Joey Hess [Mon, 10 Apr 2023 16:56:45 +0000 (12:56 -0400)]
git style filename quoting for giveup
When the filenames are part of the git repository or other files that
might have attacker-controlled names, quote them in error messages.
This is fairly complete, although I didn't do the one in
Utility.DirWatcher.INotify.hs because that doesn't have access to
Git.Filename or Annex.
But it's also quite possible I missed some. And also while scanning for
these, I found giveup used with other things that could be attacker
controlled to contain control characters (eg Keys). So, I'm thinking
it would also be good for giveup to just filter out control characters.
This commit is then not the only line of defence, but just good
formatting when git-annex displays a filename in an error message.
Sponsored-by: Kevin Mueller on Patreon
Joey Hess [Mon, 10 Apr 2023 16:13:26 +0000 (12:13 -0400)]
addurl --preserve-filename: reject control characters
As well as escape sequences, control characters seem unlikely to be desired when
doing addurl, and likely to trip someone up. So disallow them as well.
I did consider going the other way and allowing filenames with control characters
and escape sequences, since git-annex is in the process of escaping display
of all filenames. Might still be a better idea?
Also display the illegal filename git quoted when it rejects it.
Sponsored-by: Nicholas Golder-Manning on Patreon
Joey Hess [Sun, 9 Apr 2023 16:53:13 +0000 (12:53 -0400)]
avoid unncessary nested lists for combineing StringContainingQuotedPath
Joey Hess [Sat, 8 Apr 2023 19:48:32 +0000 (15:48 -0400)]
git style quoting for ActionItemOther
Added StringContainingQuotedPath, which is used for ActionItemOther.
In the process, checked every ActionItemOther for those containing
filenames, and made them use quoting.
Sponsored-by: Graham Spencer on Patreon
Joey Hess [Sat, 8 Apr 2023 18:20:02 +0000 (14:20 -0400)]
git style filename quoting controlled by core.quotePath
This is by no means complete, but escaping filenames in actionItemDesc does
cover most commands.
Note that for ActionItemBranchFilePath, the value is branch:file, and I
choose to only quote the file part (if necessary). I considered quoting the
whole thing. But, branch names cannot contain control characters, and while
they can contain unicode, git coes not quote unicode when displaying branch
names. So, it would be surprising for git-annex to quote unicode in a
branch name.
The find command is the most obvious command that still needs to be
dealt with. There are probably other places that filenames also get
displayed, eg embedded in error messages.
Some other commands use ActionItemOther with a filename, I think that
ActionItemOther should either be pre-sanitized, or should explicitly not
be used for filenames, so that needs more work.
When --json is used, unicode does not get escaped, but control
characters were already escaped in json.
(Key escaping may turn out to be needed, but I'm ignoring that for now.)
Sponsored-by: unqueued on Patreon
Joey Hess [Fri, 7 Apr 2023 21:20:58 +0000 (17:20 -0400)]
clean up
Joey Hess [Fri, 7 Apr 2023 21:12:55 +0000 (17:12 -0400)]
full emulation of git filename escaping
Not yet used, but the plan is to make git-annex use this when displaying
filenames similar to how git does.
Sponsored-by: Lawrence Brogan on Patreon
Joey Hess [Fri, 7 Apr 2023 20:47:26 +0000 (16:47 -0400)]
convert encode_c to ByteString
This turns out to be possible after all, because the old one decomposed
a unicode Char to multiple Word8s and encoded those. It should be faster
in some places, particularly in Git.Filename.encodeAlways.
The old version encoded all unicode by default as well as ascii control
characters and also '"'. The new one only encodes ascii control
characters by default.
That old behavior was visible in Utility.Format.format, which did escape
'"' when used in eg git-annex find --format='${escaped_file}\n'
So made sure to keep that working the same. Although the man page only
says it will escape "unusual" characters, so it might be able to be
changed.
Git.Filename.encodeAlways also needs to escape '"' ; that was the
original reason that was escaped.
Types.Transferrer I judge is ok to not escape '"', because the escaped
value is sent in a line-based protocol, which is decoded at the other
end by decode_c. So old git-annex and new will be fine whether that is
escaped or not, the result will be the same.
Note that when asked to escape a double quote, it is escaped to \"
rather than to \042. That's the same behavior as git has. It's
perhaps somehow more of a special case than it needs to be.
