diff options
| author | Bryce Kwon <bryce@brycekwon.com> | |
|---|---|---|
| committer | Bryce Kwon <bryce@brycekwon.com> | |
| commit | ||
| parent | ||
| tree | ||
| download | ||
Harden the request path, scan and error recovery
Diffstat (limited to '')
| -rwxr-xr-x | tests/t0301-security.sh | 31 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
1 file changed, 26 insertions, 5 deletions
diff --git a/tests/t0301-security.sh b/tests/t0301-security.sh index 6d6d493..ece60f1 100755 --- a/tests/t0301-security.sh +++ b/tests/t0301-security.sh @@ -242,11 +242,12 @@ test_expect_success 'name-sorted branches are unaffected' ' grep "</html>" tmp ' -# module-link is a template and scan-path lets a repository set its own from -# a cgitrc in the tree, so handing that string to printf let the owner of a -# scanned repository crash the process, or read stack memory into the served -# page, merely by adding conversions past the two that are filled. The tests -# after the fixture also pin down the templates that must keep working. +# module-link is a template and a trusted scan lets a repository set its own +# from a cgitrc in the tree, so handing that string to printf let the owner +# of a scanned repository crash the process, or read stack memory into the +# served page, merely by adding conversions past the two that are filled. +# The tests after the fixture also pin down the templates that must keep +# working. test_expect_success 'set up a submodule fixture with a hostile module-link' ' mkrepo repos/modlink 1 && ( @@ -261,6 +262,7 @@ test_expect_success 'set up a submodule fixture with a hostile module-link' ' { echo "virtual-root=/" && echo "cache-size=0" && + echo "trust-scan-config=1" && echo "scan-path=$PWD/scan" } >modlinkrc ' @@ -313,6 +315,25 @@ test_expect_success 'a doubled percent in a module-link renders as one' ' grep "href=./m/submod/%/$sub." tmp ' +# An unknown page under a repository used to reach the page header with no +# head resolved and crash in the branch switcher. +test_expect_success 'an unknown page under a repository answers 404 with its header' ' + cgit_url "foo/nonsense/" >tmp && + grep "^Status: 404 Not Found" tmp && + grep "Invalid request" tmp && + grep "<select name=.h. " tmp +' + +test_expect_success 'a clone endpoint with http clone off answers the same way' ' + { + echo "enable-http-clone=0" && + cat cgitrc + } >noclonerc && + CGIT_CONFIG="$PWD/noclonerc" QUERY_STRING="url=foo/info/refs" cgit >tmp && + grep "^Status: 404 Not Found" tmp && + grep "<select name=.h. " tmp +' + # The .gitmodules file is commit-controlled content, so a derived link may # carry any scheme and any byte an author can commit. Only http and https # may reach an href, and everything lands attribute-escaped. |
