From 1456483a0b2b835d326f1a92571166c2c8ee41f6 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Thu, 1 Oct 2026 14:30:23 -1000 Subject: Gate html serving behind trust-scan-config `enable-html-serving` makes the plain page send a repository file as text/html on the site's own origin, with no nosniff and no policy, so a scanned repository could switch it on from its git config or cgitrc without `trust-scan-config` and run script against every visitor. The warning for a key read from git config also named a null repository, because `repo->path` was set only after that file had been read. --- tests/t0303-robustness.sh | 42 +++++++++++++++++++++++++++++++++++++++--- 1 file changed, 39 insertions(+), 3 deletions(-) (limited to 'tests') diff --git a/tests/t0303-robustness.sh b/tests/t0303-robustness.sh index ea50eac..cb16957 100755 --- a/tests/t0303-robustness.sh +++ b/tests/t0303-robustness.sh @@ -1,8 +1,8 @@ #!/bin/sh -# Regression tests from the September 2026 audit. Each case is a config, -# repository or request that used to crash cgit, end it inside git, or hand -# a visitor something other than what was asked for. +# Regression tests from the audits of September and October 2026. Each case +# is a config, repository or request that used to crash cgit, end it inside +# git, or hand a visitor something other than what was asked for. test_description='Check the audit regressions' . ./setup.sh @@ -112,6 +112,42 @@ test_expect_success 'a filesystem readme from a scanned repository is refused' ' grep "Ignoring readme in " err ' +# A repository served as html runs its pages on the site's own origin, so +# the switch waits on trust like the keys that place markup. The warning has +# to name the repository, which it did not for a key read from git config. +test_expect_success 'html serving from a scanned repository waits on trust' ' + ( + cd repos/rob && + printf "

page

\n" >page.html && + git add page.html && + git commit -m html + ) && + mkdir -p scan2 && + git clone -q --bare repos/rob/.git scan2/c.git && + git -C scan2/c.git config cgit.enable-html-serving 1 && + { + echo "virtual-root=/" && + echo "cache-size=0" && + echo "enable-git-config=1" && + echo "mimetype.html=text/html" && + echo "scan-path=$PWD/scan2" + } >htmlrc && + CGIT_CONFIG="$PWD/htmlrc" QUERY_STRING="url=c.git/plain/page.html" cgit >tmp 2>err && + grep "^Content-Type: text/plain" tmp && + grep "^X-Content-Type-Options: nosniff" tmp && + grep "Ignoring enable-html-serving in $PWD/scan2/c.git/: trust-scan-config is not set" err +' + +test_expect_success 'with trust-scan-config the same repository serves html' ' + { + echo "trust-scan-config=1" && + cat htmlrc + } >htmltrustrc && + CGIT_CONFIG="$PWD/htmltrustrc" QUERY_STRING="url=c.git/plain/page.html" cgit >tmp && + grep "^Content-Type: text/html" tmp && + ! grep "^X-Content-Type-Options" tmp +' + test_expect_success SYMLINKS 'a symlink cycle under the scan path is entered once' ' ln -s . scan/loop && CGIT_CONFIG="$PWD/gitcfgrc" QUERY_STRING="url=" cgit >tmp && -- cgit v2.8.0