mc/lib/vfs/mc-vfs
Slava Zanko 7ea4dfb4ca Ticket #1902: (reopened defect) Possible security risk in mcserv.c
Comment by Oswald Buddenhagen:
first, you decided to ignore my advice about not
obfuscating the code with nonsense-checks, and on top of that you
broke the string comparison (just see what happens when you try a user
named "ftpmaster").

This commit contain changes for respect this critic.

Signed-off-by: Slava Zanko <slavazanko@gmail.com>
2010-02-05 17:36:19 +02:00
..
extfs Ticket #1921: Fix lslR VFS 2010-02-02 22:25:54 +02:00
samba Reorganized pathes to files in '#include' directives 2010-01-26 10:30:22 +02:00
.gitignore Moved dir $(srcdir)/vfs into $(srcdir)/lib/vfs/mc-vfs 2010-01-26 10:30:21 +02:00
COPYING.LGPL Moved dir $(srcdir)/vfs into $(srcdir)/lib/vfs/mc-vfs 2010-01-26 10:30:21 +02:00
cpio.c Changes for build after moving util.[ch] 2010-01-26 10:30:24 +02:00
direntry.c Ticket #1990: code cleanup before 4.7.0.2 release. 2010-02-02 21:45:05 +03:00
extfs.c Reorganization of sources. Part 1. 2010-01-26 10:30:23 +02:00
fish.c Moved strecape.[ch] into library 2010-01-26 10:30:25 +02:00
fish.h Moved dir $(srcdir)/vfs into $(srcdir)/lib/vfs/mc-vfs 2010-01-26 10:30:21 +02:00
ftpfs.c Move all interface includes from subdirs lib/*/*.h into lib/*.h 2010-01-26 10:30:25 +02:00
ftpfs.h Moved dir $(srcdir)/vfs into $(srcdir)/lib/vfs/mc-vfs 2010-01-26 10:30:21 +02:00
gc.c Reorganization of sources. Part 1. 2010-01-26 10:30:23 +02:00
gc.h Moved dir $(srcdir)/vfs into $(srcdir)/lib/vfs/mc-vfs 2010-01-26 10:30:21 +02:00
HACKING Moved dir $(srcdir)/vfs into $(srcdir)/lib/vfs/mc-vfs 2010-01-26 10:30:21 +02:00
local.c Reorganization of sources. Part 1. 2010-01-26 10:30:23 +02:00
local.h Moved dir $(srcdir)/vfs into $(srcdir)/lib/vfs/mc-vfs 2010-01-26 10:30:21 +02:00
Makefile.am Reorganized pathes to files in '#include' directives 2010-01-26 10:30:22 +02:00
mcfs.c Reorganization of sources. Part 1. 2010-01-26 10:30:23 +02:00
mcfs.h Moved dir $(srcdir)/vfs into $(srcdir)/lib/vfs/mc-vfs 2010-01-26 10:30:21 +02:00
mcfsutil.c Ticket #1925: Fixed conditional compile of mcserver 2010-01-27 21:56:46 +01:00
mcfsutil.h Moved dir $(srcdir)/vfs into $(srcdir)/lib/vfs/mc-vfs 2010-01-26 10:30:21 +02:00
mcserv.c Ticket #1902: (reopened defect) Possible security risk in mcserv.c 2010-02-05 17:36:19 +02:00
netutil.c Reorganization of sources. Part 1. 2010-01-26 10:30:23 +02:00
netutil.h Moved dir $(srcdir)/vfs into $(srcdir)/lib/vfs/mc-vfs 2010-01-26 10:30:21 +02:00
README Moved dir $(srcdir)/vfs into $(srcdir)/lib/vfs/mc-vfs 2010-01-26 10:30:21 +02:00
README.fish Moved dir $(srcdir)/vfs into $(srcdir)/lib/vfs/mc-vfs 2010-01-26 10:30:21 +02:00
sfs.c Reorganization of sources. Part 1. 2010-01-26 10:30:23 +02:00
smbfs.c Reorganization of sources. Part 1. 2010-01-26 10:30:23 +02:00
smbfs.h Moved dir $(srcdir)/vfs into $(srcdir)/lib/vfs/mc-vfs 2010-01-26 10:30:21 +02:00
tar.c Reorganization of sources. Part 1. 2010-01-26 10:30:23 +02:00
undelfs.c Reorganization of sources. Part 1. 2010-01-26 10:30:23 +02:00
utilvfs.c Changes for build after moving util.[ch] 2010-01-26 10:30:24 +02:00
utilvfs.h Reorganization of sources. Part 1. 2010-01-26 10:30:23 +02:00
vfs-impl.h Reorganization of sources. Part 1. 2010-01-26 10:30:23 +02:00
vfs.c patches for AIX with ncurses support 2010-01-27 10:04:38 +02:00
vfs.h Moved dir $(srcdir)/vfs into $(srcdir)/lib/vfs/mc-vfs 2010-01-26 10:30:21 +02:00
xdirentry.h Moved dir $(srcdir)/vfs into $(srcdir)/lib/vfs/mc-vfs 2010-01-26 10:30:21 +02:00

NOTE: Although vfs has been meant to be implemented as a separate
entity redistributable under the LGPL in its current implementation it
uses GPLed code from src/. So there are two possibilities if you want
to use vfs:

1. Distribute your copy of vfs under the GPL. Then you can freely
include the GPLed functions from the rest of the mc source code.

2. Distribute your copy of vfs under the LGPL. Then you cannot include
the functions outside the vfs subdirectory. You must then either
rewrite them or work around them in other ways.

========================================================================

Hi!

I'm midnight commander's vfs layer. Before you start hacking me,
please read this file. I'm integral part of midnight commander, but I
try to go out and live my life myself as a shared library, too. That
means that I should try to use as little functions from midnight as
possible (so I'm tiny, nice and people like me), that I should not
pollute name space by unnecessary symbols (so I do not crash fellow
programs) and that I should have a clean interface between myself and
midnight.

Because I'm rather close to midnight, try to:

* Keep the indentation as the rest of the code. Following could help
you with your friend emacs:

(defun mc-c-mode ()
	"C mode with adjusted defaults for use with the Midnight commander."
	(interactive)
	(c-mode)
	(c-set-style "K&R")
	(setq	c-indent-level 4
		c-continued-statement-offset 4
		c-brace-offset 0
		c-argdecl-indent 4
		c-label-offset -4
		c-brace-imaginary-offset 0
		c-continued-brace-offset 0
		c-tab-always-indent nil
		c-basic-offset 4
		tab-width 8
		comment-column 60))

(setq auto-mode-alist (cons '(".*/mc/.*\\.[ch]$" . mc-c-mode)
                       auto-mode-alist))

And because I'm trying to live life on my own as libvfs.so, try to:

* Make sure all exported symbols are defined in vfs.h and begin with
'vfs_'.

* Do not make any references from midnight into modules like tar. It
would probably pollute name space and midnight would depend on concrete
configuration of libvfs. mc_setctl() and mc_ctl() are your
friends. (And mine too :-).

							 Pavel Machek
							 pavel@ucw.cz

PS: If you'd like to use my features in whole operating system, you
might want to link me to rpc.nfsd. On
http://atrey.karlin.mff.cuni.cz/~pavel/podfuk/podfuk.html you'll find
how to do it.

PPS: I have a friend, shared library called avfs, which is LD_PRELOAD
capable. You can reach her at http://www.inf.bme.hu/~mszeredi/avfs.