# HG changeset patch # User Matt Mackall # Date 1230762440 21600 # Node ID 71be8688f2dbbf2a38eca7a80aabc7763884f68f # Parent e8b818029ed6a6e90ad22f4ba489cfae071993ac audit: reject paths with .hg (issue 1450) Spotted by Peter Arrenbrecht diff -r e8b818029ed6 -r 71be8688f2db mercurial/util.py --- a/mercurial/util.py Wed Dec 31 14:21:00 2008 +0100 +++ b/mercurial/util.py Wed Dec 31 16:27:20 2008 -0600 @@ -814,9 +814,15 @@ return normpath = os.path.normcase(path) parts = splitpath(normpath) - if (os.path.splitdrive(path)[0] or parts[0] in ('.hg', '') + if (os.path.splitdrive(path)[0] or parts[0] in ('.hg', '.hg.', '') or os.pardir in parts): raise Abort(_("path contains illegal component: %s") % path) + if '.hg' in path: + for p in '.hg', '.hg.': + if p in parts[1:-1]: + pos = parts.index(p) + base = os.path.join(*parts[:pos]) + raise Abort(_('path %r is inside repo %r') % (path, base)) def check(prefix): curpath = os.path.join(self.root, prefix) try: