git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH maint 0/3] do not write files outside of work-dir

From
Johannes Sixt <j.sixt@viscovery.net>
Date
Jun 1, 2011, 06:31 UTC
Message-ID
<4DE5DCDD.4020303@viscovery.net>
In-Reply-To
<20110601041439.GH29958@ece.pdx.edu>
Am 6/1/2011 6:14, schrieb Tait:
Show 6 quoted lines
>> Theo Niessink has uncovered a serious sercurity issue in Git for Windows,
>> where cloning an evil repository can arbitrarily overwrite files outside
>> the repository...
> 
> Filenames starting with C: are not necessarily absolute. Consider
> "c:foo.txt" where c: is the current directory on drive C, or

We have a different notion of "absolute path". This one *is* absolute per our definition. See below.

> "c:stream1" where c is a single-letter filename in the current directory
> with an alternate data stream such as would be shown by dir /r. The

On my system, this does not create a file in the current directory with an alternate data stream, but - while the working directory is somewhere on drive D - a file is created on drive C.

Show 11 quoted lines
> has_dos_drive_prefix check is overly broad. Maybe this is intentional and
> just needs to be documented. Absolute paths like \\localhost\C$\file.txt
> and \\?\C:\file.txt do seem to be caught, because they start with '\'.
> 
> Microsoft says[1] a path is relative unless:
>   - it begins with "\\"
>   - it begins with a disk designator followed by a directory separator
>   - it begins with a single "\"
> 
> On that basis, has_dos_drive_prefix(path) should be:
>   isalpha(*(path)) && (path)[1] == ':' && is_dir_sep((path)[2])

This is not the definition of "relative path" that we are interested in. Let $PWD be the current directory. For our purposes, a path $P is relative if $P and $PWD/$P designate the same file system entry. Otherwise, $P is an absolute path.

With this definition, the current has_dos_drive_prefix() is good enough.
> However, there are also paths within the NT namespace (as opposed to the
> Win32 namespace, [1] again) that might be considered absolute, or at least
> to which git should not try to write. Examples would be PRN, CONOUT$, AUX,

For our purposes, these names are all relative paths. It's a case of "Doctor, it hurts when I stick my finger in my eye" if you have a repository with these names.

Note that git never writes to these files: It always first allocates a temporary file, eg. nul.123456; but this will already fail because these special file names are forbidden even when a file extension is attached.

-- Hannes
Previous: Tait
Message 20 of 20 in “do not write files outside of work-dir”
  1. 0/3 do not write files outside of work-dirErik Faye-Lund, May 27, 2011
  2. 1/3 A Windows path starting with a backslash is absoluteErik Faye-Lund, May 27, 2011
  3. 2/3 real_path: do not assume '/' is the path seperatorErik Faye-Lund, May 27, 2011
  4. 3/3 verify_path: consider dos drive prefixErik Faye-Lund, May 27, 2011
  5. Johannes SixtMay 27, 2011
  6. Erik Faye-LundMay 30, 2011
  7. Theo NiessinkMay 30, 2011
  8. Erik Faye-LundMay 30, 2011
  9. Junio C HamanoJun 7, 2011
  10. Erik Faye-LundJun 7, 2011
  11. Erik Faye-LundJun 7, 2011
  12. Junio C HamanoJun 7, 2011
  13. Erik Faye-LundJun 7, 2011
  14. Theo NiessinkJun 7, 2011
  15. Johannes SixtMay 30, 2011
  16. Junio C HamanoMay 27, 2011
  17. Johannes SchindelinMay 27, 2011
  18. Junio C HamanoMay 27, 2011
  19. TaitJun 1, 2011
  20. Johannes SixtJun 1, 2011

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.