git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFH/PATCH] prefix_path(): disallow absolute paths

From
Junio C Hamano <gitster@pobox.com>
Date
Jan 30, 2008, 00:43 UTC
Message-ID
<7vhcgwkurj.fsf@gitster.siamese.dyndns.org>
In-Reply-To
<200801292158.m0TLwA7u019321@mi0.bluebottle.com>
しらいしななこ  <nanako3@bluebottle.com> writes:
Show 10 quoted lines
> Quoting Junio C Hamano <gitster@pobox.com>:
>...
>> And not passing such ambiguous path like "fo//o" to the core
>> level but sanitizing matters.  Then core level can always do
>> memcmp() with "fo/o" to see they are talking about the same
>> path.
>
> I may be mistaken but I think "fo//o" and "fo//o/" are
> returned as two different strings "fo/o" and "fo/o/" from your
> patch. Shouldn't you clean-up the second one to "fo/o", too?

That certainly is a potentially possible sanitization, and I actually thought about it when I did these patches.

However, I chose not to because I was not sure if some core functions want to differentiate pathspecs "foo/" and "foo". The former says "I want to make sure that 'foo' is a directory, and want to affect everything under it", the latter says "I do not care if 'foo' is a blob or a directory, but I want to affect it (if a blob) or everything under it (if a directory)".

In fact, stripping trailing slashes off would break this pair:
	git ls-files --error-unmatch Makefile/
	git ls-files --error-unmatch Makefile

Things like "git add Makefile/" relies on the former to fail loudly. So the answer is no, we do not want to clean it up.

Incidentally, I notice that in addition to the squashed patch from yesterday, we would need to teach "error-unmatch" code that it should trigger when get_pathspec() returns a pathspec that has fewer number of paths than its input.

It should be a pretty straightforward patch, but I haven't looked into fixing it. I'm lazy and I'd rather have other people to do the fixing for me. Hint, hint... ;-)

By the way, please keep your lines to reasonable length by wrapping in your e-mailed messages.

Previous: しらいしななこ
Message 47 of 47 in “git-clean buglet”
  1. Johannes SixtJan 23, 2008
  2. Johannes SixtJan 23, 2008
  3. Johannes SchindelinJan 23, 2008
  4. Johannes SixtJan 23, 2008
  5. Fix off by one error in prep_exclude.Shawn Bohrer, Jan 27, 2008
  6. Johannes SchindelinJan 27, 2008
  7. Shawn BohrerJan 27, 2008
  8. Junio C HamanoJan 27, 2008
  9. Shawn BohrerJan 28, 2008
  10. Fix off by one error in prep_exclude.Shawn Bohrer, Jan 28, 2008
  11. Johannes SchindelinJan 28, 2008
  12. Junio C HamanoJan 28, 2008
  13. Junio C HamanoJan 28, 2008
  14. Johannes SixtJan 28, 2008
  15. Junio C HamanoJan 28, 2008
  16. Johannes SixtJan 28, 2008
  17. Junio C HamanoJan 28, 2008
  18. prefix_path(): disallow absolute pathsJohannes Schindelin, Jan 28, 2008
  19. prefix_path(): disallow absolute pathsJohannes Schindelin, Jan 28, 2008
  20. Junio C HamanoJan 29, 2008
  21. Junio C HamanoJan 29, 2008
  22. Junio C HamanoJan 29, 2008
  23. Junio C HamanoJan 29, 2008
  24. setup: sanitize absolute and funny paths in get_pathspec()Junio C Hamano, Jan 29, 2008
  25. Make blame accept absolute pathsRobin Rosenberg, Feb 1, 2008
  26. More test cases for sanitized path namesRobin Rosenberg, Feb 1, 2008
  27. Junio C HamanoFeb 1, 2008
  28. Robin RosenbergFeb 1, 2008
  29. Junio C HamanoFeb 1, 2008
  30. Junio C HamanoFeb 1, 2008
  31. Junio C HamanoFeb 1, 2008
  32. Robin RosenbergFeb 1, 2008
  33. Junio C HamanoFeb 1, 2008
  34. Karl HasselströmFeb 1, 2008
  35. Sane use of test_expect_failureJunio C Hamano, Feb 1, 2008
  36. Junio C HamanoFeb 2, 2008
  37. Junio C HamanoMar 7, 2008
  38. Robin RosenbergMar 7, 2008
  39. Johannes SchindelinJan 29, 2008
  40. Junio C HamanoJan 29, 2008
  41. Johannes SchindelinJan 29, 2008
  42. Johannes SixtJan 29, 2008
  43. Junio C HamanoJan 29, 2008
  44. Johannes SixtJan 29, 2008
  45. Junio C HamanoJan 29, 2008
  46. しらいしななこJan 29, 2008
  47. Junio C HamanoJan 30, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.