mirror of
https://github.com/RsyncProject/rsync.git
synced 2026-09-12 21:28:25 -04:00
util1: fix clean_fname ".." collapse off-by-one
After the backward walk, s points at the first char of the prior component and s[-1] is its leading '/', so the boundary test must read s[-1] (not *s) and t must reset to s (not s+1). The old off-by-one left CFN_COLLAPSE_DOT_DOT_DIRS dead for all multi-component and absolute paths. The peer-traversal guard CFN_REFUSE_DOT_DOT_DIRS is checked first and is unaffected, so this is a normalization-correctness fix, not a traversal hole. Reported-by: Leonid Bugaev
This commit is contained in:
1 parent
07bf9af5b5
commit
fbeb553b73
1 file changed
+8
-3
@@ -1085,9 +1085,14 @@ int clean_fname(char *name, int flags)
|
||||
while (s > limit && s[-1] != '/')
|
||||
s--;
|
||||
|
||||
/* If found prior '/', or we reached the start, adjust t. */
|
||||
if (s != t - 1 && (s <= name || *s == '/')) {
|
||||
t = (s == name) ? name : s + 1;
|
||||
/* If found prior '/', or we reached the start, adjust t.
|
||||
* After the backward walk, s points at the first char of the
|
||||
* prior component and s[-1] is its leading '/' -- so test
|
||||
* s[-1] (not *s) and reset t to s (not s+1) to actually drop
|
||||
* the component; the old off-by-one left CFN_COLLAPSE_DOT_DOT_DIRS
|
||||
* dead for multi-component and absolute paths. */
|
||||
if (s != t - 1 && (s <= name || s[-1] == '/')) {
|
||||
t = (s == name) ? name : s;
|
||||
f += 2;
|
||||
continue;
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user