From 969e9554a31385b2d2c09695dab984d585dc2693 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Mon, 21 Sep 2026 06:42:39 -1000 Subject: Harden the request path, scan and error recovery --- tests/t0205-config.sh | 6 +++--- tests/t0301-security.sh | 31 ++++++++++++++++++++++++++----- 2 files changed, 29 insertions(+), 8 deletions(-) (limited to 'tests') diff --git a/tests/t0205-config.sh b/tests/t0205-config.sh index 26231af..4691b8f 100755 --- a/tests/t0205-config.sh +++ b/tests/t0205-config.sh @@ -2,7 +2,7 @@ # Checks what the configuration parser reports on stderr. A key it does not # know, a repo key before any repository and a filter set by a scanned -# repository without trust-scan-filters are each ignored with a warning naming +# repository without trust-scan-config are each ignored with a warning naming # the key, a repo filter in the main cgitrc passes without one, a repository # whose path is missing answers 404 on every page, and a config cgit fully # understands stays silent. @@ -52,12 +52,12 @@ test_expect_success 'a filter in a scanned repository is reported without its fl } >scanrc && CGIT_CONFIG="$PWD/scanrc" QUERY_STRING="url=foo.git/commit/" cgit >tmp 2>err && grep "
commit 5" tmp && - grep "Ignoring commit-filter in $PWD/scan/foo.git/: trust-scan-filters is not set" err + grep "Ignoring commit-filter in $PWD/scan/foo.git/: trust-scan-config is not set" err ' test_expect_success 'the flag lets a scanned repository set its filters' ' { - echo "trust-scan-filters=1" && + echo "trust-scan-config=1" && cat scanrc } >scanrc-on && CGIT_CONFIG="$PWD/scanrc-on" QUERY_STRING="url=foo.git/commit/" cgit >tmp 2>err && diff --git a/tests/t0301-security.sh b/tests/t0301-security.sh index 6d6d493..ece60f1 100755 --- a/tests/t0301-security.sh +++ b/tests/t0301-security.sh @@ -242,11 +242,12 @@ test_expect_success 'name-sorted branches are unaffected' ' grep "" tmp ' -# module-link is a template and scan-path lets a repository set its own from -# a cgitrc in the tree, so handing that string to printf let the owner of a -# scanned repository crash the process, or read stack memory into the served -# page, merely by adding conversions past the two that are filled. The tests -# after the fixture also pin down the templates that must keep working. +# module-link is a template and a trusted scan lets a repository set its own +# from a cgitrc in the tree, so handing that string to printf let the owner +# of a scanned repository crash the process, or read stack memory into the +# served page, merely by adding conversions past the two that are filled. +# The tests after the fixture also pin down the templates that must keep +# working. test_expect_success 'set up a submodule fixture with a hostile module-link' ' mkrepo repos/modlink 1 && ( @@ -261,6 +262,7 @@ test_expect_success 'set up a submodule fixture with a hostile module-link' ' { echo "virtual-root=/" && echo "cache-size=0" && + echo "trust-scan-config=1" && echo "scan-path=$PWD/scan" } >modlinkrc ' @@ -313,6 +315,25 @@ test_expect_success 'a doubled percent in a module-link renders as one' ' grep "href=./m/submod/%/$sub." tmp ' +# An unknown page under a repository used to reach the page header with no +# head resolved and crash in the branch switcher. +test_expect_success 'an unknown page under a repository answers 404 with its header' ' + cgit_url "foo/nonsense/" >tmp && + grep "^Status: 404 Not Found" tmp && + grep "Invalid request" tmp && + grep "