Repository navigation
Commit 999c765
committed
fix(util): reject symbolic links that alias
`_validate_repo_path` mirrors Git's `verify_path` for tree and index entry
paths, but it only ever saw the path. Git's check there is mode dependent: an
entry that makes `.gitmodules` a symbolic link is refused, because the
submodule configuration would then be read through the link, from outside the
repository. That is why `git update-index --add --cacheinfo
120000,<sha>,.gitmodules` fails with `Invalid path`, `git read-tree` fails with
`invalid path`, and `git fsck --strict` reports `gitmodulesSymlink`.
GitPython accepted such an entry in both directions. `IndexFile.add` with a
`BaseIndexEntry` of mode `120000` and path `.gitmodules` was stored,
`write_tree` serialized the tree, and `IndexFile.commit` wrote a commit Git
refuses to read back and a server with `transfer.fsckObjects` set rejects.
Coming the other way, `read_cache` and `tree_entries_from_data` accepted the
same entry out of an untrusted repository's index or tree.
`_validate_repo_path` now takes the entry mode and, for a symbolic link,
rejects every spelling Git recognizes: `.gitmodules` with trailing spaces or
periods, the HFS form with ignorable code points removed, and the NTFS short
names `gitmod~1` through `gitmod~4` and `gi7eba~1` through `gi7eba~9`. The
mode is passed at the boundaries that have one: `write_cache`, `read_cache`,
`write_tree_from_cache`, `_tree_entry_to_baseindexentry`,
`IndexFile._preprocess_add_items`, `IndexFile.add`, `tree_to_stream`,
`tree_entries_from_data` and `TreeModifier.add`. Paths reached without a mode,
such as the directories walked by `IndexFile._iter_expand_paths`, keep their
previous behavior, and a regular file named `.gitmodules` stays valid.
Checked against `git update-index --add --cacheinfo` on git 2.52.0 for modes
`100644`, `120000`, `160000` and `40000` over the alias corpus: no path is
left that Git rejects and GitPython accepts. Like the existing `.git` rule the
name is tested per component, so a link below a directory spelled like one of
those aliases is refused as well, which Git happens to allow. Adds regression
tests in `test/test_index.py` and `test/test_tree.py`; `mypy`,
`basedpyright --warnings` and `ruff` are clean..gitmodules
1 parent 1af7ce6 commit 999c765
7 files changed
Lines changed: 81 additions & 14 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
729 | 729 | | |
730 | 730 | | |
731 | 731 | | |
732 | | - | |
| 732 | + | |
733 | 733 | | |
734 | 734 | | |
735 | 735 | | |
| |||
1026 | 1026 | | |
1027 | 1027 | | |
1028 | 1028 | | |
1029 | | - | |
| 1029 | + | |
1030 | 1030 | | |
1031 | 1031 | | |
1032 | 1032 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
279 | 279 | | |
280 | 280 | | |
281 | 281 | | |
282 | | - | |
| 282 | + | |
283 | 283 | | |
284 | 284 | | |
285 | 285 | | |
| |||
394 | 394 | | |
395 | 395 | | |
396 | 396 | | |
397 | | - | |
| 397 | + | |
398 | 398 | | |
399 | 399 | | |
400 | 400 | | |
| |||
462 | 462 | | |
463 | 463 | | |
464 | 464 | | |
465 | | - | |
| 465 | + | |
466 | 466 | | |
467 | 467 | | |
468 | 468 | | |
| |||
510 | 510 | | |
511 | 511 | | |
512 | 512 | | |
513 | | - | |
| 513 | + | |
514 | 514 | | |
515 | 515 | | |
516 | 516 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
39 | 39 | | |
40 | 40 | | |
41 | 41 | | |
42 | | - | |
| 42 | + | |
43 | 43 | | |
44 | 44 | | |
45 | 45 | | |
46 | | - | |
| 46 | + | |
47 | 47 | | |
48 | 48 | | |
49 | 49 | | |
| |||
82 | 82 | | |
83 | 83 | | |
84 | 84 | | |
85 | | - | |
| 85 | + | |
86 | 86 | | |
87 | 87 | | |
88 | 88 | | |
| |||
112 | 112 | | |
113 | 113 | | |
114 | 114 | | |
115 | | - | |
| 115 | + | |
116 | 116 | | |
117 | 117 | | |
118 | 118 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
110 | 110 | | |
111 | 111 | | |
112 | 112 | | |
113 | | - | |
| 113 | + | |
114 | 114 | | |
115 | 115 | | |
116 | 116 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
385 | 385 | | |
386 | 386 | | |
387 | 387 | | |
| 388 | + | |
| 389 | + | |
| 390 | + | |
| 391 | + | |
| 392 | + | |
| 393 | + | |
| 394 | + | |
388 | 395 | | |
389 | | - | |
| 396 | + | |
390 | 397 | | |
391 | 398 | | |
392 | 399 | | |
393 | 400 | | |
| 401 | + | |
| 402 | + | |
| 403 | + | |
| 404 | + | |
| 405 | + | |
| 406 | + | |
394 | 407 | | |
395 | 408 | | |
396 | 409 | | |
| |||
406 | 419 | | |
407 | 420 | | |
408 | 421 | | |
| 422 | + | |
| 423 | + | |
| 424 | + | |
| 425 | + | |
| 426 | + | |
409 | 427 | | |
410 | 428 | | |
411 | 429 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
189 | 189 | | |
190 | 190 | | |
191 | 191 | | |
192 | | - | |
| 192 | + | |
193 | 193 | | |
194 | 194 | | |
195 | | - | |
| 195 | + | |
196 | 196 | | |
197 | 197 | | |
198 | 198 | | |
| |||
340 | 340 | | |
341 | 341 | | |
342 | 342 | | |
| 343 | + | |
| 344 | + | |
| 345 | + | |
| 346 | + | |
| 347 | + | |
| 348 | + | |
| 349 | + | |
| 350 | + | |
| 351 | + | |
| 352 | + | |
| 353 | + | |
| 354 | + | |
| 355 | + | |
| 356 | + | |
| 357 | + | |
| 358 | + | |
| 359 | + | |
| 360 | + | |
| 361 | + | |
| 362 | + | |
| 363 | + | |
| 364 | + | |
| 365 | + | |
| 366 | + | |
| 367 | + | |
| 368 | + | |
| 369 | + | |
343 | 370 | | |
344 | 371 | | |
345 | 372 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
138 | 138 | | |
139 | 139 | | |
140 | 140 | | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
141 | 163 | | |
142 | 164 | | |
143 | 165 | | |
| |||
0 commit comments