Sponsored-by: k0ld on Patreon
Joey Hess [Fri, 7 Apr 2023 18:44:19 +0000 (14:44 -0400)]
decode_c converted to ByteString
This speeds up a few things, notably CmdLine.Seek using Git.Filename
which uses decode_c and this avoids a conversion to String and back,
and probably the ByteString implementation of decode_c is also faster
for simple cases at least than the string version.
encode_c cannot be converted to ByteString (or if it did, it would have
to convert right back to String in order to handle unicode).
Sponsored-by: Brock Spratlen on Patreon
Joey Hess [Fri, 7 Apr 2023 17:37:18 +0000 (13:37 -0400)]
add news item for git-annex 10.
20230407
Joey Hess [Fri, 7 Apr 2023 17:37:03 +0000 (13:37 -0400)]
releasing package git-annex version 10.
20230407
Joey Hess [Fri, 7 Apr 2023 17:13:16 +0000 (13:13 -0400)]
expand
Joey Hess [Fri, 7 Apr 2023 17:00:56 +0000 (13:00 -0400)]
response
Joey Hess [Fri, 7 Apr 2023 16:52:43 +0000 (12:52 -0400)]
response
Joey Hess [Fri, 7 Apr 2023 16:42:09 +0000 (12:42 -0400)]
Merge branch 'master' of ssh://git-annex.branchable.com
jwodder [Fri, 7 Apr 2023 15:19:04 +0000 (15:19 +0000)]
mih [Fri, 7 Apr 2023 09:17:22 +0000 (09:17 +0000)]
Added a comment: Status of the import/export protocol implementation
Joey Hess [Wed, 5 Apr 2023 23:37:21 +0000 (19:37 -0400)]
todo
Joey Hess [Wed, 5 Apr 2023 20:59:44 +0000 (16:59 -0400)]
restore old registerurl location tracking behavior
registerurl: When an url is claimed by a special remote other than the web,
update location tracking for that special remote.
registerurl's behavior was changed in commit
451171b7c1eaccfd0f39d4ec1d64c6964613f55a, apparently accidentially to not
update location tracking except for the web.
This makes registerurl followed by unregisterurl not be a no-op, when the
url happens to be claimed by a remote other than the web. It is a noop when
the url is unclaimed except by the web. I don't like the inconsistency,
and wish that registerurl and unregisterurl never updated location
tracking, which would be more in keeping with them being plumbing.
But there is the fact that it used to behave this way, and also it was
inconsistent that it updated location tracking for the web but not for
other remotes, unlike addurl. And there's an argument that the user might
not know what remote to expect to claim an url, so would be considerably in
the dark when using registerurl. (Although they have to know what content
gets downloaded, since they specify a key..)
Sponsored-By: the NIH-funded NICEMAN (ReproNim TR&D3) project
Joey Hess [Wed, 5 Apr 2023 20:36:18 +0000 (16:36 -0400)]
hm
Joey Hess [Wed, 5 Apr 2023 19:56:31 +0000 (15:56 -0400)]
Merge branch 'master' of ssh://git-annex.branchable.com
Joey Hess [Wed, 5 Apr 2023 19:46:51 +0000 (15:46 -0400)]
registerurl, unregisterurl: Added --remote option
This serves two purposes. --remote=web bypasses other special remotes that
claim the url, same as addurl --raw. And, specifying some other remote
allows making sure that an url is claimed by the remote you expect,
which makes then using setpresentkey not be fragile.
Sponsored-By: the NIH-funded NICEMAN (ReproNim TR&D3) project
yarikoptic [Wed, 5 Apr 2023 19:36:41 +0000 (19:36 +0000)]
Added a comment
Joey Hess [Wed, 5 Apr 2023 19:00:39 +0000 (15:00 -0400)]
comments
Joey Hess [Wed, 5 Apr 2023 15:04:55 +0000 (11:04 -0400)]
Merge branch 'master' of ssh://git-annex.branchable.com
Joey Hess [Wed, 5 Apr 2023 15:04:35 +0000 (11:04 -0400)]
update
jkniiv [Wed, 5 Apr 2023 09:42:12 +0000 (09:42 +0000)]
Added a comment
yarikoptic [Wed, 5 Apr 2023 01:03:38 +0000 (01:03 +0000)]
Added a comment
yarikoptic [Wed, 5 Apr 2023 00:30:00 +0000 (00:30 +0000)]
Added a comment
yarikoptic [Tue, 4 Apr 2023 20:15:59 +0000 (20:15 +0000)]
Added a comment
Joey Hess [Tue, 4 Apr 2023 19:21:50 +0000 (15:21 -0400)]
improve comments
Joey Hess [Tue, 4 Apr 2023 19:19:25 +0000 (15:19 -0400)]
fixed
Joey Hess [Tue, 4 Apr 2023 19:15:02 +0000 (15:15 -0400)]
Revert "override rather than setting user.name and user.email"
This reverts commit
66eb63dd820ade940b26b8eb00759d1b0f9242a0.
