apply: do not read from beyond a symbolic link
We should reject a patch, whether it renames/copies dir/file to elsewhere with or without modificiation, or updates dir/file in place, if "dir/" part is actually a symbolic link to elsewhere, by making sure that the code to read the preimage does not read from a path that is beyond a symbolic link. Signed-off-by: Junio C Hamano <gitster@pobox.com>
Junio C Hamano committed
Jan 30, 2015 at 15:34 UTC
fdc2c3a926c21e24986677abd02c8bc568a5de32
2 files changed
+21
builtin/apply.c
+2
@@ -3145,6 +3145,8 @@ static int load_patch_target(struct strbuf *buf,
3145
return read_file_or_gitlink(ce, buf);
3146
else
3147
return SUBMODULE_PATCH_WITHOUT_INDEX;
3148
+ } else if (has_symlink_leading_path(name, strlen(name))) {
3149
+ return error(_("reading from '%s' beyond a symbolic link"), name);
3150
} else {
3151
if (read_old_data(st, name, buf))
3152
return error(_("read of %s failed"), name);
t/t4122-apply-symlink-inside.sh
+19
@@ -52,4 +52,23 @@ test_expect_success 'check result' '
52
53
'
54
55
+test_expect_success SYMLINKS 'do not read from beyond symbolic link' '
56
+ git reset --hard &&
57
+ mkdir -p arch/x86_64/dir &&
58
+ >arch/x86_64/dir/file &&
59
+ git add arch/x86_64/dir/file &&
60
+ echo line >arch/x86_64/dir/file &&
61
+ git diff >patch &&
62
+ git reset --hard &&
63
+
64
+ mkdir arch/i386/dir &&
65
+ >arch/i386/dir/file &&
66
+ ln -s ../i386/dir arch/x86_64/dir &&
67
+
68
+ test_must_fail git apply patch &&
69
+ test_must_fail git apply --cached patch &&
70
+ test_must_fail git apply --index patch
71
+
72
+'
73
+
74
test_done