git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH] prefix_path(): disallow absolute paths

From
Johannes Schindelin <johannes.schindelin@gmx.de>
Date
Jan 28, 2008, 15:05 UTC
Message-ID
<alpine.LSU.1.00.0801281503350.23907@racer.site>
In-Reply-To
<alpine.LSU.1.00.0801281210440.23907@racer.site>

Without this fix, "git ls-files --others /" would list _all_ files, except for those tracked in the current repository. Worse, "git clean /" would start removing them.

Noticed by Johannes Sixt.

Incidentally, it fixes some strange code in builtin-mv.c by yours truly, where a slash was added to "dst" but then ignored, and instead taken from the source path. This triggered the new check for absolute paths.

A test in t3101 started failing, too, because it tested ls-tree with not-really-absolute paths (expecting the leading "/" to be ignored). Those paths were changed to relative paths.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
---
	On Mon, 28 Jan 2008, Johannes Schindelin wrote:
	> The failure of t3101 has something to do with ls-tree filtering 
	> out invalid paths; I maintain that this behaviour is wrong to 
	> begin with.
	This patch fixes the test.
	But as this fix illustrates, it is a change in semantics: where 
	earlier
		git ls-tree /README
	was allowed, it is no longer.
	Comments?
 builtin-mv.c               |    4 ++--
 setup.c                    |    2 ++
 t/t3101-ls-tree-dirname.sh |    2 +-
 3 files changed, 5 insertions(+), 3 deletions(-)
diff --git a/builtin-mv.c b/builtin-mv.c
index 990e213..94f6dd2 100644
--- a/builtin-mv.c
+++ b/builtin-mv.c
@@ -164,7 +164,7 @@ int cmd_mv(int argc, const char **argv, const char *prefix)
 				}
 
 				dst = add_slash(dst);
-				dst_len = strlen(dst) - 1;
+				dst_len = strlen(dst);
 
 				for (j = 0; j < last - first; j++) {
 					const char *path =
@@ -172,7 +172,7 @@ int cmd_mv(int argc, const char **argv, const char *prefix)
 					source[argc + j] = path;
 					destination[argc + j] =
 						prefix_path(dst, dst_len,
-							path + length);
+							path + length + 1);
 					modes[argc + j] = INDEX;
 				}
 				argc += last - first;
diff --git a/setup.c b/setup.c
index 2174e78..5a4aadc 100644
--- a/setup.c
+++ b/setup.c
@@ -13,6 +13,8 @@ const char *get_current_prefix()
 const char *prefix_path(const char *prefix, int len, const char *path)
 {
 	const char *orig = path;
+	if (is_absolute_path(path))
+		die("no absolute paths allowed: '%s'", path);
 	for (;;) {
 		char c;
 		if (*path != '.')
diff --git a/t/t3101-ls-tree-dirname.sh b/t/t3101-ls-tree-dirname.sh
index 39fe267..cc5b982 100755
--- a/t/t3101-ls-tree-dirname.sh
+++ b/t/t3101-ls-tree-dirname.sh
@@ -120,7 +120,7 @@ EOF
 # having 1.txt and path3
 test_expect_success \
     'ls-tree filter odd names' \
-    'git ls-tree $tree 1.txt /1.txt //1.txt path3/1.txt /path3/1.txt //path3//1.txt path3 /path3/ path3// >current &&
+    'git ls-tree $tree 1.txt ./1.txt .//1.txt path3/1.txt ./path3/1.txt .//path3//1.txt path3 ./path3/ path3// >current &&
      cat >expected <<\EOF &&
 100644 blob X	1.txt
 100644 blob X	path3/1.txt
-- 
1.5.4.rc5.15.g8231f
Previous: Johannes SchindelinNext: Junio C Hamano
Message 19 of 47 in “git-clean buglet”
  1. Johannes SixtJan 23, 2008
  2. Johannes SixtJan 23, 2008
  3. Johannes SchindelinJan 23, 2008
  4. Johannes SixtJan 23, 2008
  5. Fix off by one error in prep_exclude.Shawn Bohrer, Jan 27, 2008
  6. Johannes SchindelinJan 27, 2008
  7. Shawn BohrerJan 27, 2008
  8. Junio C HamanoJan 27, 2008
  9. Shawn BohrerJan 28, 2008
  10. Fix off by one error in prep_exclude.Shawn Bohrer, Jan 28, 2008
  11. Johannes SchindelinJan 28, 2008
  12. Junio C HamanoJan 28, 2008
  13. Junio C HamanoJan 28, 2008
  14. Johannes SixtJan 28, 2008
  15. Junio C HamanoJan 28, 2008
  16. Johannes SixtJan 28, 2008
  17. Junio C HamanoJan 28, 2008
  18. prefix_path(): disallow absolute pathsJohannes Schindelin, Jan 28, 2008
  19. prefix_path(): disallow absolute pathsJohannes Schindelin, Jan 28, 2008
  20. Junio C HamanoJan 29, 2008
  21. Junio C HamanoJan 29, 2008
  22. Junio C HamanoJan 29, 2008
  23. Junio C HamanoJan 29, 2008
  24. setup: sanitize absolute and funny paths in get_pathspec()Junio C Hamano, Jan 29, 2008
  25. Make blame accept absolute pathsRobin Rosenberg, Feb 1, 2008
  26. More test cases for sanitized path namesRobin Rosenberg, Feb 1, 2008
  27. Junio C HamanoFeb 1, 2008
  28. Robin RosenbergFeb 1, 2008
  29. Junio C HamanoFeb 1, 2008
  30. Junio C HamanoFeb 1, 2008
  31. Junio C HamanoFeb 1, 2008
  32. Robin RosenbergFeb 1, 2008
  33. Junio C HamanoFeb 1, 2008
  34. Karl HasselströmFeb 1, 2008
  35. Sane use of test_expect_failureJunio C Hamano, Feb 1, 2008
  36. Junio C HamanoFeb 2, 2008
  37. Junio C HamanoMar 7, 2008
  38. Robin RosenbergMar 7, 2008
  39. Johannes SchindelinJan 29, 2008
  40. Junio C HamanoJan 29, 2008
  41. Johannes SchindelinJan 29, 2008
  42. Johannes SixtJan 29, 2008
  43. Junio C HamanoJan 29, 2008
  44. Johannes SixtJan 29, 2008
  45. Junio C HamanoJan 29, 2008
  46. しらいしななこJan 29, 2008
  47. Junio C HamanoJan 30, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.