go/src
Julie Qiu 5ebd862b17 [release-branch.go1.18] path/filepath: fix stack exhaustion in Glob
A limit is added to the number of path separators allowed by an input to
Glob, to prevent stack exhaustion issues.

Thanks to Juho Nurminen of Mattermost who reported the issue.

Fixes #53714
Updates #53416
Fixes CVE-2022-30632

Change-Id: I1b9fd4faa85411a05dbc91dceae1c0c8eb021f07
Reviewed-on: https://team-review.git.corp.google.com/c/golang/go-private/+/1498176
Reviewed-by: Roland Shoemaker <bracewell@google.com>
(cherry picked from commit d182a6d1217fd0d04c9babfa9a7ccd3515435c39)
Reviewed-on: https://go-review.googlesource.com/c/go/+/417059
TryBot-Result: Gopher Robot <gobot@golang.org>
Reviewed-by: Heschi Kreinick <heschi@google.com>
Run-TryBot: Michael Knyszek <mknyszek@google.com>
2022-07-12 15:06:43 +00:00
..
archive all: add a handful of fuzz targets 2022-01-13 18:06:33 +00:00
bufio all: fix typo in comment 2021-12-15 19:56:22 +00:00
builtin builtin: clarify that interface types do not implement comparable 2022-02-08 21:59:36 +00:00
bytes [release-branch.go1.18] bytes: restore old Trim/TrimLeft behavior for nil 2022-03-30 16:42:29 +00:00
cmd [release-branch.go1.18] cmd/compile: only check implicit dots for method call enabled by a type bound 2022-07-07 17:30:11 +00:00
compress [release-branch.go1.18] compress/gzip: fix stack exhaustion bug in Reader.Read 2022-07-12 15:06:32 +00:00
container all: gofmt -w -r 'interface{} -> any' src 2021-12-13 18:45:54 +00:00
context all: gofmt -w -r 'interface{} -> any' src 2021-12-13 18:45:54 +00:00
crypto [release-branch.go1.18] crypto/tls: avoid extra allocations in steady-state Handshake calls 2022-05-27 14:59:08 +00:00
database/sql database/sql: make WAIT tests more robust, rely on waiter trigger 2022-02-16 18:05:27 +00:00
debug runtime/debug: replace (*BuildInfo).Marshal methods with Parse and String 2022-02-09 19:44:03 +00:00
embed all: gofmt -w -r 'interface{} -> any' src 2021-12-13 18:45:54 +00:00
encoding [release-branch.go1.18] encoding/xml: limit depth of nesting in unmarshal 2022-07-12 15:06:21 +00:00
errors all: gofmt -w -r 'interface{} -> any' src 2021-12-13 18:45:54 +00:00
expvar all: gofmt -w -r 'interface{} -> any' src 2021-12-13 18:45:54 +00:00
flag all: gofmt -w -r 'interface{} -> any' src 2021-12-13 18:45:54 +00:00
fmt all: gofmt -w -r 'interface{} -> any' src 2021-12-13 18:45:54 +00:00
go [release-branch.go1.18] go/parser: limit recursion depth 2022-07-12 15:06:26 +00:00
hash
html all: gofmt -w -r 'interface{} -> any' src 2021-12-13 18:45:54 +00:00
image all: add a handful of fuzz targets 2022-01-13 18:06:33 +00:00
index/suffixarray
internal [release-branch.go1.18] internal/fuzz: minimization should not reduce coverage 2022-03-14 16:31:27 +00:00
io [release-branch.go1.18] io/fs: fix stack exhaustion in Glob 2022-07-12 15:06:37 +00:00
log all: gofmt -w -r 'interface{} -> any' src 2021-12-13 18:45:54 +00:00
math math/big: prevent overflow in (*Rat).SetString 2022-01-27 21:25:18 +00:00
mime all: gofmt -w -r 'interface{} -> any' src 2021-12-13 18:45:54 +00:00
net [release-branch.go1.18] net/http: preserve nil values in Header.Clone 2022-07-12 14:51:53 +00:00
os [release-branch.go1.18] os/exec: return clear error for missing cmd.Path 2022-05-27 14:57:10 +00:00
path [release-branch.go1.18] path/filepath: fix stack exhaustion in Glob 2022-07-12 15:06:43 +00:00
plugin all: gofmt -w -r 'interface{} -> any' src 2021-12-13 18:45:54 +00:00
reflect [release-branch.go1.18] reflect: ensure map keys match key type in MapIndex and SetMapIndex 2022-05-09 20:23:04 +00:00
regexp regexp/syntax: reject very deeply nested regexps in Parse 2022-02-10 15:23:05 +00:00
runtime [release-branch.go1.18] runtime: add race annotations to cbs.lock 2022-07-06 20:16:26 +00:00
sort all: gofmt -w -r 'interface{} -> any' src 2021-12-13 18:45:54 +00:00
strconv
strings strings: fix typo in comment 2022-02-19 00:00:52 +00:00
sync [release-branch.go1.18] sync/atomic: use consistent first-store-in-progress marker 2022-05-09 20:12:59 +00:00
syscall [release-branch.go1.18] syscall: check correct group in Faccessat 2022-05-09 20:17:54 +00:00
testdata
testing testing: panic in Fuzz if the function returns a value 2022-02-16 16:06:39 +00:00
text [release-branch.go1.18] text/template/parse: allow space after continue or break 2022-05-26 17:27:08 +00:00
time time: document that Parse truncates to nanosecond precision 2022-02-15 22:54:38 +00:00
unicode
unsafe
vendor all: update vendored golang.org/x/crypto for cryptobyte fix 2021-12-21 19:17:52 +00:00
Make.dist
README.vendor
all.bash
all.bat
all.rc
bootstrap.bash
buildall.bash
clean.bash
clean.bat
clean.rc
cmp.bash
go.mod all: update vendored golang.org/x/crypto for cryptobyte fix 2021-12-21 19:17:52 +00:00
go.sum all: update vendored golang.org/x/crypto for cryptobyte fix 2021-12-21 19:17:52 +00:00
make.bash
make.bat
make.rc
race.bash
race.bat
run.bash
run.bat
run.rc

