{"thread":{"id":"7879","subject":"gitweb search page link slightly wrong","startedAt":"2007-04-27T20:43:13Z","lastAt":"2007-05-01T10:22:50Z","messageCount":3,"participants":["Johannes Berg"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"40628","messageId":"1177706593.3565.59.camel@johannes.berg","threadId":"7879","inReplyTo":null,"subject":"gitweb search page link slightly wrong","fromName":"Johannes Berg","fromEmail":"johannes@sipsolutions.net","sentAt":"2007-04-27T20:43:13Z","receivedAt":"2007-04-27T20:43:13Z","isPatch":false,"sender":{"key":"johannes@sipsolutions.net","avatar":"https://avatars.githubusercontent.com/u/5159728?v=4"},"body":"Hi,\n\nJust noticed on the git.kernel.org interface that when you do a search\nfor something that includes an \"@\" sign, then the \"next page\" link will\ninclude \"\\@\" instead and gitweb won't actually find anything on the next\npage. No idea if that bug was fixed already somewhere else, but at least\nit's visible on git.kernel.org.\n\njohannes\n"},{"id":"40814","messageId":"1178014409.3483.12.camel@johannes.berg","threadId":"7879","inReplyTo":"1177706593.3565.59.camel@johannes.berg","subject":"Re: gitweb search page link slightly wrong","fromName":"Johannes Berg","fromEmail":"johannes@sipsolutions.net","sentAt":"2007-05-01T10:13:29Z","receivedAt":"2007-05-01T10:13:29Z","isPatch":false,"sender":{"key":"johannes@sipsolutions.net","avatar":"https://avatars.githubusercontent.com/u/5159728?v=4"},"body":"This seems to fix it but I have no idea what it breaks. Command\ninjection should be stopped a few lines above that, and no other\nparameter is ever quoted using quotemeta, so I'm not sure what the point\nis, but I suppose it is actually necessary because the search text is\nthen wrapped into a regular expression or something?\n\n--- git.orig/gitweb/gitweb.perl\t2007-05-01 11:58:27.000000000 +0200\n+++ git/gitweb/gitweb.perl\t2007-05-01 12:11:56.000000000 +0200\n@@ -368,7 +368,6 @@ if (defined $searchtext) {\n \tif (length($searchtext) < 2) {\n \t\tdie_error(undef, \"At least two characters are required for search parameter\");\n \t}\n-\t$searchtext = quotemeta $searchtext;\n }\n \n our $searchtype = $cgi->param('st');\n\n"},{"id":"40816","messageId":"1178014970.3483.15.camel@johannes.berg","threadId":"7879","inReplyTo":"1178014409.3483.12.camel@johannes.berg","subject":"Re: gitweb search page link slightly wrong","fromName":"Johannes Berg","fromEmail":"johannes@sipsolutions.net","sentAt":"2007-05-01T10:22:50Z","receivedAt":"2007-05-01T10:22:50Z","isPatch":false,"sender":{"key":"johannes@sipsolutions.net","avatar":"https://avatars.githubusercontent.com/u/5159728?v=4"},"body":"On Tue, 2007-05-01 at 12:13 +0200, Johannes Berg wrote:\n> This seems to fix it but I have no idea what it breaks. Command\n> injection should be stopped a few lines above that, and no other\n> parameter is ever quoted using quotemeta, so I'm not sure what the point\n> is, but I suppose it is actually necessary because the search text is\n> then wrapped into a regular expression or something?\n\nAh, I understand now. Here's a possibly complete fix.\n\nFrom: Johannes Berg <johannes@sipsolutions.net>\nSubject: quote $searchtext only before use\n\n$searchtext is used in two ways\n (1) to do the search\n (2) to put it back into the output\n\nFor (1) it needs to have meta chars quoted, but for (2) not, so quote\nthem only when needed.\n\nSigned-off-by: Johannes Berg <johannes@sipsolutions.net>\n\n--- git.orig/gitweb/gitweb.perl\t2007-05-01 11:58:27.000000000 +0200\n+++ git/gitweb/gitweb.perl\t2007-05-01 12:20:27.000000000 +0200\n@@ -368,7 +368,6 @@ if (defined $searchtext) {\n \tif (length($searchtext) < 2) {\n \t\tdie_error(undef, \"At least two characters are required for search parameter\");\n \t}\n-\t$searchtext = quotemeta $searchtext;\n }\n \n our $searchtype = $cgi->param('st');\n@@ -2927,6 +2926,7 @@ sub git_heads_body {\n \n sub git_search_grep_body {\n \tmy ($commitlist, $from, $to, $extra) = @_;\n+\tmy $_searchtext = quotemeta $searchtext;\n \t$from = 0 unless defined $from;\n \t$to = $#{$commitlist} if (!defined $to || $#{$commitlist} < $to);\n \n@@ -2951,7 +2951,7 @@ sub git_search_grep_body {\n \t\t\t       esc_html(chop_str($co{'title'}, 50)) . \"<br/>\");\n \t\tmy $comment = $co{'comment'};\n \t\tforeach my $line (@$comment) {\n-\t\t\tif ($line =~ m/^(.*)($searchtext)(.*)$/i) {\n+\t\t\tif ($line =~ m/^(.*)($_searchtext)(.*)$/i) {\n \t\t\t\tmy $lead = esc_html($1) || \"\";\n \t\t\t\t$lead = chop_str($lead, 30, 10);\n \t\t\t\tmy $match = esc_html($2) || \"\";\n@@ -4325,7 +4325,7 @@ sub git_search {\n \t\t} elsif ($searchtype eq 'committer') {\n \t\t\t$greptype = \"--committer=\";\n \t\t}\n-\t\t$greptype .= $searchtext;\n+\t\t$greptype .= quotemeta $searchtext;\n \t\tmy @commitlist = parse_commits($hash, 101, (100 * $page), $greptype);\n \n \t\tmy $paging_nav = '';\n@@ -4374,8 +4374,9 @@ sub git_search {\n \t\tmy $alternate = 1;\n \t\t$/ = \"\\n\";\n \t\tmy $git_command = git_cmd_str();\n+\t\tmy $_searchtext = quotemeta $searchtext;\n \t\topen my $fd, \"-|\", \"$git_command rev-list $hash | \" .\n-\t\t\t\"$git_command diff-tree -r --stdin -S\\'$searchtext\\'\";\n+\t\t\t\"$git_command diff-tree -r --stdin -S\\'$_searchtext\\'\";\n \t\tundef %co;\n \t\tmy @files;\n \t\twhile (my $line = <$fd>) {\n"}]}