[Freeciv-Dev] [bug #18781] /save - strips everything from dot to eol
Update of bug #18781 (project freeciv): Status: Ready For Test = Fixed Assigned to:None = cazfi Open/Closed:Open = Closed ___ Reply to this item at: http://gna.org/bugs/?18781 ___ Message sent via/by Gna! http://gna.org/ ___ Freeciv-dev mailing list Freeciv-dev@gna.org https://mail.gna.org/listinfo/freeciv-dev
[Freeciv-Dev] [bug #18781] /save - strips everything from dot to eol
Update of bug #18781 (project freeciv): Planned Release: 2.3.3, 2.4.0, 2.5.0 = 2.2.8, 2.3.3, 2.4.0, 2.5.0 ___ Follow-up Comment #5: Attached new version for branches earlier than S2_4. To be pedantic, .xz is not known suffix there as .xz compression support was added in 2.4 only. (file #15472) ___ Additional Item Attachment: File name: StripOnlyKnownExtensions-S2_3-2.diff Size:0 KB ___ Reply to this item at: http://gna.org/bugs/?18781 ___ Message sent via/by Gna! http://gna.org/ ___ Freeciv-dev mailing list Freeciv-dev@gna.org https://mail.gna.org/listinfo/freeciv-dev
[Freeciv-Dev] [bug #18781] /save - strips everything from dot to eol
Update of bug #18781 (project freeciv): Category:None = general Status:None = Ready For Test Planned Release: = 2.3.3, 2.4.0, 2.5.0 ___ Follow-up Comment #4: Attached patch makes extension stripping to remove only those known extensions that refer to savegame format and which are automatically added (back) by lower level save function. (file #15446) ___ Additional Item Attachment: File name: StripOnlyKnownExtensions.diff Size:0 KB ___ Reply to this item at: http://gna.org/bugs/?18781 ___ Message sent via/by Gna! http://gna.org/ ___ Freeciv-dev mailing list Freeciv-dev@gna.org https://mail.gna.org/listinfo/freeciv-dev
[Freeciv-Dev] [bug #18781] /save - strips everything from dot to eol
Follow-up Comment #2, bug #18781 (project freeciv): I don't understand how this helps with security. Is it supposed to prevent escaping from a save directory? ___ Reply to this item at: http://gna.org/bugs/?18781 ___ Message sent via/by Gna! http://gna.org/ ___ Freeciv-dev mailing list Freeciv-dev@gna.org https://mail.gna.org/listinfo/freeciv-dev
[Freeciv-Dev] [bug #18781] /save - strips everything from dot to eol
Follow-up Comment #3, bug #18781 (project freeciv): For normal users it is OK if the savegame is saved in the standard dirs I don't think this report has anything to do with directories. It's security feature that you cannot escape from savedirs, but this seem like everything after dot is considered part of suffix. It's correct to strip .sav, .sav.gz, .sav.bz2, or .sav.xz as those are again added by the actual saving functions, but .necomer should not be stripped. ___ Reply to this item at: http://gna.org/bugs/?18781 ___ Message sent via/by Gna! http://gna.org/ ___ Freeciv-dev mailing list Freeciv-dev@gna.org https://mail.gna.org/listinfo/freeciv-dev
[Freeciv-Dev] [bug #18781] /save - strips everything from dot to eol
Follow-up Comment #1, bug #18781 (project freeciv): Is this deliberate? I think it is (security?). If so, /help save does not say anything about it. For normal users it is OK if the savegame is saved in the standard dirs (if I remeber correctly it is the current directory for the build dir or ./freeciv/save for an installed version of freeciv) ___ Reply to this item at: http://gna.org/bugs/?18781 ___ Nachricht geschickt von/durch Gna! http://gna.org/ ___ Freeciv-dev mailing list Freeciv-dev@gna.org https://mail.gna.org/listinfo/freeciv-dev
[Freeciv-Dev] [bug #18781] /save - strips everything from dot to eol
URL: http://gna.org/bugs/?18781 Summary: /save - strips everything from dot to eol Project: Freeciv Submitted by: akfaew Submitted on: Mon Oct 3 09:40:21 2011 Category: None Severity: 3 - Normal Priority: 5 - Normal Status: None Assigned to: None Originator Email: Open/Closed: Open Release: Discussion Lock: Any Operating System: None Planned Release: ___ Details: /save 111003.newcomer [11:34:ttypn][longturn@spock:~/server:3]$ ls -lrt ltex2.3/save/ ... -rw-r--r-- 1 longturn longturn625940 Oct 3 11:28 111003.sav.gz Is this deliberate? If so, /help save does not say anything about it. ___ Reply to this item at: http://gna.org/bugs/?18781 ___ Message sent via/by Gna! http://gna.org/ ___ Freeciv-dev mailing list Freeciv-dev@gna.org https://mail.gna.org/listinfo/freeciv-dev