git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH] Escape project name in regexp

From
MKmartin f. krafft <madduck@madduck.net>
Date
Apr 20, 2008, 21:03 UTC
Message-ID
<1208725436-25408-1-git-send-email-madduck@madduck.net>
In-Reply-To
<20080420210320.GA22732@piper.oerlikon.madduck.net>

The project name, when used in a regular expression, needs to be quoted properly, so that stuff like '++' in the project name does not cause Perl to barf.

Related info: http://bugs.debian.org/476076 This is a bug in Perl's CGI.pm, but fixing that exposed a similar bug in gitweb.perl

Signed-off-by: martin f. krafft <madduck@madduck.net>
---
 gitweb/gitweb.perl |    2 +-
 1 files changed, 1 insertions(+), 1 deletions(-)
diff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl
index a48bebb..9865f9a 100755
--- a/gitweb/gitweb.perl
+++ b/gitweb/gitweb.perl
@@ -511,7 +511,7 @@ sub evaluate_path_info {
 	}
 	# do not change any parameters if an action is given using the query string
 	return if $action;
-	$path_info =~ s,^$project/*,,;
+	$path_info =~ s,^\Q$project\E/*,,;
 	my ($refname, $pathname) = split(/:/, $path_info, 2);
 	if (defined $pathname) {
 		# we got "project.git/branch:filename" or "project.git/branch:dir/"
-- 
1.5.5.rc2
Previous: martin f krafftNext: martin f. krafft
Message 4 of 6 in “gitweb fails with pathinfo and project with ++ in the name”
  1. martin f krafftApr 20, 2008
  2. Frank LichtenheldApr 20, 2008
  3. martin f krafftApr 20, 2008
  4. Escape project name in regexpmartin f. krafft, Apr 20, 2008
  5. Escape project names before creating pathinfo URLsmartin f. krafft, Apr 20, 2008
  6. Junio C HamanoApr 22, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.