Commit ae7ffea9 by nulltoken Committed by Vicent Marti

Fixed a parsing issue in git_prettify_dir_path().

parent b29e8f19
...@@ -394,8 +394,9 @@ static int retrieve_previous_path_component_start(const char *path) ...@@ -394,8 +394,9 @@ static int retrieve_previous_path_component_start(const char *path)
int git_prettify_dir_path(char *buffer_out, const char *path) int git_prettify_dir_path(char *buffer_out, const char *path)
{ {
int len = 0; int len = 0;
char *current; char *current, *end;
const char *buffer_out_start, *buffer_end; const char *buffer_out_start, *buffer_end;
int only_dots;
buffer_out_start = buffer_out; buffer_out_start = buffer_out;
current = (char *)path; current = (char *)path;
...@@ -408,39 +409,51 @@ int git_prettify_dir_path(char *buffer_out, const char *path) ...@@ -408,39 +409,51 @@ int git_prettify_dir_path(char *buffer_out, const char *path)
continue; continue;
} }
/* Skip current directory */ end = current;
if (*current == '.') { only_dots = 1;
current++;
/* Handle the double-dot upward directory navigation */ /* Seek end of path segment */
if (current < buffer_end && *current == '.') { while (end < buffer_end && *end !='/')
current++; {
only_dots &= (*end == '.');
end++;
}
/* Guard against potential multiple dot path traversal (cf http://cwe.mitre.org/data/definitions/33.html) */ /* Skip current directory */
if (*current == '.') if (only_dots && end == current + 1)
return GIT_ERROR; {
current += 2;
continue;
}
/* Handle the double-dot upward directory navigation */
if (only_dots && end == current + 2)
{
*buffer_out ='\0'; *buffer_out ='\0';
len = retrieve_previous_path_component_start(buffer_out_start); len = retrieve_previous_path_component_start(buffer_out_start);
if (len < GIT_SUCCESS) if (len < GIT_SUCCESS)
return GIT_ERROR; return GIT_ERROR;
buffer_out = (char *)buffer_out_start + len; buffer_out = (char *)buffer_out_start + len;
}
if (current < buffer_end && *current == '/')
current++;
current += 3;
continue; continue;
} }
/* Guard against potential multiple dot path traversal (cf http://cwe.mitre.org/data/definitions/33.html) */
if (only_dots && end > current)
return GIT_ERROR;
/* Copy to output the path segment */
while (current < end)
{
*buffer_out++ = *current++; *buffer_out++ = *current++;
len++; len++;
} }
/* Add a trailing slash if required */
if (len > 0 && buffer_out_start[len-1] != '/')
*buffer_out++ = '/'; *buffer_out++ = '/';
len++;
}
*buffer_out = '\0'; *buffer_out = '\0';
......
...@@ -20,6 +20,10 @@ static int ensure_normalized(const char *input_path, const char *expected_path) ...@@ -20,6 +20,10 @@ static int ensure_normalized(const char *input_path, const char *expected_path)
} }
BEGIN_TEST(path_prettifying) BEGIN_TEST(path_prettifying)
must_pass(ensure_normalized("./testrepo.git", "testrepo.git/"));
must_pass(ensure_normalized("./.git", ".git/"));
must_pass(ensure_normalized("./git.", "git./"));
must_pass(ensure_normalized("git./", "git./"));
must_pass(ensure_normalized("", "")); must_pass(ensure_normalized("", ""));
must_pass(ensure_normalized(".", "")); must_pass(ensure_normalized(".", ""));
must_pass(ensure_normalized("./", "")); must_pass(ensure_normalized("./", ""));
...@@ -54,6 +58,10 @@ BEGIN_TEST(path_prettifying) ...@@ -54,6 +58,10 @@ BEGIN_TEST(path_prettifying)
must_fail(ensure_normalized("d1/.../", NULL)); must_fail(ensure_normalized("d1/.../", NULL));
must_fail(ensure_normalized("d1/.../d2", NULL)); must_fail(ensure_normalized("d1/.../d2", NULL));
must_pass(ensure_normalized("/./testrepo.git", "/testrepo.git/"));
must_pass(ensure_normalized("/./.git", "/.git/"));
must_pass(ensure_normalized("/./git.", "/git./"));
must_pass(ensure_normalized("/git./", "/git./"));
must_pass(ensure_normalized("/", "/")); must_pass(ensure_normalized("/", "/"));
must_pass(ensure_normalized("//", "/")); must_pass(ensure_normalized("//", "/"));
must_pass(ensure_normalized("///", "/")); must_pass(ensure_normalized("///", "/"));
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment