Re: [PATCH] git-daemon extra paranoia
- From
Junio C Hamano <junkio@cox.net>
- Date
- Oct 18, 2005, 21:19 UTC
- Message-ID
- <7vll0qploy.fsf@assigned-by-dhcp.cox.net>
- In-Reply-To
- <435560F7.4080006@zytor.com>
"H. Peter Anvin" <hpa@zytor.com> writes:
Show 6 quoted lines
> This patch adds some extra paranoia to the git-daemon filename test. In > particular, it now rejects pathnames containing // or ending with /; it > also adds a redundant test for pathname absoluteness (belts and suspenders.) > > Signed-off-by: H. Peter Anvin <hpa@zytor.com> > Extra paranoia about non-canonical pathnames
I would understand rejecting /../, and perhaps /./, but why reject // in between or / at the end?
Especially, I think this part in daemon.c::upload():
if (!path_ok(dir)) {
logerror("Forbidden directory: %s\n", dir);
return -1;
} if (chdir(dir) < 0) {
logerror("Cannot chdir('%s'): %s", dir, strerror(errno));
return -1;
} chdir(".git");relies on the fact that you can say "/home/junio/git/" for me to publish "/home/junio/git/.git/" repository, so I would suspect that it is necessary to allow "ending with /" at least.