git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 3/7] Extract, test and enhance the logic to collapse ../foo paths.

From
EWEric Wong <normalperson@yhbt.net>
Date
Jul 30, 2012, 19:51 UTC
Message-ID
<20120730195108.GA20137@dcvr.yhbt.net>
In-Reply-To
<1343468312-72024-4-git-send-email-schwern@pobox.com>
"Michael G. Schwern" <schwern@pobox.com> wrote:
Show 6 quoted lines
> From: "Michael G. Schwern" <schwern@pobox.com>
> 
> The SVN API functions will not accept ../foo but their canonicalization
> functions will not collapse it.  So we'll have to do it ourselves.
> 
> _collapse_dotdot() works better than the existing regex did.

I don't dispute it's better, but it's worth explaining in the commit message to reviewers why something is "better".

> This will be used shortly when canonicalize_path() starts using the
> SVN API.
> ---
Show 7 quoted lines
> +# Turn foo/../bar into bar
> +sub _collapse_dotdot {
> +	my $path = shift;
> +
> +	1 while $path =~ s{/[^/]+/+\.\.}{};
> +	1 while $path =~ s{[^/]+/+\.\./}{};
> +	1 while $path =~ s{[^/]+/+\.\.}{};

This is a bug that's gone unnoticed[1] for over 5 years now, but I've just noticed this doesn' handle "foo/..bar" or "foo/...bar" cases correctly.

Show 9 quoted lines
>  sub canonicalize_path {
>  	my ($path) = @_;
>  	my $dot_slash_added = 0;
> @@ -83,7 +95,7 @@ sub canonicalize_path {
>  	# good reason), so let's do this manually.
>  	$path =~ s#/+#/#g;
>  	$path =~ s#/\.(?:/|$)#/#g;
> -	$path =~ s#/[^/]+/\.\.##g;
> +	$path = _collapse_dotdot($path);
[1] - I doubt anybody uses paths like these, though...
Previous: Michael G. SchwernNext: Michael G Schwern
Message 16 of 39 in “Canonicalize the git-svn path & url accessors”
  1. Michael G. SchwernJul 28, 2012
  2. 1/7 Move the canonicalization functions to Git::SVN::UtilsMichael G. Schwern, Jul 28, 2012
  3. 2/7 Change canonicalize_url() to use the SVN 1.7 API when available.Michael G. Schwern, Jul 28, 2012
  4. Jonathan NiederJul 28, 2012
  5. Michael G SchwernJul 28, 2012
  6. Jonathan NiederJul 28, 2012
  7. Michael G SchwernJul 28, 2012
  8. Jonathan NiederJul 28, 2012
  9. Jonathan NiederJul 28, 2012
  10. Michael G SchwernJul 28, 2012
  11. 0/2 Re: [PATCH 2/7] Change canonicalize_url() to use the SVN 1.7 API when available.Jonathan Nieder, Oct 14, 2012
  12. 1/2 git svn: do not overescape URLs (fallback case)Jonathan Nieder, Oct 14, 2012
  13. 2/2 git svn: canonicalize_url(): use svn_path_canonicalize when availableJonathan Nieder, Oct 14, 2012
  14. Eric WongOct 23, 2012
  15. 3/7 Extract, test and enhance the logic to collapse ../foo paths.Michael G. Schwern, Jul 28, 2012
  16. Eric WongJul 30, 2012
  17. Michael G SchwernJul 30, 2012
  18. Jonathan NiederSep 26, 2012
  19. Eric WongSep 26, 2012
  20. Jonathan NiederSep 26, 2012
  21. Eric WongSep 26, 2012
  22. Jonathan NiederSep 26, 2012
  23. Eric WongSep 27, 2012
  24. Jonathan NiederSep 27, 2012
  25. 4/7 Add join_paths() to safely concatenate paths.Michael G. Schwern, Jul 28, 2012
  26. Jonathan NiederSep 26, 2012
  27. 5/7 Remove irrelevant comment.Michael G. Schwern, Jul 28, 2012
  28. 6/7 Switch path canonicalization to use the SVN API.Michael G. Schwern, Jul 28, 2012
  29. Jonathan NiederJul 28, 2012
  30. Michael G SchwernJul 28, 2012
  31. Eric WongJul 30, 2012
  32. Eric WongAug 2, 2012
  33. Michael G SchwernAug 2, 2012
  34. git-svn: keep leading slash when canonicalizing paths (fallback case)Jonathan Nieder, Oct 5, 2012
  35. Eric WongOct 5, 2012
  36. Junio C HamanoOct 6, 2012
  37. 7/7 Make Git::SVN and Git::SVN::Ra canonicalize paths and urls.Michael G. Schwern, Jul 28, 2012
  38. Jonathan NiederJul 28, 2012
  39. Michael G SchwernJul 28, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.