From ea618c5e257a6aabded76e63567ec0e7b99ac6c4 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Mon, 24 Aug 2026 16:21:18 -1000 Subject: Renumber the test scripts into themed ranges t000x the ground the suite stands on: git version, html validity, the cache t01xx page content, one script per page t02xx features that cut across pages: filters, submodule links, dates, limits t03xx defence, the security regressions and the $HOME promise t04xx the helper tools under tools/ --- tests/t0302-home-access.sh | 62 ++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 62 insertions(+) create mode 100755 tests/t0302-home-access.sh (limited to 'tests/t0302-home-access.sh') diff --git a/tests/t0302-home-access.sh b/tests/t0302-home-access.sh new file mode 100755 index 0000000..7078596 --- /dev/null +++ b/tests/t0302-home-access.sh @@ -0,0 +1,62 @@ +#!/bin/sh + +# Guards the promise that cgit reads nothing out of the home directory of +# whichever account the web server happens to run as. Every page is fetched +# under strace with HOME pointed at a path that is known not to exist, and +# the run fails if any access call names that path, which is how a stray +# read of a personal gitconfig would show up. + +test_description='Ensure that git does not access $HOME' +. ./setup.sh + +# strace needs ptrace, which containers and hardened kernels refuse even +# where the binary is installed, so a working run is checked as well as a +# present binary. +test -n "$(which strace 2>/dev/null)" || { + skip_all='Skipping access validation tests: strace not found' + test_done + exit +} + +strace true 2>/dev/null || { + skip_all='Skipping access validation tests: strace not functional' + test_done + exit +} + +test_no_home_access () { + # A home that happened to exist would be one git may legitimately + # read, leaving the check below with nothing to catch, so extend the + # path until nothing is there. + missing_home="/path/to/some/place/that/does/not/possibly/exist" + depth=0 + while test -d "$missing_home"; do + depth=$((depth + 1)) + missing_home="$missing_home/$depth" + done && + strace \ + -E HOME="$missing_home" \ + -E CGIT_CONFIG="$PWD/cgitrc" \ + -E QUERY_STRING="url=$1" \ + -e access -f -o strace.out cgit && + ! grep "$missing_home" strace.out +} + +test_no_home_access_success() { + test_expect_success "do not access \$HOME: $1" " + test_no_home_access '$1' + " +} + +test_no_home_access_success +test_no_home_access_success foo +test_no_home_access_success foo/refs +test_no_home_access_success foo/log +test_no_home_access_success foo/tree +test_no_home_access_success foo/tree/file-1 +test_no_home_access_success foo/commit +test_no_home_access_success foo/diff +test_no_home_access_success foo/patch +test_no_home_access_success foo/snapshot/master.tar.gz + +test_done -- cgit v2.8.0