diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Tidy the test comments and shell portability
Diffstat (limited to '')
-rwxr-xr-xtests/t0109-gitconfig.sh24
1 file changed, 19 insertions, 5 deletions
diff --git a/tests/t0109-gitconfig.sh b/tests/t0109-gitconfig.sh
index 189ef28..7078596 100755
--- a/tests/t0109-gitconfig.sh
+++ b/tests/t0109-gitconfig.sh
@@ -1,8 +1,17 @@
#!/bin/sh
+# Guards the promise that cgit reads nothing out of the home directory of
+# whichever account the web server happens to run as. Every page is fetched
+# under strace with HOME pointed at a path that is known not to exist, and
+# the run fails if any access call names that path, which is how a stray
+# read of a personal gitconfig would show up.
+
test_description='Ensure that git does not access $HOME'
. ./setup.sh
+# strace needs ptrace, which containers and hardened kernels refuse even
+# where the binary is installed, so a working run is checked as well as a
+# present binary.
test -n "$(which strace 2>/dev/null)" || {
skip_all='Skipping access validation tests: strace not found'
test_done
@@ -16,16 +25,21 @@ strace true 2>/dev/null || {
}
test_no_home_access () {
- non_existent_path="/path/to/some/place/that/does/not/possibly/exist"
- while test -d "$non_existent_path"; do
- non_existent_path="$non_existent_path/$(date +%N)"
+ # A home that happened to exist would be one git may legitimately
+ # read, leaving the check below with nothing to catch, so extend the
+ # path until nothing is there.
+ missing_home="/path/to/some/place/that/does/not/possibly/exist"
+ depth=0
+ while test -d "$missing_home"; do
+ depth=$((depth + 1))
+ missing_home="$missing_home/$depth"
done &&
strace \
- -E HOME="$non_existent_path" \
+ -E HOME="$missing_home" \
-E CGIT_CONFIG="$PWD/cgitrc" \
-E QUERY_STRING="url=$1" \
-e access -f -o strace.out cgit &&
- ! grep "$non_existent_path" strace.out
+ ! grep "$missing_home" strace.out
}
test_no_home_access_success() {