From 4bc114f972315651176ff72b32a7b4604086c9a5 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Thu, 1 Oct 2026 19:56:43 -1000 Subject: Pin the advisory classes with tests and name an empty author Each class behind cgit's published advisories now has a check against the current code, from a newline in a file name to shell syntax handed to a filter. The feed also treated an ident with an empty name and an empty address as present and wrote an empty person, which Atom forbids. --- tests/t0301-security.sh | 110 ++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 110 insertions(+) (limited to 'tests') diff --git a/tests/t0301-security.sh b/tests/t0301-security.sh index f1af8e9..1a5ee44 100755 --- a/tests/t0301-security.sh +++ b/tests/t0301-security.sh @@ -373,4 +373,114 @@ test_expect_success 'a quote in a web url cannot break out of the href' ' grep "href=.https://example.com/x'><script>" tmp ' +# The classes behind cgit's published advisories, each pinned against the +# current code: a newline in a file name splitting the headers, a posted +# length overflowing its buffer, a path climbing out on the dumb transport +# and the about page, a commit with an empty author, a percent sign with no +# digits behind it, script in a file name shown by the diff, and shell +# syntax in a file name handed to a filter. +test_expect_success 'set up the advisory fixtures' ' + mkrepo repos/cve 1 && + ( + cd repos/cve && + printf "x\n" >"$(printf "crlf\r\nX-Injected: 1.txt")" && + printf "x\n" >"