From b034fde5cb6463d354670e26eeaaae765810d6bd Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Thu, 1 Oct 2026 16:58:07 -1000 Subject: Withhold the alternates file on the dumb transport It lists object directories by their path on the server, which a client fetching over http can neither use nor needs to learn. The http-alternates file written for such clients still goes out. --- tests/t0303-robustness.sh | 13 +++++++++++++ 1 file changed, 13 insertions(+) (limited to 'tests') diff --git a/tests/t0303-robustness.sh b/tests/t0303-robustness.sh index 8d64c1e..be98644 100755 --- a/tests/t0303-robustness.sh +++ b/tests/t0303-robustness.sh @@ -494,6 +494,19 @@ test_expect_success 'the dumb transport sends a file with its size' ' cmp body repos/rob/.git/objects/pack/$pack ' +# The alternates file lists object directories by their path on the server, +# which a client fetching over http cannot use and should not learn. +test_expect_success 'the dumb transport withholds the alternates file' ' + mkdir -p repos/rob/.git/objects/info && + echo "$PWD/repos/foo/.git/objects" >repos/rob/.git/objects/info/alternates && + robq "url=rob/objects/info/alternates" >tmp && + grep "^Status: 404" tmp && + ! grep "repos/foo" tmp && + rm repos/rob/.git/objects/info/alternates && + robq "url=rob/objects/info/packs" >tmp && + grep "^Status: 200" tmp +' + test_expect_success 'a symlink whose target is a large blob is listed without it' ' big=$(head -c 5000 /dev/zero | tr "\0" a | git -C repos/rob hash-object -w --stdin) && ( -- cgit v2.8.0