read-cache: optionally disallow HFS+ .git variants

The point of disallowing ".git" in the index is that we would never want to accidentally overwrite files in the repository directory. But this means we need to respect the filesystem's idea of when two paths are equal. The prior commit added a helper to make such a comparison for HFS+; let's use it in verify_path. We make this check optional for two reasons: 1. It restricts the set of allowable filenames, which is unnecessary for people who are not on HFS+. In practice this probably doesn't matter, though, as the restricted names are rather obscure and almost certainly would never come up in practice. 2. It has a minor performance penalty for every path we insert into the index. This patch ties the check to the core.protectHFS config option. Though this is expected to be most useful on OS X, we allow it to be set everywhere, as HFS+ may be mounted on other platforms. The variable does default to on for OS X, though. Signed-off-by: Jeff King <peff@peff.net> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Jeff King committed Dec 15, 2014 at 18:15 UTC a42643aa8d88a2278acad2da6bc702e426476e9b
8 files changed +45 -5
Documentation/config.txt
+5
@@ -234,6 +234,11 @@ core.precomposeunicode::
234 When false, file names are handled fully transparent by Git,
235 which is backward compatible with older versions of Git.
236
237 +core.protectHFS::
238 + If set to true, do not allow checkout of paths that would
239 + be considered equivalent to `.git` on an HFS+ filesystem.
240 + Defaults to `true` on Mac OS, and `false` elsewhere.
241 +
242 core.trustctime::
243 If false, the ctime differences between the index and the
244 working tree are ignored; useful when the inode change time
cache.h
+1
@@ -584,6 +584,7 @@ extern int fsync_object_files;
584 extern int core_preload_index;
585 extern int core_apply_sparse_checkout;
586 extern int precomposed_unicode;
587 +extern int protect_hfs;
588
589 /*
590 * The character that begins a commented line in user-editable file
config.c
+5
@@ -881,6 +881,11 @@ static int git_default_core_config(const char *var, const char *value)
881 return 0;
882 }
883
884 + if (!strcmp(var, "core.protecthfs")) {
885 + protect_hfs = git_config_bool(var, value);
886 + return 0;
887 + }
888 +
889 /* Add other config variables here and to Documentation/config.txt. */
890 return 0;
891 }
config.mak.uname
+1
@@ -97,6 +97,7 @@ ifeq ($(uname_S),Darwin)
97 HAVE_DEV_TTY = YesPlease
98 COMPAT_OBJS += compat/precompose_utf8.o
99 BASIC_CFLAGS += -DPRECOMPOSE_UNICODE
100 + BASIC_CFLAGS += -DPROTECT_HFS_DEFAULT=1
101 endif
102 ifeq ($(uname_S),SunOS)
103 NEEDS_SOCKET = YesPlease
environment.c
+5
@@ -63,6 +63,11 @@ int precomposed_unicode = -1; /* see probe_utf8_pathname_composition() */
63 struct startup_info *startup_info;
64 unsigned long pack_size_limit_cfg;
65
66 +#ifndef PROTECT_HFS_DEFAULT
67 +#define PROTECT_HFS_DEFAULT 0
68 +#endif
69 +int protect_hfs = PROTECT_HFS_DEFAULT;
70 +
71 /*
72 * The character that begins a commented line in user-editable file
73 * that is subject to stripspace.
read-cache.c
+3
@@ -14,6 +14,7 @@
14 #include "resolve-undo.h"
15 #include "strbuf.h"
16 #include "varint.h"
17 +#include "utf8.h"
18
19 static struct cache_entry *refresh_cache_entry(struct cache_entry *ce, int really);
20
@@ -786,6 +787,8 @@ int verify_path(const char *path)
787 return 1;
788 if (is_dir_sep(c)) {
789 inside:
790 + if (protect_hfs && is_hfs_dotgit(path))
791 + return 0;
792 c = *path++;
793 if ((c == '.' && !verify_dotfile(path)) ||
794 is_dir_sep(c) || c == '\0')
t/t1014-read-tree-confusing.sh
+20 -4
@@ -11,23 +11,39 @@ test_expect_success 'create base tree' '
11 tree=$(git rev-parse HEAD^{tree})
12 '
13
14 -while read path; do
15 - test_expect_success "reject $path at end of path" '
14 +test_expect_success 'enable core.protectHFS for rejection tests' '
15 + git config core.protectHFS true
16 +'
17 +
18 +while read path pretty; do
19 + : ${pretty:=$path}
20 + test_expect_success "reject $pretty at end of path" '
21 printf "100644 blob %s\t%s" "$blob" "$path" >tree &&
22 bogus=$(git mktree <tree) &&
23 test_must_fail git read-tree $bogus
24 '
25
21 - test_expect_success "reject $path as subtree" '
26 + test_expect_success "reject $pretty as subtree" '
27 printf "040000 tree %s\t%s" "$tree" "$path" >tree &&
28 bogus=$(git mktree <tree) &&
29 test_must_fail git read-tree $bogus
30 '
26 -done <<-\EOF
31 +done <<-EOF
32 .
33 ..
34 .git
35 .GIT
36 +${u200c}.Git {u200c}.Git
37 +.gI${u200c}T .gI{u200c}T
38 +.GiT${u200c} .GiT{u200c}
39 EOF
40
41 +test_expect_success 'utf-8 paths allowed with core.protectHFS off' '
42 + test_when_finished "git read-tree HEAD" &&
43 + test_config core.protectHFS false &&
44 + printf "100644 blob %s\t%s" "$blob" ".gi${u200c}t" >tree &&
45 + ok=$(git mktree <tree) &&
46 + git read-tree $ok
47 +'
48 +
49 test_done
t/test-lib.sh
+5 -1
@@ -154,7 +154,11 @@ _z40=0000000000000000000000000000000000000000
154 LF='
155 '
156
157 -export _x05 _x40 _z40 LF
157 +# UTF-8 ZERO WIDTH NON-JOINER, which HFS+ ignores
158 +# when case-folding filenames
159 +u200c=$(printf '\342\200\214')
160 +
161 +export _x05 _x40 _z40 LF u200c
162
163 # Each test should start with something like this, after copyright notices:
164 #