187
188
/*
189
* Bit values for ref_entry::flag. REF_ISSYMREF=0x01,
190
- * REF_ISPACKED=0x02, and REF_ISBROKEN=0x04 are public values; see
191
- * refs.h.
190
+ * REF_ISPACKED=0x02, REF_ISBROKEN=0x04 and REF_BAD_NAME=0x08 are
191
+ * public values; see refs.h.
192
*/
193
194
/*
196
* the correct peeled value for the reference, which might be
197
* null_sha1 if the reference is not a tag or if it is broken.
198
*/
199
-#define REF_KNOWS_PEELED 0x08
199
+#define REF_KNOWS_PEELED 0x10
200
201
/* ref_entry represents a directory of references */
202
-#define REF_DIR 0x10
202
+#define REF_DIR 0x20
203
204
/*
205
* Entry has not yet been read from disk (used only for REF_DIR
206
* entries representing loose references)
207
*/
208
-#define REF_INCOMPLETE 0x20
208
+#define REF_INCOMPLETE 0x40
209
210
/*
211
* A ref_entry represents either a reference or a "subdirectory" of
274
return dir;
275
}
276
277
+/*
278
+ * Check if a refname is safe.
279
+ * For refs that start with "refs/" we consider it safe as long they do
280
+ * not try to resolve to outside of refs/.
281
+ *
282
+ * For all other refs we only consider them safe iff they only contain
283
+ * upper case characters and '_' (like "HEAD" AND "MERGE_HEAD", and not like
284
+ * "config").
285
+ */
286
+static int refname_is_safe(const char *refname)
287
+{
288
+ if (starts_with(refname, "refs/")) {
289
+ char *buf;
290
+ int result;
291
+
292
+ buf = xmalloc(strlen(refname) + 1);
293
+ /*
294
+ * Does the refname try to escape refs/?
295
+ * For example: refs/foo/../bar is safe but refs/foo/../../bar
296
+ * is not.
297
+ */
298
+ result = !normalize_path_copy(buf, refname + strlen("refs/"));
299
+ free(buf);
300
+ return result;
301
+ }
302
+ while (*refname) {
303
+ if (!isupper(*refname) && *refname != '_')
304
+ return 0;
305
+ refname++;
306
+ }
307
+ return 1;
308
+}
309
+
310
static struct ref_entry *create_ref_entry(const char *refname,
311
const unsigned char *sha1, int flag,
312
int check_name)
317
if (check_name &&
318
check_refname_format(refname, REFNAME_ALLOW_ONELEVEL))
319
die("Reference has invalid format: '%s'", refname);
320
+ if (!check_name && !refname_is_safe(refname))
321
+ die("Reference has invalid name: '%s'", refname);
322
len = strlen(refname) + 1;
323
ref = xmalloc(sizeof(struct ref_entry) + len);
324
hashcpy(ref->u.value.sha1, sha1);
1146
1147
refname = parse_ref_line(refline, sha1);
1148
if (refname) {
1114
- last = create_ref_entry(refname, sha1, REF_ISPACKED, 1);
1149
+ int flag = REF_ISPACKED;
1150
+
1151
+ if (check_refname_format(refname, REFNAME_ALLOW_ONELEVEL)) {
1152
+ hashclr(sha1);
1153
+ flag |= REF_BAD_NAME | REF_ISBROKEN;
1154
+ }
1155
+ last = create_ref_entry(refname, sha1, flag, 0);
1156
if (peeled == PEELED_FULLY ||
1157
(peeled == PEELED_TAGS && starts_with(refname, "refs/tags/")))
1158
last->flag |= REF_KNOWS_PEELED;
1290
hashclr(sha1);
1291
flag |= REF_ISBROKEN;
1292
}
1293
+ if (check_refname_format(refname.buf,
1294
+ REFNAME_ALLOW_ONELEVEL)) {
1295
+ hashclr(sha1);
1296
+ flag |= REF_BAD_NAME | REF_ISBROKEN;
1297
+ }
1298
add_entry_to_dir(dir,
1253
- create_ref_entry(refname.buf, sha1, flag, 1));
1299
+ create_ref_entry(refname.buf, sha1, flag, 0));
1300
}
1301
strbuf_setlen(&refname, dirnamelen);
1302
}
1415
* A loose ref file doesn't exist; check for a packed ref. The
1416
* options are forwarded from resolve_safe_unsafe().
