From 75450307c0c5a0fdf9826e5b06bdf252cfe22df0 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Sun, 6 Sep 2026 20:14:48 -1000 Subject: Trim the comments and dead code across the tree --- tests/extensions/harness.lua | 8 +------ tests/extensions/lib.sh | 5 ++--- tests/filters/dump.lua | 5 ++--- tests/setup.sh | 29 +++++++++--------------- tests/t0001-git-version.sh | 8 +++---- tests/t0002-html-validity.sh | 10 ++++----- tests/t0003-cache.sh | 10 ++++----- tests/t0004-docs.sh | 4 +--- tests/t0101-index.sh | 10 ++++----- tests/t0102-summary.sh | 10 ++++----- tests/t0103-log.sh | 8 +++---- tests/t0104-tree.sh | 10 ++++----- tests/t0105-plain.sh | 10 ++++----- tests/t0106-commit.sh | 8 +++---- tests/t0107-diff.sh | 11 +++++---- tests/t0108-rawdiff.sh | 8 +++---- tests/t0109-patch.sh | 49 +++++++++++++++++++++++++---------------- tests/t0110-snapshot.sh | 13 +++++------ tests/t0111-atom.sh | 9 +++----- tests/t0201-filters.sh | 11 ++++----- tests/t0202-submodule-links.sh | 10 ++++----- tests/t0204-limits.sh | 14 +++++------- tests/t0301-security.sh | 6 ++--- tests/t0502-syntax-highlight.sh | 16 +++++++------- tests/t0505-auth.sh | 15 +++++-------- 25 files changed, 126 insertions(+), 171 deletions(-) (limited to 'tests') diff --git a/tests/extensions/harness.lua b/tests/extensions/harness.lua index 9085010..d0299e3 100644 --- a/tests/extensions/harness.lua +++ b/tests/extensions/harness.lua @@ -118,9 +118,7 @@ end -- Deterministic bytes standing in for a digest, built from djb2 style lanes -- in plain arithmetic so they compute the same on every Lua version. Not --- remotely cryptographic, and enough for what the checks assert, that equal --- input hashes equal, different input hashes different and a tampered --- payload no longer verifies. +-- cryptographic, just stable and collision-shy enough for the checks. local function fake_digest_bytes(text) local lanes = { 5381, 52711, 1313, 7919 } for i = 1, #text do @@ -140,8 +138,6 @@ local function fake_digest_bytes(text) return table.concat(bytes) end -harness.fake_digest_bytes = fake_digest_bytes - -- The slice of the luaossl digest interface the avatar filters use. function harness.stub_digest() harness.preload("openssl.digest", { @@ -168,8 +164,6 @@ local function fake_crypt(password, setting) return prefix .. password end -harness.fake_crypt = fake_crypt - -- The slices of luaossl and luaposix the auth filters use. The link and -- unlink stubs serve the secret creation path, which the auth checks bypass -- by replacing get_secret, so they only have to exist. diff --git a/tests/extensions/lib.sh b/tests/extensions/lib.sh index 1b31a4b..f472faf 100644 --- a/tests/extensions/lib.sh +++ b/tests/extensions/lib.sh @@ -15,9 +15,8 @@ ext_lua_version() { } # Prints the interpreters found on the path whose version falls between 5.1 -# and the given 5.x ceiling, one per line, since each extension states the -# versions it runs on and a test must not fail a script on a version it never -# claimed. +# and the given 5.x ceiling, one per line, so a script is never failed on a +# version it never claimed to run on. ext_lua_interpreters() { ext_lua_ceiling=$1 for ext_lua_bin in luajit lua5.1 lua5.2 lua5.3 lua5.4 lua5.5 lua diff --git a/tests/filters/dump.lua b/tests/filters/dump.lua index aa16dfd..d654621 100644 --- a/tests/filters/dump.lua +++ b/tests/filters/dump.lua @@ -1,7 +1,6 @@ -- Test fixture for the cgit Lua filter API, exercised by t0201-filters.sh. --- It echoes the filter_open arguments and upper-cases the body, which lets the --- test confirm that arguments and content flow through the lua: filter path. It --- is not a production filter. Runs on Lua 5.1 through 5.4 and LuaJIT. +-- It echoes the filter_open arguments and upper-cases the body, which lets +-- the test confirm arguments and content flow through the lua: filter path. function filter_open(...) buffer = "" diff --git a/tests/setup.sh b/tests/setup.sh index 757ae04..de4fcc6 100755 --- a/tests/setup.sh +++ b/tests/setup.sh @@ -6,16 +6,13 @@ # CGIT_TEST_NO_CREATE_REPOS to get the helpers without paying for the fixtures. # The Git test library would run every Git command under Valgrind if it saw -# --valgrind, and only cgit itself is worth watching, so the option is taken out -# here and acted on further down. The arguments are carried