From 50de1169e4bf5cff947e10f64e9855669fdd2849 Mon Sep 17 00:00:00 2001 From: Justin Tobler Date: Wed, 8 Jul 2026 17:03:35 +0200 Subject: [PATCH] bundle-uri: stop sending invalid bundle configuration When bundle-URI info is requested by the client, the server responds with all "bundle.*" config lines as key=value packet lines. On the client-side, the received bundle config packet lines are always expected to contain both a key and a value otherwise the client errors out during parsing. The server performs no validation of the read bundle configuration though which results in any misconfiguration on the server-side, such as bundle configuration with an empty value, being blindly sent to the client. To avoid having the server transmit invalid configuration to clients, only send bundle configuration that has non-empty values. This change makes bundle-URI information sent by the server syntactically correct, but semantically it still can be invalid. For example the server may end up sending `bundle.bundle-1.creationToken`, but be lacking a `bundle.bundle-1.uri` for that bundle. The `uri` is mandatory, thus the client cannot process this bundle and will error with the message: error: bundle 'bundle-1' has no uri Fixing this would require a more complex solution, because bundles need to be validated as a whole and not line-by-line. This is considered outside the scope of this change. Co-authored-by: Toon Claes Signed-off-by: Justin Tobler Signed-off-by: Toon Claes Signed-off-by: Junio C Hamano --- bundle-uri.c | 8 ++++++-- t/lib-bundle-uri-protocol.sh | 23 +++++++++++++++++++++++ 2 files changed, 29 insertions(+), 2 deletions(-) diff --git a/bundle-uri.c b/bundle-uri.c index 3b2e347288..f956d3db7b 100644 --- a/bundle-uri.c +++ b/bundle-uri.c @@ -946,8 +946,12 @@ static int config_to_packet_line(const char *key, const char *value, { struct packet_reader *writer = data; - if (starts_with(key, "bundle.")) - packet_write_fmt(writer->fd, "%s=%s", key, value); + if (starts_with(key, "bundle.")) { + if (value && *value) + packet_write_fmt(writer->fd, "%s=%s", key, value); + else + warning(_("config '%s' has no value"), key); + } return 0; } diff --git a/t/lib-bundle-uri-protocol.sh b/t/lib-bundle-uri-protocol.sh index de09b6b02e..e0e19715cd 100644 --- a/t/lib-bundle-uri-protocol.sh +++ b/t/lib-bundle-uri-protocol.sh @@ -214,3 +214,26 @@ test_expect_success "test bundle-uri with $BUNDLE_URI_PROTOCOL:// using protocol >actual && test_cmp_config_output expect actual ' + +test_expect_success "test bundle-uri with $BUNDLE_URI_PROTOCOL:// using protocol v2 with empty value" ' + test_config -C "$BUNDLE_URI_PARENT" \ + bundle.bundle1.uri "$BUNDLE_URI_BUNDLE_URI_ESCAPED-1.bdl" && + test_config -C "$BUNDLE_URI_PARENT" \ + bundle.bundle2.uri "" && + + # The empty bundle.bundle2.uri value is invalid configuration and the + # server must not advertise it to the client. + cat >expect <<-EOF && + [bundle] + version = 1 + mode = all + [bundle "bundle1"] + uri = $BUNDLE_URI_BUNDLE_URI_ESCAPED-1.bdl + EOF + + test-tool bundle-uri \ + ls-remote \ + "$BUNDLE_URI_REPO_URI" \ + >actual && + test_cmp_config_output expect actual +'