{"thread":{"id":"25357","subject":"[stgit PATCH] commands.{new,rename}: verify patch names","startedAt":"2010-10-05T12:56:31Z","lastAt":"2010-11-03T02:43:29Z","messageCount":2,"participants":["Max Kellermann","Shinya Kuribayashi"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"152670","messageId":"20101005125631.17466.95192.stgit@woodpecker.blarg.de","threadId":"25357","inReplyTo":null,"subject":"[stgit PATCH] commands.{new,rename}: verify patch names","fromName":"Max Kellermann","fromEmail":"max@duempel.org","sentAt":"2010-10-05T12:56:31Z","receivedAt":"2010-10-05T12:56:31Z","isPatch":true,"sender":{"key":"max@duempel.org","avatar":null},"body":"Don't allow patches with invalid names.  For example, a patch with a\nslash in the name will cause the underlying git command to fail, and\nstgit doesn't handle this error condition properly.\n---\n stgit/commands/new.py    |    3 +++\n stgit/commands/rename.py |    3 +++\n stgit/utils.py           |    6 ++++++\n 3 files changed, 12 insertions(+), 0 deletions(-)\n\ndiff --git a/stgit/commands/new.py b/stgit/commands/new.py\nindex d5c5382..6bd7314 100644\n--- a/stgit/commands/new.py\n+++ b/stgit/commands/new.py\n@@ -61,6 +61,9 @@ def func(parser, options, args):\n         name = args[0]\n         if stack.patches.exists(name):\n             raise common.CmdException('%s: patch already exists' % name)\n+\n+        if not utils.check_patch_name(name):\n+            raise common.CmdException('%s: invalid patch name' % name)\n     else:\n         parser.error('incorrect number of arguments')\n \ndiff --git a/stgit/commands/rename.py b/stgit/commands/rename.py\nindex db898cb..7c229be 100644\n--- a/stgit/commands/rename.py\n+++ b/stgit/commands/rename.py\n@@ -51,6 +51,9 @@ def func(parser, options, args):\n     else:\n         parser.error('incorrect number of arguments')\n \n+    if not check_patch_name(new):\n+        raise CmdException('%s: invalid patch name' % new)\n+\n     out.start('Renaming patch \"%s\" to \"%s\"' % (old, new))\n     crt_series.rename_patch(old, new)\n \ndiff --git a/stgit/utils.py b/stgit/utils.py\nindex 2955adf..a41457b 100644\n--- a/stgit/utils.py\n+++ b/stgit/utils.py\n@@ -241,6 +241,12 @@ def make_patch_name(msg, unacceptable, default_name = 'patch'):\n         patchname = default_name\n     return find_patch_name(patchname, unacceptable)\n \n+def check_patch_name(name):\n+    \"\"\"Checks if the specified name is a valid patch name. For\n+    technical reasons, we cannot allow a slash and other characters.\"\"\"\n+    return len(name) > 0 and name[0] not in '.-' and '/' not in name and \\\n+           '..' not in name and re.search(r'[\\x00-\\x20]', name) is None\n+\n # any and all functions are builtin in Python 2.5 and higher, but not\n # in 2.4.\n if not 'any' in dir(__builtins__):\n"},{"id":"155016","messageId":"4CD0CC51.5030402@pobox.com","threadId":"25357","inReplyTo":"20101005125631.17466.95192.stgit@woodpecker.blarg.de","subject":"Re: [stgit PATCH] commands.{new,rename}: verify patch names","fromName":"Shinya Kuribayashi","fromEmail":"skuribay@pobox.com","sentAt":"2010-11-03T02:43:29Z","receivedAt":"2010-11-03T02:43:29Z","isPatch":true,"sender":{"key":"skuribay@pobox.com","avatar":null},"body":"Hi,\n\nOn 10/5/10 9:56 PM, Max Kellermann wrote:\n> Don't allow patches with invalid names.  For example, a patch with a\n> slash in the name will cause the underlying git command to fail, and\n> stgit doesn't handle this error condition properly.\n> ---\n>   stgit/commands/new.py    |    3 +++\n>   stgit/commands/rename.py |    3 +++\n>   stgit/utils.py           |    6 ++++++\n>   3 files changed, 12 insertions(+), 0 deletions(-)\n\nIt would be nice to mention about what's updated when revising\npatches, even though it's even +1 line.  And we'd also like to\nhave a sign within Subject:, e.g., [stgit PATCH v2] will suffice.\n\n> diff --git a/stgit/utils.py b/stgit/utils.py\n> index 2955adf..a41457b 100644\n> --- a/stgit/utils.py\n> +++ b/stgit/utils.py\n> @@ -241,6 +241,12 @@ def make_patch_name(msg, unacceptable, default_name = 'patch'):\n>           patchname = default_name\n>       return find_patch_name(patchname, unacceptable)\n>\n> +def check_patch_name(name):\n> +    \"\"\"Checks if the specified name is a valid patch name. For\n> +    technical reasons, we cannot allow a slash and other characters.\"\"\"\n> +    return len(name)>  0 and name[0] not in '.-' and '/' not in name and \\\n> +           '..' not in name and re.search(r'[\\x00-\\x20]', name) is None\n> +\n>   # any and all functions are builtin in Python 2.5 and higher, but not\n>   # in 2.4.\n>   if not 'any' in dir(__builtins__):\n\n\"..\" is now taken care, too.  That's nice.\n\nBy the way, you're not the first person encountered this issue,\nand we already have corresponding bug# at gna.org, you might be\ninterested in:\n\n* https://gna.org/bugs/?10919\n   sanity check patch names\n\n* https://gna.org/bugs/?15654\n   stg new when path contains slash stops stg from doing everything\n\nI don't speak Python, so couldn't help the patch itself.\nCatalin and Karl hopefully will guide you (they seem to busy\nthese days, or just failed to find this thread).\n"}]}