From e4263b952faba40be27f2f5118dc99bb962750d0 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Mon, 24 Aug 2026 16:11:31 -1000 Subject: Resolve submodule links from `.gitmodules` --- tests/t0112-submodule-links.sh | 109 +++++++++++++++++++++++++++++++++++++++++ tests/t0200-security.sh | 41 +++++++++++++++- 2 files changed, 149 insertions(+), 1 deletion(-) create mode 100755 tests/t0112-submodule-links.sh (limited to 'tests') diff --git a/tests/t0112-submodule-links.sh b/tests/t0112-submodule-links.sh new file mode 100755 index 0000000..bbd99b4 --- /dev/null +++ b/tests/t0112-submodule-links.sh @@ -0,0 +1,109 @@ +#!/bin/sh + +# Submodule rows can derive their links from the .gitmodules entry at the +# shown revision once enable-gitmodules-links is set. The url is matched +# against the repositories this instance serves first, so ssh and relative +# urls still land on an internal page, a plain web url is linked directly, +# an ssh url to a known host is rewritten to its web form, and anything +# else stays unlinked with the url offered as a tooltip. + +test_description='Check submodule links derived from .gitmodules' +. ./setup.sh + +test_expect_success 'set up a parent repo with submodules' ' + mkrepo repos/subtarget 1 && + mkrepo repos/subparent 1 && + ( + cd repos/subparent && + sub=$(git rev-parse HEAD) && + git update-index --add --cacheinfo 160000,$sub,local-ssh && + git update-index --add --cacheinfo 160000,$sub,sibling && + git update-index --add --cacheinfo 160000,$sub,forge-https && + git update-index --add --cacheinfo 160000,$sub,forge-ssh && + git update-index --add --cacheinfo 160000,$sub,opaque && + git update-index --add --cacheinfo 160000,$sub,cgit-host && + cat >.gitmodules <<-\EOF && + [submodule "local-ssh"] + path = local-ssh + url = git@example.com:mirrors/subtarget.git + [submodule "sibling"] + path = sibling + url = ../subtarget.git + [submodule "forge-https"] + path = forge-https + url = https://github.com/example/project.git + [submodule "forge-ssh"] + path = forge-ssh + url = git@github.com:example/other.git + [submodule "opaque"] + path = opaque + url = git@private.example.com:closed/thing.git + [submodule "cgit-host"] + path = cgit-host + url = https://git.kernel.org/pub/scm/git/git.git + EOF + git add .gitmodules && + git commit -m submodules + ) && + { + echo "virtual-root=/" && + echo "cache-size=0" && + echo "enable-gitmodules-links=1" && + echo "repo.url=subparent" && + echo "repo.path=$PWD/repos/subparent/.git" && + echo "repo.url=subtarget" && + echo "repo.path=$PWD/repos/subtarget/.git" + } >subrc +' + +test_expect_success 'generate subparent/tree' ' + CGIT_CONFIG="$PWD/subrc" QUERY_STRING="url=subparent/tree/" cgit >tmp +' + +test_expect_success 'an ssh url served here links to the local repo' ' + sub=$(git -C repos/subparent rev-parse HEAD~1) && + grep "href=./subtarget/tree/?id=$sub.>local-ssh" tmp +' + +test_expect_success 'its hash links to the local commit page' ' + sub=$(git -C repos/subparent rev-parse HEAD~1) && + grep "href=./subtarget/commit/?id=$sub." tmp +' + +test_expect_success 'a relative url resolves against this repository' ' + sub=$(git -C repos/subparent rev-parse HEAD~1) && + grep "href=./subtarget/tree/?id=$sub.>sibling" tmp +' + +test_expect_success 'a web url is linked as it is' ' + grep "href=.https://github.com/example/project.git.>forge-https" tmp +' + +test_expect_success 'a known forge hash links to its commit page' ' + sub=$(git -C repos/subparent rev-parse HEAD~1) && + grep "href=.https://github.com/example/project/commit/$sub." tmp +' + +test_expect_success 'an ssh url to a known forge is rewritten' ' + sub=$(git -C repos/subparent rev-parse HEAD~1) && + grep "href=.https://github.com/example/other.>forge-ssh" tmp && + grep "href=.https://github.com/example/other/commit/$sub." tmp +' + +test_expect_success 'a cgit host keeps its .git suffix in the commit link' ' + sub=$(git -C repos/subparent rev-parse HEAD~1) && + grep "href=.https://git.kernel.org/pub/scm/git/git.git/commit/?id=$sub." tmp +' + +test_expect_success 'an unresolvable url stays unlinked with a tooltip' ' + grep "class=.ls-mod. title=.git@private.example.com:closed/thing.git.>opaque" tmp +' + +test_expect_success 'the links stay off without the flag' ' + sed "/enable-gitmodules-links/d" subrc >subrcoff && + CGIT_CONFIG="$PWD/subrcoff" QUERY_STRING="url=subparent/tree/" cgit >tmp && + ! grep "subtarget/tree" tmp && + grep "class=.ls-mod.>local-ssh" tmp +' + +test_done diff --git a/tests/t0200-security.sh b/tests/t0200-security.sh index f475301..8fce5f4 100755 --- a/tests/t0200-security.sh +++ b/tests/t0200-security.sh @@ -277,7 +277,7 @@ test_expect_success 'a surplus conversion is shown literally, not filled' ' grep "href=./m/submod/[0-9a-f]*/%s/%s/" tmp ' -test_expect_success 'a well-formed module-link still takes path and sha1' ' +test_expect_success 'a well-formed module-link still takes name and sha1' ' { echo "virtual-root=/" && echo "cache-size=0" && @@ -316,4 +316,43 @@ test_expect_success 'a doubled percent in a module-link renders as one' ' grep "href=./m/submod/%/$sub." tmp ' +# The .gitmodules file is commit-controlled content, so a derived link may +# carry any scheme and any byte an author can commit. Only http and https +# may reach an href, and everything lands attribute-escaped. +test_expect_success 'set up a hostile .gitmodules' ' + ( + cd repos/modlink && + sub=$(git rev-parse HEAD) && + git update-index --add --cacheinfo 160000,$sub,quoted && + cat >.gitmodules <<-EOF && + [submodule "submod"] + path = submod + url = javascript:alert(1) + [submodule "quoted"] + path = quoted + url = https://example.com/x'\''> + EOF + git add .gitmodules && + git commit -m hostile + ) && + { + echo "virtual-root=/" && + echo "cache-size=0" && + echo "enable-gitmodules-links=1" && + echo "repo.url=modlink" && + echo "repo.path=$PWD/repos/modlink/.git" + } >modlinkgmrc +' + +test_expect_success 'a javascript url never reaches an href' ' + CGIT_CONFIG="$PWD/modlinkgmrc" QUERY_STRING="url=modlink/tree/" cgit >tmp && + ! grep "href=.javascript:" tmp && + grep "class=.ls-mod. title=.javascript:alert(1).>submod" tmp +' + +test_expect_success 'a quote in a web url cannot break out of the href' ' + ! grep "