Skip to content

Commit e8c30a5

Browse files
newrengitster
authored andcommitted
object-name: be more strict in parsing describe-like output
From Documentation/revisions.txt: '<describeOutput>', e.g. 'v1.7.4.2-679-g3bee7fb':: Output from `git describe`; i.e. a closest tag, optionally followed by a dash and a number of commits, followed by a dash, a 'g', and an abbreviated object name. which means that output of the format ${REFNAME}-${INTEGER}-g${HASH} should parse to fully expand ${HASH}. This is fine. However, we currently don't validate any of ${REFNAME}-${INTEGER}, we only parse -g${HASH} and assume the rest is valid. That is problematic, since it breaks things like git cat-file -p branchname:path/to/file/named/i-gaffed which, when commit affed exists, will not return us information about a file we are looking for but will instead tell us about commit affed. Similarly, we should probably not treat refs/tags/invalid/./../...../// ~^:/?*\\&[}/busted.lock-g049e0ef6 as a request for commit 050e0ef either. Tighten up the parsing to make sure ${REFNAME} and ${INTEGER} are present and valid. Reported-by: Gabriel Amaral <[email protected]> Signed-off-by: Elijah Newren <[email protected]> Signed-off-by: Junio C Hamano <[email protected]>
1 parent 65cd7ad commit e8c30a5

File tree

2 files changed

+76
-1
lines changed

2 files changed

+76
-1
lines changed

object-name.c

Lines changed: 54 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1272,6 +1272,58 @@ static int peel_onion(struct repository *r, const char *name, int len,
12721272
return 0;
12731273
}
12741274

1275+
/*
1276+
* Documentation/revisions.txt says:
1277+
* '<describeOutput>', e.g. 'v1.7.4.2-679-g3bee7fb'::
1278+
* Output from `git describe`; i.e. a closest tag, optionally
1279+
* followed by a dash and a number of commits, followed by a dash, a
1280+
* 'g', and an abbreviated object name.
1281+
*
1282+
* which means that the stuff before '-g${HASH}' needs to be a valid
1283+
* refname, a dash, and a non-negative integer. This function verifies
1284+
* that.
1285+
*
1286+
* In particular, we do not want to treat
1287+
* branchname:path/to/file/named/i-gaffed
1288+
* as a request for commit affed.
1289+
*
1290+
* More generally, we should probably not treat
1291+
* 'refs/heads/./../.../ ~^:/?*[////\\\&}/busted.lock-g050e0ef6ead'
1292+
* as a request for object 050e0ef6ead either.
1293+
*
1294+
* We are called with name[len] == '-' and name[len+1] == 'g', i.e.
1295+
* we are verifying ${REFNAME}-{INTEGER} part of the name.
1296+
*/
1297+
static int ref_and_count_parts_valid(const char *name, int len)
1298+
{
1299+
struct strbuf sb;
1300+
const char *cp;
1301+
int flags = REFNAME_ALLOW_ONELEVEL;
1302+
int ret = 1;
1303+
1304+
/* Ensure we have at least one digit */
1305+
if (!isxdigit(name[len-1]))
1306+
return 0;
1307+
1308+
/* Skip over digits backwards until we get to the dash */
1309+
for (cp = name + len - 2; name < cp; cp--) {
1310+
if (*cp == '-')
1311+
break;
1312+
if (!isxdigit(*cp))
1313+
return 0;
1314+
}
1315+
/* Ensure we found the leading dash */
1316+
if (*cp != '-')
1317+
return 0;
1318+
1319+
len = cp - name;
1320+
strbuf_init(&sb, len);
1321+
strbuf_add(&sb, name, len);
1322+
ret = !check_refname_format(sb.buf, flags);
1323+
strbuf_release(&sb);
1324+
return ret;
1325+
}
1326+
12751327
static int get_describe_name(struct repository *r,
12761328
const char *name, int len,
12771329
struct object_id *oid)
@@ -1285,7 +1337,8 @@ static int get_describe_name(struct repository *r,
12851337
/* We must be looking at g in "SOMETHING-g"
12861338
* for it to be describe output.
12871339
*/
1288-
if (ch == 'g' && cp[-1] == '-') {
1340+
if (ch == 'g' && cp[-1] == '-' &&
1341+
ref_and_count_parts_valid(name, cp - 1 - name)) {
12891342
cp++;
12901343
len -= cp - name;
12911344
return get_short_oid(r,

t/t6120-describe.sh

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -725,4 +725,26 @@ test_expect_success '--exact-match does not show --always fallback' '
725725
test_must_fail git describe --exact-match --always
726726
'
727727

728+
test_expect_success 'avoid being fooled by describe-like filename' '
729+
test_when_finished rm out &&
730+
731+
git rev-parse --short HEAD >out &&
732+
FILENAME=filename-g$(cat out) &&
733+
touch $FILENAME &&
734+
git add $FILENAME &&
735+
git commit -m "Add $FILENAME" &&
736+
737+
git cat-file -t HEAD:$FILENAME >actual &&
738+
739+
echo blob >expect &&
740+
test_cmp expect actual
741+
'
742+
743+
test_expect_success 'do not be fooled by invalid describe format ' '
744+
test_when_finished rm out &&
745+
746+
git rev-parse --short HEAD >out &&
747+
test_must_fail git cat-file -t "refs/tags/super-invalid/./../...../ ~^:/?*[////\\\\\\&}/busted.lock-42-g"$(cat out)
748+
'
749+
728750
test_done

0 commit comments

Comments
 (0)