across as a newline -# separated list, which keeps any other whitespace in them intact but assumes -# that none holds a newline of its own. +# --valgrind, and only cgit is worth watching, so the option is taken out +# here and acted on further down. LF=' ' -# Trash directories are collected under one trash/ rather than left beside -# the scripts, which keeps the ignore and clean rules to a single plain -# name. The option is seeded ahead of the real arguments so one given on -# the command line still wins. +# Trash directories are collected under one trash/, which keeps the ignore +# and clean rules to a single name. Seeded ahead of the real arguments so +# one given on the command line still wins. test_argv="${LF}--root=trash" while test $# != 0 @@ -45,17 +42,15 @@ TEST_NO_CREATE_REPO=YesPlease . "$TEST_DIRECTORY"/test-lib.sh # The library spells its results directory test-results and derives these -# variables before it can be told otherwise, so they are re-pointed here and -# every count lands under the plainer results/ instead. The rarely used -# --tee and --stress options write their raw logs before this line and keep -# the library's own name. +# variables before it can be told otherwise, so they are re-pointed at the +# plainer results/. The --tee and --stress raw logs write earlier and keep +# the library's name. TEST_RESULTS_DIR="$TEST_OUTPUT_DIRECTORY/results" TEST_RESULTS_BASE="$TEST_RESULTS_DIR/$TEST_NAME$TEST_STRESS_JOB_SFX" TEST_RESULTS_SAN_DIR="$TEST_RESULTS_BASE.$TEST_RESULTS_SAN_DIR_SFX" -# The library has moved into the trash directory by now, so everything the -# tests reach outside it is anchored to TEST_OUTPUT_DIRECTORY, which still -# names this directory whatever depth the trash sits at. +# The library has moved into the trash directory by now, so paths outside +# it are anchored to TEST_OUTPUT_DIRECTORY. # The tests run cgit by name, so the binary just built has to come ahead of any # copy already installed. Under Valgrind the wrappers take that place instead. @@ -138,9 +133,7 @@ enable-filter-overrides=1 repo.url=foo repo.path=$PWD/repos/foo/.git -# Do not specify a description for this repo, as it then will be assigned -# the constant value "[no description]" (which actually used to cause a -# segfault). +# No repo.desc here, so the [no description] default gets exercised. repo.url=bar repo.path=$PWD/repos/bar/.git diff --git a/tests/t0001-git-version.sh b/tests/t0001-git-version.sh index 7dd9c40..dd49002 100755 --- a/tests/t0001-git-version.sh +++ b/tests/t0001-git-version.sh @@ -1,11 +1,9 @@ #!/bin/sh # Checks that the Git version cgit says it is built for is the one it is -# actually built against. The top-level Makefile names a version, the tree -# under vendor/git records its own, and the submodule is pinned to a tag, so -# all three have to agree or cgit is being built on something other than what -# it claims. Set CGIT_TEST_NO_GIT_VERSION to YesPlease when Git comes from -# elsewhere and the comparison has nothing to say. +# built against, so the Makefile, vendor/git and the submodule pin must name +# the same version. Set CGIT_TEST_NO_GIT_VERSION to YesPlease when Git comes +# from elsewhere. if test "$CGIT_TEST_NO_GIT_VERSION" = "YesPlease" then diff --git a/tests/t0002-html-validity.sh b/tests/t0002-html-validity.sh index f22b2b6..0784092 100755 --- a/tests/t0002-html-validity.sh +++ b/tests/t0002-html-validity.sh @@ -1,11 +1,9 @@ #!/bin/sh -# Runs the tidy checker over one page of each kind cgit renders, so that markup -# broken enough to confuse a browser is caught here rather than in the browser. -# Only the shape of the markup matters, since what the pages actually say is -# the business of the t01xx scripts. Tidy is optional and old versions of it -# predate the elements cgit uses, so the whole file steps aside when a usable -# one cannot be found. +# Runs the tidy checker over one page of each kind cgit renders, caring only +# about the shape of the markup. What the pages say is the business of the +# t01xx scripts. Tidy is optional and old versions predate the elements cgit +# uses, so the file steps aside when a usable one cannot be found. test_description='Validate html with tidy' . ./setup.sh diff --git a/tests/t0003-cache.sh b/tests/t0003-cache.sh index 7ad2a79..61bf45c 100755 --- a/tests/t0003-cache.sh +++ b/tests/t0003-cache.sh @@ -1,11 +1,9 @@ #!