README.vendor

Vendoring in std and cmd
========================

The Go command maintains copies of external packages needed by the
standard library in the src/vendor and src/cmd/vendor directories.

In GOPATH mode, imports of vendored packages are resolved to these
directories following normal vendor directory logic
(see golang.org/s/go15vendor).

In module mode, std and cmd are modules (defined in src/go.mod and
src/cmd/go.mod). When a package outside std or cmd is imported
by a package inside std or cmd, the import path is interpreted
as if it had a "vendor/" prefix. For example, within "crypto/tls",
an import of "golang.org/x/crypto/cryptobyte" resolves to
"vendor/golang.org/x/crypto/cryptobyte". When a package with the
same path is imported from a package outside std or cmd, it will
be resolved normally. Consequently, a binary may be built with two
copies of a package at different versions if the package is
imported normally and vendored by the standard library.

Vendored packages are internally renamed with a "vendor/" prefix
to preserve the invariant that all packages have distinct paths.
This is necessary to avoid compiler and linker conflicts. Adding
a "vendor/" prefix also maintains the invariant that standard
library packages begin with a dotless path element.

The module requirements of std and cmd do not influence version
selection in other modules. They are only considered when running
module commands like 'go get' and 'go mod vendor' from a directory
in GOROOT/src.

Maintaining vendor directories
==============================

Before updating vendor directories, ensure that module mode is enabled.
Make sure GO111MODULE=off is not set ('on' or 'auto' should work).

Requirements may be added, updated, and removed with 'go get'.
The vendor directory may be updated with 'go mod vendor'.
A typical sequence might be:

    cd src
    go get -d golang.org/x/net@latest
    go mod tidy
    go mod vendor

Use caution when passing '-u' to 'go get'. The '-u' flag updates
modules providing all transitively imported packages, not only
the module providing the target package.

Note that 'go mod vendor' only copies packages that are transitively
imported by packages in the current module. If a new package is needed,
it should be imported before running 'go mod vendor'.