diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Bound the search and cache key a request can ask
Diffstat (limited to '')
-rwxr-xr-xtests/t0020-validate-cache.sh21
-rwxr-xr-xtests/t0201-limits.sh19
2 files changed, 40 insertions, 0 deletions
diff --git a/tests/t0020-validate-cache.sh b/tests/t0020-validate-cache.sh
index 7e6334c..510e51c 100755
--- a/tests/t0020-validate-cache.sh
+++ b/tests/t0020-validate-cache.sh
@@ -124,4 +124,25 @@ test_expect_success 'the page ends where it should, so nothing was dropped' '
tail -c 200 big.second.body | grep "</html>"
'
+# --- A key too long to read back must not claim a slot ----------------------
+# A slot stores its key ahead of the content and only the first few kilobytes
+# are read back, so a longer key could never match. Such a request used to
+# write a slot on every visit that no later request could ever use.
+test_expect_success 'an over-long cache key leaves no slot behind' '
+ rm -rf cache3 && mkdir cache3 &&
+ sed -e "s|^cache-root=.*|cache-root=$PWD/cache3|" bigrc >bigkeyrc &&
+ long=$(awk "BEGIN{s=\"\";for(i=0;i<6000;i++)s=s \"k\"; print s}") &&
+ CGIT_CONFIG="$PWD/bigkeyrc" QUERY_STRING="url=bigpage/&q=$long" cgit >key.out 2>key.err &&
+ grep "</html>" key.out &&
+ ls cache3 >key.slots &&
+ test_line_count = 0 key.slots
+'
+
+test_expect_success 'an ordinary key still fills a slot' '
+ rm -rf cache3 && mkdir cache3 &&
+ CGIT_CONFIG="$PWD/bigkeyrc" QUERY_STRING="url=bigpage/" cgit >/dev/null &&
+ ls cache3 >key.slots &&
+ test_line_count = 1 key.slots
+'
+
test_done
diff --git a/tests/t0201-limits.sh b/tests/t0201-limits.sh
index a8dce62..72d8a23 100755
--- a/tests/t0201-limits.sh
+++ b/tests/t0201-limits.sh
@@ -43,6 +43,25 @@ test_expect_success 'set up limit fixtures' '
limitq() { CGIT_CONFIG="$PWD/limitrc" QUERY_STRING="$1" cgit; }
+# --- A request cannot ask for an unbounded amount of matching ---------------
+# The query is compared against every repository the index lists, so an
+# enormous one would multiply out across the whole listing. It is clamped
+# rather than rejected, so an ordinary query still narrows the page.
+test_expect_success 'an enormous query is clamped, not rejected' '
+ long=$(awk "BEGIN{s=\"\";for(i=0;i<4000;i++)s=s \"a\"; print s}") &&
+ test ${#long} -eq 4000 &&
+ cgit_query "q=$long" >tmp &&
+ grep "</html>" tmp &&
+ longest=$(grep -o "aaaa*" tmp | awk "{print length}" | sort -n | tail -1) &&
+ test "$longest" -eq 512
+'
+
+test_expect_success 'an ordinary query still filters the index' '
+ cgit_query "q=foo" >tmp &&
+ grep "foo" tmp &&
+ ! grep ">bar<" tmp
+'
+
# --- The refs page caps each section and links to the category pages --------
test_expect_success 'refs page lists max-ref-count branches and tags' '
limitq "url=limits/refs/" >tmp &&