the git command, after which the process 

145 should be killed. 

146 """ 

147 

148 # Use 2 "pump" threads and wait for both to finish. 

149 def pump_stream( 

150 cmdline: List[str], 

151 name: str, 

152 stream: Union[BinaryIO, TextIO], 

153 is_decode: bool, 

154 handler: Union[None, Callable[[Union[bytes, str]], None]], 

155 ) -> None: 

156 try: 

157 for line in stream: 

158 if handler: 

159 if is_decode: 

160 assert isinstance(line, bytes) 

161 line_str = line.decode(defenc) 

162 handler(line_str) 

163 else: 

164 handler(line) 

165 

166 except Exception as ex: 

167 _logger.error(f"Pumping {name!r} of cmd({remove_password_if_present(cmdline)}) failed due to: {ex!r}") 

168 if "I/O operation on closed file" not in str(ex): 

169 # Only reraise if the error was not due to the stream closing. 

170 raise CommandError([f"<{name}-pump>"] + remove_password_if_present(cmdline), ex) from ex 

171 finally: 

172 stream.close() 

173 

174 if hasattr(process, "proc"): 

175 process = cast("Git.AutoInterrupt", process) 

176 cmdline: str | Tuple[str, ...] | List[str] = getattr(process.proc, "args", "") 

177 p_stdout = process.proc.stdout if process.proc else None 

178 p_stderr = process.proc.stderr if process.proc else None 

179 else: 

180 process = cast(Popen, process) # type: ignore[redundant-cast] 

181 cmdline = getattr(process, "args", "") 

182 p_stdout = process.stdout 

183 p_stderr = process.stderr 

184 

185 if not isinstance(cmdline, (tuple, list)): 

186 cmdline = cmdline.split() 

187 

188 pumps: List[Tuple[str, IO, Callable[..., None] | None]] = [] 

189 if p_stdout: 

190 pumps.append(("stdout", p_stdout, stdout_handler)) 

191 if p_stderr: 

192 pumps.append(("stderr", p_stderr, stderr_handler)) 

193 

194 threads: List[threading.Thread] = [] 

195 

196 for name, stream, handler in pumps: 

197 t = threading.Thread(target=pump_stream, args=(cmdline, name, stream, decode_streams, handler)) 

198 t.daemon = True 

199 t.start() 

200 threads.append(t) 

201 

202 # FIXME: Why join? Will block if stdin needs feeding... 

203 for t in threads: 

204 t.join(timeout=kill_after_timeout) 

205 if t.is_alive(): 

206 if isinstance(process, Git.AutoInterrupt): 

207 process._terminate() 

208 else: # Don't want to deal with the other case. 

209 raise RuntimeError( 

210 "Thread join() timed out in cmd.handle_process_output()." 

211 f" kill_after_timeout={kill_after_timeout} seconds" 

212 ) 

213 if stderr_handler: 

214 error_str: Union[str, bytes] = ( 

215 f"error: process killed because it timed out. kill_after_timeout={kill_after_timeout} seconds" 

216 ) 

217 if not decode_streams and isinstance(p_stderr, BinaryIO): 

218 # Assume stderr_handler needs binary input. 

219 error_str = cast(str, error_str) 

220 error_str = error_str.encode() 

221 # We ignore typing on the next line because mypy does not like the way 

222 # we inferred that stderr takes str or bytes. 

223 stderr_handler(error_str) # type: ignore[arg-type] 

224 

225 if finalizer: 

226 finalizer(process) 

227 

228 

229safer_popen: Callable[..., Popen] 

230 

231if sys.platform == "win32": 

232 

233 def _safer_popen_windows( 

234 command: Union[str, Sequence[Any]], 

235 *, 

236 shell: bool = False, 

237 env: Optional[Mapping[str, str]] = None, 

238 **kwargs: Any, 

239 ) -> Popen: 

240 """Call :class:`subprocess.Popen` on Windows but don't include a CWD in the 

241 search. 

242 

243 This avoids an untrusted search path condition where a file like ``git.exe`` in 

244 a malicious repository would be run when GitPython operates on the repository. 

245 The process using GitPython may have an untrusted repository's working tree as 

246 its current working directory. Some operations may temporarily change to that 

247 directory before running a subprocess. In addition, while by default GitPython 

248 does not run external commands with a shell, it can be made to do so, in which 

249 case the CWD of the subprocess, which GitPython usually sets to a repository 

250 working tree, can itself be searched automatically by the shell. This wrapper 

251 covers all those cases. 

252 

253 :note: 

254 This currently works by setting the 

255 :envvar:`NoDefaultCurrentDirectoryInExePath` environment variable during 

256 subprocess creation. It also takes care of passing Windows-specific process 

257 creation flags, but that is unrelated to path search. 

258 

259 :note: 

260 The current implementation contains a race condition on :attr:`os.environ`. 

261 GitPython isn't thread-safe, but a program using it on one thread should 

262 ideally be able to mutate :attr:`os.environ` on another, without 

263 unpredictable results. See comments in: 

264 https://github.com/gitpython-developers/GitPython/pull/1650 

265 """ 

266 # CREATE_NEW_PROCESS_GROUP is needed for some ways of killing it afterwards. 

267 # https://docs.python.org/3/library/subprocess.html#subprocess.Popen.send_signal 

268 # https://docs.python.org/3/library/subprocess.html#subprocess.CREATE_NEW_PROCESS_GROUP 

269 creationflags = subprocess.CREATE_NO_WINDOW | subprocess.CREATE_NEW_PROCESS_GROUP 

270 

271 # When using a shell, the shell is the direct subprocess, so the variable must 

272 # be set in its environment, to affect its search behavior. 

273 if shell: 

274 # The original may be immutable, or the caller may reuse it. Mutate a copy. 

275 env = {} if env is None else dict(env) 

276 env["NoDefaultCurrentDirectoryInExePath"] = "1" # The "1" can be any value. 

277 

278 # When not using a shell, the current process does the search in a 

279 # CreateProcessW API call, so the variable must be set in our environment. With 

280 # a shell, that's unnecessary if https://github.com/python/cpython/issues/101283 

281 # is patched. In Python versions where it is unpatched, in the rare case the 

282 # ComSpec environment variable is unset, the search for the shell itself is 

283 # unsafe. Setting NoDefaultCurrentDirectoryInExePath in all cases, as done here, 

284 # is simpler and protects against that. (As above, the "1" can be any value.) 

285 with patch_env("NoDefaultCurrentDirectoryInExePath", "1"): 

286 return Popen( 

287 command, 

288 shell=shell, 

289 env=env, 

290 creationflags=creationflags, 

291 **kwargs, 

292 ) 

293 

294 safer_popen = _safer_popen_windows 

295else: 

296 safer_popen = Popen 

297 

298 

299def dashify(string: str) -> str: 

300 return string.replace("_", "-") 

301 

302 

303def slots_to_dict(self: "Git", exclude: Sequence[str] = ()) -> Dict[str, Any]: 

304 return {s: getattr(self, s) for s in self.__slots__ if s not in exclude} 

305 

306 

307def dict_to_slots_and__excluded_are_none(self: object, d: Mapping[str, Any], excluded: Sequence[str] = ()) -> None: 

308 for k, v in d.items(): 

309 setattr(self, k, v) 

310 for k in excluded: 

311 setattr(self, k, None) 

312 

313 

314## -- End Utilities -- @} 

315 

316 

317class _AutoInterrupt: 

318 """Process wrapper that terminates the wrapped process on finalization. 

319 

320 This kills/interrupts the stored process instance once this instance goes out of 

321 scope. It is used to prevent processes piling up in case iterators stop reading. 

322 

323 All attributes are wired through to the contained process object. 

324 

325 The wait method is overridden to perform automatic status code checking and possibly 

326 raise. 

327 """ 

328 

329 __slots__ = ("proc", "args", "status") 

330 

331 # If this is non-zero it will override any status code during _terminate, used 

332 # to prevent race conditions in testing. 

333 _status_code_if_terminate: int = 0 

334 

335 def __init__(self, proc: Union[None, subprocess.Popen], args: Any) -> None: 

336 self.proc = proc 

337 self.args = args 

338 self.status: Union[int, None] = None 

339 

340 def _terminate(self) -> None: 

341 """Terminate the underlying process.""" 

342 if self.proc is None: 

343 return 

344 

345 proc = self.proc 

346 self.proc = None 

347 if proc.stdin: 

348 proc.stdin.close() 

349 if proc.stdout: 

350 proc.stdout.close() 

351 if proc.stderr: 

352 proc.stderr.close() 

353 # Did the process finish already so we have a return code? 

354 try: 

355 if proc.poll() is not None: 

356 self.status = self._status_code_if_terminate or proc.poll() 

357 return 

358 except OSError as ex: 

359 _logger.info("Ignored error after process had died: %r", ex) 

360 

361 # It can be that nothing really exists anymore... 

362 if os is None or getattr(os, "kill", None) is None: 

363 return 

364 

365 # Try to kill it. 

366 try: 

367 proc.terminate() 

368 status = proc.wait() # Ensure the process goes away. 