git-annex init is the only thing that uses ensureCommit. So overriding
there will make later commits to the git-annex branch or by git-annex sync
fail.
It's ugly that git-annex init sets user.name and user.email, but it only
does it on systems that are badly configured.
Joey Hess [Tue, 4 Apr 2023 19:12:52 +0000 (15:12 -0400)]
Support user.useConfigOnly git config
When it's set and git cannot determine user.name or user.email, this will
result in git-annex init failing when committing to create the git-annex
branch. Other git-annex commands that commit can also fail.
Sponsored-by: Jack Hill on Patreon
Joey Hess [Tue, 4 Apr 2023 18:56:44 +0000 (14:56 -0400)]
override rather than setting user.name and user.email
Avoid setting user.name and user.email in the git config when git is unable
to detect them.
git-annex has good reason to want to ensure git commit succeeds when eg
committing to the git-annex branch. But it's not playing nice to set these
values where other commands can see them.
Sponsored-by: Brett Eisenberg on Patreon
Joey Hess [Tue, 4 Apr 2023 18:43:33 +0000 (14:43 -0400)]
comment
Joey Hess [Tue, 4 Apr 2023 18:31:25 +0000 (14:31 -0400)]
comment
Joey Hess [Tue, 4 Apr 2023 18:25:55 +0000 (14:25 -0400)]
probably fixed but I didn't actually reproduce it
Joey Hess [Tue, 4 Apr 2023 18:25:01 +0000 (14:25 -0400)]
readFileStrict to avoid laziness bug
Fix laziness bug introduced in last release that breaks use of
--unlock-present and --hide-missing adjusted branches.
Since there is a writeFile of the same file immediately after readFile, it
may still have the file open for read (or may have happened to read it
already and closed it).
I was not able to reproduce the problem in brief testing, but this seems
obvious.
Sponsored-by: Luke Shumaker on Patreona
Joey Hess [Tue, 4 Apr 2023 18:09:02 +0000 (14:09 -0400)]
comment
Joey Hess [Tue, 4 Apr 2023 17:52:23 +0000 (13:52 -0400)]
comments
Joey Hess [Tue, 4 Apr 2023 17:34:32 +0000 (13:34 -0400)]
comment
jkniiv [Mon, 3 Apr 2023 11:48:10 +0000 (11:48 +0000)]
Added a comment: happens during sync too
gioele@678b7c03f524f2669b179b603f65352fcc16774e [Mon, 3 Apr 2023 09:05:45 +0000 (09:05 +0000)]
gioele@678b7c03f524f2669b179b603f65352fcc16774e [Sat, 1 Apr 2023 11:09:49 +0000 (11:09 +0000)]
Added a comment
gioele@678b7c03f524f2669b179b603f65352fcc16774e [Sat, 1 Apr 2023 11:06:26 +0000 (11:06 +0000)]
Added a comment
Added a comment
yarikoptic [Fri, 31 Mar 2023 22:36:02 +0000 (22:36 +0000)]
reporting an annoying registerurl issue not registering a URL
yarikoptic [Fri, 31 Mar 2023 22:15:26 +0000 (22:15 +0000)]
initial todo for adding --remote to registerurl
gioele@678b7c03f524f2669b179b603f65352fcc16774e [Fri, 31 Mar 2023 20:16:04 +0000 (20:16 +0000)]
Added a comment
Joey Hess [Fri, 31 Mar 2023 19:16:28 +0000 (15:16 -0400)]
Merge branch 'master' of ssh://git-annex.branchable.com
Joey Hess [Fri, 31 Mar 2023 18:34:18 +0000 (14:34 -0400)]
Sped up sqlite inserts 2x when built with persistent 2.14.5.0
https://github.com/yesodweb/persistent/issues/1457
Sponsored-by: Dartmouth College's DANDI project
Added a comment
Joey Hess [Fri, 31 Mar 2023 18:18:50 +0000 (14:18 -0400)]
clarify
Joey Hess [Fri, 31 Mar 2023 18:18:36 +0000 (14:18 -0400)]
fix link
Joey Hess [Fri, 31 Mar 2023 17:11:35 +0000 (13:11 -0400)]
idea
Joey Hess [Fri, 31 Mar 2023 16:52:23 +0000 (12:52 -0400)]
git-annex.cabal: Prevent building with unix-compat 0.7
Which removed System.PosixCompat.User.
