git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH (BUGFIX)] gitweb: Handle invalid regexp in regexp search

From
Jakub Narebski <jnareb@gmail.com>
Date
Feb 28, 2012, 18:41 UTC
Message-ID
<20120228183919.26435.86795.stgit@localhost.localdomain>

When using regexp search ('sr' parameter / $search_use_regexp variable is true), check first that regexp is valid.

Without this patch we would get an error from Perl during search (if searching is performed by gitweb), or highlighting matches substring (if applicable), if user provided invalid regexp... which means broken HTML, with error page (including HTTP headers) generated after gitweb already produced some output.

Add test that illustrates such error: for example for regexp "*\.git" we would get the following error:

  Quantifier follows nothing in regex; marked by <-- HERE in m/* <-- HERE \.git/
  at /var/www/cgi-bin/gitweb.cgi line 3084.
Reported-by: Ramsay Jones <ramsay@ramsay1.demon.co.uk>
Signed-off-by: Jakub Narebski <jnareb@gmail.com>
---
See "Re: gitweb: (potential) problems with new installation"
http://thread.gmane.org/gmane.comp.version-control.git/191746
 gitweb/gitweb.perl                       |   11 ++++++++++-
 t/t9501-gitweb-standalone-http-status.sh |   10 ++++++++++
 2 files changed, 20 insertions(+), 1 deletions(-)
diff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl
index 1fc5361..22ad279 100755
--- a/gitweb/gitweb.perl
+++ b/gitweb/gitweb.perl
@@ -1081,7 +1081,16 @@ sub evaluate_and_validate_params {
 		if (length($searchtext) < 2) {
 			die_error(403, "At least two characters are required for search parameter");
 		}
-		$search_regexp = $search_use_regexp ? $searchtext : quotemeta $searchtext;
+		if ($search_use_regexp) {
+			$search_regexp = $searchtext;
+			if (!eval { qr/$search_regexp/; 1; }) {
+				(my $error = $@) =~ s/ at \S+ line \d+.*\n?//;
+				die_error(400, "Invalid search regexp '$search_regexp'",
+				          esc_html($error));
+			}
+		} else {
+			$search_regexp = quotemeta $searchtext;
+		}
 	}
 }
 
diff --git a/t/t9501-gitweb-standalone-http-status.sh b/t/t9501-gitweb-standalone-http-status.sh
index 26102ee..31076ed 100755
--- a/t/t9501-gitweb-standalone-http-status.sh
+++ b/t/t9501-gitweb-standalone-http-status.sh
@@ -134,4 +134,14 @@ our $maxload = undef;
 EOF
 
 
+# ----------------------------------------------------------------------
+# invalid arguments
+
+test_expect_success 'invalid arguments: invalid regexp (in project search)' '
+	gitweb_run "a=project_list;s=*\.git;sr=1" &&
+	grep "Status: 400" gitweb.headers &&
+	grep "400 - Invalid.*regexp" gitweb.body
+'
+test_debug 'cat gitweb.headers'
+
 test_done
Next: Junio C Hamano
Message 1 of 18 in “gitweb: Handle invalid regexp in regexp search”
  1. gitweb: Handle invalid regexp in regexp searchJakub Narebski, Feb 28, 2012
  2. Junio C HamanoFeb 28, 2012
  3. Jakub NarebskiFeb 29, 2012
  4. Ramsay JonesMar 2, 2012
  5. gitweb: Fix fixed string (non-regexp) project searchJakub Narebski, Mar 2, 2012
  6. Junio C HamanoMar 3, 2012
  7. Jakub NarebskiMar 3, 2012
  8. gitweb: Fix fixed string (non-regexp) project searchJakub Narebski, Mar 4, 2012
  9. Junio C HamanoMar 5, 2012
  10. Jakub NarebskiMar 5, 2012
  11. Junio C HamanoMar 5, 2012
  12. Junio C HamanoMar 5, 2012
  13. Jakub NarebskiMar 6, 2012
  14. Jakub NarebskiMar 4, 2012
  15. Junio C HamanoMar 4, 2012
  16. Jakub NarebskiMar 5, 2012
  17. Ramsay JonesMar 5, 2012
  18. Jakub NarebskiMar 6, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.