/bin/sh -# Exercises the cache, which keeps a rendered page in a slot on disk and -# replays it for the next request that asks for the same thing. The first three -# tests set cache-size to nothing, to one slot and to the full table in turn, -# then count what the requests left behind. The rest cover the two ways a slot -# can come out wrong, a page longer than the output buffer and a key too long -# to be read back. +# Exercises the cache. The first three tests set cache-size to nothing, one +# slot and the full table in turn, then count what the requests left behind. +# The rest cover a page longer than the output buffer and a key too long to +# be read back. test_description='Validate cache' . ./setup.sh diff --git a/tests/t0004-docs.sh b/tests/t0004-docs.sh index ef12493..292223f 100755 --- a/tests/t0004-docs.sh +++ b/tests/t0004-docs.sh @@ -3,9 +3,7 @@ # Checks that the configuration documents stay consistent with each other. # The manual documents every key the reference config sets, the reference # config sets every key the manual documents, and both settings sections of -# the manual keep their entries sorted so a reader can find a key by -# scanning. An audit found the two files drifting apart, so this pins them -# together. +# the manual keep their entries sorted. test_description='Check the configuration documents' . ./setup.sh diff --git a/tests/t0101-index.sh b/tests/t0101-index.sh index be382ad..60f71e8 100755 --- a/tests/t0101-index.sh +++ b/tests/t0101-index.sh @@ -1,11 +1,9 @@ #!/bin/sh -# The index page is what cgit serves at the root of a site, one row for every -# repository named in cgitrc. These checks look for each repository the shared -# setup builds along with its description, and for the escaping a name that -# contains a plus or a space needs before it can go into a link. They also -# confirm the index stays a plain list, without the tree and log links that -# belong to a repository's own pages. +# The index page, one row per repository in cgitrc. The checks look for each +# fixture repository and its description, for the escaping a name with a +# plus or a space needs in a link, and for the absence of the tree and log +# links that belong to a repository's own pages. test_description='Check content on index page' . ./setup.sh diff --git a/tests/t0102-summary.sh b/tests/t0102-summary.sh index 5ce1fab..181040d 100755 --- a/tests/t0102-summary.sh +++ b/tests/t0102-summary.sh @@ -1,11 +1,9 @@ #!/bin/sh -# The summary page is the landing page for a single repository, holding its -# most recent commits together with its branches and its tags. The shared -# setup caps that log at five entries, so the checks against the fifty commit -# repository are really checking that the cut lands where it should. They also -# confirm the clone url template from cgitrc has had the repository name -# substituted into it. +# The summary page for a single repository. The shared setup caps its log at +# five entries, so the checks against the fifty commit repository prove the +# cut lands where it should, and the clone url template has the repository +# name substituted in. test_description='Check content on summary page' . ./setup.sh diff --git a/tests/t0103-log.sh b/tests/t0103-log.sh index dfb5176..16fabda 100755 --- a/tests/t0103-log.sh +++ b/tests/t0103-log.sh @@ -1,10 +1,8 @@ #!/bin/sh -# The log page lists the commits on a branch and can narrow that list down -# with a search. The searching checks run against the repository whose name -# contains a space and search for a term containing a space, so every link -# cgit writes back out has to escape both the path it points at and the query -# it carries, and the two are escaped differently. +# The log page and its search. The searching checks use the repository whose +# name contains a space and a term containing a space, so every link cgit +# writes back has to escape the path and the query, which escape differently. test_description='Check content on log page' . ./setup.sh diff --git a/tests/t0104-tree.sh b/tests/t0104-tree.sh index a30297f..66686c0 100755 --- a/tests/t0104-tree.sh +++ b/tests/t0104-tree.sh @@ -1,11 +1,9 @@ #!