1417
*/
1372
-static const char *handle_missing_loose_ref(const char *refname,
1373
- int resolve_flags,
1374
- unsigned char *sha1,
1375
- int *flags)
1418
+static int resolve_missing_loose_ref(const char *refname,
1419
+ int resolve_flags,
1420
+ unsigned char *sha1,
1421
+ int *flags)
1422
{
1423
struct ref_entry *entry;
1424
1431
hashcpy(sha1, entry->u.value.sha1);
1432
if (flags)
1433
*flags |= REF_ISPACKED;
1388
- return refname;
1434
+ return 0;
1435
}
1436
/* The reference is not a packed reference, either. */
1437
if (resolve_flags & RESOLVE_REF_READING) {
1392
- return NULL;
1438
+ errno = ENOENT;
1439
+ return -1;
1440
} else {
1441
hashclr(sha1);
1395
- return refname;
1442
+ return 0;
1443
}
1444
}
1445
1450
ssize_t len;
1451
char buffer[256];
1452
static char refname_buffer[256];
1453
+ int bad_name = 0;
1454
1455
if (flags)
1456
*flags = 0;
1457
1458
if (check_refname_format(refname, REFNAME_ALLOW_ONELEVEL)) {
1411
- errno = EINVAL;
1412
- return NULL;
1459
+ if (flags)
1460
+ *flags |= REF_BAD_NAME;
1461
+
1462
+ if (!(resolve_flags & RESOLVE_REF_ALLOW_BAD_NAME) ||
1463
+ !refname_is_safe(refname)) {
1464
+ errno = EINVAL;
1465
+ return NULL;
1466
+ }
1467
+ /*
1468
+ * dwim_ref() uses REF_ISBROKEN to distinguish between
1469
+ * missing refs and refs that were present but invalid,
1470
+ * to complain about the latter to stderr.
1471
+ *
1472
+ * We don't know whether the ref exists, so don't set
1473
+ * REF_ISBROKEN yet.
1474
+ */
1475
+ bad_name = 1;
1476
}
1477
for (;;) {
1478
char path[PATH_MAX];
1498
*/
1499
stat_ref:
1500
if (lstat(path, &st) < 0) {
1438
- if (errno == ENOENT)
1439
- return handle_missing_loose_ref(refname,
1440
- resolve_flags, sha1, flags);
1441
- else
1501
+ if (errno != ENOENT)
1502
+ return NULL;
1503
+ if (resolve_missing_loose_ref(refname, resolve_flags,
1504
+ sha1, flags))
1505
return NULL;
1506
+ if (bad_name) {
1507
+ hashclr(sha1);
1508
+ if (flags)
1509
+ *flags |= REF_ISBROKEN;
1510
+ }
1511
+ return refname;
1512
}
1513
1514
/* Follow "normalized" - ie "refs/.." symlinks by hand */
1581
errno = EINVAL;
1582
return NULL;
1583
}
1584
+ if (bad_name) {
1585
+ hashclr(sha1);
1586
+ if (flags)
1587
+ *flags |= REF_ISBROKEN;
1588
+ }
1589
return refname;
1590
}
1591
if (flags)
1601
if (check_refname_format(buf, REFNAME_ALLOW_ONELEVEL)) {
1602
if (flags)
1603
*flags |= REF_ISBROKEN;
1530
- errno = EINVAL;
1531
- return NULL;
1604
+
1605
+ if (!(resolve_flags & RESOLVE_REF_ALLOW_BAD_NAME) ||
1606
+ !refname_is_safe(buf)) {
1607
+ errno = EINVAL;
1608
+ return NULL;
1609
+ }
1610
+ bad_name = 1;
1611
}
1612
}
1613
}
2239
int missing = 0;
2240
int attempts_remaining = 3;
2241
2163
- if (check_refname_format(refname, REFNAME_ALLOW_ONELEVEL)) {
2164
- errno = EINVAL;
2165
- return NULL;
2166
- }
2167
-
2242
lock = xcalloc(1, sizeof(struct ref_lock));
2243
lock->lock_fd = -1;
2244
2245
if (mustexist)
2246
resolve_flags |= RESOLVE_REF_READING;
2173
- if (flags & REF_NODEREF && flags & REF_DELETING)
2174
- resolve_flags |= RESOLVE_REF_NO_RECURSE;
2247
+ if (flags & REF_DELETING) {
2248
+ resolve_flags |= RESOLVE_REF_ALLOW_BAD_NAME;
2249
+ if (flags & REF_NODEREF)
2250
+ resolve_flags |= RESOLVE_REF_NO_RECURSE;
2251
+ }
2252
2253
refname = resolve_ref_unsafe(refname, resolve_flags,
2254
lock->old_sha1, &type);
3596
if (have_old && !old_sha1)
3597
die("BUG: have_old is true but old_sha1 is NULL");
3598
3599
+ if (!is_null_sha1(new_sha1) &&
3600
+ check_refname_format(refname, REFNAME_ALLOW_ONELEVEL)) {
3601
+ strbuf_addf(err, "refusing to update ref with bad name %s",
3602
+ refname);
3603
+ return -1;
3604
+ }
3605
+
3606
update = add_update(transaction, refname);
3607
hashcpy(update->new_sha1, new_sha1);
3608
update->flags = flags;
3628
if (!new_sha1 || is_null_sha1(new_sha1))
3629
die("BUG: create ref with null new_sha1");
3630
3631
+ if (check_refname_format(refname, REFNAME_ALLOW_ONELEVEL)) {
3632
+ strbuf_addf(err, "refusing to create ref with bad name %s",
3633
+ refname);
3634
+ return -1;
3635
+ }
3636
+
3637
update = add_update(transaction, refname);
3638
3639
hashcpy(update->new_sha1, new_sha1);