diff options
context:
space:
mode:
Diffstat (limited to 'tests')
-rwxr-xr-xtests/t0200-security.sh71
1 file changed, 71 insertions, 0 deletions
diff --git a/tests/t0200-security.sh b/tests/t0200-security.sh
index de248ca..df60174 100755
--- a/tests/t0200-security.sh
+++ b/tests/t0200-security.sh
@@ -172,4 +172,75 @@ test_expect_success 'a message-less commit renders without crashing' '
grep "no commit message" tmp
'
+# --- A repository cannot supply a printf format string ----------------------
+# module-link is a template, and scan-path lets a repository set it through its
+# own cgitrc. Handing it to printf let a repo owner crash the process, or read
+# stack memory into the served page, with surplus conversions.
+test_expect_success 'set up a submodule fixture with a hostile module-link' '
+ mkrepo repos/modlink 1 &&
+ (
+ cd repos/modlink &&
+ sub=$(git rev-parse HEAD) &&
+ git update-index --add --cacheinfo 160000,$sub,submod &&
+ git commit -m gitlink
+ ) &&
+ mkdir -p scan &&
+ cp -R repos/modlink scan/modlink &&
+ printf "module-link=/m/%%s/%%s/%%s/%%s/%%s/%%s/%%s/%%s/%%s/%%s\n" \
+ >scan/modlink/.git/cgitrc &&
+ {
+ echo "virtual-root=/" &&
+ echo "cache-size=0" &&
+ echo "scan-path=$PWD/scan"
+ } >modlinkrc
+'
+
+test_expect_success 'a surplus conversion does not crash the tree view' '
+ CGIT_CONFIG="$PWD/modlinkrc" QUERY_STRING="url=modlink/tree/" cgit >tmp &&
+ grep "ls-mod" tmp
+'
+
+test_expect_success 'a surplus conversion is shown literally, not filled' '
+ grep "href=./m/submod/[0-9a-f]*/%s/%s/" tmp
+'
+
+test_expect_success 'a well-formed module-link still takes path and sha1' '
+ {
+ echo "virtual-root=/" &&
+ echo "cache-size=0" &&
+ echo "module-link=/mod/%s/commit/?id=%s" &&
+ echo "repo.url=modlink" &&
+ echo "repo.path=$PWD/repos/modlink/.git"
+ } >modlinkokrc &&
+ sub=$(git -C repos/modlink rev-parse HEAD~1) &&
+ CGIT_CONFIG="$PWD/modlinkokrc" QUERY_STRING="url=modlink/tree/" cgit >tmp &&
+ grep "href=./mod/submod/commit/?id=$sub." tmp
+'
+
+test_expect_success 'a per-path module-link takes only the sha1' '
+ {
+ echo "virtual-root=/" &&
+ echo "cache-size=0" &&
+ echo "repo.url=modlink" &&
+ echo "repo.path=$PWD/repos/modlink/.git" &&
+ echo "repo.module-link.submod=https://example.com/s/?id=%s"
+ } >modlinkpathrc &&
+ sub=$(git -C repos/modlink rev-parse HEAD~1) &&
+ CGIT_CONFIG="$PWD/modlinkpathrc" QUERY_STRING="url=modlink/tree/" cgit >tmp &&
+ grep "href=.https://example.com/s/?id=$sub." tmp
+'
+
+test_expect_success 'a doubled percent in a module-link renders as one' '
+ {
+ echo "virtual-root=/" &&
+ echo "cache-size=0" &&
+ echo "module-link=/m/%s/%%/%s" &&
+ echo "repo.url=modlink" &&
+ echo "repo.path=$PWD/repos/modlink/.git"
+ } >modlinkpctrc &&
+ sub=$(git -C repos/modlink rev-parse HEAD~1) &&
+ CGIT_CONFIG="$PWD/modlinkpctrc" QUERY_STRING="url=modlink/tree/" cgit >tmp &&
+ grep "href=./m/submod/%/$sub." tmp
+'
+
test_done