{"thread":{"id":"48898","subject":"clean filter run in top of repo with wrong GIT_WORK_TREE","startedAt":"2018-07-17T17:08:21Z","lastAt":"2018-07-17T17:32:43Z","messageCount":2,"participants":["Joey Hess"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"352799","messageId":"20180717165834.GA5615@kitenet.net","threadId":"48898","inReplyTo":null,"subject":"clean filter run in top of repo with wrong GIT_WORK_TREE","fromName":"Joey Hess","fromEmail":"id@joeyh.name","sentAt":"2018-07-17T16:58:34Z","receivedAt":"2018-07-17T17:08:21Z","isPatch":false,"sender":{"key":"id@joeyh.name","avatar":"https://avatars.githubusercontent.com/u/16392?v=4"},"body":"When git is running inside a subdirectory of the repository, \nand needs to run the clean filter, it runs it chdired back to the top of\nthe repository. However, if git was run with a relative --work-tree,\nit passes that relative path in GIT_WORK_TREE on to the clean filter.\n\nIf git was run with eg, \"--work-tree=..\", the clean filter sees a work\ntree that is outside the repository. It might then read files located\noutside the repository. That seems like it could have security\nconsequences, but it's certianly a surprising problem to need to deal\nwith when writing a clean filter.\n\nBrian posted a fix for a very similar bug in sequencer.c on the 14th, \nso it seems likely there are other occurances of the same problem\nelsewhere.\n\nDemonstration of this bug:\n\njoey@darkstar:~/tmp/repo>cat .gitattributes\n* filter=foo\njoey@darkstar:~/tmp/repo>git config filter.foo.clean\nclean-filter %f\njoey@darkstar:~/tmp/repo>cat ~/bin/clean-filter \n#!/bin/sh\npwd >&2\necho $GIT_WORK_TREE >&2\nls \"$GIT_WORK_TREE/$1\"\njoey@darkstar:~/tmp/repo>cd foo/bar/\njoey@darkstar:~/tmp/repo/foo/bar>ls\nx\njoey@darkstar:~/tmp/repo/foo/bar>touch x\njoey@darkstar:~/tmp/repo/foo/bar>git --work-tree=../.. ls-files --modified\n/home/joey/tmp/repo\n../..\nls: cannot access '../../foo/bar/x': No such file or directory\n\ngit version 2.18.0\n\n-- \nsee shy jo\n"},{"id":"352802","messageId":"20180717173233.GA15251@kitenet.net","threadId":"48898","inReplyTo":"20180717165834.GA5615@kitenet.net","subject":"Re: clean filter run in top of repo with wrong GIT_WORK_TREE","fromName":"Joey Hess","fromEmail":"id@joeyh.name","sentAt":"2018-07-17T17:32:33Z","receivedAt":"2018-07-17T17:32:43Z","isPatch":false,"sender":{"key":"id@joeyh.name","avatar":"https://avatars.githubusercontent.com/u/16392?v=4"},"body":"The clean filter can work around this problem by chdir GIT_PREFIX,\nbut needing to do this in unusual cases seems to be asking for bugs.\n\n-- \nsee shy jo\n"}]}