diff --git a/backend/src/workspaces/git-repository.ts b/backend/src/workspaces/git-repository.ts index bb85a43f..b38a982f 100644 --- a/backend/src/workspaces/git-repository.ts +++ b/backend/src/workspaces/git-repository.ts @@ -16,6 +16,12 @@ export interface GitStatus { lastError?: WorkspaceErrorCode; } +export interface EvidenceTreeObject { + mode: "100644" | "100755"; + oid: string; + posixPath: string; +} + export class WorkspaceRegistryError extends Error { constructor(readonly code: WorkspaceErrorCode, message: string) { super(message); @@ -266,16 +272,69 @@ export class GitWorkspaceRepository { throw new WorkspaceRegistryError("workspace_invalid", "Workspace annotations object is invalid"); } const blobId = match[3]; - const contents = await this.gitBlobBuffer(blobId, 16 * 1024 * 1024); + const contents = await this.gitBlobBytes(blobId, 16 * 1024 * 1024, "annotations"); if (!isValidUtf8(contents)) { throw new WorkspaceRegistryError("workspace_invalid", "Workspace annotations object is not valid UTF-8"); } return { blobId, contents }; } - private async gitBlobBuffer(objectId: string, maxBytes: number): Promise { + /** + * Recursively enumerate a canonical `/evidence` tree at an exact commit as regular Git blobs. + * Symlinks (120000), gitlinks (160000), non-regular modes, non-blob types, traversal/absolute/ + * duplicate/cross-namespace paths, and NUL/newline-bearing names are refused. + */ + async evidenceTreeObjects(revision: string, id: string): Promise { + if (!/^[0-9a-f]{40}$/.test(revision)) { + throw new WorkspaceRegistryError("workspace_invalid", "Workspace Evidence revision is invalid"); + } + if (!/^[a-z][a-z0-9-]{2,62}$/.test(id)) { + throw new WorkspaceRegistryError("workspace_invalid", "Workspace Evidence path is invalid"); + } + const prefix = `${id}/evidence`; + const listing = await this.git(["ls-tree", "-r", "-z", "--full-tree", revision, "--", prefix]); + const entries = listing.split("\0").filter((entry) => entry.length > 0); + const seen = new Set(); + const objects: EvidenceTreeObject[] = []; + for (const entry of entries) { + const tab = entry.lastIndexOf("\t"); + if (tab < 0) throw new WorkspaceRegistryError("workspace_invalid", "Workspace Evidence object is invalid"); + const name = entry.slice(tab + 1); + const meta = entry.slice(0, tab); + const match = /^([0-9]{6}) (blob|commit|tree) ([0-9a-f]{40})$/.exec(meta); + if (match === null || match[2] !== "blob" || (match[1] !== "100644" && match[1] !== "100755")) { + throw new WorkspaceRegistryError("workspace_invalid", "Workspace Evidence object is invalid"); + } + if (name === prefix) { + // The Evidence root resolves to a single regular blob (or symlink/gitlink already refused above). + throw new WorkspaceRegistryError("workspace_invalid", "Workspace Evidence root is invalid"); + } + if (!name.startsWith(`${prefix}/`)) { + throw new WorkspaceRegistryError("workspace_invalid", "Workspace Evidence object escapes its namespace"); + } + const rel = name.slice(prefix.length + 1); + if (rel.length === 0 || rel.includes("\0") || rel.includes("\n") || rel.includes("\r")) { + throw new WorkspaceRegistryError("workspace_invalid", "Workspace Evidence path is invalid"); + } + const segments = rel.split("/"); + if (segments.some((segment) => segment === "" || segment === "." || segment === "..")) { + throw new WorkspaceRegistryError("workspace_invalid", "Workspace Evidence path is invalid"); + } + if (seen.has(rel)) throw new WorkspaceRegistryError("workspace_invalid", "Workspace Evidence path is duplicated"); + seen.add(rel); + objects.push({ mode: match[1] as "100644" | "100755", oid: match[3], posixPath: rel }); + } + return objects; + } + + /** Read one Evidence blob with a per-object byte bound. */ + evidenceBlobBytes(objectId: string, maxBytes: number): Promise { + return this.gitBlobBytes(objectId, maxBytes, "Evidence"); + } + + private async gitBlobBytes(objectId: string, maxBytes: number, label: string): Promise { if (!/^[0-9a-f]{40}$/.test(objectId)) { - throw new WorkspaceRegistryError("workspace_invalid", "Workspace annotations object is invalid"); + throw new WorkspaceRegistryError("workspace_invalid", `Workspace ${label} object is invalid`); } try { const { stdout } = await execFileAsync( @@ -289,14 +348,14 @@ export class GitWorkspaceRepository { }, ); if (stdout.length > maxBytes) { - throw new WorkspaceRegistryError("workspace_invalid", "Workspace annotations object is too large"); + throw new WorkspaceRegistryError("workspace_invalid", `Workspace ${label} object is too large`); } return stdout; } catch (error) { if (error instanceof WorkspaceRegistryError) throw error; const detail = error instanceof Error ? error.message : ""; if (/maxBuffer|stdout maxBuffer/i.test(detail)) { - throw new WorkspaceRegistryError("workspace_invalid", "Workspace annotations object is too large"); + throw new WorkspaceRegistryError("workspace_invalid", `Workspace ${label} object is too large`); } throw this.sanitizeGitError(error); } diff --git a/backend/test/workspaces-git-evidence.test.ts b/backend/test/workspaces-git-evidence.test.ts new file mode 100644 index 00000000..9ad14517 --- /dev/null +++ b/backend/test/workspaces-git-evidence.test.ts @@ -0,0 +1,129 @@ +import { execFile } from "node:child_process"; +import { mkdtempSync, mkdirSync, rmSync, symlinkSync, writeFileSync } from "node:fs"; +import { tmpdir } from "node:os"; +import { join } from "node:path"; +import { promisify } from "node:util"; +import { afterEach, expect, test } from "vitest"; +import { GitWorkspaceRepository } from "../src/workspaces/git-repository.js"; +import type { WorkspaceRegistryConfig } from "../src/workspaces/types.js"; + +const runFile = promisify(execFile); +const temporaryRoots: string[] = []; + +afterEach(() => { + temporaryRoots.splice(0).forEach((root) => rmSync(root, { recursive: true, force: true })); +}); + +async function git(cwd: string, args: string[]): Promise { + const { stdout } = await runFile("git", args, { cwd }); + return stdout.trim(); +} + +function config(root: string, remoteUrl: string): WorkspaceRegistryConfig { + return { + root, + remoteUrl, + branch: "main", + gitAuthorName: "Evidence Test", + gitAuthorEmail: "evidence@example.invalid", + installationId: "test", + secretRoots: [], + maxImportBytes: 1024, + maxImportEntries: 1, + }; +} + +type EvidenceLayout = "tree" | "empty" | "root-file" | "root-symlink" | "nested-symlink"; + +async function fixture(layout: EvidenceLayout): Promise<{ root: string; remote: string; commit: string }> { + const root = mkdtempSync(join(tmpdir(), "thoth-evidence-git-")); + temporaryRoots.push(root); + const remote = join(root, "remote.git"); + const source = join(root, "source"); + await git(root, ["init", "--bare", "--initial-branch=main", remote]); + mkdirSync(source); + await git(source, ["init", "--initial-branch=main"]); + await git(source, ["config", "user.name", "Evidence Test"]); + await git(source, ["config", "user.email", "evidence@example.invalid"]); + writeFileSync(join(source, "thoth-workspaces.yaml"), "schema_version: 1\nworkspaces: [{id: research, name: Research}]\n"); + mkdirSync(join(source, "research"), { recursive: true }); + writeFileSync(join(source, "research", "workspace.yaml"), "workspace:\n schema_version: 3\n id: research\n"); + const evidence = join(source, "research", "evidence"); + if (layout === "tree") { + mkdirSync(join(evidence, "nested"), { recursive: true }); + writeFileSync(join(evidence, "guide.md"), "# guide\n"); + writeFileSync(join(evidence, "nested", "deep.md"), "# deep\n"); + } else if (layout === "empty") { + mkdirSync(evidence, { recursive: true }); + } else if (layout === "root-file") { + writeFileSync(evidence, "not a tree\n"); + } else if (layout === "root-symlink") { + writeFileSync(join(source, "research", "target.md"), "# target\n"); + symlinkSync("target.md", evidence); + } else if (layout === "nested-symlink") { + mkdirSync(evidence, { recursive: true }); + writeFileSync(join(source, "research", "outside.md"), "# outside\n"); + symlinkSync("../outside.md", join(evidence, "link.md")); + } + await git(source, ["add", "-A"]); + await git(source, ["commit", "-m", "initial"]); + await git(source, ["remote", "add", "origin", remote]); + await git(source, ["push", "origin", "main"]); + const commit = await git(source, ["rev-parse", "HEAD"]); + return { root, remote, commit }; +} + +async function bootstrapped(fixture: { root: string; remote: string }): Promise { + const repository = new GitWorkspaceRepository(config(join(fixture.root, "registry"), fixture.remote)); + await repository.bootstrap(); + return repository; +} + +test("enumerates a regular Evidence tree with ordered relative paths", async () => { + const fixtureValue = await fixture("tree"); + const repository = await bootstrapped(fixtureValue); + + const objects = await repository.evidenceTreeObjects(fixtureValue.commit, "research"); + + expect(objects.map((entry) => entry.posixPath)).toEqual(["guide.md", "nested/deep.md"]); + expect(objects.every((entry) => /^[0-9a-f]{40}$/.test(entry.oid))).toBe(true); + expect(objects.every((entry) => entry.mode === "100644" || entry.mode === "100755")).toBe(true); +}); + +test("accepts an empty Evidence tree", async () => { + const fixtureValue = await fixture("empty"); + const repository = await bootstrapped(fixtureValue); + + await expect(repository.evidenceTreeObjects(fixtureValue.commit, "research")).resolves.toEqual([]); +}); + +test("refuses a non-tree Evidence root and symlinks at any depth", async () => { + for (const layout of ["root-file", "root-symlink", "nested-symlink"] as const) { + const fixtureValue = await fixture(layout); + const repository = await bootstrapped(fixtureValue); + await expect(repository.evidenceTreeObjects(fixtureValue.commit, "research")) + .rejects.toMatchObject({ code: "workspace_invalid" }); + } +}); + +test("refuses malformed revisions and workspace ids", async () => { + const fixtureValue = await fixture("tree"); + const repository = await bootstrapped(fixtureValue); + + await expect(repository.evidenceTreeObjects("HEAD", "research")) + .rejects.toMatchObject({ code: "workspace_invalid" }); + await expect(repository.evidenceTreeObjects(fixtureValue.commit, "../research")) + .rejects.toMatchObject({ code: "workspace_invalid" }); +}); + +test("streams bounded Evidence blobs and refuses oversized objects", async () => { + const fixtureValue = await fixture("tree"); + const repository = await bootstrapped(fixtureValue); + const [guide] = await repository.evidenceTreeObjects(fixtureValue.commit, "research"); + + const bytes = await repository.evidenceBlobBytes(guide.oid, 1024); + expect(bytes.toString("utf8")).toBe("# guide\n"); + + await expect(repository.evidenceBlobBytes(guide.oid, 1)) + .rejects.toMatchObject({ code: "workspace_invalid" }); +});