369 

370 self.status = self._status_code_if_terminate or status 

371 except (OSError, AttributeError) as ex: 

372 # On interpreter shutdown (notably on Windows), parts of the stdlib used by 

373 # subprocess can already be torn down (e.g. `subprocess._winapi` becomes None), 

374 # which can cause AttributeError during terminate(). In that case, we prefer 

375 # to silently ignore to avoid noisy "Exception ignored in: __del__" messages. 

376 _logger.info("Ignored error while terminating process: %r", ex) 

377 # END exception handling 

378 

379 def __del__(self) -> None: 

380 self._terminate() 

381 

382 def __getattr__(self, attr: str) -> Any: 

383 return getattr(self.proc, attr) 

384 

385 # TODO: Bad choice to mimic `proc.wait()` but with different args. 

386 def wait(self, stderr: Union[None, str, bytes] = b"") -> int: 

387 """Wait for the process and return its status code. 

388 

389 :param stderr: 

390 Previously read value of stderr, in case stderr is already closed. 

391 

392 :warn: 

393 May deadlock if output or error pipes are used and not handled separately. 

394 

395 :raise git.exc.GitCommandError: 

396 If the return status is not 0. 

397 """ 

398 if stderr is None: 

399 stderr_b = b"" 

400 stderr_b = force_bytes(data=stderr, encoding="utf-8") 

401 status: Union[int, None] 

402 if self.proc is not None: 

403 status = self.proc.wait() 

404 p_stderr = self.proc.stderr 

405 else: # Assume the underlying proc was killed earlier or never existed. 

406 status = self.status 

407 p_stderr = None 

408 

409 def read_all_from_possibly_closed_stream(stream: Union[IO[bytes], None]) -> bytes: 

410 if stream: 

411 try: 

412 return stderr_b + force_bytes(stream.read()) 

413 except (OSError, ValueError): 

414 return stderr_b or b"" 

415 else: 

416 return stderr_b or b"" 

417 

418 # END status handling 

419 

420 if status != 0: 

421 errstr = read_all_from_possibly_closed_stream(p_stderr) 

422 _logger.debug("AutoInterrupt wait stderr: %r" % (errstr,)) 

423 raise GitCommandError(remove_password_if_present(self.args), status, errstr) 

424 return status 

425 

426 

427_AutoInterrupt.__name__ = "AutoInterrupt" 

428_AutoInterrupt.__qualname__ = "Git.AutoInterrupt" 

429 

430 

431class _CatFileContentStream: 

432 """Object representing a sized read-only stream returning the contents of 

433 an object. 

434 

435 This behaves like a stream, but counts the data read and simulates an empty stream 

436 once our sized content region is empty. 

437 

438 If not all data are read to the end of the object's lifetime, we read the rest to 

439 ensure the underlying stream continues to work. 

440 """ 

441 

442 __slots__ = ("_stream", "_nbr", "_size") 

443 

444 def __init__(self, size: int, stream: IO[bytes]) -> None: 

445 self._stream = stream 

446 self._size = size 

447 self._nbr = 0 # Number of bytes read. 

448 

449 # Special case: If the object is empty, has null bytes, get the final 

450 # newline right away. 

451 if size == 0: 

452 stream.read(1) 

453 # END handle empty streams 

454 

455 def read(self, size: int = -1) -> bytes: 

456 bytes_left = self._size - self._nbr 

457 if bytes_left == 0: 

458 return b"" 

459 if size > -1: 

460 # Ensure we don't try to read past our limit. 

461 size = min(bytes_left, size) 

462 else: 

463 # They try to read all, make sure it's not more than what remains. 

464 size = bytes_left 

465 # END check early depletion 

466 data = self._stream.read(size) 

467 self._nbr += len(data) 

468 

469 # Check for depletion, read our final byte to make the stream usable by 

470 # others. 

471 if self._size - self._nbr == 0: 

472 self._stream.read(1) # final newline 

473 # END finish reading 

474 return data 

475 

476 def readline(self, size: int = -1) -> bytes: 

477 if self._nbr == self._size: 

478 return b"" 

479 

480 # Clamp size to lowest allowed value. 

481 bytes_left = self._size - self._nbr 

482 if size > -1: 

483 size = min(bytes_left, size) 

484 else: 

485 size = bytes_left 

486 # END handle size 

487 

488 data = self._stream.readline(size) 

489 self._nbr += len(data) 

490 

491 # Handle final byte. 

492 if self._size - self._nbr == 0: 

493 self._stream.read(1) 

494 # END finish reading 

495 

496 return data 

497 

498 def readlines(self, size: int = -1) -> List[bytes]: 

499 if self._nbr == self._size: 

500 return [] 

501 

502 # Leave all additional logic to our readline method, we just check the size. 

503 out = [] 

504 nbr = 0 

505 while True: 

506 line = self.readline() 

507 if not line: 

508 break 

509 out.append(line) 

510 if size > -1: 

511 nbr += len(line) 

512 if nbr > size: 

513 break 

514 # END handle size constraint 

515 # END readline loop 

516 return out 

517 

518 # skipcq: PYL-E0301 

519 def __iter__(self) -> "Git.CatFileContentStream": 

520 return self 

521 

522 def __next__(self) -> bytes: 

523 line = self.readline() 

524 if not line: 

525 raise StopIteration 

526 

527 return line 

528 

529 next = __next__ 

530 

531 def __del__(self) -> None: 

532 bytes_left = self._size - self._nbr 

533 if bytes_left: 

534 # Read and discard - seeking is impossible within a stream. 

535 # This includes any terminating newline. 

536 self._stream.read(bytes_left + 1) 

537 # END handle incomplete read 

538 

539 

540_CatFileContentStream.__name__ = "CatFileContentStream" 

541_CatFileContentStream.__qualname__ = "Git.CatFileContentStream" 

542 

543 

544_USE_SHELL_DEFAULT_MESSAGE = ( 

545 "Git.USE_SHELL is deprecated, because only its default value of False is safe. " 

546 "It will be removed in a future release." 

547) 

548 

549_USE_SHELL_DANGER_MESSAGE = ( 

550 "Setting Git.USE_SHELL to True is unsafe and insecure, as the effect of special " 

551 "shell syntax cannot usually be accounted for. This can result in a command " 

552 "injection vulnerability and arbitrary code execution. Git.USE_SHELL is deprecated " 

553 "and will be removed in a future release." 

554) 

555 

556 

557def _warn_use_shell(*, extra_danger: bool) -> None: 

558 warnings.warn( 

559 _USE_SHELL_DANGER_MESSAGE if extra_danger else _USE_SHELL_DEFAULT_MESSAGE, 

560 DeprecationWarning, 

561 stacklevel=3, 

562 ) 

563 

564 

565class _GitMeta(type): 

566 """Metaclass for :class:`Git`. 

567 

568 This helps issue :class:`DeprecationWarning` if :attr:`Git.USE_SHELL` is used. 

569 """ 

570 

571 def __getattribute(cls, name: str) -> Any: 

572 if name == "USE_SHELL": 

573 _warn_use_shell(extra_danger=False) 

574 return super().__getattribute__(name) 

575 

576 def __setattr(cls, name: str, value: Any) -> Any: 

577 if name == "USE_SHELL": 

578 _warn_use_shell(extra_danger=value) 

579 super().__setattr__(name, value) 

580 

581 if not TYPE_CHECKING: 

582 # To preserve static checking for undefined/misspelled attributes while letting 

583 # the methods' bodies be type-checked, these are defined as non-special methods, 

584 # then bound to special names out of view of static type checkers. (The original 

585 # names invoke name mangling (leading "__") to avoid confusion in other scopes.) 

586 __getattribute__ = __getattribute 

587 __setattr__ = __setattr 

588 

589 

590GitMeta = _GitMeta 

591"""Alias of :class:`Git`'s metaclass, whether it is :class:`type` or a custom metaclass. 

592 

593Whether the :class:`Git` class has the default :class:`type` as its metaclass or uses a 

594custom metaclass is not documented and may change at any time. This statically checkable 

595metaclass alias is equivalent at runtime to ``type(Git)``. This should almost never be 

596used. Code that benefits from it is likely to be remain brittle even if it is used. 

597 

598In view of the :class:`Git` class's intended use and :class:`Git` objects' dynamic 

599callable attributes representing git subcommands, it rarely makes sense to inherit from 

600:class:`Git` at all. Using :class:`Git` in multiple inheritance can be especially tricky 

601to do correctly. Attempting uses of :class:`Git` where its metaclass is relevant, such 

602as when a sibling class has an unrelated metaclass and a shared lower bound metaclass 

603might have to be introduced to solve a metaclass conflict, is not recommended. 

604 

605:note: 

606 The correct static type of the :class:`Git` class itself, and any subclasses, is 

607 ``Type[Git]``. (This can be written as ``type[Git]`` in Python 3.9 later.) 

608 

609 :class:`GitMeta` should never be used in any annotation where ``Type[Git]`` is 

610 intended or otherwise possible to use. This alias is truly only for very rare and 

611 inherently precarious situations where it is necessary to deal with the metaclass 

612 explicitly. 

613""" 

614 

615 

616class Git(metaclass=_GitMeta): 

617 """The Git class manages communication with the Git binary. 

