d243dce027
- Replaced manual remote client functions with remote_client! macro for archive, blame, branch, commit, and diff services - Simplified remote client creation logic using declarative macro approach - Maintained same functionality while reducing code duplication across services security(bare): enhance path traversal protection with comprehensive validation - Added early relative_path validation to prevent path traversal attacks - Implemented unified path validation to avoid TOCTOU race conditions - Enhanced canonicalization checks for both existing and non-existent paths - Added detailed logging for path traversal detection attempts feat(cache): migrate from CLruCache to Moka with TTL and invalidation support - Replaced clru dependency with moka for improved caching capabilities - Added 300-second time-to-live for cache entries - Implemented repository-specific cache invalidation mechanism - Enhanced cache operations with thread-safe async support refactor(commit): improve security validation for commit operations - Added ref name validation to prevent command injection in cherry_pick_commit - Implemented revision validation for commit selectors - Added comprehensive input validation for create_commit parameters - Enhanced file path validation to prevent traversal
133 lines
4.5 KiB
Rust
133 lines
4.5 KiB
Rust
use crate::bare::GitBare;
|
|
use crate::commit::create_commit::command_ok;
|
|
use crate::error::{GitError, GitResult};
|
|
use crate::pb::{MergeResult, ResolveMergeConflictsRequest, merge_result};
|
|
|
|
impl GitBare {
|
|
pub fn resolve_merge_conflicts(
|
|
&self,
|
|
request: ResolveMergeConflictsRequest,
|
|
) -> GitResult<MergeResult> {
|
|
let target_branch = request.target_branch.clone();
|
|
crate::sanitize::validate_ref_name(&target_branch)?;
|
|
let source_revision = match request.source.and_then(|s| s.selector) {
|
|
Some(crate::pb::object_selector::Selector::Oid(oid)) => oid.hex,
|
|
Some(crate::pb::object_selector::Selector::Revision(name)) => {
|
|
crate::sanitize::validate_revision(&name.revision)?;
|
|
name.revision
|
|
}
|
|
None => return Err(GitError::InvalidArgument("source is required".into())),
|
|
};
|
|
|
|
let repo = self.gix_repo()?;
|
|
let branch_ref = format!("refs/heads/{}", target_branch);
|
|
let target_id = repo
|
|
.find_reference(branch_ref.as_str())
|
|
.ok()
|
|
.and_then(|mut r| r.peel_to_id().ok())
|
|
.map(|id| id.to_string())
|
|
.ok_or_else(|| GitError::RefNotFound(target_branch.clone()))?;
|
|
|
|
let source_id = repo.rev_parse_single(source_revision.as_str())?.to_string();
|
|
|
|
let bare = self.bare_dir.to_string_lossy().into_owned();
|
|
let tmp_index = tempfile::Builder::new()
|
|
.prefix("gitks-resolve-")
|
|
.tempfile_in(&self.bare_dir)?;
|
|
let idx_path = tmp_index.path().to_string_lossy().into_owned();
|
|
|
|
let read_tree = duct::cmd(
|
|
"git",
|
|
["--git-dir", bare.as_str(), "read-tree", target_id.as_str()],
|
|
)
|
|
.env("GIT_INDEX_FILE", &idx_path)
|
|
.stdout_capture()
|
|
.stderr_capture()
|
|
.unchecked()
|
|
.run()?;
|
|
command_ok(read_tree)?;
|
|
|
|
for resolution in &request.resolutions {
|
|
let hash = duct::cmd(
|
|
"git",
|
|
["--git-dir", bare.as_str(), "hash-object", "-w", "--stdin"],
|
|
)
|
|
.stdin_bytes(resolution.content.clone())
|
|
.stdout_capture()
|
|
.stderr_capture()
|
|
.unchecked()
|
|
.run()?;
|
|
let blob = command_ok(hash)?.trim().to_string();
|
|
|
|
let update = duct::cmd(
|
|
"git",
|
|
[
|
|
"--git-dir",
|
|
bare.as_str(),
|
|
"update-index",
|
|
"--add",
|
|
"--cacheinfo",
|
|
"100644",
|
|
&blob,
|
|
&resolution.path,
|
|
],
|
|
)
|
|
.env("GIT_INDEX_FILE", &idx_path)
|
|
.env("GIT_WORK_TREE", bare.as_str())
|
|
.stdout_capture()
|
|
.stderr_capture()
|
|
.unchecked()
|
|
.run()?;
|
|
command_ok(update)?;
|
|
}
|
|
|
|
let write_tree = duct::cmd("git", ["--git-dir", bare.as_str(), "write-tree"])
|
|
.env("GIT_INDEX_FILE", &idx_path)
|
|
.stdout_capture()
|
|
.stderr_capture()
|
|
.unchecked()
|
|
.run()?;
|
|
let tree_id = command_ok(write_tree)?.trim().to_string();
|
|
|
|
let message = if !request.message.is_empty() {
|
|
request.message.clone()
|
|
} else {
|
|
format!(
|
|
"Merge '{}' into {} (resolved conflicts)",
|
|
source_revision, target_branch
|
|
)
|
|
};
|
|
|
|
let parents = vec![target_id.clone(), source_id.clone()];
|
|
let commit_id = self.commit_tree(
|
|
&tree_id,
|
|
&parents,
|
|
&message,
|
|
request.committer.as_ref(),
|
|
request.committer.as_ref(),
|
|
)?;
|
|
|
|
self.update_branch_ref(&target_branch, &commit_id, Some(&target_id), false)?;
|
|
|
|
Ok(MergeResult {
|
|
status: merge_result::Status::MergeResultStatusMerged as i32,
|
|
commit: Some(self.get_commit(crate::pb::GetCommitRequest {
|
|
repository: request.repository,
|
|
revision: Some(crate::pb::ObjectSelector {
|
|
selector: Some(crate::pb::object_selector::Selector::Revision(
|
|
crate::pb::ObjectName {
|
|
revision: commit_id,
|
|
},
|
|
)),
|
|
}),
|
|
include_stats: false,
|
|
include_raw: false,
|
|
})?),
|
|
merge_base: None,
|
|
conflicts: vec![],
|
|
stats: None,
|
|
message,
|
|
})
|
|
}
|
|
}
|