{"thread":{"id":"13185","subject":"gitweb fails with pathinfo and project with ++ in the name","startedAt":"2008-04-20T14:46:54Z","lastAt":"2008-04-22T06:31:13Z","messageCount":6,"participants":["martin f krafft","Frank Lichtenheld","martin f. krafft","Junio C Hamano"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"74805","messageId":"20080420144654.GA11479@piper.oerlikon.madduck.net","threadId":"13185","inReplyTo":null,"subject":"gitweb fails with pathinfo and project with ++ in the name","fromName":"martin f krafft","fromEmail":"madduck@madduck.net","sentAt":"2008-04-20T14:46:54Z","receivedAt":"2008-04-20T14:46:54Z","isPatch":false,"sender":{"key":"madduck@madduck.net","avatar":null},"body":"Hi all,\n\nplease have a look at http://git.madduck.net/v/code/libfactory++.git\nor http://git.madduck.net/v/code/libfactory%2b%2b.git.\n\nI narrowed this down to the first line of CGI.pm's path_info sub:\n\n  my ($self,$info) = self_or_default(@_);\n\nbut then my perl-foo wouldn't take me further.\n\ngitweb works fine if I turn off pathinfo, but when it's turned on,\nit cannot deal with two ++ in the name of projects.\n\nThe bug seems to be in CGI.pm, and I now wonder what to do about it.\n\nPlease keep the bug address <476076@bugs.debian.org> in Cc.\n\n-- \nmartin | http://madduck.net/ | http://two.sentenc.es/\n \n\"the association on this web site and in peter chappell\n publications, articles and books, made between remedy and diseases\n is used for clarity, but is not the functional reality and does not\n imply these resonances treat any disease. they merely vitalise and\n inform the self healing system.\"\n                                                   -- peter chappell\n \nspamtraps: madduck.bogus@madduck.net\n"},{"id":"74807","messageId":"20080420155318.GV6024@mail-vs.djpig.de","threadId":"13185","inReplyTo":"20080420144654.GA11479@piper.oerlikon.madduck.net","subject":"Re: Bug#476076: gitweb fails with pathinfo and project with ++ in the name","fromName":"Frank Lichtenheld","fromEmail":"djpig@debian.org","sentAt":"2008-04-20T15:53:18Z","receivedAt":"2008-04-20T15:53:18Z","isPatch":false,"sender":{"key":"frank@lichtenheld.de","avatar":"https://gravatar.com/avatar/b9f1d4b120e138f157c9e480d0818197c474628923786adb98f30017cdb99c3c?d=mp&s=160"},"body":"On Sun, Apr 20, 2008 at 04:46:54PM +0200, martin f krafft wrote:\n> The bug seems to be in CGI.pm, and I now wonder what to do about it.\n\nCGI->path_info in etch's version is broken, you need either use a newer\nCGI.pm or $ENV{PATH_INFO} directly.\n\nGruesse,\n-- \nFrank Lichtenheld <djpig@debian.org>\nwww: http://www.djpig.de/\n"},{"id":"74832","messageId":"20080420210320.GA22732@piper.oerlikon.madduck.net","threadId":"13185","inReplyTo":"20080420155318.GV6024@mail-vs.djpig.de","subject":"Re: Bug#476076: gitweb fails with pathinfo and project with ++ in the name","fromName":"martin f krafft","fromEmail":"madduck@debian.org","sentAt":"2008-04-20T21:03:20Z","receivedAt":"2008-04-20T21:03:20Z","isPatch":false,"sender":{"key":"madduck@debian.org","avatar":null},"body":"reassign 476076 perl-modules\nforcemerge 411735 476076\nthanks\n\nalso sprach Frank Lichtenheld <djpig@debian.org> [2008.04.20.1753 +0200]:\n> CGI->path_info in etch's version is broken, you need either use a newer\n> CGI.pm or $ENV{PATH_INFO} directly.\n\nFwiw: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=411735\n\nFixing it exposed a similar bug in gitweb.perl; the patch will\nfollow in a few minutes.\n\n-- \n .''`.   