| @@ -64,12 +64,13 @@ func TestRepoImportRefusesGitScheme(t *testing.T) { |
| 64 | 64 | } |
| 65 | 65 | } |
| 66 | 66 | |
| 67 | | // A source on loopback is refused on a default instance, and nothing is |
| 68 | | // left behind. |
| 67 | // A reachable source on loopback is refused on a default instance, and |
| 68 | // nothing is left behind. |
| 69 | 69 | func TestRepoImportRefusesALocalAddress(t *testing.T) { |
| 70 | remote, _ := importUpstream(t) |
| 70 | 71 | c, errOut, st, root := importCtx(t, false) |
| 71 | | code := Dispatch(c, []string{"repo", "import", "alice/x", "--from", "http://127.0.0.1:9/x.git"}) |
| 72 | | if code != protocol.ExitFailure || !strings.Contains(errOut.String(), "127.0.0.1") { |
| 72 | code := Dispatch(c, []string{"repo", "import", "alice/x", "--from", remote}) |
| 73 | if code != protocol.ExitFailure || !strings.Contains(errOut.String(), "private or local address") { |
| 73 | 74 | t.Fatalf("exit %d, %q", code, errOut.String()) |
| 74 | 75 | } |
| 75 | 76 | if _, err := st.RepoByPath("alice/x"); err == nil { |
| @@ -80,11 +81,47 @@ func TestRepoImportRefusesALocalAddress(t *testing.T) { |
| 80 | 81 | } |
| 81 | 82 | } |
| 82 | 83 | |
| 84 | // A query or fragment could carry a credential into the log and the |
| 85 | // event row; import refuses it before either. |
| 86 | func TestRepoImportRefusesAQuery(t *testing.T) { |
| 87 | for _, from := range []string{"https://git.example/x.git?token=abc", "https://git.example/x.git#abc"} { |
| 88 | c, errOut, st, _ := importCtx(t, true) |
| 89 | code := Dispatch(c, []string{"repo", "import", "alice/x", "--from", from}) |
| 90 | if code != protocol.ExitUsage || !strings.Contains(errOut.String(), "plain clone URL") || strings.Contains(errOut.String(), "abc") { |
| 91 | t.Fatalf("%s: exit %d, %q", from, code, errOut.String()) |
| 92 | } |
| 93 | if _, err := st.RepoByPath("alice/x"); err == nil { |
| 94 | t.Fatalf("%s: a refused import created a repository", from) |
| 95 | } |
| 96 | } |
| 97 | } |
| 98 | |
| 83 | 99 | // import.test does not resolve; the import works only because git was |
| 84 | 100 | // pinned to the address import looked up and checked. |
| 85 | 101 | func TestRepoImportConnectsToTheCheckedAddress(t *testing.T) { |
| 102 | importThroughPin(t, func(string) {}) |
| 103 | } |
| 104 | |
| 105 | // git runs with its own environment, not the daemon's: a proxy or a |
| 106 | // global URL rewrite there would take it around the pin. |
| 107 | func TestRepoImportIgnoresTheDaemonEnvironment(t *testing.T) { |
| 108 | importThroughPin(t, func(port string) { |
| 109 | t.Setenv("http_proxy", "http://127.0.0.1:1") |
| 110 | t.Setenv("HTTP_PROXY", "http://127.0.0.1:1") |
| 111 | global := filepath.Join(t.TempDir(), "gitconfig") |
| 112 | rewrite := "[url \"http://127.0.0.1:1/\"]\n\tinsteadOf = http://import.test:" + port + "/\n" |
| 113 | if err := os.WriteFile(global, []byte(rewrite), 0o644); err != nil { |
| 114 | t.Fatal(err) |
| 115 | } |
| 116 | t.Setenv("GIT_CONFIG_GLOBAL", global) |
| 117 | }) |
| 118 | } |
| 119 | |
| 120 | func importThroughPin(t *testing.T, setup func(port string)) { |
| 121 | t.Helper() |
| 86 | 122 | remote, sha := importUpstream(t) |
| 87 | 123 | u, _ := url.Parse(remote) |
| 124 | setup(u.Port()) |
| 88 | 125 | c, errOut, _, root := importCtx(t, true) |
| 89 | 126 | var asked []string |
| 90 | 127 | prev := importLookup |