git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFH/PATCH] prefix_path(): disallow absolute paths

From
Johannes Sixt <j.sixt@viscovery.net>
Date
Jan 29, 2008, 07:20 UTC
Message-ID
<479ED3AE.5000403@viscovery.net>
In-Reply-To
<7vwspts9vj.fsf@gitster.siamese.dyndns.org>
Junio C Hamano schrieb:
Show 10 quoted lines
> +static int sanitary_path_copy(char *dst, const char *src)
>  {
> -	const char *orig = path;
> +	char *dst0 = dst;
> +
> +	if (*src == '/') {
> +		*dst++ = '/';
> +		while (*src == '/')
> +			src++;
> +	}

Advance notice: In this function, tests of the kind *src == '/' need to be turned into is_dir_sep(*src) when we port to Windows.

Show 9 quoted lines
> +		/* copy up to the next '/', and eat all '/' */
> +		while ((c = *src++) != '\0' && c != '/')
> +			*dst++ = c;
>  		if (c == '/') {
> -			path += 2;
> -			continue;
> -		}
> -		if (c != '.')
> +			*dst++ = c;
			*dst++ = '/';
will be needed on Windows to sanitize all is_dir_sep(c) to '/'.
Show 5 quoted lines
> +			while (c == '/')
> +				c = *src++;
> +			src--;
> +		} else if (!c)
>  			break;
...
Show 5 quoted lines
> +const char *prefix_path(const char *prefix, int len, const char *path)
> +{
> +	const char *orig = path;
> +	char *sanitized = xmalloc(len + strlen(path) + 1);
> +	if (*orig == '/')
	if (is_absolute_path(*orig))
Show 10 quoted lines
> +		strcpy(sanitized, path);
> +	else {
> +		if (len)
> +			memcpy(sanitized, prefix, len);
> +		strcpy(sanitized + len, path);		
>  	}
> -	return path;
> +	if (sanitary_path_copy(sanitized, sanitized))
> +		goto error_out;
> +	if (*orig == '/') {
Ditto.
Show 12 quoted lines
> +		const char *work_tree = get_git_work_tree();
> +		size_t len = strlen(work_tree);
> +		if (strncmp(sanitized, work_tree, len) ||
> +		    (sanitized[len] != '\0' && sanitized[len] != '/')) {
> +		error_out:
> +			error("'%s' is outside repository", orig);
> +			free(sanitized);
> +			return NULL;
> +		}
> +	}
> +	return sanitized;
>  }

I appreciate this new sanitary_copy_path() because I expect that we will need at least one less #ifdef __MINGW32__/#endif compared to our current Windows port.

-- Hannes
Previous: Johannes SchindelinNext: Junio C Hamano
Message 42 of 47 in “git-clean buglet”
  1. Johannes SixtJan 23, 2008
  2. Johannes SixtJan 23, 2008
  3. Johannes SchindelinJan 23, 2008
  4. Johannes SixtJan 23, 2008
  5. Fix off by one error in prep_exclude.Shawn Bohrer, Jan 27, 2008
  6. Johannes SchindelinJan 27, 2008
  7. Shawn BohrerJan 27, 2008
  8. Junio C HamanoJan 27, 2008
  9. Shawn BohrerJan 28, 2008
  10. Fix off by one error in prep_exclude.Shawn Bohrer, Jan 28, 2008
  11. Johannes SchindelinJan 28, 2008
  12. Junio C HamanoJan 28, 2008
  13. Junio C HamanoJan 28, 2008
  14. Johannes SixtJan 28, 2008
  15. Junio C HamanoJan 28, 2008
  16. Johannes SixtJan 28, 2008
  17. Junio C HamanoJan 28, 2008
  18. prefix_path(): disallow absolute pathsJohannes Schindelin, Jan 28, 2008
  19. prefix_path(): disallow absolute pathsJohannes Schindelin, Jan 28, 2008
  20. Junio C HamanoJan 29, 2008
  21. Junio C HamanoJan 29, 2008
  22. Junio C HamanoJan 29, 2008
  23. Junio C HamanoJan 29, 2008
  24. setup: sanitize absolute and funny paths in get_pathspec()Junio C Hamano, Jan 29, 2008
  25. Make blame accept absolute pathsRobin Rosenberg, Feb 1, 2008
  26. More test cases for sanitized path namesRobin Rosenberg, Feb 1, 2008
  27. Junio C HamanoFeb 1, 2008
  28. Robin RosenbergFeb 1, 2008
  29. Junio C HamanoFeb 1, 2008
  30. Junio C HamanoFeb 1, 2008
  31. Junio C HamanoFeb 1, 2008
  32. Robin RosenbergFeb 1, 2008
  33. Junio C HamanoFeb 1, 2008
  34. Karl HasselströmFeb 1, 2008
  35. Sane use of test_expect_failureJunio C Hamano, Feb 1, 2008
  36. Junio C HamanoFeb 2, 2008
  37. Junio C HamanoMar 7, 2008
  38. Robin RosenbergMar 7, 2008
  39. Johannes SchindelinJan 29, 2008
  40. Junio C HamanoJan 29, 2008
  41. Johannes SchindelinJan 29, 2008
  42. Johannes SixtJan 29, 2008
  43. Junio C HamanoJan 29, 2008
  44. Johannes SixtJan 29, 2008
  45. Junio C HamanoJan 29, 2008
  46. しらいしななこJan 29, 2008
  47. Junio C HamanoJan 30, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.