See https://github.com/haskell-pkg-janitors/unix-compat/issues/3
Sponsored-by: Noam Kremen on Patreon
wolf480@8ad1ccdd08efc303a88f7e88c4e629be6637a44e [Thu, 30 Mar 2023 17:33:58 +0000 (17:33 +0000)]
Added a comment
wolf480@8ad1ccdd08efc303a88f7e88c4e629be6637a44e [Thu, 30 Mar 2023 17:33:10 +0000 (17:33 +0000)]
Added a comment
ptilopteri [Wed, 29 Mar 2023 22:32:06 +0000 (22:32 +0000)]
Joey Hess [Wed, 29 Mar 2023 20:09:15 +0000 (16:09 -0400)]
add news item for git-annex 10.
20230329
Joey Hess [Wed, 29 Mar 2023 20:09:05 +0000 (16:09 -0400)]
releasing package git-annex version 10.
20230329
sawmke [Wed, 29 Mar 2023 11:47:13 +0000 (11:47 +0000)]
dpifke [Wed, 29 Mar 2023 03:13:50 +0000 (03:13 +0000)]
Added a comment
Joey Hess [Tue, 28 Mar 2023 21:13:04 +0000 (17:13 -0400)]
fix whitespace
Joey Hess [Tue, 28 Mar 2023 21:02:34 +0000 (17:02 -0400)]
prep for release tomorrow
Joey Hess [Tue, 28 Mar 2023 21:01:25 +0000 (17:01 -0400)]
close
Joey Hess [Tue, 28 Mar 2023 21:00:08 +0000 (17:00 -0400)]
external protocol VERSION 2
Support VERSION 2 in the external special remote protocol, which is
identical to VERSION 1, but avoids external remote programs neededing to
work around the above bug. External remote program that support
exporttree=yes are recommended to be updated to send VERSION 2.
Sponsored-by: Kevin Mueller on Patreon
Joey Hess [Tue, 28 Mar 2023 20:08:46 +0000 (16:08 -0400)]
comment
Joey Hess [Tue, 28 Mar 2023 19:26:26 +0000 (15:26 -0400)]
fixed
Joey Hess [Tue, 28 Mar 2023 19:21:10 +0000 (15:21 -0400)]
fix concurrency bug causing EXPORT to be sent to the wrong external
Fix bug that caused broken protocol to be used with external remotes that
use exporttree=yes. In some cases this could result in the wrong content
being exported to, or retrieved from the remote.
Sponsored-by: Nicholas Golder-Manning on Patreon
Joey Hess [Tue, 28 Mar 2023 19:17:56 +0000 (15:17 -0400)]
clarify EXPORT
Joey Hess [Tue, 28 Mar 2023 18:31:00 +0000 (14:31 -0400)]
comment
Joey Hess [Tue, 28 Mar 2023 18:26:19 +0000 (14:26 -0400)]
comment
Joey Hess [Tue, 28 Mar 2023 18:09:22 +0000 (14:09 -0400)]
Merge branch 'master' of ssh://git-annex.branchable.com
Joey Hess [Tue, 28 Mar 2023 18:08:24 +0000 (14:08 -0400)]
comment
Joey Hess [Tue, 28 Mar 2023 17:40:17 +0000 (13:40 -0400)]
fix comment
Joey Hess [Tue, 28 Mar 2023 17:13:34 +0000 (13:13 -0400)]
comment
Joey Hess [Tue, 28 Mar 2023 17:06:11 +0000 (13:06 -0400)]
Copy with a reflink when exporting a tree to a directory special remote
Remote.Directory makes a temp file, then calls this, and since the temp
file exists, it prevented probing if CoW works.
