Go to file
Christian Halstrick a09b1b6c3d ObjectChecker: Disallow Windows shortname "GIT~1"
Windows creates shortnames for all non-8.3 files (see [1]). Hence we
need to disallow all names which could potentially be a shortname for
".git". Example: in an empty directory create a folder "GIT~1". Now you
can't create another folder ".git".

The path "GIT~1" may map to ".git" on Windows. A potential victim to
such an attack first has to initialize a git repository in order to
receive any git commits. Hence the .git folder created by init will get
the shortname "GIT~1". ".git" will only get a different shortname if the
user has created a file "GIT~1" before initialization of the git
repository.

[1] http://en.wikipedia.org/wiki/8.3_filename

Change-Id: I9978ab8f2d2951c46c1b9bbde57986d64d26b9b2
Signed-off-by: Christian Halstrick <christian.halstrick@sap.com>
Signed-off-by: Matthias Sohn <matthias.sohn@sap.com>
2014-12-18 14:49:17 +01:00
org.eclipse.jgit ObjectChecker: Disallow Windows shortname "GIT~1" 2014-12-18 14:49:17 +01:00
org.eclipse.jgit.ant Prepare 3.4.2-SNAPSHOT builds 2014-06-21 00:57:43 +02:00
org.eclipse.jgit.ant.test Prepare 3.4.2-SNAPSHOT builds 2014-06-21 00:57:43 +02:00
org.eclipse.jgit.archive Prepare 3.4.2-SNAPSHOT builds 2014-06-21 00:57:43 +02:00
org.eclipse.jgit.console Prepare 3.4.2-SNAPSHOT builds 2014-06-21 00:57:43 +02:00
org.eclipse.jgit.http.apache Apache HttpClientConnection: replace calls to deprecated LocalFile() 2014-11-26 01:35:59 +01:00
org.eclipse.jgit.http.server Prepare 3.4.2-SNAPSHOT builds 2014-06-21 00:57:43 +02:00
org.eclipse.jgit.http.test Prepare 3.4.2-SNAPSHOT builds 2014-06-21 00:57:43 +02:00
org.eclipse.jgit.java7 Prepare 3.4.2-SNAPSHOT builds 2014-06-21 00:57:43 +02:00
org.eclipse.jgit.java7.test Prepare 3.4.2-SNAPSHOT builds 2014-06-21 00:57:43 +02:00
org.eclipse.jgit.junit Prepare 3.4.2-SNAPSHOT builds 2014-06-21 00:57:43 +02:00
org.eclipse.jgit.junit.http Prepare 3.4.2-SNAPSHOT builds 2014-06-21 00:57:43 +02:00
org.eclipse.jgit.packaging Prepare 3.4.2-SNAPSHOT builds 2014-06-21 00:57:43 +02:00
org.eclipse.jgit.pgm Prepare 3.4.2-SNAPSHOT builds 2014-06-21 00:57:43 +02:00
org.eclipse.jgit.pgm.test Prepare 3.4.2-SNAPSHOT builds 2014-06-21 00:57:43 +02:00
org.eclipse.jgit.test ObjectChecker: Disallow Windows shortname "GIT~1" 2014-12-18 14:49:17 +01:00
org.eclipse.jgit.ui Prepare 3.4.2-SNAPSHOT builds 2014-06-21 00:57:43 +02:00
tools Add script to create JGit release 2014-05-21 20:10:19 +02:00
.eclipse_iplog Update Eclipse IP log for 1.0 2011-05-25 20:14:35 +02:00
.gitattributes Initial JGit contribution to eclipse.org 2009-09-29 16:47:03 -07:00
.gitignore Ignore /target 2012-03-05 21:11:57 -08:00
LICENSE Clean up LICENSE file 2010-07-02 14:52:49 -07:00
README.md Implement recursive merge strategy 2013-02-22 23:51:50 +01:00
SUBMITTING_PATCHES Correcting explanation of EDL 2009-10-28 14:12:07 +01:00
pom.xml Prepare 3.4.2-SNAPSHOT builds 2014-06-21 00:57:43 +02:00

README.md

Java Git

An implementation of the Git version control system in pure Java.

This package is licensed under the EDL (Eclipse Distribution License).

  • org.eclipse.jgit

    A pure Java library capable of being run standalone, with no additional support libraries. It provides classes to read and write a Git repository and operate on a working directory.

    All portions of jgit are covered by the EDL. Absolutely no GPL, LGPL or EPL contributions are accepted within this package.

  • org.eclipse.jgit.ant

    Ant tasks based on JGit.

  • org.eclipse.jgit.http.server

    Server for the smart and dumb Git HTTP protocol.

  • org.eclipse.jgit.pgm

    Command-line interface Git commands implemented using JGit ("pgm" stands for program).

  • org.eclipse.jgit.test

    Unit tests for org.eclipse.jgit and the same licensing rules.

Warnings/Caveats

  • Symbolic links are not supported because java does not support it. Such links could be damaged.

  • Only the timestamp of the index is used by jgit check if the index is dirty.

  • Don't try the library with a JDK other than 1.6 (Java 6) unless you are prepared to investigate problems yourself. JDK 1.5.0_11 and later Java 5 versions may work. Earlier versions do not. JDK 1.4 is not supported. Apple's Java 1.5.0_07 is reported to work acceptably. We have no information about other vendors. Please report your findings if you try.

  • CRLF conversion is performed depending on the core.autocrlf setting, however Git for Windows by default stores that setting during installation in the "system wide" configuration file. If Git is not installed, use the global or repository configuration for the core.autocrlf setting.

  • The system wide configuration file is located relative to where C Git is installed. Make sure Git can be found via the PATH environment variable. When installing Git for Windows check the "Run Git from the Windows Command Prompt" option. There are other options like the jgit.gitprefix system propety or Eclipse settings that can be used for pointing out where C Git is installed. Modifying PATH is the recommended option if C Git is installed.

  • We try to use the same notation of $HOME as C Git does. On Windows this is often not same value as the user.home system property.

Package Features

  • org.eclipse.jgit/

    • Read loose and packed commits, trees, blobs, including deltafied objects.

    • Read objects from shared repositories

    • Write loose commits, trees, blobs.

    • Write blobs from local files or Java InputStreams.

    • Read blobs as Java InputStreams.

    • Copy trees to local directory, or local directory to a tree.

    • Lazily loads objects as necessary.

    • Read and write .git/config files.

    • Create a new repository.

    • Read and write refs, including walking through symrefs.

    • Read, update and write the Git index.

    • Checkout in dirty working directory if trivial.

    • Walk the history from a given set of commits looking for commits introducing changes in files under a specified path.

    • Object transport Fetch via ssh, git, http, Amazon S3 and bundles. Push via ssh, git and Amazon S3. JGit does not yet deltify the pushed packs so they may be a lot larger than C Git packs.

  • org.eclipse.jgit.pgm/

    • Assorted set of command line utilities. Mostly for ad-hoc testing of jgit log, glog, fetch etc.

Missing Features

There are some missing features:

  • gitattributes support

Support

Post question, comments or patches to the jgit-dev@eclipse.org mailing list. You need to be subscribed to post, see here:

https://dev.eclipse.org/mailman/listinfo/jgit-dev

Contributing

See the EGit Contributor Guide:

http://wiki.eclipse.org/EGit/Contributor_Guide

About Git

More information about Git, its repository format, and the canonical C based implementation can be obtained from the Git website:

http://git-scm.com/