From: Junio C Hamano Date: Tue, 18 Oct 2005 21:19:41 GMT Subject: Re: [PATCH] git-daemon extra paranoia Message-ID: <7vll0qploy.fsf@assigned-by-dhcp.cox.net> In-Reply-To: <435560F7.4080006@zytor.com> "H. Peter Anvin" writes: > This patch adds some extra paranoia to the git-daemon filename test. In > particular, it now rejects pathnames containing // or ending with /; it > also adds a redundant test for pathname absoluteness (belts and suspenders.) > > Signed-off-by: H. Peter Anvin > Extra paranoia about non-canonical pathnames I would understand rejecting /../, and perhaps /./, but why reject // in between or / at the end? Especially, I think this part in daemon.c::upload(): if (!path_ok(dir)) { logerror("Forbidden directory: %s\n", dir); return -1; } if (chdir(dir) < 0) { logerror("Cannot chdir('%s'): %s", dir, strerror(errno)); return -1; } chdir(".git"); relies on the fact that you can say "/home/junio/git/" for me to publish "/home/junio/git/.git/" repository, so I would suspect that it is necessary to allow "ending with /" at least.