git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v2] correct verify_path for Windows

From
Dmitry Potapov <dpotapov@gmail.com>
Date
Oct 7, 2008, 03:26 UTC
Message-ID
<20081007032623.GX21650@dpotapov.dyndns.org>
In-Reply-To
<B985AE98-F6E2-4C23-8D34-5A22A9F89FA7@gmail.com>

Colon and backslash in names may be used on Windows to overwrite files outside of the working directory. Due to the file-system being case- insensitive, .git can be written as any combination of upper and lower characters, so we should check that too.

Signed-off-by: Dmitry Potapov <dpotapov@gmail.com>
---
In this version, I have added the check that files in .git/ will not
be overwritten by checkout. Overwriting such files as .git/config is
potentially exploitable.
Josh,

Does OS X need the same check below? I believe it has case-insensitive filesystem, so it needs that too, but I am not sure what is the right define should be used.

Thanks, Dmitry

 read-cache.c |   19 +++++++++++++++++++
 1 files changed, 19 insertions(+), 0 deletions(-)
diff --git a/read-cache.c b/read-cache.c
index aff6390..7f855ee 100644
--- a/read-cache.c
+++ b/read-cache.c
@@ -668,10 +668,19 @@ static int verify_dotfile(const char *rest)
 	 * shares the path end test with the ".." case.
 	 */
 	case 'g':
+#if defined(_WIN32) || defined(__CYGWIN__)
+	/* On Windows, file names are case-insensitive */
+	case 'G':
+		if ((rest[1]|0x20) != 'i')
+			break;
+		if ((rest[2]|0x20) != 't')
+			break;
+#else
 		if (rest[1] != 'i')
 			break;
 		if (rest[2] != 't')
 			break;
+#endif
 		rest += 2;
 	/* fallthrough */
 	case '.':
@@ -703,6 +712,16 @@ inside:
 			}
 			return 0;
 		}
+#if defined(_WIN32) || defined(__CYGWIN__)
+		/*
+		 * There is a bunch of other characters that are not allowed
+		 * in Win32 API, but the following two create a security hole
+		 * by allowing to overwrite files outside of the working tree,
+		 * therefore they are explicitly prohibited.
+		 */
+		else if (c == ':' || c == '\\')
+			return 0;
+#endif
 		c = *path++;
 	}
 }
-- 
1.6.0
Previous: Joshua JuranNext: Johannes Sixt
Message 11 of 19 in “Files with colons under Cygwin”
  1. Giovanni FunchalOct 2, 2008
  2. Dmitry PotapovOct 4, 2008
  3. Alex RiesenOct 5, 2008
  4. Alex RiesenOct 5, 2008
  5. Dmitry PotapovOct 5, 2008
  6. Giovanni FunchalOct 5, 2008
  7. Johannes SixtOct 6, 2008
  8. Dmitry PotapovOct 7, 2008
  9. Johannes SixtOct 7, 2008
  10. Joshua JuranOct 7, 2008
  11. correct verify_path for WindowsDmitry Potapov, Oct 7, 2008
  12. Johannes SixtOct 7, 2008
  13. Dmitry PotapovOct 11, 2008
  14. Alex RiesenOct 11, 2008
  15. Dmitry PotapovOct 12, 2008
  16. Alex RiesenOct 12, 2008
  17. Johannes SixtOct 13, 2008
  18. Alex RiesenOct 13, 2008
  19. Alex RiesenOct 7, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.