From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!.POSTED!not-for-mail From: npostavs@users.sourceforge.net Newsgroups: gmane.emacs.bugs Subject: bug#16984: dired-do-rename susceptible to .../~/... hijack Date: Sat, 22 Oct 2016 22:21:20 -0400 Message-ID: <87pomrst3z.fsf@users.sourceforge.net> References: <87eh2aq60w.fsf@jidanni.org> NNTP-Posting-Host: blaine.gmane.org Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable X-Trace: blaine.gmane.org 1477189292 17049 195.159.176.226 (23 Oct 2016 02:21:32 GMT) X-Complaints-To: usenet@blaine.gmane.org NNTP-Posting-Date: Sun, 23 Oct 2016 02:21:32 +0000 (UTC) User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/25.1 (gnu/linux) Cc: 16984@debbugs.gnu.org To: =?UTF-8?Q?=E7=A9=8D=E4=B8=B9=E5=B0=BC?= Dan Jacobson Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Sun Oct 23 04:21:28 2016 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by blaine.gmane.org with esmtp (Exim 4.84_2) (envelope-from ) id 1by8PQ-0002ON-MA for geb-bug-gnu-emacs@m.gmane.org; Sun, 23 Oct 2016 04:21:12 +0200 Original-Received: from localhost ([::1]:39416 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1by8PS-0000nX-SF for geb-bug-gnu-emacs@m.gmane.org; Sat, 22 Oct 2016 22:21:14 -0400 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:57095) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1by8PJ-0000mB-RR for bug-gnu-emacs@gnu.org; Sat, 22 Oct 2016 22:21:06 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1by8PG-0003q7-Mb for bug-gnu-emacs@gnu.org; Sat, 22 Oct 2016 22:21:05 -0400 Original-Received: from debbugs.gnu.org ([208.118.235.43]:59539) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1by8PG-0003pi-I2 for bug-gnu-emacs@gnu.org; Sat, 22 Oct 2016 22:21:02 -0400 Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1by8PG-000137-9n for bug-gnu-emacs@gnu.org; Sat, 22 Oct 2016 22:21:02 -0400 X-Loop: help-debbugs@gnu.org Resent-From: npostavs@users.sourceforge.net Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org Resent-Date: Sun, 23 Oct 2016 02:21:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 16984 X-GNU-PR-Package: emacs X-GNU-PR-Keywords: Original-Received: via spool by 16984-submit@debbugs.gnu.org id=B16984.14771892503994 (code B ref 16984); Sun, 23 Oct 2016 02:21:02 +0000 Original-Received: (at 16984) by debbugs.gnu.org; 23 Oct 2016 02:20:50 +0000 Original-Received: from localhost ([127.0.0.1]:46705 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1by8P4-00012H-DC for submit@debbugs.gnu.org; Sat, 22 Oct 2016 22:20:50 -0400 Original-Received: from mail-it0-f49.google.com ([209.85.214.49]:38863) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1by8P2-000120-R2; Sat, 22 Oct 2016 22:20:49 -0400 Original-Received: by mail-it0-f49.google.com with SMTP id 66so79060682itl.1; Sat, 22 Oct 2016 19:20:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=sender:from:to:cc:subject:references:date:in-reply-to:message-id :user-agent:mime-version:content-transfer-encoding; bh=StDGif7hBnijeDg4LYpacSTQzlrPZKo54dKzUtxlB/c=; b=SQYzKTCHMwQEG66h1wnoSEbQbBp0Mo6vfRD+mh42Ui1xygYZhMYlpvf8La0hr2yndq 3sfVOX8vivDy5tCOiBRhNU3AolmSxqkaL/GGE0fVMtGTJvcL91hZk1B8Re4DgXQUHKuK +3xvm6rlYj9qCMi/sLcg8PQmQ2HYT+dK5ez7G/HbJBzpEZzUX2/RR7BBShFUT7R8ZGRx tMWSCVdBo5RqVZ05Y3iwDtF/o0AkKTuU9ebZttRlqseO2rowAndd1+t0kV5zmTWMOr2Z ZV98tE1rbsxPo25wcBF04edhiopF3pfagwVIH79JbIjE7RdxGcflqxbC6DrDicbIwO+a E+KA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:sender:from:to:cc:subject:references:date :in-reply-to:message-id:user-agent:mime-version :content-transfer-encoding; bh=StDGif7hBnijeDg4LYpacSTQzlrPZKo54dKzUtxlB/c=; b=mxwBKXsSQpeF1ppBpkVN76ySsIRRM4Ifl+yqjNOnDw2Ks56JxUBGSyKvCdMzQeo5T9 Ud42VnlqkK5/UvDxtLv2n3wFqb0oAmGysKUIOmP8UMQhJFGgYjUBItMHgmbMTo4pm0W6 kHgm8jB41KHLRjgivB2StZE10t/EQeSK6vLrQ6UW7TgOfiaNBDVgmudBcZtRJHrM+bAR VuM8FpQT6Kb20nk97QoNjsD1Gdyx1a3qka5lK4OimSpRqnaKpBexfGhG4xv3kWVM9Iu6 QMDVjnAmb4A9w0fiF8wIrzrS0ugNYAleapG8DJ6/3irD+tUAVxvqx+ky0a6trTZu/CSB mHSA== X-Gm-Message-State: ABUngvdv4VzKJnGBqOyjwsHLObaFvCjCNBslcmteHWpdccyt/lqKlh9Q4dT5tf4JR3rmkA== X-Received: by 10.36.89.206 with SMTP id p197mr7447922itb.103.1477189243113; Sat, 22 Oct 2016 19:20:43 -0700 (PDT) Original-Received: from zony ([45.2.7.130]) by smtp.googlemail.com with ESMTPSA id e6sm2865178ite.2.2016.10.22.19.20.42 (version=TLS1_2 cipher=ECDHE-RSA-CHACHA20-POLY1305 bits=256/256); Sat, 22 Oct 2016 19:20:42 -0700 (PDT) In-Reply-To: <87eh2aq60w.fsf@jidanni.org> ("=?UTF-8?Q?=E7=A9=8D=E4=B8=B9=E5=B0=BC?= Dan Jacobson"'s message of "Tue, 11 Mar 2014 02:10:07 +0800") X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] X-Received-From: 208.118.235.43 X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Original-Sender: "bug-gnu-emacs" Xref: news.gmane.org gmane.emacs.bugs:124863 Archived-At: tags 16984 confirmed found 16984 25.1 quit =E7=A9=8D=E4=B8=B9=E5=B0=BC Dan Jacobson writes: > R runs the command dired-do-rename, which is an interactive autoloaded > compiled Lisp function in `dired-aux.el'. > > Using it, I got this strange error: > > Move `/home/jidanni/.cpanm/work/1327389327.6650' to `/tmp/1327389327.6650= ' failed: > (file-error Opening output file permission denied > /home/jidanni/perl5/lib/perl5/i486-linux-gnu-thread-multi-64int/.meta/acc= essors-1.01/MYMETA.json) > > Well it turns out emacs' file name simplifying rules are being applied > in inappropriate places like when encountering > > /home/jidanni/.cpanm/work/1327389327.6650/accessors-1.01/~/perl5/lib/pe= rl5/i486-linux-gnu-thread-multi-64int/.meta/accessors-1.01: The essential problem seems to be that there is no way to escape filenames from substitute-in-file-name to protect a file named "~", therefore read-file-name-default can never return a filename in a directory with that name.