The Folder Called .GIT — Python Bug Hunt
Modelled on Git CVE-2014-9390 (December 2014). Git refused to check out a tree entry named .git, but compared the name exactly.
- Language: Python
- Layer: Backend
- Difficulty: Medium
- Concepts: Security, Validation, Unicode
- Modelled on: Git · CVE-2014-9390
- Visible tests: ordinary paths are allowed; other spellings of .git are blocked
- Reward: 50 XP for a complete fix
Briefing
Modelled on Git CVE-2014-9390 (December 2014). Git refused to check out a tree entry named .git, but compared the name exactly. On case-insensitive filesystems — Windows and macOS by default — a malicious repository could ship .Git/config or .GIT/config, and checking it out overwrote the repository's own configuration, which can lead to arbitrary command execution. Fixed Git releases compare the way the filesystem does (and also reject names that HFS+ treats as equivalent).
This reconstruction's verify_path blocks only the exact spelling.
Fix verify_path so no spelling of .git passes.
Bug report
BUG-CVE-2014-9390 · Priority: Critical · Reported by: security
verify_path(path) returns False when ANY of these hold, True otherwise:
- path is empty or starts with "/"
- a component (split on "/") is empty, "." or ".."
- a component equals ".git" compared case-insensitively (".GIT", ".Git", ".gIt" … at any depth)
Names that merely start with .git (".gitignore", ".github") are fine. checkout() validates every path before writing any file.
Observed: cloning a repository containing .Git/config on a Mac replaced .git/config with the repository's copy.
Logs
[checkout] writing .Git/config (fs: case-insensitive)
[checkout] .git/config modified by checkoutThe code as shipped
src/checkout/paths.py (editable)
BLOCKED = ("", ".", "..", ".git")
def verify_path(path):
if path == "" or path.startswith("/"):
return False
for part in path.split("/"):
if part in BLOCKED:
return False
return True
Read-only context: src/checkout/checkout.py, src/checkout/fs.py.
Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More Python bug hunts.