git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH] Revised - git-daemon extra paranoia

From
HAH. Peter Anvin <hpa@zytor.com>
Date
Oct 18, 2005, 22:13 UTC
Message-ID
<43557388.2060508@zytor.com>
In-Reply-To
<43557254.3010807@zytor.com>

This patch adds some extra paranoia to the git-daemon filename test. In particular, it now rejects pathnames containing //; it also adds a redundant test for pathname absoluteness (belts and suspenders.)

A single / at the end of the path is still permitted, however.
Signed-off-by: H. Peter Anvin <hpa@zytor.com>
diff --git a/daemon.c b/daemon.c
--- a/daemon.c
+++ b/daemon.c
@@ -80,17 +80,29 @@ static int path_ok(const char *dir)
 {
 	const char *p = dir;
 	char **pp;
-	int sl = 1, ndot = 0;
+	int sl, ndot;
+
+	/* The pathname here should be an absolute path. */
+	if ( *p++ != '/' )
+		return 0;
+
+	sl = 1;  ndot = 0;
 
 	for (;;) {
 		if ( *p == '.' ) {
 			ndot++;
-		} else if ( *p == '/' || *p == '\0' ) {
+		} else if ( *p == '\0' ) {
+			/* Reject "." and ".." at the end of the path */
 			if ( sl && ndot > 0 && ndot < 3 )
-				return 0; /* . or .. in path */
+				return 0;
+
+			/* Otherwise OK */
+			break;
+		} else if ( *p == '/' ) {
+			/* Refuse "", "." or ".." */
+			if ( sl && ndot < 3 )
+				return 0;
 			sl = 1;
-			if ( *p == '\0' )
-				break; /* End of string and all is good */
 		} else {
 			sl = ndot = 0;
 		}
Previous: H. Peter AnvinNext: Linus Torvalds
Message 5 of 12 in “git-daemon extra paranoia”
  1. git-daemon extra paranoiaH. Peter Anvin, Oct 18, 2005
  2. Junio C HamanoOct 18, 2005
  3. H. Peter AnvinOct 18, 2005
  4. H. Peter AnvinOct 18, 2005
  5. Revised - git-daemon extra paranoiaH. Peter Anvin, Oct 18, 2005
  6. Linus TorvaldsOct 18, 2005
  7. Junio C HamanoOct 18, 2005
  8. Linus TorvaldsOct 18, 2005
  9. H. Peter AnvinOct 19, 2005
  10. Linus TorvaldsOct 19, 2005
  11. H. Peter AnvinOct 19, 2005
  12. Junio C HamanoOct 19, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.