credential-cache--daemon: disallow relative socket path

Relative socket paths are dangerous since the user cannot generally control when the daemon starts (initially, after a timeout, kill or crash). Since the daemon creates but does not delete the socket directory, this could lead to spurious directory creation relative to the users cwd. Suggested-by: Jeff King <peff@peff.net> Signed-off-by: Jon Griffiths <jon_p_griffiths@yahoo.com> Signed-off-by: Jeff King <peff@peff.net> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Jon Griffiths committed Feb 23, 2016 at 02:15 UTC bd93b8d9becb01d21871b63e34c2e824c60b1e8c
2 files changed +4 -1
Documentation/git-credential-cache.txt
+1 -1
@@ -36,7 +36,7 @@ OPTIONS
36 cache daemon if one is not started). Defaults to
37 `~/.git-credential-cache/socket`. If your home directory is on a
38 network-mounted filesystem, you may need to change this to a
39 - local filesystem.
39 + local filesystem. You must specify an absolute path.
40
41 CONTROLLING THE DAEMON
42 ----------------------
credential-cache--daemon.c
+3
@@ -262,6 +262,9 @@ int main(int argc, const char **argv)
262 if (!socket_path)
263 usage_with_options(usage, options);
264
265 + if (!is_absolute_path(socket_path))
266 + die("socket directory must be an absolute path");
267 +
268 init_socket_directory(socket_path);
269 register_tempfile(&socket_file, socket_path);
270