Visitar URL original
transport: reject unknown URL schemes before SSH fallback by sb123sb123 · Pull Request #7384 · libgit2/libgit2 · GitHub
Skip to content

transport: reject unknown URL schemes before SSH fallback - #7384

Open
sb123sb123 wants to merge 1 commit into
libgit2:mainfrom
sb123sb123:fix/7377-unknown-url-scheme
Open

sb123sb123 wants to merge 1 commit into
libgit2:mainfrom
sb123sb123:fix/7377-unknown-url-scheme

Conversation

@sb123sb123

Copy link
Copy Markdown
Contributor

Problem

git_clone() crashes on Windows when given an unregistered URL scheme such as foo://example.com instead of returning a libgit2 error. The issue reports an access violation in the SSH transport.

Cause

When no registered transport matched an URL, transport_find_fn() treated any URL containing a colon as an SCP-style SSH path. That routed unknown scheme://... inputs into the SSH transport, where behavior depended on the configured SSH provider.

Fix

Only apply the SSH fallback to non-URL colon syntax. Unknown URL schemes now return the existing unsupported URL protocol error, while SCP-style paths continue to use SSH. The regression test also verifies that git_clone() removes its temporary destination.

Fixes #7377

Tests

  • cmake -S ./work/libgit2-7377 -B ./work/libgit2-7377-msvc -G "Visual Studio 17 2022" -A x64 -DBUILD_SHARED_LIBS=OFF -DBUILD_TESTS=ON -DUSE_SSH=exec -DUSE_HTTP=OFF -DUSE_HTTPS=OFF
  • cmake --build ./work/libgit2-7377-msvc --config Release --target libgit2_tests --parallel 2
  • Release/libgit2_tests.exe -sclone::nonetwork::unknown_url_scheme
  • Release/libgit2_tests.exe -sclone::nonetwork (19 passed)
  • git diff --check

The full test binary loaded 3,159 tests; two unrelated existing diff::rename cases failed on this Windows host because their expected diff text differs in line-ending/content representation.

Limitations

The reported LibGit2Sharp/libssh2 access violation was not reproducible with the installed toolchain because libssh2 is unavailable. The Windows build used the OpenSSH exec provider and reproduced the shared misclassification as an unintended SSH/network attempt. HTTP/HTTPS transports and network-enabled tests were not exercised.

AI assistance

This pull request was prepared with AI assistance for issue triage, code investigation, patch drafting, and test execution. I reviewed the resulting diff and test output.

Treat only non-URL colon paths as SSH remotes. Unknown URL schemes such as foo://example.com were otherwise mistaken for SCP-style SSH paths, which could terminate the process in the SSH transport or attempt an unintended network connection. Preserve the existing unsupported URL error and add a clone regression test that verifies the destination is cleaned up. Fixes libgit2#7377.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] git_clone crashes on an unregistered URL scheme

1 participant