|
|
Message-ID: <d1f1537a-07f1-460c-ae24-24981538fd24@gmail.com>
Date: Thu, 8 Oct 2026 22:18:20 -0400
From: Demi Marie Obenour <demiobenour@...il.com>
To: musl@...ts.openwall.com, Rich Felker <dalias@...c.org>
Subject: Re: fnmatch: invalid multibyte sequence in the string is taken
as end of string ("" matches "\xff" in UTF-8 locales)
On 10/8/26 21:46, Rich Felker wrote:
> On Fri, Oct 09, 2026 at 12:25:31PM +1100, raf wrote:
>> On Thu, Oct 08, 2026 at 09:44:20PM +0200, Thorsten Glaser <tg@...bsd.de> wrote:
>>
>>> On Thu, 8 Oct 2026, Rich Felker wrote:
>>>
>>>> Putting byte strings that are not valid characters into filenames is
>>>> generally not a supported usage (by musl or by the standards).
>>>
>>> It is, in POSIX. Filenames are indeed just bytes, not characters;
>>> arbitrary bytes except slash and NUL.
>>>
>>> bye,
>>> //mirabilos
>>> --
>>> “It is inappropriate to require that a time represented as
>>> seconds since the Epoch precisely represent the number of
>>> seconds between the referenced time and the Epoch.”
>>> -- IEEE Std 1003.1b-1993 (POSIX) Section B.2.2.2
>>
>> Linux, FreeBSD, OpenBSD, NetBSD, and Solaris allow binary filenames.
>> Windows/Cygwin and macOS are the only systems I have that require them
>> to be text.
>>
>> Also, if one user's locale uses UTF-8, and another user on the same
>> system uses a Latin-1 locale, there can be text filenames created
>> by one user that look like binary to the other user.
>
> A musl-based system doesn't have users with latin-1 locales because it
> does not have latin-1 locales.
>
> "All text is UTF-8" was one of the founding principles of musl. That's
> why we have iconv interfaces to support reading/converting legacy data
> (and in some cases, speaking it over legacy protocols) but don't have
> any way to use these as the multibyte encoding.
>
> Yes it's possible to use hybrid system with multiple libcs present in
> the same filesystem. It's now 2026 and the advisible way to do this
> even 15 years ago when musl first appeared was to use UTF-8 for all of
> them. If you really insist on not doing that, nobody can stop you, but
> it's not usage the project aims to facilitate.
>
> Rich
I agree that filenames *should* be UTF-8, but there is no guarantee
that they *are*. Worse, filenames are sometimes attacker-controlled,
in which case an attacker could *deliberately* use a filename that
is not valid UTF-8 as part of an exploit.
For instance, `rm -rf ./* ./.[!.]* ./..?*` should remove all files
and folders in the current directory, regardless of the current
locale.
--
Sincerely,
Demi Marie Obenour (she/her/hers)
Download attachment "OpenPGP_signature.asc" of type "application/pgp-signature" (834 bytes)
Powered by blists - more mailing lists
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.