#!/bin/sh # Guards the promise that cgit reads nothing out of the home directory of # whichever account the web server happens to run as. Every page is fetched # under strace with HOME pointed at a path that is known not to exist, and # the run fails if any access call names that path, which is how a stray # read of a personal gitconfig would show up. test_description='Ensure that git does not access $HOME' . ./setup.sh # strace needs ptrace, which containers and hardened kernels refuse even # where the binary is installed, so a working run is checked as well as a # present binary. command -v strace >/dev/null 2>&1 || { skip_all='Skipping access validation tests: strace not found' test_done exit } strace true 2>/dev/null || { skip_all='Skipping access validation tests: strace not functional' test_done exit } test_no_home_access() { # A home that happened to exist would be one git may legitimately # read, leaving the check below with nothing to catch, so extend the # path until nothing is there. missing_home="/path/to/some/place/that/does/not/possibly/exist" depth=0 while test -d "$missing_home" do depth=$((depth + 1)) missing_home="$missing_home/$depth" done && strace \ -E HOME="$missing_home" \ -E CGIT_CONFIG="$PWD/cgitrc" \ -E QUERY_STRING="url=$1" \ -e access -f -o strace.out cgit && ! grep "$missing_home" strace.out } test_no_home_access_success() { test_expect_success "do not access \$HOME: $1" " test_no_home_access '$1' " } test_no_home_access_success test_no_home_access_success foo test_no_home_access_success foo/refs test_no_home_access_success foo/log test_no_home_access_success foo/tree test_no_home_access_success foo/tree/file-1 test_no_home_access_success foo/commit test_no_home_access_success foo/diff test_no_home_access_success foo/patch test_no_home_access_success foo/snapshot/master.tar.gz test_done