diff --git a/tests/test-convert-git.t b/tests/test-convert-git.t --- a/tests/test-convert-git.t +++ b/tests/test-convert-git.t @@ -948,7 +948,7 @@ damage git repository by renaming a tree $ hg convert git-repo4 git-repo4-broken-hg 2>&1 | grep 'abort:' abort: cannot read changes in 1c0ce3c5886f83a1d78a7b517cdff5cf9ca17bdd -#if no-windows +#if no-windows git19 test for escaping the repo name (CVE-2016-3069) diff --git a/tests/test-subrepo-git.t b/tests/test-subrepo-git.t --- a/tests/test-subrepo-git.t +++ b/tests/test-subrepo-git.t @@ -1137,6 +1137,8 @@ make sure we show changed files, rather ? s/foobar.orig ? s/snake.python.orig +#if git19 + test for Git CVE-2016-3068 $ hg init malicious-subrepository $ cd malicious-subrepository @@ -1178,3 +1180,5 @@ whitelisting of ext should be respected [255] $ f -Dq pwned.txt pwned: you asked for it + +#endif