diff options
| author | Bryce Kwon <bryce@brycekwon.com> | |
|---|---|---|
| committer | Bryce Kwon <bryce@brycekwon.com> | |
| commit | ||
| parent | ||
| tree | ||
| download | ||
Expand `module-link` placeholders outside printf
Diffstat (limited to '')
| -rwxr-xr-x | tests/t0200-security.sh | 71 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
1 file changed, 71 insertions, 0 deletions
diff --git a/tests/t0200-security.sh b/tests/t0200-security.sh index de248ca..df60174 100755 --- a/tests/t0200-security.sh +++ b/tests/t0200-security.sh @@ -172,4 +172,75 @@ test_expect_success 'a message-less commit renders without crashing' ' grep "no commit message" tmp ' +# --- A repository cannot supply a printf format string ---------------------- +# module-link is a template, and scan-path lets a repository set it through its +# own cgitrc. Handing it to printf let a repo owner crash the process, or read +# stack memory into the served page, with surplus conversions. +test_expect_success 'set up a submodule fixture with a hostile module-link' ' + mkrepo repos/modlink 1 && + ( + cd repos/modlink && + sub=$(git rev-parse HEAD) && + git update-index --add --cacheinfo 160000,$sub,submod && + git commit -m gitlink + ) && + mkdir -p scan && + cp -R repos/modlink scan/modlink && + printf "module-link=/m/%%s/%%s/%%s/%%s/%%s/%%s/%%s/%%s/%%s/%%s\n" \ + >scan/modlink/.git/cgitrc && + { + echo "virtual-root=/" && + echo "cache-size=0" && + echo "scan-path=$PWD/scan" + } >modlinkrc +' + +test_expect_success 'a surplus conversion does not crash the tree view' ' + CGIT_CONFIG="$PWD/modlinkrc" QUERY_STRING="url=modlink/tree/" cgit >tmp && + grep "ls-mod" tmp +' + +test_expect_success 'a surplus conversion is shown literally, not filled' ' + grep "href=./m/submod/[0-9a-f]*/%s/%s/" tmp +' + +test_expect_success 'a well-formed module-link still takes path and sha1' ' + { + echo "virtual-root=/" && + echo "cache-size=0" && + echo "module-link=/mod/%s/commit/?id=%s" && + echo "repo.url=modlink" && + echo "repo.path=$PWD/repos/modlink/.git" + } >modlinkokrc && + sub=$(git -C repos/modlink rev-parse HEAD~1) && + CGIT_CONFIG="$PWD/modlinkokrc" QUERY_STRING="url=modlink/tree/" cgit >tmp && + grep "href=./mod/submod/commit/?id=$sub." tmp +' + +test_expect_success 'a per-path module-link takes only the sha1' ' + { + echo "virtual-root=/" && + echo "cache-size=0" && + echo "repo.url=modlink" && + echo "repo.path=$PWD/repos/modlink/.git" && + echo "repo.module-link.submod=https://example.com/s/?id=%s" + } >modlinkpathrc && + sub=$(git -C repos/modlink rev-parse HEAD~1) && + CGIT_CONFIG="$PWD/modlinkpathrc" QUERY_STRING="url=modlink/tree/" cgit >tmp && + grep "href=.https://example.com/s/?id=$sub." tmp +' + +test_expect_success 'a doubled percent in a module-link renders as one' ' + { + echo "virtual-root=/" && + echo "cache-size=0" && + echo "module-link=/m/%s/%%/%s" && + echo "repo.url=modlink" && + echo "repo.path=$PWD/repos/modlink/.git" + } >modlinkpctrc && + sub=$(git -C repos/modlink rev-parse HEAD~1) && + CGIT_CONFIG="$PWD/modlinkpctrc" QUERY_STRING="url=modlink/tree/" cgit >tmp && + grep "href=./m/submod/%/$sub." tmp +' + test_done |
