diff options
| author | Bryce Kwon <bryce@brycekwon.com> | |
|---|---|---|
| committer | Bryce Kwon <bryce@brycekwon.com> | |
| commit | ||
| parent | ||
| tree | ||
| download | ||
Renumber the test scripts into themed ranges
t000x the ground the suite stands on: git version, html validity,
the cache
t01xx page content, one script per page
t02xx features that cut across pages: filters, submodule links,
dates, limits
t03xx defence, the security regressions and the $HOME promise
t04xx the helper tools under tools/
Diffstat (limited to 'tests/t0302-home-access.sh')
| -rwxr-xr-x | tests/t0302-home-access.sh | 62 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
1 file changed, 62 insertions, 0 deletions
diff --git a/tests/t0302-home-access.sh b/tests/t0302-home-access.sh new file mode 100755 index 0000000..7078596 --- /dev/null +++ b/tests/t0302-home-access.sh @@ -0,0 +1,62 @@ +#!/bin/sh + +# Guards the promise that cgit reads nothing out of the home directory of +# whichever account the web server happens to run as. Every page is fetched +# under strace with HOME pointed at a path that is known not to exist, and +# the run fails if any access call names that path, which is how a stray +# read of a personal gitconfig would show up. + +test_description='Ensure that git does not access $HOME' +. ./setup.sh + +# strace needs ptrace, which containers and hardened kernels refuse even +# where the binary is installed, so a working run is checked as well as a +# present binary. +test -n "$(which strace 2>/dev/null)" || { + skip_all='Skipping access validation tests: strace not found' + test_done + exit +} + +strace true 2>/dev/null || { + skip_all='Skipping access validation tests: strace not functional' + test_done + exit +} + +test_no_home_access () { + # A home that happened to exist would be one git may legitimately + # read, leaving the check below with nothing to catch, so extend the + # path until nothing is there. + missing_home="/path/to/some/place/that/does/not/possibly/exist" + depth=0 + while test -d "$missing_home"; do + depth=$((depth + 1)) + missing_home="$missing_home/$depth" + done && + strace \ + -E HOME="$missing_home" \ + -E CGIT_CONFIG="$PWD/cgitrc" \ + -E QUERY_STRING="url=$1" \ + -e access -f -o strace.out cgit && + ! grep "$missing_home" strace.out +} + +test_no_home_access_success() { + test_expect_success "do not access \$HOME: $1" " + test_no_home_access '$1' + " +} + +test_no_home_access_success +test_no_home_access_success foo +test_no_home_access_success foo/refs +test_no_home_access_success foo/log +test_no_home_access_success foo/tree +test_no_home_access_success foo/tree/file-1 +test_no_home_access_success foo/commit +test_no_home_access_success foo/diff +test_no_home_access_success foo/patch +test_no_home_access_success foo/snapshot/master.tar.gz + +test_done |