/bin/sh -# The tree page browses a repository at one revision, either as a listing of a -# directory or as a single file with an anchor on every line. The checks -# against the repository named foo+bar cover a file name and a branch name -# that both contain a plus, which cgit percent-encodes in a path as well as in -# a query, since a bare plus in a served path would read back as a space when -# the link is requested through a query string. +# The tree page. The checks against foo+bar cover a file name and a branch +# name that both contain a plus, which cgit percent-encodes in a path as +# well as in a query, since a bare plus in a served path reads back as a +# space through a query string. test_description='Check content on tree page' . ./setup.sh diff --git a/tests/t0105-plain.sh b/tests/t0105-plain.sh index b950098..2fbe87f 100755 --- a/tests/t0105-plain.sh +++ b/tests/t0105-plain.sh @@ -1,11 +1,9 @@ #!/bin/sh -# The plain page hands over a repository's own bytes rather than a rendered -# view of them, so these checks read the response headers and then compare -# the body against what git says the blob holds. A file with no better guess -# is served as text unless its bytes look binary, a directory answers with a -# bare listing of links rather than one of the themed pages, and a path that -# names nothing has to come back as a 404 rather than an empty document. +# The plain page hands over a repository's own bytes. A file with no better +# guess is served as text unless its bytes look binary, a directory answers +# with a bare listing of links, and a path that names nothing comes back as +# a 404 rather than an empty document. test_description='Check content on plain page' . ./setup.sh diff --git a/tests/t0106-commit.sh b/tests/t0106-commit.sh index ca41830..39f1822 100755 --- a/tests/t0106-commit.sh +++ b/tests/t0106-commit.sh @@ -1,10 +1,8 @@ #!/bin/sh -# The commit page shows a single commit, its message, the files it touched and -# the diff for them. Most of these checks read the markup cgit emits for the -# tree link, the parent link, the subject and the diffstat. The last few ask -# for the root commit of a repository, which has no parent and so goes through -# the code that compares a commit against an empty tree. +# The commit page. Most checks read the markup for the tree link, the parent +# link, the subject and the diffstat. The last few use a root commit, which +# has no parent and diffs against the empty tree. test_description='Check content on commit page' . ./setup.sh diff --git a/tests/t0107-diff.sh b/tests/t0107-diff.sh index 175f609..f058246 100755 --- a/tests/t0107-diff.sh +++ b/tests/t0107-diff.sh @@ -1,11 +1,10 @@ #!/bin/sh -# The diff page renders the change a commit made, either as unified text or, -# when dt=1 asks for it, as a side by side table. The first checks read the -# markup for one added file in the repository the shared setup builds. The -# rest build small repositories of their own, shaped so the side by side -# renderer meets the two cases it used to get wrong, a hunk covering a single -# line and a file where every line changed. +# The diff page, unified or side by side under dt=1. The first checks read +# the markup for one added file in the fixture repository. The rest build +# repositories of their own, shaped for the side by side renderer's two +# trickiest cases, a hunk covering a single line and a file where every +# line changed. test_description='Check content on diff page' . ./setup.sh diff --git a/tests/t0108-rawdiff.sh b/tests/t0108-rawdiff.sh index c546993..7753bdb 100755 --- a/tests/t0108-rawdiff.sh +++ b/tests/t0108-rawdiff.sh @@ -1,10 +1,8 @@ #!/bin/sh -# Checks the rawdiff page, which serves a diff as plain text with no markup -# around it so that the result can be fed straight to patch. Every test runs -# the git command the page is meant to mirror and compares the two byte for -# byte, covering an ordinary commit, the initial commit that has no parent, -# and a range spanning several commits. +# The rawdiff page serves a diff as plain text fit for patch. Every test +# runs the git command the page mirrors and compares the two byte for byte, +# over an ordinary commit, the parentless initial commit and a range. test_description='Check content on rawdiff page' . ./setup.sh diff --git a/tests/t0109-patch.sh b/tests/t0109-patch.sh index ae4dc83..0982102 100755 --- a/tests/t0109-patch.sh +++ b/tests/t0109-patch.sh @@ -1,15 +1,22 @@ #!