git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] gitweb: fix support for repository directories with spaces

From
Jakub Narebski <jnareb@gmail.com>
Date
Jun 17, 2008, 01:38 UTC
Message-ID
<m3k5goon7v.fsf@localhost.localdomain>
In-Reply-To
<1213664977-23964-1-git-send-email-LeWiemann@gmail.com>
Lea Wiemann <lewiemann@gmail.com> writes:
Show 9 quoted lines
> git_cmd_str does not quote the directory names without this patch.
> 
> Signed-off-by: Lea Wiemann <LeWiemann@gmail.com>
> ---
> git_cmd_str is really really bad from a security POV: Where it is
> used, command lines are passed to the shell, which (I believe) just
> *happen* to open no security holes.  Hence the function should
> ultimately go away.  However, let's make the tests work for the
> meantime while it's still there.

I'd like to do away with need for git_cmd_str(), but unfortunately it is needed in a place where git has to form pipeline, namely in creating externally compressed snapshot (in git_snapshot), and to redirect stderr to /dev/null in git_object.

Perhaps we could simply do without second, but this pipeline is here
to stay (there was pipeline in git-search, but was replaced by
invoking git-log instead of rev-list | diff-tree pipeline).  And it is
not easy to create pipeline using some variant of list form of open;
if you search git mailing list archive you can find aborted (RFC only)
attempt to create pipeline safely
  http://thread.gmane.org/gmane.comp.version-control.git/76566

If you are extending Git.pm (please do not foget Cc Petr Baudis, as it is mainly his code) for gitweb, you can try to add this. It doesn't have to be very generic...

-- 
Jakub Narebski
Poland
ShadeHawk on #git
Previous: Junio C HamanoNext: Lea Wiemann
Message 7 of 9 in “gitweb: fix support for repository directories with spaces”
  1. gitweb: fix support for repository directories with spacesLea Wiemann, Jun 17, 2008
  2. Junio C HamanoJun 17, 2008
  3. Junio C HamanoJun 17, 2008
  4. gitweb: quote commands properly when calling the shellLea Wiemann, Jun 17, 2008
  5. Lea WiemannJun 17, 2008
  6. Junio C HamanoJun 17, 2008
  7. Jakub NarebskiJun 17, 2008
  8. Lea WiemannJun 17, 2008
  9. Jakub NarebskiJun 17, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.