618 

619 It provides a convenient interface to calling the Git binary, such as in:: 

620 

621 g = Git( git_dir ) 

622 g.init() # calls 'git init' program 

623 rval = g.ls_files() # calls 'git ls-files' program 

624 

625 Debugging: 

626 

627 * Set the :envvar:`GIT_PYTHON_TRACE` environment variable to print each invocation 

628 of the command to stdout. 

629 * Set its value to ``full`` to see details about the returned values. 

630 """ 

631 

632 __slots__ = ( 

633 "_working_dir", 

634 "cat_file_all", 

635 "cat_file_header", 

636 "_version_info", 

637 "_version_info_token", 

638 "_git_options", 

639 "_persistent_git_options", 

640 "_environment", 

641 ) 

642 

643 _excluded_ = ( 

644 "cat_file_all", 

645 "cat_file_header", 

646 "_version_info", 

647 "_version_info_token", 

648 ) 

649 

650 re_unsafe_protocol = re.compile(r"(.+)::.+") 

651 

652 unsafe_git_ls_remote_options = [ 

653 # This option allows arbitrary command execution in git-ls-remote. 

654 "--upload-pack", 

655 "--exec", 

656 ] 

657 

658 unsafe_git_pathspec_from_file_options = [ 

659 # Reads pathspecs from a caller-controlled file. Some commands include an 

660 # unmatched pathspec in their error output, which can disclose the file. 

661 "--pathspec-from-file", 

662 ] 

663 

664 def __getstate__(self) -> Dict[str, Any]: 

665 return slots_to_dict(self, exclude=self._excluded_) 

666 

667 def __setstate__(self, d: Dict[str, Any]) -> None: 

668 dict_to_slots_and__excluded_are_none(self, d, excluded=self._excluded_) 

669 

670 # CONFIGURATION 

671 

672 git_exec_name = "git" 

673 """Default git command that should work on Linux, Windows, and other systems.""" 

674 

675 GIT_PYTHON_TRACE = os.environ.get("GIT_PYTHON_TRACE", False) 

676 """Enables debugging of GitPython's git commands.""" 

677 

678 USE_SHELL: bool = False 

679 """Deprecated. If set to ``True``, a shell will be used when executing git commands. 

680 

681 Code that uses ``USE_SHELL = True`` or that passes ``shell=True`` to any GitPython 

682 functions should be updated to use the default value of ``False`` instead. ``True`` 

683 is unsafe unless the effect of syntax treated specially by the shell is fully 

684 considered and accounted for, which is not possible under most circumstances. As 

685 detailed below, it is also no longer needed, even where it had been in the past. 

686 

687 It is in many if not most cases a command injection vulnerability for an application 

688 to set :attr:`USE_SHELL` to ``True``. Any attacker who can cause a specially crafted 

689 fragment of text to make its way into any part of any argument to any git command 

690 (including paths, branch names, etc.) can cause the shell to read and write 

691 arbitrary files and execute arbitrary commands. Innocent input may also accidentally 

692 contain special shell syntax, leading to inadvertent malfunctions. 

693 

694 In addition, how a value of ``True`` interacts with some aspects of GitPython's 

695 operation is not precisely specified and may change without warning, even before 

696 GitPython 4.0.0 when :attr:`USE_SHELL` may be removed. This includes: 

697 

698 * Whether or how GitPython automatically customizes the shell environment. 

699 

700 * Whether, outside of Windows (where :class:`subprocess.Popen` supports lists of 

701 separate arguments even when ``shell=True``), this can be used with any GitPython 

702 functionality other than direct calls to the :meth:`execute` method. 

703 

704 * Whether any GitPython feature that runs git commands ever attempts to partially 

705 sanitize data a shell may treat specially. Currently this is not done. 

706 

707 Prior to GitPython 2.0.8, this had a narrow purpose in suppressing console windows 

708 in graphical Windows applications. In 2.0.8 and higher, it provides no benefit, as 

709 GitPython solves that problem more robustly and safely by using the 

710 ``CREATE_NO_WINDOW`` process creation flag on Windows. 

711 

712 Because Windows path search differs subtly based on whether a shell is used, in rare 

713 cases changing this from ``True`` to ``False`` may keep an unusual git "executable", 

714 such as a batch file, from being found. To fix this, set the command name or full 

715 path in the :envvar:`GIT_PYTHON_GIT_EXECUTABLE` environment variable or pass the 

716 full path to :func:`git.refresh` (or invoke the script using a ``.exe`` shim). 

717 

718 Further reading: 

719 

720 * :meth:`Git.execute` (on the ``shell`` parameter). 

721 * https://github.com/gitpython-developers/GitPython/commit/0d9390866f9ce42870d3116094cd49e0019a970a 

722 * https://learn.microsoft.com/en-us/windows/win32/procthread/process-creation-flags 

723 * https://github.com/python/cpython/issues/91558#issuecomment-1100942950 

724 * https://learn.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-createprocessw 

725 """ 

726 

727 _git_exec_env_var = "GIT_PYTHON_GIT_EXECUTABLE" 

728 _refresh_env_var = "GIT_PYTHON_REFRESH" 

729 

730 GIT_PYTHON_GIT_EXECUTABLE = None 

731 """Provide the full path to the git executable. Otherwise it assumes git is in the 

732 executable search path. 

733 

734 :note: 

735 The git executable is actually found during the refresh step in the top level 

736 ``__init__``. It can also be changed by explicitly calling :func:`git.refresh`. 

737 """ 

738 

739 _refresh_token = object() # Since None would match an initial _version_info_token. 

740 

741 @classmethod 

742 def refresh(cls, path: Union[None, PathLike] = None) -> bool: 

743 """Update information about the git executable :class:`Git` objects will use. 

744 

745 Called by the :func:`git.refresh` function in the top level ``__init__``. 

746 

747 :param path: 

748 Optional path to the git executable. If not absolute, it is resolved 

749 immediately, relative to the current directory. (See note below.) 

750 

751 :note: 

752 The top-level :func:`git.refresh` should be preferred because it calls this 

753 method and may also update other state accordingly. 

754 

755 :note: 

756 There are three different ways to specify the command that refreshing causes 

757 to be used for git: 

758 

759 1. Pass no `path` argument and do not set the 

760 :envvar:`GIT_PYTHON_GIT_EXECUTABLE` environment variable. The command 

761 name ``git`` is used. It is looked up in a path search by the system, in 

762 each command run (roughly similar to how git is found when running 

763 ``git`` commands manually). This is usually the desired behavior. 

764 

765 2. Pass no `path` argument but set the :envvar:`GIT_PYTHON_GIT_EXECUTABLE` 

766 environment variable. The command given as the value of that variable is 

767 used. This may be a simple command or an arbitrary path. It is looked up 

768 in each command run. Setting :envvar:`GIT_PYTHON_GIT_EXECUTABLE` to 

769 ``git`` has the same effect as not setting it. 

770 

771 3. Pass a `path` argument. This path, if not absolute, is immediately 

772 resolved, relative to the current directory. This resolution occurs at 

773 the time of the refresh. When git commands are run, they are run using 

774 that previously resolved path. If a `path` argument is passed, the 

775 :envvar:`GIT_PYTHON_GIT_EXECUTABLE` environment variable is not 

776 consulted. 

777 

778 :note: 

779 Refreshing always sets the :attr:`Git.GIT_PYTHON_GIT_EXECUTABLE` class 

780 attribute, which can be read on the :class:`Git` class or any of its 

781 instances to check what command is used to run git. This attribute should 

782 not be confused with the related :envvar:`GIT_PYTHON_GIT_EXECUTABLE` 

783 environment variable. The class attribute is set no matter how refreshing is 

784 performed. 

785 """ 

786 # Discern which path to refresh with. 

787 if path is not None: 

788 new_git = os.path.expanduser(path) 

789 new_git = os.path.abspath(new_git) 

790 else: 

791 new_git = os.environ.get(cls._git_exec_env_var, cls.git_exec_name) 

792 

793 # Keep track of the old and new git executable path. 

794 old_git = cls.GIT_PYTHON_GIT_EXECUTABLE 

795 old_refresh_token = cls._refresh_token 

796 cls.GIT_PYTHON_GIT_EXECUTABLE = new_git 

797 cls._refresh_token = object() 

798 

799 # Test if the new git executable path is valid. A GitCommandNotFound error is 

800 # raised by us. A PermissionError is raised if the git executable cannot be 

801 # executed for whatever reason. 

802 has_git = False 

803 try: 

804 cls().version() 

805 has_git = True 

806 except (GitCommandNotFound, PermissionError): 

807 pass 

808 

809 # Warn or raise exception if test failed. 

810 if not has_git: 

811 err = ( 

812 dedent( 

813 """\ 

814 Bad git executable. 

815 The git executable must be specified in one of the following ways: 

816 - be included in your $PATH 

817 - be set via $%s 

818 - explicitly set via git.refresh(<full-path-to-git-executable>) 

819 """ 

820 ) 

821 % cls._git_exec_env_var 

822 ) 

823 

824 # Revert to whatever the old_git was. 

825 cls.GIT_PYTHON_GIT_EXECUTABLE = old_git 

826 cls._refresh_token = old_refresh_token 

827 

828 if old_git is None: 

829 # On the first refresh (when GIT_PYTHON_GIT_EXECUTABLE is None) we only 

830 # are quiet, warn, or error depending on the GIT_PYTHON_REFRESH value. 

