git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] gitweb: Harden UTF-8 handling in generated links

From
MWMichael Wagner <mail@mwagner.org>
Date
Jun 4, 2014, 20:47 UTC
Message-ID
<20140604204746.GA1855@localhost.localdomain>
In-Reply-To
<538F69DA.9010201@gmail.com>
On Wed, Jun 04, 2014 at 08:47:54PM +0200, Jakub Narębski wrote:
Show 37 quoted lines
> Michael Wagner wrote:
> > On Tue, May 27, 2014 at 04:22:42PM +0200, Jakub Narębski wrote:
> 
> >> Subject: [PATCH] gitweb: Harden UTF-8 handling in generated links
> >>
> >> esc_html() ensures that its input is properly UTF-8 encoded and marked
> >> as UTF-8 with to_utf8().  Make esc_param() (used for query parameters
> >> in generated URLs), esc_path_info() (for escaping path_info
> >> components) and esc_url() use it too.
> >>
> >> This hardens gitweb against errors in UTF-8 handling; because
> >> to_utf8() is idempotent it won't change correct output.
> [...]
> >>   sub esc_param {
> >>   	my $str = shift;
> >>   	return undef unless defined $str;
> >> +
> >> +	$str = to_utf8($str);
> >>   	$str =~ s/([^A-Za-z0-9\-_.~()\/:@ ]+)/CGI::escape($1)/eg;
> >>   	$str =~ s/ /\+/g;
> >> +
> >>   	return $str;
> >>   }   
>  
> > While trying to view a "blob_plain" of "Gütekritierien.txt", a 404 error
> > occured. "git_get_hash_by_path" tries to resolve the hash with the wrong
> > filename (git ls-tree -z HEAD -- Gütekriterien.txt) and fails.
> > 
> > The filename needs the correct encoding. Something like this is probably
> > needed for all filenames and should be done at a prior stage:
> 
> True.
> 
> First, I wonder why the tests I did for this situation didn't
> show any errors even before the "harden href()" patch. What
> is different in your config that you see those errors?
> 
Nothing special. It is reproducible with git 1.9.3 (Fedora 20), git
instaweb (lighttpd) and LANG=de_DE.UTF-8.  
 
Previous: Jakub NarębskiNext: Jakub Narębski
Message 20 of 21 in “Gitweb: Convert UTF-8 encoded file names”
  1. Gitweb: Convert UTF-8 encoded file namesMichael Wagner, May 14, 2014
  2. Junio C HamanoMay 14, 2014
  3. Jakub NarębskiMay 14, 2014
  4. Michael WagnerMay 15, 2014
  5. Peter KreftingMay 15, 2014
  6. Junio C HamanoMay 15, 2014
  7. Michael WagnerMay 15, 2014
  8. Jakub NarębskiMay 15, 2014
  9. Jakub NarębskiMay 15, 2014
  10. Junio C HamanoMay 15, 2014
  11. Jakub NarębskiMay 15, 2014
  12. Junio C HamanoMay 16, 2014
  13. Jakub NarębskiMay 16, 2014
  14. Junio C HamanoMay 16, 2014
  15. Jakub NarębskiMay 27, 2014
  16. Junio C HamanoMay 16, 2014
  17. gitweb: Harden UTF-8 handling in generated linksJakub Narębski, May 27, 2014
  18. Michael WagnerJun 4, 2014
  19. Jakub NarębskiJun 4, 2014
  20. Michael WagnerJun 4, 2014
  21. Jakub NarębskiMay 15, 2014

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.