git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Files with colons under Cygwin

From
Johannes Sixt <j.sixt@viscovery.net>
Date
Oct 7, 2008, 06:13 UTC
Message-ID
<48EAFE00.3040907@viscovery.net>
In-Reply-To
<20081007005327.GT21650@dpotapov.dyndns.org>
Dmitry Potapov schrieb:
Show 12 quoted lines
> On Mon, Oct 06, 2008 at 08:54:44AM +0200, Johannes Sixt wrote:
>> [*] I say "meaningful" and not "necessary" because the situation is just
>> like when you grab some random SoftwarePackage.tar.gz, and run ./configure
>> without looking first what it is going to do.
> 
> When I grab any tar, I can look at its context without myself of any
> risk that some files can be overwritten on my file system. And when
> I want to look at some remote git repository, I usually do:
> 
>    git clone URL
> 
> If it can overwrite some files behind my back, it is security a hole.
Fair enough.
> On Linux (or other sane file systems), we have all required checks to
> prevent that from happening, and they are places in verify_path, which
> prevents malicious names entering into the index and thus to the file
> system too. So, we should do all required checks on Windows too.

I don't object the intention of your patch. But I cannot judge whether verify_path() is the correct location to put the checks because I don't know this part of the code. I leave the final word to others.

-- Hannes
Previous: Dmitry PotapovNext: Joshua Juran
Message 9 of 19 in “Files with colons under Cygwin”
  1. Giovanni FunchalOct 2, 2008
  2. Dmitry PotapovOct 4, 2008
  3. Alex RiesenOct 5, 2008
  4. Alex RiesenOct 5, 2008
  5. Dmitry PotapovOct 5, 2008
  6. Giovanni FunchalOct 5, 2008
  7. Johannes SixtOct 6, 2008
  8. Dmitry PotapovOct 7, 2008
  9. Johannes SixtOct 7, 2008
  10. Joshua JuranOct 7, 2008
  11. correct verify_path for WindowsDmitry Potapov, Oct 7, 2008
  12. Johannes SixtOct 7, 2008
  13. Dmitry PotapovOct 11, 2008
  14. Alex RiesenOct 11, 2008
  15. Dmitry PotapovOct 12, 2008
  16. Alex RiesenOct 12, 2008
  17. Johannes SixtOct 13, 2008
  18. Alex RiesenOct 13, 2008
  19. Alex RiesenOct 7, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.