831 

832 # Determine what the user wants to happen during the initial refresh. We 

833 # expect GIT_PYTHON_REFRESH to either be unset or be one of the 

834 # following values: 

835 # 

836 # 0|q|quiet|s|silence|silent|n|none 

837 # 1|w|warn|warning|l|log 

838 # 2|r|raise|e|error|exception 

839 

840 mode = os.environ.get(cls._refresh_env_var, "raise").lower() 

841 

842 quiet = ["quiet", "q", "silence", "s", "silent", "none", "n", "0"] 

843 warn = ["warn", "w", "warning", "log", "l", "1"] 

844 error = ["error", "e", "exception", "raise", "r", "2"] 

845 

846 if mode in quiet: 

847 pass 

848 elif mode in warn or mode in error: 

849 err = dedent( 

850 """\ 

851 %s 

852 All git commands will error until this is rectified. 

853 

854 This initial message can be silenced or aggravated in the future by setting the 

855 $%s environment variable. Use one of the following values: 

856 - %s: for no message or exception 

857 - %s: for a warning message (logging level CRITICAL, displayed by default) 

858 - %s: for a raised exception 

859 

860 Example: 

861 export %s=%s 

862 """ 

863 ) % ( 

864 err, 

865 cls._refresh_env_var, 

866 "|".join(quiet), 

867 "|".join(warn), 

868 "|".join(error), 

869 cls._refresh_env_var, 

870 quiet[0], 

871 ) 

872 

873 if mode in warn: 

874 _logger.critical(err) 

875 else: 

876 raise ImportError(err) 

877 else: 

878 err = dedent( 

879 """\ 

880 %s environment variable has been set but it has been set with an invalid value. 

881 

882 Use only the following values: 

883 - %s: for no message or exception 

884 - %s: for a warning message (logging level CRITICAL, displayed by default) 

885 - %s: for a raised exception 

886 """ 

887 ) % ( 

888 cls._refresh_env_var, 

889 "|".join(quiet), 

890 "|".join(warn), 

891 "|".join(error), 

892 ) 

893 raise ImportError(err) 

894 

895 # We get here if this was the initial refresh and the refresh mode was 

896 # not error. Go ahead and set the GIT_PYTHON_GIT_EXECUTABLE such that we 

897 # discern the difference between the first refresh at import time 

898 # and subsequent calls to git.refresh or this refresh method. 

899 cls.GIT_PYTHON_GIT_EXECUTABLE = cls.git_exec_name 

900 else: 

901 # After the first refresh (when GIT_PYTHON_GIT_EXECUTABLE is no longer 

902 # None) we raise an exception. 

903 raise GitCommandNotFound(new_git, err) 

904 

905 return has_git 

906 

907 @classmethod 

908 def is_cygwin(cls) -> bool: 

909 return is_cygwin_git(cls.GIT_PYTHON_GIT_EXECUTABLE) 

910 

911 @overload 

912 @classmethod 

913 def polish_url(cls, url: str, is_cygwin: Literal[False] = ..., expand_vars: bool = ...) -> str: ... 

914 

915 @overload 

916 @classmethod 

917 def polish_url(cls, url: str, is_cygwin: Union[None, bool] = None, expand_vars: bool = True) -> str: ... 

918 

919 @classmethod 

920 def polish_url(cls, url: str, is_cygwin: Union[None, bool] = None, expand_vars: bool = True) -> PathLike: 

921 """Remove any backslashes from URLs to be written in config files. 

922 

923 Windows might create config files containing paths with backslashes, but git 

924 stops liking them as it will escape the backslashes. Hence we undo the escaping 

925 just to be sure. 

926 

927 :param expand_vars: 

928 Expand environment variables and an initial ``~``. Disable this for values 

929 obtained from an untrusted source, such as remote URLs. 

930 """ 

931 if is_cygwin is None: 

932 is_cygwin = cls.is_cygwin() 

933 

934 if is_cygwin: 

935 url = cygpath(url, expand_vars=expand_vars) 

936 else: 

937 if expand_vars: 

938 url = os.path.expandvars(url) 

939 if url.startswith("~"): 

940 url = os.path.expanduser(url) 

941 url = url.replace("\\\\", "\\").replace("\\", "/") 

942 return url 

943 

944 @classmethod 

945 def check_unsafe_protocols(cls, url: str) -> None: 

946 """Check for unsafe protocols. 

947 

948 Apart from the usual protocols (http, git, ssh), Git allows "remote helpers" 

949 that have the form ``<transport>::<address>``. One of these helpers (``ext::``) 

950 can be used to invoke any arbitrary command. 

951 

952 See: 

953 

954 - https://git-scm.com/docs/gitremote-helpers 

955 - https://git-scm.com/docs/git-remote-ext 

956 """ 

957 match = cls.re_unsafe_protocol.match(url) 

958 if match: 

959 protocol = match.group(1) 

960 raise UnsafeProtocolError( 

961 f"The `{protocol}::` protocol looks suspicious, use `allow_unsafe_protocols=True` to allow it." 

962 ) 

963 

964 @classmethod 

965 def _canonicalize_option_name(cls, option: str) -> str: 

966 """Return the option name used for unsafe-option checks. 

967 

968 Examples: 

969 ``"--upload-pack=/tmp/helper"`` -> ``"upload-pack"`` 

970 ``"upload_pack"`` -> ``"upload-pack"`` 

971 ``"--config core.filemode=false"`` -> ``"config"`` 

972 """ 

973 option_name = option.lstrip("-").split("=", 1)[0] 

974 option_tokens = option_name.split(None, 1) 

975 if not option_tokens: 

976 return "" 

977 return dashify(option_tokens[0]) 

978 

979 @classmethod 

980 def check_unsafe_options( 

981 cls, options: List[str], unsafe_options: List[str], clusterable_short_options: str = "46flnqsv" 

982 ) -> None: 

983 """Raise :class:`~git.exc.UnsafeOptionError` for blocked option spellings. 

984 

985 In addition to exact matches, this rejects abbreviated long options accepted 

986 by Git (for example, ``--upl`` for ``--upload-pack``) and unsafe short options 

987 whose values are joined to the same token, including after clusterable flags 

988 (for example, ``-uVALUE`` and ``-fuVALUE``). 

989 

990 A list containing only bare names is treated as normalized keyword arguments, 

991 so multi-character names such as ``upload_p`` are checked as long-option 

992 abbreviations. If any item starts with ``-``, the list is treated as tokenized 

993 command-line input: bare items can be option values and are not checked as 

994 abbreviations. Thus ``["--origin", "upload"]`` is allowed. Single-dash options 

995 use short-option parsing rather than broad prefix matching, preserving safe 

996 attached values such as ``-oupstream`` and ``-bcurrent``. 

997 

998 Some options passed to ``git <command>`` can execute arbitrary commands and 

999 are therefore blocked by default unless the caller explicitly allows them. 

1000 """ 

1001 # Options can be of the form `foo`, `--foo`, `--foo bar`, or `--foo=bar`. 

1002 # Git accepts any unambiguous prefix of a long option, so an abbreviated 

1003 # spelling such as `--upl` for `--upload-pack` must be rejected too. An 

1004 # option is unsafe if its canonical name is a prefix of any blocked 

1005 # option's canonical name. Only long options and multi-character kwargs 

1006 # can be abbreviations; single-character short options remain exact-match 

1007 # only. 

1008 canonical_unsafe_options = {cls._canonicalize_option_name(option): option for option in unsafe_options} 

1009 unsafe_short_options = { 

1010 canonical: option 

1011 for canonical, option in canonical_unsafe_options.items() 

1012 if option.startswith("-") and not option.startswith("--") and len(canonical) == 1 

1013 } 

1014 # These value-less Git flags can be clustered before another short option 

1015 # (for example, ``-fuVALUE``). Stop at any other character because it may 

1016 # begin an attached value, as ``o`` does in the safe option ``-oupstream``. 

1017 clusterable_short_options_set = frozenset(clusterable_short_options) 

1018 options_are_kwargs = all(not option.startswith("-") for option in options) 

1019 for option in options: 

1020 candidate = cls._canonicalize_option_name(option) 

1021 if not candidate: 

1022 continue 

1023 unsafe_option = canonical_unsafe_options.get(candidate) 

1024 if unsafe_option is not None: 

1025 raise UnsafeOptionError(f"{unsafe_option} is not allowed, use `allow_unsafe_options=True` to allow it.") 

1026 option_token = option.split("=", 1)[0].split(None, 1)[0] 

1027 if option_token.startswith("-") and not option_token.startswith("--"): 

1028 for option_char in option_token[1:]: 

1029 unsafe_option = unsafe_short_options.get(option_char) 

1030 if unsafe_option is not None: 

1031 raise UnsafeOptionError( 

1032 f"{unsafe_option} is not allowed, use `allow_unsafe_options=True` to allow it." 

1033 ) 

1034 if option_char not in clusterable_short_options_set: 

1035 break 

1036 if not (option.startswith("--") or (options_are_kwargs and len(candidate) > 1)): 

1037 continue 

1038 for canonical, unsafe_option in canonical_unsafe_options.items(): 

1039 if canonical.startswith(candidate): 

1040 raise UnsafeOptionError( 

1041 f"{unsafe_option} is not allowed, use `allow_unsafe_options=True` to allow it." 