Note that deleting the empty file does mean there's a small window for a
race. If another process is also exporting to the remote, that could let it
make the same temp file. However, the temp filename actually has the
processes's pid in it, which avoids that being a problem.
This may have been a reversion caused by commits around
63d508e8855b2e61a725c906ea17d1c7f4a2e125, but I haven't gone back and
tested to be sure. The directory special remote had supposedly supported
CoW for this going back to about half a year before that.
Sponsored-by: Graham Spencer on Patreon
Joey Hess [Tue, 28 Mar 2023 16:38:47 +0000 (12:38 -0400)]
fix comment
Joey Hess [Tue, 28 Mar 2023 16:14:23 +0000 (12:14 -0400)]
comment
Added a comment: annex.bwlimit and jobs
Joey Hess [Mon, 27 Mar 2023 19:10:46 +0000 (15:10 -0400)]
addurl, importfeed: Fix failure when annex.securehashesonly is set
The temporary URL key used for the download, before the real key is
generated, was blocked by annex.securehashesonly.
Fixed by passing the Backend that will be used for the final key into
runTransfer. When a Backend is provided, have preCheckSecureHashes
check that, rather than the key being transferred.
Sponsored-by: unqueued on Patreon
Joey Hess [Mon, 27 Mar 2023 18:34:00 +0000 (14:34 -0400)]
remove unused Key parameter from isCryptographicallySecure
This will allow using isCryptographicallySecure on a Backend, before a
Key has been generated.
Sponsored-by: Lawrence Brogan on Patreon
Joey Hess [Mon, 27 Mar 2023 18:10:32 +0000 (14:10 -0400)]
promote comment to bug
Joey Hess [Mon, 27 Mar 2023 17:58:16 +0000 (13:58 -0400)]
verified fixed
Joey Hess [Mon, 27 Mar 2023 17:38:13 +0000 (13:38 -0400)]
Merge branch 'master' of ssh://git-annex.branchable.com
Joey Hess [Mon, 27 Mar 2023 17:38:02 +0000 (13:38 -0400)]
Windows: Support urls like "file:///c:/path"
That is a legal url, but parseUrl parses it to "/c:/path"
which is not a valid path on Windows. So as a workaround, use
parseURIPortable everywhere, which removes the leading slash when
run on windows.
Note that if an url is parsed like this and then serialized back
to a string, it will be different from the input. Which could
potentially be a problem, but is probably not in practice.
An alternative way to do it would be to have an uriPathPortable
that fixes up the path after parsing. But it would be harder to
make sure that is used everywhere, since uriPath is also used
when constructing an URI.
It's also worth noting that System.FilePath.normalize "/c:/path"
yields "c:/path". The reason I didn't use it is that it also
may change "/" to "\" in the path and I wanted to keep the url
changes minimal. Also noticed that convertToWindowsNativeNamespace
handles "/c:/path" the same as "c:/path".
Sponsored-By: the NIH-funded NICEMAN (ReproNim TR&D3) project
Joey Hess [Mon, 27 Mar 2023 16:36:21 +0000 (12:36 -0400)]
comment
Joey Hess [Mon, 27 Mar 2023 16:21:40 +0000 (12:21 -0400)]
avoid build warning on windows
Joey Hess [Mon, 27 Mar 2023 16:20:35 +0000 (12:20 -0400)]
avoid build warning on windows
Joey Hess [Mon, 27 Mar 2023 16:19:26 +0000 (12:19 -0400)]
avoid build warning on windows
Joey Hess [Mon, 27 Mar 2023 16:17:55 +0000 (12:17 -0400)]
fix build warning on windows
jonas [Sun, 26 Mar 2023 20:04:22 +0000 (20:04 +0000)]
wolf480@8ad1ccdd08efc303a88f7e88c4e629be6637a44e [Sun, 26 Mar 2023 19:00:42 +0000 (19:00 +0000)]
wolf480@8ad1ccdd08efc303a88f7e88c4e629be6637a44e [Sun, 26 Mar 2023 18:39:20 +0000 (18:39 +0000)]
gioele@678b7c03f524f2669b179b603f65352fcc16774e [Sat, 25 Mar 2023 08:47:01 +0000 (08:47 +0000)]
Added a comment