git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] gitweb: Harden UTF-8 handling in generated links

From
Jakub Narębski <jnareb@gmail.com>
Date
Jun 4, 2014, 18:47 UTC
Message-ID
<538F69DA.9010201@gmail.com>
In-Reply-To
<20140604154128.GA28549@localhost.localdomain>
Michael Wagner wrote:
> On Tue, May 27, 2014 at 04:22:42PM +0200, Jakub Narębski wrote:
Show 9 quoted lines
>> Subject: [PATCH] gitweb: Harden UTF-8 handling in generated links
>>
>> esc_html() ensures that its input is properly UTF-8 encoded and marked
>> as UTF-8 with to_utf8().  Make esc_param() (used for query parameters
>> in generated URLs), esc_path_info() (for escaping path_info
>> components) and esc_url() use it too.
>>
>> This hardens gitweb against errors in UTF-8 handling; because
>> to_utf8() is idempotent it won't change correct output.
[...]
Show 10 quoted lines
>>   sub esc_param {
>>   	my $str = shift;
>>   	return undef unless defined $str;
>> +
>> +	$str = to_utf8($str);
>>   	$str =~ s/([^A-Za-z0-9\-_.~()\/:@ ]+)/CGI::escape($1)/eg;
>>   	$str =~ s/ /\+/g;
>> +
>>   	return $str;
>>   }   
Show 6 quoted lines
> While trying to view a "blob_plain" of "Gütekritierien.txt", a 404 error
> occured. "git_get_hash_by_path" tries to resolve the hash with the wrong
> filename (git ls-tree -z HEAD -- Gütekriterien.txt) and fails.
> 
> The filename needs the correct encoding. Something like this is probably
> needed for all filenames and should be done at a prior stage:
True.

First, I wonder why the tests I did for this situation didn't show any errors even before the "harden href()" patch. What is different in your config that you see those errors?

Show 14 quoted lines
> ---
>   gitweb/gitweb.perl |    2 +-
>   1 files changed, 1 insertions(+), 1 deletions(-)
> 
> diff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl
> index 77e1312..e4a50e7 100755
> --- a/gitweb/gitweb.perl
> +++ b/gitweb/gitweb.perl
> @@ -4725,7 +4725,7 @@ sub git_print_tree_entry {
>                  }
>                  print " | " .
>                          $cgi->a({-href => href(action=>"blob_plain", hash_base=>$hash_base,
> -                                              file_name=>"$basedir$t->{'name'}")},
> +                                              file_name=>"$basedir" . to_utf8($t->{'name'}))},

Second, my "harder href()" patch does not work for this because concatenation of non-UFT8 with UTF8 string screws up Perl knowledge what is and isn't UTF8. So to_utf8() after concat doesn't help.

>                                  "raw");
>                  print "</td>\n";
> 
Previous: Michael WagnerNext: Michael Wagner
Message 19 of 21 in “Gitweb: Convert UTF-8 encoded file names”
  1. Gitweb: Convert UTF-8 encoded file namesMichael Wagner, May 14, 2014
  2. Junio C HamanoMay 14, 2014
  3. Jakub NarębskiMay 14, 2014
  4. Michael WagnerMay 15, 2014
  5. Peter KreftingMay 15, 2014
  6. Junio C HamanoMay 15, 2014
  7. Michael WagnerMay 15, 2014
  8. Jakub NarębskiMay 15, 2014
  9. Jakub NarębskiMay 15, 2014
  10. Junio C HamanoMay 15, 2014
  11. Jakub NarębskiMay 15, 2014
  12. Junio C HamanoMay 16, 2014
  13. Jakub NarębskiMay 16, 2014
  14. Junio C HamanoMay 16, 2014
  15. Jakub NarębskiMay 27, 2014
  16. Junio C HamanoMay 16, 2014
  17. gitweb: Harden UTF-8 handling in generated linksJakub Narębski, May 27, 2014
  18. Michael WagnerJun 4, 2014
  19. Jakub NarębskiJun 4, 2014
  20. Michael WagnerJun 4, 2014
  21. Jakub NarębskiMay 15, 2014

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.