Files
gitks/merge/resolve_merge_conflicts.rs
T
zhenyi d243dce027 refactor(server): replace custom remote clients with macro-based implementation
- Replaced manual remote client functions with remote_client! macro for archive, blame, branch, commit, and diff services
- Simplified remote client creation logic using declarative macro approach
- Maintained same functionality while reducing code duplication across services

security(bare): enhance path traversal protection with comprehensive validation

- Added early relative_path validation to prevent path traversal attacks
- Implemented unified path validation to avoid TOCTOU race conditions
- Enhanced canonicalization checks for both existing and non-existent paths
- Added detailed logging for path traversal detection attempts

feat(cache): migrate from CLruCache to Moka with TTL and invalidation support

- Replaced clru dependency with moka for improved caching capabilities
- Added 300-second time-to-live for cache entries
- Implemented repository-specific cache invalidation mechanism
- Enhanced cache operations with thread-safe async support

refactor(commit): improve security validation for commit operations

- Added ref name validation to prevent command injection in cherry_pick_commit
- Implemented revision validation for commit selectors
- Added comprehensive input validation for create_commit parameters
- Enhanced file path validation to prevent traversal
2026-06-08 09:43:57 +08:00

133 lines
4.5 KiB
Rust

use crate::bare::GitBare;
use crate::commit::create_commit::command_ok;
use crate::error::{GitError, GitResult};
use crate::pb::{MergeResult, ResolveMergeConflictsRequest, merge_result};
impl GitBare {
pub fn resolve_merge_conflicts(
&self,
request: ResolveMergeConflictsRequest,
) -> GitResult<MergeResult> {
let target_branch = request.target_branch.clone();
crate::sanitize::validate_ref_name(&target_branch)?;
let source_revision = match request.source.and_then(|s| s.selector) {
Some(crate::pb::object_selector::Selector::Oid(oid)) => oid.hex,
Some(crate::pb::object_selector::Selector::Revision(name)) => {
crate::sanitize::validate_revision(&name.revision)?;
name.revision
}
None => return Err(GitError::InvalidArgument("source is required".into())),
};
let repo = self.gix_repo()?;
let branch_ref = format!("refs/heads/{}", target_branch);
let target_id = repo
.find_reference(branch_ref.as_str())
.ok()
.and_then(|mut r| r.peel_to_id().ok())
.map(|id| id.to_string())
.ok_or_else(|| GitError::RefNotFound(target_branch.clone()))?;
let source_id = repo.rev_parse_single(source_revision.as_str())?.to_string();
let bare = self.bare_dir.to_string_lossy().into_owned();
let tmp_index = tempfile::Builder::new()
.prefix("gitks-resolve-")
.tempfile_in(&self.bare_dir)?;
let idx_path = tmp_index.path().to_string_lossy().into_owned();
let read_tree = duct::cmd(
"git",
["--git-dir", bare.as_str(), "read-tree", target_id.as_str()],
)
.env("GIT_INDEX_FILE", &idx_path)
.stdout_capture()
.stderr_capture()
.unchecked()
.run()?;
command_ok(read_tree)?;
for resolution in &request.resolutions {
let hash = duct::cmd(
"git",
["--git-dir", bare.as_str(), "hash-object", "-w", "--stdin"],
)
.stdin_bytes(resolution.content.clone())
.stdout_capture()
.stderr_capture()
.unchecked()
.run()?;
let blob = command_ok(hash)?.trim().to_string();
let update = duct::cmd(
"git",
[
"--git-dir",
bare.as_str(),
"update-index",
"--add",
"--cacheinfo",
"100644",
&blob,
&resolution.path,
],
)
.env("GIT_INDEX_FILE", &idx_path)
.env("GIT_WORK_TREE", bare.as_str())
.stdout_capture()
.stderr_capture()
.unchecked()
.run()?;
command_ok(update)?;
}
let write_tree = duct::cmd("git", ["--git-dir", bare.as_str(), "write-tree"])
.env("GIT_INDEX_FILE", &idx_path)
.stdout_capture()
.stderr_capture()
.unchecked()
.run()?;
let tree_id = command_ok(write_tree)?.trim().to_string();
let message = if !request.message.is_empty() {
request.message.clone()
} else {
format!(
"Merge '{}' into {} (resolved conflicts)",
source_revision, target_branch
)
};
let parents = vec![target_id.clone(), source_id.clone()];
let commit_id = self.commit_tree(
&tree_id,
&parents,
&message,
request.committer.as_ref(),
request.committer.as_ref(),
)?;
self.update_branch_ref(&target_branch, &commit_id, Some(&target_id), false)?;
Ok(MergeResult {
status: merge_result::Status::MergeResultStatusMerged as i32,
commit: Some(self.get_commit(crate::pb::GetCommitRequest {
repository: request.repository,
revision: Some(crate::pb::ObjectSelector {
selector: Some(crate::pb::object_selector::Selector::Revision(
crate::pb::ObjectName {
revision: commit_id,
},
)),
}),
include_stats: false,
include_raw: false,
})?),
merge_base: None,
conflicts: vec![],
stats: None,
message,
})
}
}