http: limit redirection depth
By default, libcurl will follow circular http redirects forever. Let's put a cap on this so that somebody who can trigger an automated fetch of an arbitrary repository (e.g., for CI) cannot convince git to loop infinitely. The value chosen is 20, which is the same default that Firefox uses. Signed-off-by: Jeff King <peff@peff.net> Signed-off-by: Junio C Hamano <gitster@pobox.com>
Blake Burkhart committed
Sep 22, 2015 at 18:06 UTC
b258116462399b318c86165c61a5c7123043cfd4
3 files changed
+8
http.c
+1
@@ -352,6 +352,7 @@ static CURL *get_curl_handle(void)
352
}
353
354
curl_easy_setopt(result, CURLOPT_FOLLOWLOCATION, 1);
355
+ curl_easy_setopt(result, CURLOPT_MAXREDIRS, 20);
356
#if LIBCURL_VERSION_NUM >= 0x071301
357
curl_easy_setopt(result, CURLOPT_POSTREDIR, CURL_REDIR_POST_ALL);
358
#elif LIBCURL_VERSION_NUM >= 0x071101
t/lib-httpd/apache.conf
+3
@@ -121,6 +121,9 @@ RewriteRule ^/smart-redir-auth/(.*)$ /auth/smart/$1 [R=301]
121
RewriteRule ^/smart-redir-limited/(.*)/info/refs$ /smart/$1/info/refs [R=301]
122
RewriteRule ^/ftp-redir/(.*)$ ftp://localhost:1000/$1 [R=302]
123
124
+RewriteRule ^/loop-redir/x-x-x-x-x-x-x-x-x-x-x-x-x-x-x-x-x-x-x-x-(.*) /$1 [R=302]
125
+RewriteRule ^/loop-redir/(.*)$ /loop-redir/x-$1 [R=302]
126
+
127
<IfDefine SSL>
128
LoadModule ssl_module modules/mod_ssl.so
129
t/t5812-proto-disable-http.sh
+4
@@ -25,5 +25,9 @@ test_expect_success 'curl redirects respect whitelist' '
25
}
26
'
27
28
+test_expect_success 'curl limits redirects' '
29
+ test_must_fail git clone "$HTTPD_URL/loop-redir/smart/repo.git"
30
+'
31
+
32
stop_httpd
33
test_done