/bin/sh -# The patch page serves a commit as a mail ready patch, so that a change read -# from cgit can be fed straight to git am. The checks compare that output -# against git format-patch for a single commit and for a range of them, once -# the CGI headers have been stripped, which means the two have to agree line -# for line. The last one sets max-patch-count so a range wider than the limit -# comes back cut short. +# The patch page serves mail ready patches, compared line for line against +# git format-patch for a single commit and for a range, once the CGI headers +# are stripped. The last check sets max-patch-count so a range wider than +# the limit comes back cut short. test_description='Check content on patch page' . ./setup.sh +# The signature sits on the second-to-last line, above the trailing blank. +check_cgit_signature() { + tail -2 tmp | head -1 | grep "^cgit" +} + +# The version the built binary signs its patches with. +CGIT_VERSION=$(sed -n "s/CGIT_VERSION = //p" \ + "$TEST_OUTPUT_DIRECTORY/../build/VERSION") + test_expect_success 'generate foo/patch' ' cgit_query "url=foo/patch" >tmp ' @@ -27,26 +34,27 @@ test_expect_success 'find `Subject:` line' ' ' test_expect_success 'find `cgit` signature' ' - tail -2 tmp | head -1 | grep "^cgit" + check_cgit_signature ' test_expect_success 'compare with output of git-format-patch(1)' ' - CGIT_VERSION=$(sed -n "s/CGIT_VERSION = //p" "$TEST_OUTPUT_DIRECTORY/../build/VERSION") && - git --git-dir="$PWD/repos/foo/.git" format-patch --subject-prefix="" --signature="cgit $CGIT_VERSION" --stdout HEAD^ >tmp2 && + git --git-dir="$PWD/repos/foo/.git" format-patch --subject-prefix="" \ + --signature="cgit $CGIT_VERSION" --stdout HEAD^ >tmp2 && strip_headers tmp_ && test_cmp tmp_ tmp2 ' test_expect_success 'find initial commit' ' - root=$(git --git-dir="$PWD/repos/foo/.git" rev-list --max-parents=0 HEAD) + root=$(git --git-dir="$PWD/repos/foo/.git" \ + rev-list --max-parents=0 HEAD) ' test_expect_success 'generate patch for initial commit' ' cgit_query "url=foo/patch&id=$root" >tmp ' -test_expect_success 'find `cgit` signature' ' - tail -2 tmp | head -1 | grep "^cgit" +test_expect_success 'find `cgit` signature on the initial commit' ' + check_cgit_signature ' test_expect_success 'generate patches for multiple commits' ' @@ -55,13 +63,14 @@ test_expect_success 'generate patches for multiple commits' ' cgit_query "url=foo/patch&id=$id&id2=$id2" >tmp ' -test_expect_success 'find `cgit` signature' ' - tail -2 tmp | head -1 | grep "^cgit" +test_expect_success 'find `cgit` signature on the range' ' + check_cgit_signature ' -test_expect_success 'compare with output of git-format-patch(1)' ' - CGIT_VERSION=$(sed -n "s/CGIT_VERSION = //p" "$TEST_OUTPUT_DIRECTORY/../build/VERSION") && - git --git-dir="$PWD/repos/foo/.git" format-patch -N --subject-prefix="" --signature="cgit $CGIT_VERSION" --stdout HEAD~3..HEAD >tmp2 && +test_expect_success 'compare the range with git-format-patch(1)' ' + git --git-dir="$PWD/repos/foo/.git" format-patch --subject-prefix="" \ + -N --signature="cgit $CGIT_VERSION" --stdout \ + HEAD~3..HEAD >tmp2 && strip_headers tmp_ && test_cmp tmp_ tmp2 ' @@ -74,8 +83,10 @@ test_expect_success 'max-patch-count bounds a patch range' ' echo "repo.path=$PWD/repos/foo/.git" } >patchcountrc && id=$(git --git-dir="$PWD/repos/foo/.git" rev-parse HEAD) && - root=$(git --git-dir="$PWD/repos/foo/.git" rev-list --max-parents=0 HEAD) && - CGIT_CONFIG="$PWD/patchcountrc" QUERY_STRING="url=foo/patch&id=$id&id2=$root" cgit >tmp && + root=$(git --git-dir="$PWD/repos/foo/.git" \ + rev-list --max-parents=0 HEAD) && + CGIT_CONFIG="$PWD/patchcountrc" \ + QUERY_STRING="url=foo/patch&id=$id&id2=$root" cgit >tmp && test $(grep -c "^From " tmp) -eq 2 ' diff --git a/tests/t0110-snapshot.sh b/tests/t0110-snapshot.sh index 9dc177f..9c8ce35 100755 --- a/tests/t0110-snapshot.sh +++ b/tests/t0110-snapshot.sh @@ -1,13 +1,10 @@ #!