git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [stgit PATCH] commands.{new,rename}: verify patch names

From
SKShinya Kuribayashi <skuribay@pobox.com>
Date
Nov 3, 2010, 02:43 UTC
Message-ID
<4CD0CC51.5030402@pobox.com>
In-Reply-To
<20101005125631.17466.95192.stgit@woodpecker.blarg.de>
Hi,
On 10/5/10 9:56 PM, Max Kellermann wrote:
Show 8 quoted lines
> Don't allow patches with invalid names.  For example, a patch with a
> slash in the name will cause the underlying git command to fail, and
> stgit doesn't handle this error condition properly.
> ---
>   stgit/commands/new.py    |    3 +++
>   stgit/commands/rename.py |    3 +++
>   stgit/utils.py           |    6 ++++++
>   3 files changed, 12 insertions(+), 0 deletions(-)

It would be nice to mention about what's updated when revising patches, even though it's even +1 line. And we'd also like to have a sign within Subject:, e.g., [stgit PATCH v2] will suffice.

Show 17 quoted lines
> diff --git a/stgit/utils.py b/stgit/utils.py
> index 2955adf..a41457b 100644
> --- a/stgit/utils.py
> +++ b/stgit/utils.py
> @@ -241,6 +241,12 @@ def make_patch_name(msg, unacceptable, default_name = 'patch'):
>           patchname = default_name
>       return find_patch_name(patchname, unacceptable)
>
> +def check_patch_name(name):
> +    """Checks if the specified name is a valid patch name. For
> +    technical reasons, we cannot allow a slash and other characters."""
> +    return len(name)>  0 and name[0] not in '.-' and '/' not in name and \
> +           '..' not in name and re.search(r'[\x00-\x20]', name) is None
> +
>   # any and all functions are builtin in Python 2.5 and higher, but not
>   # in 2.4.
>   if not 'any' in dir(__builtins__):
".." is now taken care, too.  That's nice.

By the way, you're not the first person encountered this issue, and we already have corresponding bug# at gna.org, you might be interested in:

* https://gna.org/bugs/?10919
   sanity check patch names
* https://gna.org/bugs/?15654
   stg new when path contains slash stops stg from doing everything

I don't speak Python, so couldn't help the patch itself. Catalin and Karl hopefully will guide you (they seem to busy these days, or just failed to find this thread).

Previous: Max Kellermann
Message 2 of 2 in “commands.{new,rename}: verify patch names”
  1. commands.{new,rename}: verify patch namesMax Kellermann, Oct 5, 2010
  2. Shinya KuribayashiNov 3, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.