1042 ) 

1043 

1044 @classmethod 

1045 def _option_candidates(cls, args: Sequence[Any] = (), kwargs: Optional[Mapping[str, Any]] = None) -> List[str]: 

1046 """Collect possible option spellings before command-line transformation.""" 

1047 options = [ 

1048 option for option in cls._unpack_args([arg for arg in args if arg is not None]) if option.startswith("-") 

1049 ] 

1050 if kwargs: 

1051 split_single_char_options = kwargs.get("split_single_char_options", True) 

1052 for key, value in kwargs.items(): 

1053 values = value if isinstance(value, (list, tuple)) else (value,) 

1054 if any(value is True or (value is not False and value is not None) for value in values): 

1055 key = str(key) 

1056 if len(key) != 1: 

1057 options.append(f"--{dashify(key)}") 

1058 elif split_single_char_options: 

1059 options.append(f"-{key}") 

1060 options.extend( 

1061 str(value) 

1062 for value in values 

1063 if value is not True and value not in (False, None) and str(value).startswith("-") 

1064 ) 

1065 else: 

1066 options.extend( 

1067 f"-{key}" if value is True else f"-{key}{value}" 

1068 for value in values 

1069 if value is True or (value is not False and value is not None) 

1070 ) 

1071 return options 

1072 

1073 AutoInterrupt: TypeAlias = _AutoInterrupt 

1074 

1075 CatFileContentStream: TypeAlias = _CatFileContentStream 

1076 

1077 def __init__(self, working_dir: Union[None, PathLike] = None) -> None: 

1078 """Initialize this instance with: 

1079 

1080 :param working_dir: 

1081 Git directory we should work in. If ``None``, we always work in the current 

1082 directory as returned by :func:`os.getcwd`. 

1083 This is meant to be the working tree directory if available, or the 

1084 ``.git`` directory in case of bare repositories. 

1085 """ 

1086 super().__init__() 

1087 self._working_dir = expand_path(working_dir) 

1088 self._git_options: Union[List[str], Tuple[str, ...]] = () 

1089 self._persistent_git_options: List[str] = [] 

1090 

1091 # Extra environment variables to pass to git commands 

1092 self._environment: Dict[str, str] = {} 

1093 

1094 # Cached version slots 

1095 self._version_info: Union[Tuple[int, ...], None] = None 

1096 self._version_info_token: object = None 

1097 

1098 # Cached command slots 

1099 self.cat_file_header: Union[None, TBD] = None 

1100 self.cat_file_all: Union[None, TBD] = None 

1101 

1102 def __getattribute__(self, name: str) -> Any: 

1103 if name == "USE_SHELL": 

1104 _warn_use_shell(extra_danger=False) 

1105 return super().__getattribute__(name) 

1106 

1107 def __getattr__(self, name: str) -> Any: 

1108 """A convenience method as it allows to call the command as if it was an object. 

1109 

1110 :return: 

1111 Callable object that will execute call :meth:`_call_process` with your 

1112 arguments. 

1113 """ 

1114 if name.startswith("_"): 

1115 return super().__getattribute__(name) 

1116 return lambda *args, **kwargs: self._call_process(name, *args, **kwargs) 

1117 

1118 def set_persistent_git_options(self, **kwargs: Any) -> None: 

1119 """Specify command line options to the git executable for subsequent 

1120 subcommand calls. 

1121 

1122 :param kwargs: 

1123 A dict of keyword arguments. 

1124 These arguments are passed as in :meth:`_call_process`, but will be passed 

1125 to the git command rather than the subcommand. 

1126 """ 

1127 

1128 self._persistent_git_options = self.transform_kwargs(split_single_char_options=True, **kwargs) 

1129 

1130 def ls_remote( 

1131 self, 

1132 *args: Any, 

1133 allow_unsafe_options: bool = False, 

1134 **kwargs: Any, 

1135 ) -> Union[str, bytes, Tuple[int, Union[str, bytes], str], "Git.AutoInterrupt"]: 

1136 """List references in a remote repository. 

1137 

1138 :param allow_unsafe_options: 

1139 Allow unsafe options, like ``--upload-pack`` or ``--exec``. 

1140 """ 

1141 if not allow_unsafe_options: 

1142 candidate_options = self._option_candidates(args, kwargs) 

1143 Git.check_unsafe_options(options=candidate_options, unsafe_options=self.unsafe_git_ls_remote_options) 

1144 return self._call_process("ls_remote", *args, **kwargs) 

1145 

1146 @property 

1147 def working_dir(self) -> Union[None, PathLike]: 

1148 """:return: Git directory we are working on""" 

1149 return self._working_dir 

1150 

1151 @property 

1152 def version_info(self) -> Tuple[int, ...]: 

1153 """ 

1154 :return: Tuple with integers representing the major, minor and additional 

1155 version numbers as parsed from :manpage:`git-version(1)`. Up to four fields 

1156 are used. 

1157 

1158 This value is generated on demand and is cached. 

1159 """ 

1160 # Refreshing is global, but version_info caching is per-instance. 

1161 refresh_token = self._refresh_token # Copy token in case of concurrent refresh. 

1162 

1163 # Use the cached version if obtained after the most recent refresh. 

1164 if self._version_info_token is refresh_token: 

1165 assert self._version_info is not None, "Bug: corrupted token-check state" 

1166 return self._version_info 

1167 

1168 # Run "git version" and parse it. 

1169 process_version = self._call_process("version") 

1170 version_string = process_version.split(" ")[2] 

1171 version_fields = version_string.split(".")[:4] 

1172 leading_numeric_fields = itertools.takewhile(str.isdigit, version_fields) 

1173 self._version_info = tuple(map(int, leading_numeric_fields)) 

1174 

1175 # This value will be considered valid until the next refresh. 

1176 self._version_info_token = refresh_token 

1177 return self._version_info 

1178 

1179 @overload 

1180 def execute( 

1181 self, 

1182 command: Union[str, Sequence[Any]], 

1183 *, 

1184 as_process: Literal[True], 

1185 ) -> "AutoInterrupt": ... 

1186 

1187 @overload 

1188 def execute( 

1189 self, 

1190 command: Union[str, Sequence[Any]], 

1191 *, 

1192 as_process: Literal[False] = False, 

1193 stdout_as_string: Literal[True], 

1194 ) -> Union[str, Tuple[int, str, str]]: ... 

1195 

1196 @overload 

1197 def execute( 

1198 self, 

1199 command: Union[str, Sequence[Any]], 

1200 *, 

1201 as_process: Literal[False] = False, 

1202 stdout_as_string: Literal[False] = False, 

1203 ) -> Union[bytes, Tuple[int, bytes, str]]: ... 

1204 

1205 @overload 

1206 def execute( 

1207 self, 

1208 command: Union[str, Sequence[Any]], 

1209 *, 

1210 with_extended_output: Literal[False], 

1211 as_process: Literal[False], 

1212 stdout_as_string: Literal[True], 

1213 ) -> str: ... 

1214 

1215 @overload 

1216 def execute( 

1217 self, 

1218 command: Union[str, Sequence[Any]], 

1219 *, 

1220 with_extended_output: Literal[False], 

1221 as_process: Literal[False], 

1222 stdout_as_string: Literal[False], 

1223 ) -> bytes: ... 

1224 

1225 def execute( 

1226 self, 

1227 command: Union[str, Sequence[Any]], 

1228 istream: Union[None, BinaryIO] = None, 

1229 with_extended_output: bool = False, 

1230 with_exceptions: bool = True, 

1231 as_process: bool = False, 

1232 output_stream: Union[None, BinaryIO] = None, 

1233 stdout_as_string: bool = True, 

1234 kill_after_timeout: Union[None, float] = None, 

1235 with_stdout: bool = True, 

1236 universal_newlines: bool = False, 

1237 shell: Union[None, bool] = None, 

1238 env: Union[None, Mapping[str, str]] = None, 

1239 max_chunk_size: int = io.DEFAULT_BUFFER_SIZE, 

1240 strip_newline_in_stdout: bool = True, 

1241 **subprocess_kwargs: Any, 

1242 ) -> Union[str, bytes, Tuple[int, Union[str, bytes], str], AutoInterrupt]: 

1243 R"""Handle executing the command, and consume and return the returned 

1244 information (stdout). 

1245 

1246 :param command: 

1247 The command to execute. A sequence of program arguments is recommended. 

1248 A string is also accepted, but its meaning is strongly platform-dependent. 

1249 

1250 By default, a shell is not used. On Unix-like systems, a string is the whole 

1251 program name (so ``"git log -n 1"`` raises :class:`GitCommandNotFound`). On 

1252 Windows, the program parses the arguments itself, so multi-word strings can 

1253 work but are not portable. 

1254 

1255 Avoid ``shell=True`` (and :attr:`Git.USE_SHELL`): this runs the command in 

1256 a shell, which is generally unsafe. The shell interprets metacharacters 

1257 such as ``;``, ``|``, ``&``, ``$(...)``, ``$VAR``, ``%VAR%``, and ``^`` 

1258 (depending on the platform) as syntax. Any untrusted text in the command 

1259 can then execute arbitrary OS commands. See :attr:`Git.USE_SHELL`. 

