You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fix(submodule): validate destinations before mutation
<!-- Byron -->
Pretty much a rubber-stamp. It won't be out there long as the replacement
with CLI + Gix is already on the way.
<!-- agent -->
Submodule checkout destinations could pass the containment check and be
rejected by the index only after cloning had changed the filesystem. This
addresses `GHSA-83vg-56qc-22m7` at the shared destination boundaries, including
initialization and moves as well as creation.
Reuse `_validate_repo_path` before checkout mutations to enforce portable
NTFS/HFS metadata-alias checks and invalid-path rejection. Validate Windows
filenames and submodule-name NULs before creating directories. Compare path
components with `Repo.git_dir` and `Repo.common_dir` by filesystem identity,
so separately named metadata directories and their aliases are protected too.
Reject metadata destinations nested inside another submodule's Git directory
before cloning, reuse, or renaming. Repeat the check after cloning and disable
a clone that became nested. Preflight implicit metadata renames during moves,
while preserving supported metadata symlinks and relocation of a submodule's
own metadata directory.
Git reference: `d38352cd43ab9745686d697872408bc3249a153f`, particularly
`read-cache.c::verify_path_internal`, NTFS/HFS recognition,
`compat/mingw.c::is_valid_win32_path`, and
`submodule.c::validate_submodule_git_dir`. Related Git tests are in
`t/t7450-bad-git-dotfiles.sh` and `t/t7406-submodule-update.sh`.
Regression tests first demonstrated writes before rejection and acceptance
of nested and separately named metadata destinations. Tests use harmless
file content and compare portable aliases with native Git index validation.
Coverage includes all 16 HFS ignored characters, Windows filename rules,
relative and absolute paths, metadata reuse, and nesting during cloning.
Assisted-by: GPT 6.0 Astra
Co-authored-by: GPT 6.0 Astra <codex@openai.com>
0 commit comments