/bin/sh -# The snapshot page hands a branch back as an archive. Every tar based format -# goes through the same motions, fetch the archive, read its headers, prove -# the compression is genuine, then unpack it and compare the files inside -# against the repository the shared setup built, so one function below -# registers those checks per format. cgit pipes each format through the -# matching compressor on the server and this test needs the same program to -# unpack, so one missing tool skips that format on both grounds at once. The -# zip format follows at the end, since unzip shares no flags with the rest. +# The snapshot page hands a branch back as an archive. One function below +# registers the same checks for every tar based format, and each format +# needs the same compressor cgit pipes through on the server, so one missing +# tool skips that format on both grounds at once. zip follows at the end, +# since unzip shares no flags with the rest. test_description='Verify snapshot' . ./setup.sh diff --git a/tests/t0111-atom.sh b/tests/t0111-atom.sh index d2a678b..6ffb5b0 100755 --- a/tests/t0111-atom.sh +++ b/tests/t0111-atom.sh @@ -1,11 +1,8 @@ #!/bin/sh -# The atom page serves a repository's recent history as a feed, XML rather -# than a page, so a reader can follow the project without polling the -# browsable log. These checks read the content type, count the entries -# against the max-atom-items cap, which defaults to ten, and hand the feed to -# xmllint where one is installed, since a reader is far stricter about -# well-formedness than any of the greps here. +# The atom page serves recent history as a feed. The checks read the content +# type, count the entries against the max-atom-items cap, and hand the feed +# to xmllint where installed, a far stricter reader than any grep here. test_description='Check the atom feed' . ./setup.sh diff --git a/tests/t0201-filters.sh b/tests/t0201-filters.sh index 971ec36..a8341aa 100755 --- a/tests/t0201-filters.sh +++ b/tests/t0201-filters.sh @@ -49,13 +49,10 @@ do grep " commit C O MITTER <COMMITTER@EXAMPLE.COM>" tmp ' - # Page output is buffered, so whatever was written before a filter - # opens has to leave the buffer before the filter takes over stdout, - # and whatever was written while it was open has to leave before - # stdout is handed back, since those bytes are meant for the filter. - # A missed flush reorders the page rather than losing any of it, - # so the two tests below confirm that the markup around the filtered - # text is still on the side of it that it belongs on. + # Page output is buffered and has to be flushed as stdout is handed + # to a filter and back. A missed flush reorders the page rather than + # losing any of it, so the two tests below watch which side of the + # filtered text the surrounding markup lands on. test_expect_success "the $prefix source filter output stays inside its cell" " cgit_url 'filter-$prefix/tree/a%2bb' >tmp && tr -d '\n' flat.out && diff --git a/tests/t0202-submodule-links.sh b/tests/t0202-submodule-links.sh index bbd99b4..6db164f 100755 --- a/tests/t0202-submodule-links.sh +++ b/tests/t0202-submodule-links.sh @@ -1,11 +1,9 @@ #!/bin/sh -# Submodule rows can derive their links from the .gitmodules entry at the -# shown revision once enable-gitmodules-links is set. The url is matched -# against the repositories this instance serves first, so ssh and relative -# urls still land on an internal page, a plain web url is linked directly, -# an ssh url to a known host is rewritten to its web form, and anything -# else stays unlinked with the url offered as a tooltip. +# Submodule rows derive their links from the .gitmodules entry at the shown +# revision once enable-gitmodules-links is set, landing on an internal page, +# a plain or rewritten web url, or an unlinked tooltip depending on the url. +# Each of those outcomes is checked against a fixture .gitmodules. test_description='Check submodule links derived from .gitmodules' . ./setup.sh diff --git a/tests/t0204-limits.sh b/tests/t0204-limits.sh index 6591106..1195c93 100755 --- a/tests/t0204-limits.sh +++ b/tests/t0204-limits.sh @@ -1,13 +1,11 @@ #!