1260 

1261 Producing a sequence automatically by :func:`shlex.split` and passing it 

1262 as the command is far safer than ``shell=True``. But :func:`shlex.split` 

1263 parses POSIX shell syntax on all systems, and the result is still unsafe 

1264 for anything but *fixed, fully trusted* strings. Do not use it on strings 

1265 built by interpolating values: whitespace or quoting in an untrusted value 

1266 can still inject arguments. For input derived in any way from untrusted 

1267 data, build the argument sequence yourself, while ensuring each argument 

1268 is fully sanitized. 

1269 

1270 :param istream: 

1271 Standard input filehandle passed to :class:`subprocess.Popen`. 

1272 

1273 :param with_extended_output: 

1274 Whether to return a (status, stdout, stderr) tuple. 

1275 

1276 :param with_exceptions: 

1277 Whether to raise an exception when git returns a non-zero status. 

1278 

1279 :param as_process: 

1280 Whether to return the created process instance directly from which 

1281 streams can be read on demand. This will render `with_extended_output` 

1282 and `with_exceptions` ineffective - the caller will have to deal with 

1283 the details. It is important to note that the process will be placed 

1284 into an :class:`AutoInterrupt` wrapper that will interrupt the process 

1285 once it goes out of scope. If you use the command in iterators, you 

1286 should pass the whole process instance instead of a single stream. 

1287 

1288 :param output_stream: 

1289 If set to a file-like object, data produced by the git command will be 

1290 copied to the given stream instead of being returned as a string. 

1291 This feature only has any effect if `as_process` is ``False``. 

1292 

1293 :param stdout_as_string: 

1294 If ``False``, the command's standard output will be bytes. Otherwise, it 

1295 will be decoded into a string using the default encoding (usually UTF-8). 

1296 The latter can fail, if the output contains binary data. 

1297 

1298 :param kill_after_timeout: 

1299 Specifies a timeout in seconds for the git command, after which the process 

1300 should be killed. This will have no effect if `as_process` is set to 

1301 ``True``. It is set to ``None`` by default and will let the process run 

1302 until the timeout is explicitly specified. Uses of this feature should be 

1303 carefully considered, due to the following limitations: 

1304 

1305 1. This feature is not supported at all on Windows. 

1306 2. Effectiveness may vary by operating system. ``ps --ppid`` is used to 

1307 enumerate child processes, which is available on most GNU/Linux systems 

1308 but not most others. 

1309 3. Deeper descendants do not receive signals, though they may sometimes 

1310 terminate as a consequence of their parent processes being killed. 

1311 4. `kill_after_timeout` uses ``SIGKILL``, which can have negative side 

1312 effects on a repository. For example, stale locks in case of 

1313 :manpage:`git-gc(1)` could render the repository incapable of accepting 

1314 changes until the lock is manually removed. 

1315 

1316 :param with_stdout: 

1317 If ``True``, default ``True``, we open stdout on the created process. 

1318 

1319 :param universal_newlines: 

1320 If ``True``, pipes will be opened as text, and lines are split at all known 

1321 line endings. 

1322 

1323 :param shell: 

1324 Whether to invoke commands through a shell 

1325 (see :class:`Popen(..., shell=True) <subprocess.Popen>`). 

1326 If this is not ``None``, it overrides :attr:`USE_SHELL`. 

1327 

1328 Passing ``shell=True`` to this or any other GitPython function should be 

1329 avoided, as it is unsafe under most circumstances. This is because it is 

1330 typically not feasible to fully consider and account for the effect of shell 

1331 expansions, especially when passing ``shell=True`` to other methods that 

1332 forward it to :meth:`Git.execute`. Passing ``shell=True`` is also no longer 

1333 needed (nor useful) to work around any known operating system specific 

1334 issues. 

1335 

1336 On Unix-like systems, when migrating away from passing string commands with 

1337 ``shell=True``, :func:`shlex.split` may serve as a transitional step in rare 

1338 cases, with extreme care. (Drop ``shell=True`` and pass the resulting 

1339 sequence as the command.) See the `command` parameter above on the risks. 

1340 

1341 :param env: 

1342 A dictionary of environment variables to be passed to 

1343 :class:`subprocess.Popen`. 

1344 

1345 :param max_chunk_size: 

1346 Maximum number of bytes in one chunk of data passed to the `output_stream` 

1347 in one invocation of its ``write()`` method. If the given number is not 

1348 positive then the default value is used. 

1349 

1350 :param strip_newline_in_stdout: 

1351 Whether to strip the trailing ``\n`` of the command stdout. 

1352 

1353 :param subprocess_kwargs: 

1354 Keyword arguments to be passed to :class:`subprocess.Popen`. Please note 

1355 that some of the valid kwargs are already set by this method; the ones you 

1356 specify may not be the same ones. 

1357 

1358 :return: 

1359 * str(output), if `extended_output` is ``False`` (Default) 

1360 * tuple(int(status), str(stdout), str(stderr)), 

1361 if `extended_output` is ``True`` 

1362 

1363 If `output_stream` is ``True``, the stdout value will be your output stream: 

1364 

1365 * output_stream, if `extended_output` is ``False`` 

1366 * tuple(int(status), output_stream, str(stderr)), 

1367 if `extended_output` is ``True`` 

1368 

1369 Note that git is executed with ``LC_MESSAGES="C"`` to ensure consistent 

1370 output regardless of system language. 

1371 

1372 :raise git.exc.GitCommandError: 

1373 

1374 :note: 

1375 If you add additional keyword arguments to the signature of this method, you 

1376 must update the ``execute_kwargs`` variable housed in this module. 

1377 """ 

1378 # Remove password for the command if present. 

1379 redacted_command = remove_password_if_present(command) 

1380 if self.GIT_PYTHON_TRACE and (self.GIT_PYTHON_TRACE != "full" or as_process): 

1381 _logger.info(" ".join(redacted_command)) 

1382 

1383 # Allow the user to have the command executed in their working dir. 

1384 try: 

1385 cwd = self._working_dir or os.getcwd() # type: Optional[PathLike] 

1386 if not os.access(str(cwd), os.X_OK): 

1387 cwd = None 

1388 except FileNotFoundError: 

1389 cwd = None 

1390 

1391 # Start the process. 

1392 inline_env = env 

1393 env = os.environ.copy() 

1394 # Attempt to force all output to plain ASCII English, which is what some parsing 

1395 # code may expect. 

1396 # According to https://askubuntu.com/a/311796, we are setting LANGUAGE as well 

1397 # just to be sure. 

1398 env["LANGUAGE"] = "C" 

1399 env["LC_ALL"] = "C" 

1400 env.update(self._environment) 

1401 if inline_env is not None: 

1402 env.update(inline_env) 

1403 

1404 if sys.platform == "win32": 

1405 if kill_after_timeout is not None: 

1406 raise GitCommandError( 

1407 redacted_command, 

1408 '"kill_after_timeout" feature is not supported on Windows.', 

1409 ) 

1410 cmd_not_found_exception = OSError 

1411 else: 

1412 cmd_not_found_exception = FileNotFoundError 

1413 # END handle 

1414 

1415 stdout_sink = PIPE if with_stdout else getattr(subprocess, "DEVNULL", None) or open(os.devnull, "wb") 

1416 if shell is None: 

1417 # Get the value of USE_SHELL with no deprecation warning. Do this without 

1418 # warnings.catch_warnings, to avoid a race condition with application code 

1419 # configuring warnings. The value could be looked up in type(self).__dict__ 

1420 # or Git.__dict__, but those can break under some circumstances. This works 

1421 # the same as self.USE_SHELL in more situations; see Git.__getattribute__. 

1422 shell = super().__getattribute__("USE_SHELL") 

1423 _logger.debug( 

1424 "Popen(%s, cwd=%s, stdin=%s, shell=%s, universal_newlines=%s)", 

1425 redacted_command, 

1426 cwd, 

1427 "<valid stream>" if istream else "None", 

1428 shell, 

1429 universal_newlines, 

1430 ) 

1431 try: 

1432 proc = safer_popen( 

1433 command, 

1434 env=env, 

1435 cwd=cwd, 

1436 bufsize=-1, 

1437 stdin=(istream or DEVNULL), 

1438 stderr=PIPE, 

1439 stdout=stdout_sink, 

1440 shell=shell, 

1441 universal_newlines=universal_newlines, 

1442 encoding=defenc if universal_newlines else None, 

1443 **subprocess_kwargs, 

1444 ) 

1445 except cmd_not_found_exception as err: 

1446 raise GitCommandNotFound(redacted_command, err) from err 

1447 else: 

1448 # Replace with a typeguard for Popen[bytes]? 

1449 proc.stdout = cast(BinaryIO, proc.stdout) 

1450 proc.stderr = cast(BinaryIO, proc.stderr) 

1451 

1452 if as_process: 

1453 return self.AutoInterrupt(proc, command) 

1454 

1455 watchdog: Optional[threading.Timer] = None 

1456 kill_check: Optional[threading.Event] = None 

1457 timeout_error: Optional[Callable[[], Union[str, bytes]]] = None 

1458 

1459 if sys.platform != "win32" and kill_after_timeout is not None: 

1460 # Help mypy figure out this is not None even when used inside communicate(). 

