mirror of
https://github.com/go-gitea/gitea.git
synced 2026-08-09 17:22:28 +00:00
09f78aed19
The arch parser keeps tar member names verbatim. The index writer joins those values one per line into the pacman database. So a member name with a newline adds lines to that package's own `files` entry, which libalpm reads as further fields. The scope is one package record. An uploader cannot forge entries for another package, and can set the same fields in `.PKGINFO` anyway. This is input validation, not a privilege boundary. `ParsePackage` now drops names that contain CR or LF. `joinFields` drops such values again when writing the index, which also covers packages that are already stored. Real packages never carry newlines in file paths, so well-formed uploads are unaffected. --------- Co-authored-by: silverwind <me@silverwind.io>
18 lines
415 B
Go
18 lines
415 B
Go
// Copyright 2026 The Gitea Authors. All rights reserved.
|
|
// SPDX-License-Identifier: MIT
|
|
|
|
package arch
|
|
|
|
import (
|
|
"testing"
|
|
|
|
"github.com/stretchr/testify/assert"
|
|
)
|
|
|
|
func TestJoinFields(t *testing.T) {
|
|
values := []string{"usr/bin/a", "usr/bin/b\n\n%FILES%\netc/cron.d/x", "usr/bin/c"}
|
|
|
|
assert.Equal(t, "usr/bin/a\nusr/bin/c", joinFields(values))
|
|
assert.Len(t, values, 3) // must not modify the caller's slice
|
|
}
|