[PATCH] Revised - git-daemon extra paranoia
- From
- H. Peter Anvin <hpa@zytor.com>
- Date
- Oct 18, 2005, 22:13 UTC
- Message-ID
- <43557388.2060508@zytor.com>
- In-Reply-To
- <43557254.3010807@zytor.com>
This patch adds some extra paranoia to the git-daemon filename test. In particular, it now rejects pathnames containing //; it also adds a redundant test for pathname absoluteness (belts and suspenders.)
A single / at the end of the path is still permitted, however.
Signed-off-by: H. Peter Anvin <hpa@zytor.com>
diff --git a/daemon.c b/daemon.c --- a/daemon.c +++ b/daemon.c @@ -80,17 +80,29 @@ static int path_ok(const char *dir) { const char *p = dir; char **pp; - int sl = 1, ndot = 0; + int sl, ndot; + + /* The pathname here should be an absolute path. */ + if ( *p++ != '/' ) + return 0; + + sl = 1; ndot = 0; for (;;) { if ( *p == '.' ) { ndot++; - } else if ( *p == '/' || *p == '\0' ) { + } else if ( *p == '\0' ) { + /* Reject "." and ".." at the end of the path */ if ( sl && ndot > 0 && ndot < 3 ) - return 0; /* . or .. in path */ + return 0; + + /* Otherwise OK */ + break; + } else if ( *p == '/' ) { + /* Refuse "", "." or ".." */ + if ( sl && ndot < 3 ) + return 0; sl = 1; - if ( *p == '\0' ) - break; /* End of string and all is good */ } else { sl = ndot = 0; }