git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 1/5] Library code for user-relative paths, take three.

From
HAH. Peter Anvin <hpa@zytor.com>
Date
Nov 18, 2005, 20:33 UTC
Message-ID
<437E3A9B.1070801@zytor.com>
In-Reply-To
<437DA828.6020207@op5.se>
Andreas Ericsson wrote:
Show 17 quoted lines
> Junio C Hamano wrote:
> 
>>
>>> +    /* This is perfectly safe, and people tend to think of the 
>>> directory
>>> +     * where they ran git-init-db as their repository, so humour 
>>> them. */
>>> +    (void)chdir(".git");
>>
>>
>> It might be safe, but I think it changes the behaviour of
>> upload-pack with strict case.  My gut reaction is we would want
>> "if (!strict)" in front.  Thoughts?
> 
> As it says in the comment; People tend to think of the directory where 
> they ran "git init-db" as their repository, so humour them. It's nice 
> for sharing files between devs in the office, and it *is* safe.
No, it's not.

The whole point with --strict is that it shouldn't DWIM. DWIMming is *NOT* safe if the data has previously passed through a security screen.

Don't DWIM in strict mode, ever.  If you do, you create security holes. 
  If not immediately, then later.
	-hpa
Previous: Andreas EricssonNext: Andreas Ericsson
Message 5 of 7 in “Library code for user-relative paths, take three.”
  1. 1/5 Library code for user-relative paths, take three.Andreas Ericsson, Nov 17, 2005
  2. Junio C HamanoNov 17, 2005
  3. Andreas EricssonNov 18, 2005
  4. Andreas EricssonNov 18, 2005
  5. H. Peter AnvinNov 18, 2005
  6. Andreas EricssonNov 18, 2005
  7. Andreas EricssonNov 18, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.