git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] git-daemon extra paranoia

From
Junio C Hamano <junkio@cox.net>
Date
Oct 18, 2005, 21:19 UTC
Message-ID
<7vll0qploy.fsf@assigned-by-dhcp.cox.net>
In-Reply-To
<435560F7.4080006@zytor.com>
"H. Peter Anvin" <hpa@zytor.com> writes:
Show 6 quoted lines
> This patch adds some extra paranoia to the git-daemon filename test.  In 
> particular, it now rejects pathnames containing // or ending with /; it 
> also adds a redundant test for pathname absoluteness (belts and suspenders.)
>
> Signed-off-by: H. Peter Anvin <hpa@zytor.com>
> Extra paranoia about non-canonical pathnames

I would understand rejecting /../, and perhaps /./, but why reject // in between or / at the end?

Especially, I think this part in daemon.c::upload():
	if (!path_ok(dir)) {
		logerror("Forbidden directory: %s\n", dir);
		return -1;
	}
	if (chdir(dir) < 0) {
		logerror("Cannot chdir('%s'): %s", dir, strerror(errno));
		return -1;
	}
	chdir(".git");

relies on the fact that you can say "/home/junio/git/" for me to publish "/home/junio/git/.git/" repository, so I would suspect that it is necessary to allow "ending with /" at least.

Previous: H. Peter AnvinNext: H. Peter Anvin
Message 2 of 12 in “git-daemon extra paranoia”
  1. git-daemon extra paranoiaH. Peter Anvin, Oct 18, 2005
  2. Junio C HamanoOct 18, 2005
  3. H. Peter AnvinOct 18, 2005
  4. H. Peter AnvinOct 18, 2005
  5. Revised - git-daemon extra paranoiaH. Peter Anvin, Oct 18, 2005
  6. Linus TorvaldsOct 18, 2005
  7. Junio C HamanoOct 18, 2005
  8. Linus TorvaldsOct 18, 2005
  9. H. Peter AnvinOct 19, 2005
  10. Linus TorvaldsOct 19, 2005
  11. H. Peter AnvinOct 19, 2005
  12. Junio C HamanoOct 19, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.