diff options
| author | Bryce Kwon <bryce@brycekwon.com> | |
|---|---|---|
| committer | Bryce Kwon <bryce@brycekwon.com> | |
| commit | ||
| parent | ||
| tree | ||
| download | ||
Restyle the sources and fix the audit's findings
Diffstat (limited to '')
| -rw-r--r-- | source/cgit.c | 1349 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
1 file changed, 712 insertions, 637 deletions
diff --git a/source/cgit.c b/source/cgit.c index 7cce3d3..5c11a93 100644 --- a/source/cgit.c +++ b/source/cgit.c @@ -1,43 +1,74 @@ -/* cgit.c: cgi for the git scm - * - * Copyright (C) 2006-2014 cgit Development Team <cgit@lists.zx2c4.com> - * - * Licensed under GNU General Public License v2 - * (see LICENSE.txt for full license text) +/* + * The entry point every request passes through. It reads cgitrc and the query + * string into the global ctx, works out how long the answer may be cached, + * and then hands over to the cache, which either serves a copy it already has + * or calls back here to render one. Rendering means authenticating the + * request, resolving the repository and the branch it names, and dispatching + * to the page handler cmd.c maps the page name to. Run from a shell rather + * than from a web server the same binary instead prints what it was built + * with, or scans a directory tree and writes out the repositories it found in + * cgitrc form. */ #define USE_THE_REPOSITORY_VARIABLE -#include "cgit.h" #include "cache.h" +#include "cgit.h" #include "cmd.h" -#include "configfile.h" +#include "config.h" +#include "filter.h" #include "html.h" -#include "ui-shared.h" -#include "ui-stats.h" +#include "parsing.h" +#include "scan-tree.h" +#include "shared.h" #include "ui-blob.h" +#include "ui-diff.h" #include "ui-empty.h" -#include "ui-summary.h" -#include "scan-tree.h" +#include "ui-shared.h" +#include "ui-snapshot.h" +#include "ui-stats.h" -/* We intentionally keep this rather small, instead of looping and - * feeding it to the filter a couple bytes at a time. This way, the - * filter itself does not need to handle any denial of service or - * buffer bloat issues. If this winds up being too small, people - * will complain on the mailing list, and we'll increase it as needed. */ +// Deliberately small. The whole body is read at once and handed to the auth +// filter, so a filter never has to defend itself against a huge or a +// dribbled-out POST. #define MAX_AUTHENTICATION_POST_BYTES 4096 + +// The filter bar matches the search against every item a page lists, so this +// bounds both the work one request can ask for and the cache key the query +// lands in. +#define MAX_SEARCH_LEN 512 + +// Furthest into a listing a request may ask to start. A walk has to step over +// every row it skips, so this bounds the work an offset alone can buy. +#define MAX_QUERY_OFFSET 100000 + +// cgit knows fewer than eight archive formats, so this stands in for every bit +// a snapshots mask can carry. +#define ALL_SNAPSHOT_FORMATS 0xFF + +// An Expires header has no way of saying never, so a page whose ttl is +// negative claims ten years. +#define NEVER_EXPIRES_SECONDS (10 * 365 * 24 * 60 * 60) + +/* + * The first branch found is the fallback, so a repository whose default branch + * does not exist still has something to show. + */ +struct refmatch { + char *wanted; + char *first; + int found; +}; + const char *cgit_version = CGIT_VERSION; /* - * Isolate git from the calling user's configuration. Ignore the system and - * global config and attributes, so a snapshot cannot be broken by something - * like a core.excludesfile pointing at a "~" path that git can no longer - * expand once HOME is unset below. - * - * Called at the top of cmd_main rather than from a constructor attribute. - * git-compat-util.h defines __attribute__ away on a compiler that does not - * support it, which would leave this silently never running. Nothing git does - * before cmd_main