diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Harden the request path, scan and error recovery
Diffstat (limited to '')
-rwxr-xr-xtests/t0301-security.sh31
1 file changed, 26 insertions, 5 deletions
diff --git a/tests/t0301-security.sh b/tests/t0301-security.sh
index 6d6d493..ece60f1 100755
--- a/tests/t0301-security.sh
+++ b/tests/t0301-security.sh
@@ -242,11 +242,12 @@ test_expect_success 'name-sorted branches are unaffected' '
grep "</html>" tmp
'
-# module-link is a template and scan-path lets a repository set its own from
-# a cgitrc in the tree, so handing that string to printf let the owner of a
-# scanned repository crash the process, or read stack memory into the served
-# page, merely by adding conversions past the two that are filled. The tests
-# after the fixture also pin down the templates that must keep working.
+# module-link is a template and a trusted scan lets a repository set its own
+# from a cgitrc in the tree, so handing that string to printf let the owner
+# of a scanned repository crash the process, or read stack memory into the
+# served page, merely by adding conversions past the two that are filled.
+# The tests after the fixture also pin down the templates that must keep
+# working.
test_expect_success 'set up a submodule fixture with a hostile module-link' '
mkrepo repos/modlink 1 &&
(
@@ -261,6 +262,7 @@ test_expect_success 'set up a submodule fixture with a hostile module-link' '
{
echo "virtual-root=/" &&
echo "cache-size=0" &&
+ echo "trust-scan-config=1" &&
echo "scan-path=$PWD/scan"
} >modlinkrc
'
@@ -313,6 +315,25 @@ test_expect_success 'a doubled percent in a module-link renders as one' '
grep "href=./m/submod/%/$sub." tmp
'
+# An unknown page under a repository used to reach the page header with no
+# head resolved and crash in the branch switcher.
+test_expect_success 'an unknown page under a repository answers 404 with its header' '
+ cgit_url "foo/nonsense/" >tmp &&
+ grep "^Status: 404 Not Found" tmp &&
+ grep "Invalid request" tmp &&
+ grep "<select name=.h. " tmp
+'
+
+test_expect_success 'a clone endpoint with http clone off answers the same way' '
+ {
+ echo "enable-http-clone=0" &&
+ cat cgitrc
+ } >noclonerc &&
+ CGIT_CONFIG="$PWD/noclonerc" QUERY_STRING="url=foo/info/refs" cgit >tmp &&
+ grep "^Status: 404 Not Found" tmp &&
+ grep "<select name=.h. " tmp
+'
+
# The .gitmodules file is commit-controlled content, so a derived link may
# carry any scheme and any byte an author can commit. Only http and https
# may reach an href, and everything lands attribute-escaped.