martin f. krafft <madduck@debian.org>\n: :'  :  proud Debian developer, author, administrator, and user\n`. `'`   http://people.debian.org/~madduck - http://debiansystem.info\n  `-  Debian - when you have better things to do than fixing systems\n"},{"id":"74833","messageId":"1208725436-25408-1-git-send-email-madduck@madduck.net","threadId":"13185","inReplyTo":"20080420210320.GA22732@piper.oerlikon.madduck.net","subject":"[PATCH] Escape project name in regexp","fromName":"martin f. krafft","fromEmail":"madduck@madduck.net","sentAt":"2008-04-20T21:03:56Z","receivedAt":"2008-04-20T21:03:56Z","isPatch":true,"sender":{"key":"madduck@madduck.net","avatar":null},"body":"The project name, when used in a regular expression, needs to be quoted\nproperly, so that stuff like '++' in the project name does not cause\nPerl to barf.\n\nRelated info: http://bugs.debian.org/476076\nThis is a bug in Perl's CGI.pm, but fixing that exposed a similar bug in\ngitweb.perl\n\nSigned-off-by: martin f. krafft <madduck@madduck.net>\n---\n gitweb/gitweb.perl |    2 +-\n 1 files changed, 1 insertions(+), 1 deletions(-)\n\ndiff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl\nindex a48bebb..9865f9a 100755\n--- a/gitweb/gitweb.perl\n+++ b/gitweb/gitweb.perl\n@@ -511,7 +511,7 @@ sub evaluate_path_info {\n \t}\n \t# do not change any parameters if an action is given using the query string\n \treturn if $action;\n-\t$path_info =~ s,^$project/*,,;\n+\t$path_info =~ s,^\\Q$project\\E/*,,;\n \tmy ($refname, $pathname) = split(/:/, $path_info, 2);\n \tif (defined $pathname) {\n \t\t# we got \"project.git/branch:filename\" or \"project.git/branch:dir/\"\n-- \n1.5.5.rc2\n"},{"id":"74834","messageId":"1208726618-27477-1-git-send-email-madduck@madduck.net","threadId":"13185","inReplyTo":"1208725436-25408-1-git-send-email-madduck@madduck.net","subject":"[PATCH] Escape project names before creating pathinfo URLs","fromName":"martin f. krafft","fromEmail":"madduck@madduck.net","sentAt":"2008-04-20T21:23:38Z","receivedAt":"2008-04-20T21:23:38Z","isPatch":true,"sender":{"key":"madduck@madduck.net","avatar":null},"body":"If a project name contains special URL characters like +, gitweb's links\nbreak in subtle ways. The solution is to pass the project name through\nesc_url() and using the return value.\n\nSigned-off-by: martin f. krafft <madduck@madduck.net>\n---\n gitweb/gitweb.perl |    4 ++--\n 1 files changed, 2 insertions(+), 2 deletions(-)\n\ndiff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl\nindex a48bebb..241ae17 100755\n--- a/gitweb/gitweb.perl\n+++ b/gitweb/gitweb.perl\n@@ -633,7 +633,7 @@ sub href(%) {\n \tmy ($use_pathinfo) = gitweb_check_feature('pathinfo');\n \tif ($use_pathinfo) {\n \t\t# use PATH_INFO for project name\n-\t\t$href .= \"/$params{'project'}\" if defined $params{'project'};\n+\t\t$href .= \"/\".esc_url($params{'project'}) if defined $params{'project'};\n \t\tdelete $params{'project'};\n \n \t\t# Summary just uses the project path URL\n@@ -2575,7 +2575,7 @@ EOF\n \t\tmy $action = $my_uri;\n \t\tmy ($use_pathinfo) = gitweb_check_feature('pathinfo');\n \t\tif ($use_pathinfo) {\n-\t\t\t$action .= \"/$project\";\n+\t\t\t$action .= \"/\".esc_url($project);\n \t\t} else {\n \t\t\t$cgi->param(\"p\", $project);\n \t\t}\n-- \n1.5.5.rc2\n"},{"id":"74912","messageId":"7vfxte4czy.fsf@gitster.siamese.dyndns.org","threadId":"13185","inReplyTo":"1208726618-27477-1-git-send-email-madduck@madduck.net","subject":"Re: [PATCH] Escape project names before creating pathinfo URLs","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2008-04-22T06:31:13Z","receivedAt":"2008-04-22T06:31:13Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Both patches make sense; will apply to 'maint'.\n"}]}