git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] Set up argv0_path correctly, even when argv[0] is just the basename

From
RHRene Herman <rene.herman@keyaccess.nl>
Date
Jul 26, 2008, 15:19 UTC
Message-ID
<488B409D.40709@keyaccess.nl>
In-Reply-To
<alpine.DEB.1.00.0807261709090.26810@eeepc-johanness>
On 26-07-08 17:10, Johannes Schindelin wrote:
Show 20 quoted lines
> Hi,
> 
> On Sat, 26 Jul 2008, Rene Herman wrote:
> 
>> On 26-07-08 16:14, Johannes Schindelin wrote:
>>
>>> When the program 'git' is in the PATH, the argv[0] is set to the
>>> basename. However, argv0_path needs the full path, so add a function
>>> to discover the program by traversing the PATH manually.
>> While not having read the context for this, this ofcourse sounds like a huge
>> gaping race-condition. If applicable here (as said, did not read context) you
>> generally want to make sure that there's no window that a path could be
>> replaced -- while perhaps not here, that's often the kind of thing that
>> security attacks end up abusing.
> 
> Yeah, and that's why you would carefully time your attack just in between 
> the command invocation and the discovery of argv[0] in the PATH.
> 
> Rather than replacing the 'git' program with an infected version right 
> away.

Adding to the PATH is generally not disallowed by user level security. Replacing the GIT binary generally is.

Sure maybe it's not much of a problem here; as said, I didn't read the context and am not a GIT person. Just commented on a git-user list when this was the next message on the list. Though a heads-up might still be in order. If it wasn't useful -- so be it, but even making a command do something different than a user expected can have serious implications, for example in this case for the tree they are working on.

Rene.
Previous: Johannes SchindelinNext: Johannes Schindelin
Message 7 of 21 in “Modify mingw_main() workaround to avoid link errors”
  1. Modify mingw_main() workaround to avoid link errorsSteffen Prohaska, Jul 26, 2008
  2. Johannes SchindelinJul 26, 2008
  3. Steffen ProhaskaJul 26, 2008
  4. Set up argv0_path correctly, even when argv[0] is just the basenameJohannes Schindelin, Jul 26, 2008
  5. Rene HermanJul 26, 2008
  6. Johannes SchindelinJul 26, 2008
  7. Rene HermanJul 26, 2008
  8. Johannes SchindelinJul 26, 2008
  9. Rene HermanJul 26, 2008
  10. Junio C HamanoJul 26, 2008
  11. Johannes SchindelinJul 26, 2008
  12. Jan HudecAug 3, 2008
  13. Junio C HamanoAug 3, 2008
  14. Johannes SixtJul 26, 2008
  15. Steffen ProhaskaJul 26, 2008
  16. Johannes SixtJul 27, 2008
  17. Steffen ProhaskaJul 29, 2008
  18. Johannes SixtJul 29, 2008
  19. Steffen ProhaskaJul 29, 2008
  20. Johannes SixtAug 3, 2008
  21. Junio C HamanoAug 3, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.