reads configuration, so an ordinary call is equivalent. + * Isolate git from the calling user's configuration, so a snapshot cannot be + * broken by something like a core.excludesfile pointing at a "~" path that git + * can no longer expand once HOME is unset below. Called from cmd_main rather + * than from a constructor attribute, because git-compat-util.h defines + * __attribute__ away on a compiler that does not support it, which would leave + * this silently never running. */ static void isolate_git_environment(void) { @@ -48,101 +79,385 @@ static void isolate_git_environment(void) unsetenv("XDG_CONFIG_HOME"); } -static void add_mimetype(const char *name, const char *value) +/* + * Turn a die from anywhere inside git into a rendered page, since a CGI that + * produced no output leaves the visitor with whatever the web server makes of + * it. + */ +static NORETURN void die_routine(const char *msg, va_list params) { - struct string_list_item *item; + // A page is rendered with stdout pointed at the cache file, so the + // message would otherwise be written there instead of to the visitor. + cache_abandon_fill(); + cgit_vprint_error_page(400, "Bad request", msg, params); + exit(0); +} - item = string_list_insert(&ctx.cfg.mimetypes, name); - item->util = xstrdup(value); +static void prepare_context(void) +{ + memset(&ctx, 0, sizeof(ctx)); + ctx.cfg.agefile = "info/web/last-modified"; + ctx.cfg.cache_size = 0; + ctx.cfg.cache_root = CGIT_CACHE_ROOT; + ctx.cfg.cache_about_ttl = 15; + ctx.cfg.cache_snapshot_ttl = 5; + ctx.cfg.cache_repo_ttl = 5; + ctx.cfg.cache_root_ttl = 5; + ctx.cfg.cache_scanrc_ttl = 15; + ctx.cfg.cache_dynamic_ttl = 5; + ctx.cfg.cache_static_ttl = -1; + ctx.cfg.case_sensitive_sort = 1; + ctx.cfg.branch_sort = 0; + ctx.cfg.commit_sort = 0; + ctx.cfg.logo = "/cgit.png"; + ctx.cfg.favicon = "/favicon.ico"; + ctx.cfg.local_time = 0; + ctx.cfg.date_mode = date_mode_from_type(DATE_SHORT); + ctx.cfg.enable_relative_dates = 1; + ctx.cfg.enable_http_clone = 1; + ctx.cfg.enable_index_owner = 1; + ctx.cfg.enable_tree_linenumbers = 1; + ctx.cfg.enable_git_config = 0; + ctx.cfg.max_repo_count = 50; + ctx.cfg.max_commit_count = 50; + ctx.cfg.max_patch_count = 50; + ctx.cfg.max_diff_files = 200; + ctx.cfg.max_diff_lines = 1000; + ctx.cfg.max_msg_len = 80; + ctx.cfg.max_ref_count = 200; + ctx.cfg.max_repodesc_len = 80; + // Counted in kilobytes, so ten megabytes, which bounds the memory one + // request can be made to allocate for a blob. + ctx.cfg.max_blob_size = 10 * 1024; + ctx.cfg.max_stats = 0; + ctx.cfg.project_list = NULL; + ctx.cfg.renamelimit = -1; + ctx.cfg.remove_suffix = 0; + ctx.cfg.robots = "index, nofollow"; + ctx.cfg.root_title = "Git repository browser"; + ctx.cfg.root_desc = "a fast webinterface for the git dscm"; + ctx.cfg.scan_hidden_path = 0; + ctx.cfg.script_name = CGIT_SCRIPT_NAME; + ctx.cfg.section = ""; + ctx.cfg.repository_sort = "name"; + ctx.cfg.section_sort = 0; + ctx.cfg.summary_branches = 10; + ctx.cfg.summary_log = 10; + ctx.cfg.summary_tags = 10; + ctx.cfg.max_atom_items = 10; + ctx.cfg.difftype = DIFF_UNIFIED; + ctx.env.cgit_config = getenv("CGIT_CONFIG"); + ctx.env.http_host = getenv("HTTP_HOST"); + ctx.env.https = getenv("HTTPS"); + ctx.env.no_http = getenv("NO_HTTP"); + ctx.env.path_info = getenv("PATH_INFO"); + ctx.env.query_string = getenv("QUERY_STRING"); + ctx.env.request_method = getenv("REQUEST_METHOD"); + ctx.env.script_name = getenv("SCRIPT_NAME"); + ctx.env.server_name = getenv("SERVER_NAME"); + ctx.env.server_port = getenv("SERVER_PORT"); + ctx.env.http_cookie = getenv("HTTP_COOKIE"); + ctx.env.http_referer = getenv("HTTP_REFERER"); + ctx.env.content_length = getenv("CONTENT_LENGTH") ? + strtoul(getenv("CONTENT_LENGTH"), NULL, 10) : 0; + ctx.env.authenticated = 0; + ctx.page.mimetype = "text/html"; + ctx.page.charset = PAGE_ENCODING; + ctx.page.filename = NULL; + ctx.page.size = 0; + ctx.page.modified = time(NULL); + ctx.page.expires = ctx.page.modified; + ctx.page.etag = NULL; + string_list_init_dup(&ctx.cfg.mimetypes); + if (ctx.env.script_name) + ctx.cfg.script_name = xstrdup(ctx.env.script_name); + if (ctx.env.query_string) + ctx.qry.raw = xstrdup(ctx.env.query_string); + if (!ctx.env.cgit_config) + ctx.env.cgit_config = CGIT_CONFIG; +} + +static void print_version(void) +{ + printf("CGit %s | https://github.com/brycekwon/cgit\n\nCompiled in features:\n", CGIT_VERSION); +#ifdef NO_LUA + printf("[-] "); +#else + printf("[+] "); +#endif + printf("Lua scripting\n"); +#ifndef HAVE_LINUX_SENDFILE + printf("[-] "); +#else + printf("[+] "); +#endif + printf("Linux sendfile() usage\n"); } -static void process_cached_repolist(const char *path); +static int cmp_repos(const void *a, const void *b) +{ + const struct cgit_repo *repo_a = a, *repo_b = b; + return strcmp(repo_a->url, repo_b->url); +} -void cgit_repo_config(struct cgit_repo *repo, const char *name, const char *value) +static char *build_snapshot_setting(int mask) +{ + const struct cgit_snapshot_format *format; + struct strbuf result = STRBUF_INIT; + + for (format = cgit_snapshot_formats; format->suffix; format++) { + if (cgit_snapshot_format_bit(format) & mask) { + if (result.len) + strbuf_addch(&result, ' '); + strbuf_addstr(&result, format->suffix); + } + } + return strbuf_detach(&result, NULL); +} + +static void print_repo(FILE *f, struct cgit_repo *repo) { - const char *path; struct string_list_item *item; - if (!strcmp(name, "name")) - repo->name = cgit_strdup_first_line(value); - else if (!strcmp(name, "clone-url")) - repo->clone_url = cgit_strdup_first_line(value); - else if (!strcmp(name, "desc")) - repo->desc = cgit_strdup_first_line(value); - else if (!strcmp(name, "owner")) - repo->owner = cgit_strdup_first_line(value); - else if (!strcmp(name, "homepage")) - repo->homepage = cgit_strdup_first_line(value); - else if (!strcmp(name, "defbranch")) - repo->defbranch = cgit_strdup_first_line(value); - else if (!strcmp(name, "extra-head-content")) - repo->extra_head_content = cgit_strdup_first_line(value); - else if (!strcmp(name, "snapshots")) - repo->snapshots = ctx.cfg.snapshots & cgit_parse_snapshots_mask(value); - else if (!strcmp(name, "enable-blame")) - repo->enable_blame = atoi(value); - else if (!strcmp(name, "enable-commit-graph")) - repo->enable_commit_graph = atoi(value); - else if (!strcmp(name, "enable-follow-links")) - repo->enable_follow_links = atoi(value); - else if (!strcmp(name, "enable-log-filecount")) - repo->enable_log_filecount = atoi(value); - else if (!strcmp(name, "enable-log-linecount")) - repo->enable_log_linecount = atoi(value); - else if (!strcmp(name, "enable-remote-branches")) - repo->enable_remote_branches = atoi(value); - else if (!strcmp(name, "enable-subject-links")) - repo->enable_subject_links = atoi(value); - else if (!strcmp(name, "enable-html-serving")) - repo->enable_html_serving = atoi(value); - else if (!strcmp(name, "enable-stats")) - repo->enable_stats = atoi(value); - else if (!strcmp(name, "branch-sort")) { - if (!strcmp(value, "age")) - repo->branch_sort = 1; - if (!strcmp(value, "name")) - repo->branch_sort = 0; - } else if (!strcmp(name, "commit-sort")) { - if (!strcmp(value, "date")) - repo->commit_sort = 1; - if (!strcmp(value, "topo")) - repo->commit_sort = 2; - } else if (!strcmp(name, "max-stats")) - repo->max_stats = cgit_find_stats_period(value, NULL); - else if (!strcmp(name, "module-link")) - repo->module_link= cgit_strdup_first_line(value); - else if (skip_prefix(name, "module-link.", &path)) { - item = string_list_append(&repo->submodules, cgit_strdup_first_line(path)); - item->util = cgit_strdup_first_line(value); - } else if (!strcmp(name, "section")) - repo->section = cgit_strdup_first_line(value); - else if (!strcmp(name, "snapshot-prefix")) - repo->snapshot_prefix = cgit_strdup_first_line(value); - else