1461 timeout = kill_after_timeout 

1462 

1463 def kill_process(pid: int) -> None: 

1464 """Callback to kill a process. 

1465 

1466 This callback implementation would be ineffective and unsafe on Windows. 

1467 """ 

1468 p = Popen(["ps", "--ppid", str(pid)], stdout=PIPE) 

1469 child_pids = [] 

1470 if p.stdout is not None: 

1471 for line in p.stdout: 

1472 if len(line.split()) > 0: 

1473 local_pid = (line.split())[0] 

1474 if local_pid.isdigit(): 

1475 child_pids.append(int(local_pid)) 

1476 try: 

1477 os.kill(pid, signal.SIGKILL) 

1478 for child_pid in child_pids: 

1479 try: 

1480 os.kill(child_pid, signal.SIGKILL) 

1481 except OSError: 

1482 pass 

1483 # Tell the main routine that the process was killed. 

1484 assert kill_check is not None 

1485 kill_check.set() 

1486 except OSError: 

1487 # It is possible that the process gets completed in the duration 

1488 # after timeout happens and before we try to kill the process. 

1489 pass 

1490 return 

1491 

1492 def make_timeout_error() -> Union[str, bytes]: 

1493 err = f'Timeout: the command "{" ".join(redacted_command)}" did not complete in {timeout:g} secs.' 

1494 return err if universal_newlines else err.encode(defenc) 

1495 

1496 def communicate() -> Tuple[AnyStr, AnyStr]: 

1497 assert watchdog is not None 

1498 assert kill_check is not None 

1499 watchdog.start() 

1500 out, err = proc.communicate() 

1501 watchdog.cancel() 

1502 if kill_check.is_set(): 

1503 err = make_timeout_error() 

1504 return out, err 

1505 

1506 # END helpers 

1507 

1508 kill_check = threading.Event() 

1509 watchdog = threading.Timer(timeout, kill_process, args=(proc.pid,)) 

1510 timeout_error = make_timeout_error 

1511 else: 

1512 communicate = proc.communicate 

1513 

1514 # Wait for the process to return. 

1515 status = 0 

1516 stdout_value: Union[str, bytes] = b"" 

1517 stderr_value: Union[str, bytes] = b"" 

1518 newline = "\n" if universal_newlines else b"\n" 

1519 try: 

1520 if output_stream is None: 

1521 stdout_value, stderr_value = communicate() 

1522 # Strip trailing "\n". 

1523 if stdout_value is not None and stdout_value.endswith(newline) and strip_newline_in_stdout: # type: ignore[arg-type] 

1524 stdout_value = stdout_value[:-1] 

1525 if stderr_value is not None and stderr_value.endswith(newline): # type: ignore[arg-type] 

1526 stderr_value = stderr_value[:-1] 

1527 

1528 status = proc.returncode 

1529 else: 

1530 max_chunk_size = max_chunk_size if max_chunk_size and max_chunk_size > 0 else io.DEFAULT_BUFFER_SIZE 

1531 if watchdog is not None: 

1532 watchdog.start() 

1533 try: 

1534 if proc.stdout is not None: 

1535 stream_copy(proc.stdout, output_stream, max_chunk_size) 

1536 stdout_value = proc.stdout.read() 

1537 if proc.stderr is not None: 

1538 stderr_value = proc.stderr.read() 

1539 status = proc.wait() 

1540 finally: 

1541 if watchdog is not None: 

1542 watchdog.cancel() 

1543 # Strip trailing "\n". 

1544 if stderr_value is not None and stderr_value.endswith(newline): # type: ignore[arg-type] 

1545 stderr_value = stderr_value[:-1] 

1546 if kill_check is not None and kill_check.is_set(): 

1547 assert timeout_error is not None 

1548 stderr_value = timeout_error() 

1549 # END stdout handling 

1550 finally: 

1551 if proc.stdout is not None: 

1552 proc.stdout.close() 

1553 if proc.stderr is not None: 

1554 proc.stderr.close() 

1555 

1556 if self.GIT_PYTHON_TRACE == "full": 

1557 cmdstr = " ".join(redacted_command) 

1558 

1559 def as_text(stdout_value: Union[bytes, str]) -> str: 

1560 return not output_stream and safe_decode(stdout_value) or "<OUTPUT_STREAM>" 

1561 

1562 # END as_text 

1563 

1564 if stderr_value: 

1565 _logger.info( 

1566 "%s -> %d; stdout: '%s'; stderr: '%s'", 

1567 cmdstr, 

1568 status, 

1569 as_text(stdout_value), 

1570 safe_decode(stderr_value), 

1571 ) 

1572 elif stdout_value: 

1573 _logger.info("%s -> %d; stdout: '%s'", cmdstr, status, as_text(stdout_value)) 

1574 else: 

1575 _logger.info("%s -> %d", cmdstr, status) 

1576 # END handle debug printing 

1577 

1578 if with_exceptions and status != 0: 

1579 raise GitCommandError(redacted_command, status, stderr_value, stdout_value) 

1580 

1581 if isinstance(stdout_value, bytes) and stdout_as_string: # Could also be output_stream. 

1582 stdout_value = safe_decode(stdout_value) 

1583 

1584 # Allow access to the command's status code. 

1585 if with_extended_output: 

1586 return (status, stdout_value, safe_decode(stderr_value)) 

1587 else: 

1588 return stdout_value 

1589 

1590 def environment(self) -> Dict[str, str]: 

1591 return self._environment 

1592 

1593 def update_environment(self, **kwargs: Any) -> Dict[str, Union[str, None]]: 

1594 """Set environment variables for future git invocations. Return all changed 

1595 values in a format that can be passed back into this function to revert the 

1596 changes. 

1597 

1598 Examples:: 

1599 

1600 old_env = self.update_environment(PWD='/tmp') 

1601 self.update_environment(**old_env) 

1602 

1603 :param kwargs: 

1604 Environment variables to use for git processes. 

1605 

1606 :return: 

1607 Dict that maps environment variables to their old values 

1608 """ 

1609 old_env = {} 

1610 for key, value in kwargs.items(): 

1611 # Set value if it is None. 

1612 if value is not None: 

1613 old_env[key] = self._environment.get(key) 

1614 self._environment[key] = value 

1615 # Remove key from environment if its value is None. 

1616 elif key in self._environment: 

1617 old_env[key] = self._environment[key] 

1618 del self._environment[key] 

1619 return old_env 

1620 

1621 @contextlib.contextmanager 

1622 def custom_environment(self, **kwargs: Any) -> Iterator[None]: 

1623 """A context manager around the above :meth:`update_environment` method to 

1624 restore the environment back to its previous state after operation. 

1625 

1626 Examples:: 

1627 

1628 with self.custom_environment(GIT_SSH='/bin/ssh_wrapper'): 

1629 repo.remotes.origin.fetch() 

1630 

1631 :param kwargs: 

1632 See :meth:`update_environment`. 

1633 """ 

1634 old_env = self.update_environment(**kwargs) 

1635 try: 

1636 yield 

1637 finally: 

1638 self.update_environment(**old_env) 

1639 

1640 def transform_kwarg(self, name: str, value: Any, split_single_char_options: bool) -> List[str]: 

1641 if len(name) == 1: 

1642 if value is True: 

1643 return ["-%s" % name] 

1644 elif value not in (False, None): 

1645 if split_single_char_options: 

1646 return ["-%s" % name, "%s" % value] 

1647 else: 

1648 return ["-%s%s" % (name, value)] 

1649 else: 

1650 if value is True: 

1651 return ["--%s" % dashify(name)] 

1652 elif value is not False and value is not None: 

1653 return ["--%s=%s" % (dashify(name), value)] 

1654 return [] 

1655 

1656 def transform_kwargs(self, split_single_char_options: bool = True, **kwargs: Any) -> List[str]: 

1657 """Transform Python-style kwargs into git command line options.""" 

1658 args = [] 

1659 for k, v in kwargs.items(): 

1660 if isinstance(v, (list, tuple)): 

1661 for value in v: 

1662 args += self.transform_kwarg(k, value, split_single_char_options) 

1663 else: 

1664 args += self.transform_kwarg(k, v, split_single_char_options) 

1665 return args 

1666 

1667 @classmethod 

1668 def _unpack_args(cls, arg_list: Sequence[Any]) -> List[str]: 

1669 outlist = [] 

1670 if isinstance(arg_list, (list, tuple)): 

1671 for arg in arg_list: 

1672 outlist.extend(cls._unpack_args(arg)) 

1673 else: 

1674 outlist.append(str(arg_list)) 

1675 

1676 return outlist 

1677 

1678 def __call__(self, **kwargs: Any) -> "Git": 

1679 """Specify command line options to the git executable for a subcommand call. 

1680 

1681 :param kwargs: 

1682 A dict of keyword arguments. 

1683 These arguments are passed as in :meth:`_call_process`, but will be passed 

1684 to the git command rather than the subcommand. 

1685 

1686 Examples:: 

1687 

1688 git(work_tree='/tmp').difftool() 

1689 """ 

1690 self._git_options = self.transform_kwargs(split_single_char_options=True, **kwargs) 

1691 return self 

1692 

1693 @overload 

1694 def _call_process( 

1695 self, method: str, *args: None, **kwargs: None 

1696 ) -> str: ... # If no args were given, execute the call with all defaults. 

