git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC] submodule: munge paths to submodule git directories

From
Jonathan Nieder <jrnieder@gmail.com>
Date
Aug 7, 2018, 23:25 UTC
Message-ID
<20180807232524.GB249457@aiede.svl.corp.google.com>
In-Reply-To
<20180807230637.247200-1-bmwill@google.com>
Hi,
Brandon Williams wrote:
Show 22 quoted lines
> Commit 0383bbb901 (submodule-config: verify submodule names as paths,
> 2018-04-30) introduced some checks to ensure that submodule names don't
> include directory traversal components (e.g. "../").
>
> This addresses the vulnerability identified in 0383bbb901 but the root
> cause is that we use submodule names to construct paths to the
> submodule's git directory.  What we really should do is munge the
> submodule name before using it to construct a path.
>
> Introduce a function "strbuf_submodule_gitdir()" which callers can use
> to build a path to a submodule's gitdir.  This allows for a single
> location where we can munge the submodule name (by url encoding it)
> before using it as part of a path.
>
> Signed-off-by: Brandon Williams <bmwill@google.com>
> ---
> Using submodule names as is continues to be not such a good idea.  Maybe
> we could apply something like this to stop using them as is.  url
> encoding seems like the easiest approach, but I've also heard
> suggestions that would could use the SHA1 of the submodule name.
>
> Any thoughts?

I like this idea. It avoids the security and complexity problems of funny nested directories, while still making the submodule git dirs easy to find.

The current behavior has been particularly a problem in practice when submodule names are nested:

	[submodule "a"]
		url = https://www.example.com/a
		path = a/1
	[submodule "a/b"]
		url = https://www.example.com/a/b
		path = a/2

We don't enforce any constraint on submodule names to prevent that, but it causes hard to diagnose errors at clone time:

	fatal: not a git repository: superproject/a/1/../../.git/modules/a
	Unable to fetch in submodule path 'a/1'
	fatal: not a git repository: superproject/a/1/../../.git/modules/a
	fatal: not a git repository: superproject/a/1/../../.git/modules/a
	fatal: not a git repository: superproject/a/1/../../.git/modules/a
	Fetched in submodule 'a/1', but it did not contain 55ca6286e3e4f4fba5d0448333fa99fc5a404a73. Direct fetching of that commit failed.

because the fetch in .git/modules/a is interfered with by .git/modules/a/b.

[...]
> --- a/submodule.c
> +++ b/submodule.c
[...]
Show 16 quoted lines
> @@ -1933,9 +1938,29 @@ int submodule_to_gitdir(struct strbuf *buf, const char *submodule)
>  			goto cleanup;
>  		}
>  		strbuf_reset(buf);
> -		strbuf_git_path(buf, "%s/%s", "modules", sub->name);
> +		strbuf_submodule_gitdir(buf, the_repository, sub->name);
>  	}
>  
>  cleanup:
>  	return ret;
>  }
> +
> +void strbuf_submodule_gitdir(struct strbuf *buf, struct repository *r,
> +			     const char *submodule_name)
> +{
> +	int modules_len;
nit: size_t
Show 9 quoted lines
> +
> +	strbuf_git_common_path(buf, r, "modules/");
> +	modules_len = buf->len;
> +	strbuf_addstr(buf, submodule_name);
> +
> +	/*
> +	 * If the submodule gitdir already exists using the old location then
> +	 * return that.
> +	 */

nit: "old-fashioned location" or something. Maybe the function could use an API comment describing what's going on (that there are two naming conventions and we try first the old, then the new).

Should we validate the submodule_name here when accessing following the old convention?

Show 6 quoted lines
> +	if (!access(buf->buf, F_OK))
> +		return;
> +
> +	strbuf_setlen(buf, modules_len);
> +	strbuf_addstr_urlencode(buf, submodule_name, 1);
> +}
[...]
Show 11 quoted lines
> --- a/t/t7400-submodule-basic.sh
> +++ b/t/t7400-submodule-basic.sh
> @@ -932,7 +932,7 @@ test_expect_success 'recursive relative submodules stay relative' '
>  		cd clone2 &&
>  		git submodule update --init --recursive &&
>  		echo "gitdir: ../.git/modules/sub3" >./sub3/.git_expect &&
> -		echo "gitdir: ../../../.git/modules/sub3/modules/dirdir/subsub" >./sub3/dirdir/subsub/.git_expect
> +		echo "gitdir: ../../../.git/modules/sub3/modules/dirdir%2fsubsub" >./sub3/dirdir/subsub/.git_expect
>  	) &&
>  	test_cmp clone2/sub3/.git_expect clone2/sub3/.git &&
>  	test_cmp clone2/sub3/dirdir/subsub/.git_expect clone2/sub3/dirdir/subsub/.git
Sensible.

Can there be a test of the compatibility code as well? (I mean a test that manually sets up a submodule in .git/modules/dirdir/subsub and ensures that it gets reused.)

I'll apply this, experiment with it, and report back. Thanks for writing it.

Sincerely, Jonathan

Previous: Brandon WilliamsNext: Junio C Hamano
Message 2 of 40 in “[RFC] submodule: munge paths to submodule git directories”
  1. Brandon WilliamsAug 7, 2018
  2. Jonathan NiederAug 7, 2018
  3. Junio C HamanoAug 8, 2018
  4. 0/2 munge submodule namesBrandon Williams, Aug 8, 2018
  5. 1/2 submodule: create helper to build paths to submodule gitdirsBrandon Williams, Aug 8, 2018
  6. Stefan BellerAug 8, 2018
  7. Brandon WilliamsAug 9, 2018
  8. Junio C HamanoAug 10, 2018
  9. Brandon WilliamsAug 10, 2018
  10. 2/2 submodule: munge paths to submodule git directoriesBrandon Williams, Aug 8, 2018
  11. Jeff KingAug 9, 2018
  12. Brandon WilliamsAug 14, 2018
  13. Jonathan NiederAug 14, 2018
  14. Stefan BellerAug 14, 2018
  15. Jonathan NiederAug 14, 2018
  16. Stefan BellerAug 14, 2018
  17. Jonathan NiederAug 16, 2018
  18. Stefan BellerAug 16, 2018
  19. Jonathan NiederAug 16, 2018
  20. Brandon WilliamsAug 16, 2018
  21. submodule: add config for where gitdirs are locatedBrandon Williams, Aug 16, 2018
  22. Junio C HamanoAug 20, 2018
  23. Junio C HamanoAug 16, 2018
  24. Jeff KingAug 14, 2018
  25. Stefan BellerAug 28, 2018
  26. Jeff KingAug 29, 2018
  27. Stefan BellerAug 29, 2018
  28. Jeff KingAug 29, 2018
  29. Stefan BellerAug 29, 2018
  30. Jonathan NiederAug 29, 2018
  31. Stefan BellerAug 29, 2018
  32. Jeff KingAug 29, 2018
  33. Jonathan NiederAug 29, 2018
  34. Stefan BellerAug 29, 2018
  35. Brandon WilliamsAug 29, 2018
  36. Jeff KingAug 29, 2018
  37. Aaron SchrabAug 16, 2018
  38. Jonathan NiederJan 15, 2019
  39. Jeff KingJan 17, 2019
  40. Stefan BellerJan 17, 2019

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.