git.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Junio C Hamano <gitster@pobox.com>
To: Martin Koegler <mkoegler@auto.tuwien.ac.at>
Cc: git@vger.kernel.org
Subject: Re: [PATCH] receive-pack: reject invalid refnames
Date: Thu, 03 Jan 2008 13:40:07 -0800	[thread overview]
Message-ID: <7vy7b6oafc.fsf@gitster.siamese.dyndns.org> (raw)
In-Reply-To: <1199310726946-git-send-email-mkoegler@auto.tuwien.ac.at> (Martin Koegler's message of "Wed, 2 Jan 2008 22:52:06 +0100")

Martin Koegler <mkoegler@auto.tuwien.ac.at> writes:

> Signed-off-by: Martin Koegler <mkoegler@auto.tuwien.ac.at>
> ---
>  receive-pack.c |    7 +++++--
>  1 files changed, 5 insertions(+), 2 deletions(-)
>
> diff --git a/receive-pack.c b/receive-pack.c
> index d0a563d..a038a40 100644
> --- a/receive-pack.c
> +++ b/receive-pack.c
> @@ -165,7 +165,9 @@ static const char *update(struct command *cmd)
>  	unsigned char *new_sha1 = cmd->new_sha1;
>  	struct ref_lock *lock;
>  
> -	if (!prefixcmp(name, "refs/") && check_ref_format(name + 5)) {
> +	/* only HEAD and refs/... are allowed */
> +	if (strcmp(name, "HEAD") && 
> +	    (prefixcmp(name, "refs/") || check_ref_format(name + 5))) {
>  		error("refusing to create funny ref '%s' remotely", name);
>  		return "funny refname";
>  	}
> @@ -177,7 +179,8 @@ static const char *update(struct command *cmd)
>  	}
>  	if (deny_non_fast_forwards && !is_null_sha1(new_sha1) &&
>  	    !is_null_sha1(old_sha1) &&
> -	    !prefixcmp(name, "refs/heads/")) {
> +	    (!prefixcmp(name, "refs/heads/") ||
> +	     !strcmp(name, "HEAD"))) {
>  		struct object *old_object, *new_object;
>  		struct commit *old_commit, *new_commit;
>  		struct commit_list *bases, *ent;

Yuck.  What I was smoking.

Normal client "git push" does not even allow "git push victim
foo:HEAD".  So if name is "HEAD" that has to be a malicious
crafted push.

I think 

	if (prefixcmp(name, "refs/") || check_ref_format(name + 5))
		error();

is enough and correct.

Sorry for my earlier thinko.

  reply	other threads:[~2008-01-03 21:41 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2008-01-02 21:52 [PATCH] receive-pack: reject invalid refnames Martin Koegler
2008-01-03 21:40 ` Junio C Hamano [this message]
  -- strict thread matches above, loose matches on Subject: below --
2008-01-04 19:37 Martin Koegler

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=7vy7b6oafc.fsf@gitster.siamese.dyndns.org \
    --to=gitster@pobox.com \
    --cc=git@vger.kernel.org \
    --cc=mkoegler@auto.tuwien.ac.at \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).