1697 

1698 @overload 

1699 def _call_process( 

1700 self, 

1701 method: str, 

1702 istream: int, 

1703 as_process: Literal[True], 

1704 *args: Any, 

1705 **kwargs: Any, 

1706 ) -> "Git.AutoInterrupt": ... 

1707 

1708 @overload 

1709 def _call_process( 

1710 self, method: str, *args: Any, **kwargs: Any 

1711 ) -> Union[str, bytes, Tuple[int, Union[str, bytes], str], "Git.AutoInterrupt"]: ... 

1712 

1713 def _call_process( 

1714 self, method: str, *args: Any, **kwargs: Any 

1715 ) -> Union[str, bytes, Tuple[int, Union[str, bytes], str], "Git.AutoInterrupt"]: 

1716 """Run the given git command with the specified arguments and return the result 

1717 as a string. 

1718 

1719 :param method: 

1720 The command. Contained ``_`` characters will be converted to hyphens, such 

1721 as in ``ls_files`` to call ``ls-files``. 

1722 

1723 :param args: 

1724 The list of arguments. If ``None`` is included, it will be pruned. 

1725 This allows your commands to call git more conveniently, as ``None`` is 

1726 realized as non-existent. 

1727 

1728 :param kwargs: 

1729 Contains key-values for the following: 

1730 

1731 - The :meth:`execute()` kwds, as listed in ``execute_kwargs``. 

1732 - "Command options" to be converted by :meth:`transform_kwargs`. 

1733 - The ``insert_kwargs_after`` key which its value must match one of 

1734 ``*args``. 

1735 

1736 It also contains any command options, to be appended after the matched arg. 

1737 

1738 Examples:: 

1739 

1740 git.rev_list('master', max_count=10, header=True) 

1741 

1742 turns into:: 

1743 

1744 git rev-list --max-count=10 --header master 

1745 

1746 :return: 

1747 Same as :meth:`execute`. If no args are given, used :meth:`execute`'s 

1748 default (especially ``as_process = False``, ``stdout_as_string = True``) and 

1749 return :class:`str`. 

1750 """ 

1751 # Handle optional arguments prior to calling transform_kwargs. 

1752 # Otherwise these'll end up in args, which is bad. 

1753 exec_kwargs = {k: v for k, v in kwargs.items() if k in execute_kwargs} 

1754 opts_kwargs = {k: v for k, v in kwargs.items() if k not in execute_kwargs} 

1755 

1756 insert_after_this_arg = opts_kwargs.pop("insert_kwargs_after", None) 

1757 

1758 # Prepare the argument list. 

1759 

1760 opt_args = self.transform_kwargs(**opts_kwargs) 

1761 ext_args = self._unpack_args([a for a in args if a is not None]) 

1762 

1763 if insert_after_this_arg is None: 

1764 args_list = opt_args + ext_args 

1765 else: 

1766 try: 

1767 index = ext_args.index(insert_after_this_arg) 

1768 except ValueError as err: 

1769 raise ValueError( 

1770 "Couldn't find argument '%s' in args %s to insert cmd options after" 

1771 % (insert_after_this_arg, str(ext_args)) 

1772 ) from err 

1773 # END handle error 

1774 args_list = ext_args[: index + 1] + opt_args + ext_args[index + 1 :] 

1775 # END handle opts_kwargs 

1776 

1777 call = [self.GIT_PYTHON_GIT_EXECUTABLE] 

1778 

1779 # Add persistent git options. 

1780 call.extend(self._persistent_git_options) 

1781 

1782 # Add the git options, then reset to empty to avoid side effects. 

1783 call.extend(self._git_options) 

1784 self._git_options = () 

1785 

1786 call.append(dashify(method)) 

1787 call.extend(args_list) 

1788 

1789 return self.execute(call, **exec_kwargs) 

1790 

1791 def _parse_object_header(self, header_line: str) -> Tuple[str, str, int]: 

1792 """ 

1793 :param header_line: 

1794 A line of the form:: 

1795 

1796 <hex_sha> type_string size_as_int 

1797 

1798 :return: 

1799 (hex_sha, type_string, size_as_int) 

1800 

1801 :raise ValueError: 

1802 If the header contains indication for an error due to incorrect input sha. 

1803 """ 

1804 tokens = header_line.split() 

1805 if len(tokens) != 3: 

1806 if not tokens: 

1807 err_msg = ( 

1808 f"SHA is empty, possible dubious ownership in the repository " 

1809 f"""at {self._working_dir}.\n If this is unintended run:\n\n """ 

1810 f""" "git config --global --add safe.directory {self._working_dir}" """ 

1811 ) 

1812 raise ValueError(err_msg) 

1813 else: 

1814 raise ValueError("SHA %s could not be resolved, git returned: %r" % (tokens[0], header_line.strip())) 

1815 # END handle actual return value 

1816 # END error handling 

1817 

1818 if len(tokens[0]) != 40: 

1819 raise ValueError("Failed to parse header: %r" % header_line) 

1820 return (tokens[0], tokens[1], int(tokens[2])) 

1821 

1822 def _prepare_ref(self, ref: AnyStr) -> bytes: 

1823 # Required for command to separate refs on stdin, as bytes. 

1824 if isinstance(ref, bytes): 

1825 # Assume 40 bytes hexsha - bin-to-ascii for some reason returns bytes, not text. 

1826 refstr: str = ref.decode("ascii") 

1827 elif not isinstance(ref, str): 

1828 refstr = str(ref) # Could be ref-object. 

1829 else: 

1830 refstr = ref 

1831 

1832 if not refstr.endswith("\n"): 

1833 refstr += "\n" 

1834 return refstr.encode(defenc) 

1835 

1836 def _get_persistent_cmd(self, attr_name: str, cmd_name: str, *args: Any, **kwargs: Any) -> "Git.AutoInterrupt": 

1837 cur_val = getattr(self, attr_name) 

1838 if cur_val is not None: 

1839 return cur_val 

1840 

1841 options = {"istream": PIPE, "as_process": True} 

1842 options.update(kwargs) 

1843 

1844 cmd = self._call_process(cmd_name, *args, **options) 

1845 setattr(self, attr_name, cmd) 

1846 cmd = cast("Git.AutoInterrupt", cmd) 

1847 return cmd 

1848 

1849 def __get_object_header(self, cmd: "Git.AutoInterrupt", ref: AnyStr) -> Tuple[str, str, int]: 

1850 if cmd.stdin and cmd.stdout: 

1851 cmd.stdin.write(self._prepare_ref(ref)) 

1852 cmd.stdin.flush() 

1853 return self._parse_object_header(cmd.stdout.readline()) 

1854 else: 

1855 raise ValueError("cmd stdin was empty") 

1856 

1857 def get_object_header(self, ref: str) -> Tuple[str, str, int]: 

1858 """Use this method to quickly examine the type and size of the object behind the 

1859 given ref. 

1860 

1861 :note: 

1862 The method will only suffer from the costs of command invocation once and 

1863 reuses the command in subsequent calls. 

1864 

1865 :return: 

1866 (hexsha, type_string, size_as_int) 

1867 """ 

1868 cmd = self._get_persistent_cmd("cat_file_header", "cat_file", batch_check=True) 

1869 return self.__get_object_header(cmd, ref) 

1870 

1871 def get_object_data(self, ref: str) -> Tuple[str, str, int, bytes]: 

1872 """Similar to :meth:`get_object_header`, but returns object data as well. 

1873 

1874 :return: 

1875 (hexsha, type_string, size_as_int, data_string) 

1876 

1877 :note: 

1878 Not threadsafe. 

1879 """ 

1880 hexsha, typename, size, stream = self.stream_object_data(ref) 

1881 data = stream.read(size) 

1882 del stream 

1883 return (hexsha, typename, size, data) 

1884 

1885 def stream_object_data(self, ref: str) -> Tuple[str, str, int, "Git.CatFileContentStream"]: 

1886 """Similar to :meth:`get_object_data`, but returns the data as a stream. 

1887 

1888 :return: 

1889 (hexsha, type_string, size_as_int, stream) 

1890 

1891 :note: 

1892 This method is not threadsafe. You need one independent :class:`Git` 

1893 instance per thread to be safe! 

1894 """ 

1895 cmd = self._get_persistent_cmd("cat_file_all", "cat_file", batch=True) 

1896 hexsha, typename, size = self.__get_object_header(cmd, ref) 

1897 cmd_stdout = cmd.stdout if cmd.stdout is not None else io.BytesIO() 

1898 return (hexsha, typename, size, self.CatFileContentStream(size, cmd_stdout)) 

1899 

1900 def clear_cache(self) -> "Git": 

1901 """Clear all kinds of internal caches to release resources. 

1902 

1903 Currently persistent commands will be interrupted. 

1904 

1905 :return: 

1906 self 

1907 """ 

1908 for cmd in (self.cat_file_all, self.cat_file_header): 

1909 if cmd: 

1910 cmd.__del__() 

1911 

1912 self.cat_file_all = None 

1913 self.cat_file_header = None 

1914 return self