/bin/sh -# Checks the ceilings a config can put on a page, that is the caps on refs -# listed, on the lines and the files a diff renders inline, and on the size -# of a blob any view will inflate, along with the clamp on how long an index -# query may be. Crossing one of these has to trim the page or point the -# reader at somewhere better suited, never drop the request, so each case -# watches what survives as closely as what is left out. The last case is the -# same idea applied to a filter, which degrades to escaped text rather than -# failing when its highlighting library is absent. +# Checks the ceilings a config can put on a page, the caps on refs listed, +# on the lines and files a diff renders inline, on the size of a blob any +# view will inflate, and the clamp on index query length. Crossing one has +# to trim the page or point somewhere better suited, never drop the request. +# The last case is the same idea applied to a filter, which degrades to +# escaped text when its highlighting library is absent. test_description='Check the ref listing and diff size limits' . ./setup.sh diff --git a/tests/t0301-security.sh b/tests/t0301-security.sh index 9a3af3c..2e5127c 100755 --- a/tests/t0301-security.sh +++ b/tests/t0301-security.sh @@ -2,10 +2,8 @@ # Collects the regression tests for the security fixes and for the behaviour # this fork adds on top of upstream cgit. Each case builds the smallest -# repository and config that reproduce the original problem and then asks for -# the page that used to mishandle it. The comment above a case says what the -# page is being defended against, because a request that looks ordinary is -# usually the whole point of the attack. +# repository and config that reproduce the original problem and then asks +# for the page that used to mishandle it. test_description='Check security fixes and fork-specific behavior' . ./setup.sh diff --git a/tests/t0502-syntax-highlight.sh b/tests/t0502-syntax-highlight.sh index c7cbf89..a6e3fcb 100755 --- a/tests/t0502-syntax-highlight.sh +++ b/tests/t0502-syntax-highlight.sh @@ -1,13 +1,13 @@ #!/bin/sh -# Checks syntax-highlight.lua, the shipped source-filter. The real -# Scintillua collection is not assumed anywhere, because the fake lexer -# module under extensions/fake-lexers drives every path through the -# filter deterministically. The unit checks run twice per interpreter, once -# with the fake lexers found and once with an empty directory so the escaped -# fallback is what everything renders through. The run through cgit itself -# places the fake lexers beside the config file, which is the probe the -# filter documents for a scintillua directory next to cgitrc. +# Checks syntax-highlight.lua, the shipped source-filter. The real Scintillua +# collection is not assumed anywhere, because the fake lexer module under +# extensions/fake-lexers drives every path through the filter +# deterministically. The unit checks run twice per interpreter, once with the +# fake lexers found and once with an empty directory so the escaped fallback +# is what everything renders through. The run through cgit itself places the +# fake lexers beside the config file, which is the probe the filter documents +# for a scintillua directory next to cgitrc. test_description='Check the shipped syntax-highlight extension' CGIT_TEST_NO_CREATE_REPOS=YesPlease diff --git a/tests/t0505-auth.sh b/tests/t0505-auth.sh index d4dcd52..ca379de 100755 --- a/tests/t0505-auth.sh +++ b/tests/t0505-auth.sh @@ -1,15 +1,12 @@ #!/bin/sh # Checks auth-file.lua and auth-inline.lua, the shipped auth filters, which -# share their cookie signing, redirect vetting and action flows and differ -# only in where accounts live. The unit checks under a standalone Lua meet -# luaossl and luaposix with deterministic stand-ins from the harness, so -# they prove this script's own logic on any machine, tampered and expired -# cookies turned away, header injection stripped, unsafe redirects refused -# and the login flows answering as documented. The run through cgit itself -# needs the real modules inside the binary's own Lua, so it is probed for, -# and an unedited copy protects nothing, which is itself the behaviour worth -# proving end to end. +# differ only in where accounts live. The unit checks meet luaossl and +# luaposix with deterministic stand-ins from the harness, proving tampered +# and expired cookies turned away, header injection stripped, unsafe +# redirects refused and the login flows answering as documented. The run +# through cgit itself needs the real modules inside the binary's own Lua, so +# it is probed for, and proves an unedited copy protects nothing. test_description='Check the shipped auth extensions' CGIT_TEST_NO_CREATE_REPOS=YesPlease -- cgit v2.8.0