Re: git-annex security update ready for testing and review

2018-09-06 Thread Joey Hess
Antoine Beaupré wrote: > I'm now more confident the patchset is complete. There are one tiny bit > I'm still slightly unsure of. In Command.Reinject.perform, there was a > `boolSystem "mv"` call lying around that was turned into a `moveFile` > some time between the jessie version and 2fb3722ce. I f

Re: git-annex security update ready for testing and review

2018-08-28 Thread Joey Hess
Antoine Beaupré wrote: > It was challenging work, especially for the two main patches. > > The first big patch is "limit url downloads to whitelisted schemes": > > http://source.git-annex.branchable.com/?p=source.git;a=commitdiff;h=28720c795ff57a55b48e56d15f9b6bcb977f48d9 > > The main challenge