Commit 319867a8f1

319867a8f117750eab2ae70960433365e17c09cd

parent: 61564b7c32

Verified · cmc ci/build: success ci/sonar: success ci/test: success ci/vuln: success

cmc <hello@cleberg.net> · 2026-09-05 00:43 UTC

exec: the two smart-HTTP spawns the sweep missed

Both git upload-pack invocations behind the smart HTTP transport were
still resolving from PATH. The rewrite that converted the other
seventy-two matched exec.CommandContext with a plain identifier for the
context, and these pass r.Context(), so the pattern skipped them and I
did not notice until the next scan still reported two.

Same change as the rest: resolved once at start-up, so a spawn a
repository fetch depends on cannot be redirected by the environment and a
missing git is a start-up failure rather than a failed clone.

Closes #153

Layout: unified · split

internal/httpd/smart.go +3 −2
@@ -18,6 +18,7 @@ import (
1818 "gitbay.org/gitbay/internal/config"
1919 "gitbay.org/gitbay/internal/control"
2020 "gitbay.org/gitbay/internal/store"
21 "gitbay.org/gitbay/internal/toolpath"
2122)
2223
2324type Server struct {
@@ -74,7 +75,7 @@ func (s *Server) infoRefs(w http.ResponseWriter, r *http.Request) {
7475 pktLine(w, "# service=git-upload-pack\n")
7576 pktFlush(w)
7677 dir := control.RepoDir(s.cfg.Server.Root, repo.OwnerName, repo.Name)
77 cmd := exec.CommandContext(r.Context(), "git", "upload-pack", "--stateless-rpc", "--advertise-refs", dir)
78 cmd := exec.CommandContext(r.Context(), toolpath.Look("git"), "upload-pack", "--stateless-rpc", "--advertise-refs", dir)
7879 cmd.Env = append(os.Environ(), gitProtocolEnv(r)...)
7980 cmd.Stdout = w
8081 cmd.Run()
@@ -112,7 +113,7 @@ func (s *Server) uploadPack(w http.ResponseWriter, r *http.Request) {
112113 w.Header().Set("Content-Type", "application/x-git-upload-pack-result")
113114 w.Header().Set("Cache-Control", "no-cache")
114115 dir := control.RepoDir(s.cfg.Server.Root, repo.OwnerName, repo.Name)
115 cmd := exec.CommandContext(r.Context(), "git", "upload-pack", "--stateless-rpc", dir)
116 cmd := exec.CommandContext(r.Context(), toolpath.Look("git"), "upload-pack", "--stateless-rpc", dir)
116117 cmd.Env = append(os.Environ(), gitProtocolEnv(r)...)
117118 cmd.Stdin = body
118119 cmd.Stdout = w