if (!strcmp(name, "readme") && value != NULL) { - if (repo->readme.items == ctx.cfg.readme.items) - memset(&repo->readme, 0, sizeof(repo->readme)); - string_list_append(&repo->readme, cgit_strdup_first_line(value)); - } else if (!strcmp(name, "logo") && value != NULL) - repo->logo = cgit_strdup_first_line(value); - else if (!strcmp(name, "logo-link") && value != NULL) - repo->logo_link = cgit_strdup_first_line(value); - else if (!strcmp(name, "hide")) - repo->hide = atoi(value); - else if (!strcmp(name, "ignore")) - repo->ignore = atoi(value); - else if (ctx.cfg.enable_filter_overrides) { - if (!strcmp(name, "about-filter")) - repo->about_filter = cgit_new_filter(value, ABOUT); - else if (!strcmp(name, "commit-filter")) - repo->commit_filter = cgit_new_filter(value, COMMIT); - else if (!strcmp(name, "source-filter")) - repo->source_filter = cgit_new_filter(value, SOURCE); - else if (!strcmp(name, "email-filter")) - repo->email_filter = cgit_new_filter(value, EMAIL); + fprintf(f, "repo.url=%s\n", repo->url); + fprintf(f, "repo.name=%s\n", repo->name); + fprintf(f, "repo.path=%s\n", repo->path); + if (repo->owner) + fprintf(f, "repo.owner=%s\n", repo->owner); + if (repo->desc) + fprintf(f, "repo.desc=%s\n", repo->desc); + for_each_string_list_item(item, &repo->readme) { + if (item->util) + fprintf(f, "repo.readme=%s:%s\n", (char *)item->util, item->string); + else + fprintf(f, "repo.readme=%s\n", item->string); + } + if (repo->defbranch) + fprintf(f, "repo.defbranch=%s\n", repo->defbranch); + if (repo->extra_head_content) + fprintf(f, "repo.extra-head-content=%s\n", repo->extra_head_content); + if (repo->module_link) + fprintf(f, "repo.module-link=%s\n", repo->module_link); + if (repo->section) + fprintf(f, "repo.section=%s\n", repo->section); + if (repo->homepage) + fprintf(f, "repo.homepage=%s\n", repo->homepage); + if (repo->clone_url) + fprintf(f, "repo.clone-url=%s\n", repo->clone_url); + fprintf(f, "repo.enable-blame=%d\n", repo->enable_blame); + fprintf(f, "repo.enable-commit-graph=%d\n", repo->enable_commit_graph); + fprintf(f, "repo.enable-follow-links=%d\n", repo->enable_follow_links); + fprintf(f, "repo.enable-log-filecount=%d\n", repo->enable_log_filecount); + fprintf(f, "repo.enable-log-linecount=%d\n", repo->enable_log_linecount); + if (repo->about_filter && repo->about_filter != ctx.cfg.about_filter) + cgit_fprintf_filter(repo->about_filter, f, "repo.about-filter="); + if (repo->commit_filter && repo->commit_filter != ctx.cfg.commit_filter) + cgit_fprintf_filter(repo->commit_filter, f, "repo.commit-filter="); + if (repo->source_filter && repo->source_filter != ctx.cfg.source_filter) + cgit_fprintf_filter(repo->source_filter, f, "repo.source-filter="); + if (repo->email_filter && repo->email_filter != ctx.cfg.email_filter) + cgit_fprintf_filter(repo->email_filter, f, "repo.email-filter="); + if (repo->snapshots != ctx.cfg.snapshots) { + char *formats = build_snapshot_setting(repo->snapshots); + fprintf(f, "repo.snapshots=%s\n", formats ? formats : ""); + free(formats); + } + if (repo->snapshot_prefix) + fprintf(f, "repo.snapshot-prefix=%s\n", repo->snapshot_prefix); + if (repo->enable_stats != ctx.cfg.enable_stats) + fprintf(f, "repo.enable-stats=%d\n", repo->enable_stats); + if (repo->max_stats != ctx.cfg.max_stats) + fprintf(f, "repo.max-stats=%s\n", + cgit_find_stats_periodname(repo->max_stats)); + if (repo->logo) + fprintf(f, "repo.logo=%s\n", repo->logo); + if (repo->logo_link) + fprintf(f, "repo.logo-link=%s\n", repo->logo_link); + fprintf(f, "repo.enable-remote-branches=%d\n", repo->enable_remote_branches); + fprintf(f, "repo.enable-subject-links=%d\n", repo->enable_subject_links); + fprintf(f, "repo.enable-html-serving=%d\n", repo->enable_html_serving); + if (repo->branch_sort == 1) + fprintf(f, "repo.branch-sort=age\n"); + if (repo->commit_sort) { + if (repo->commit_sort == 1) + fprintf(f, "repo.commit-sort=date\n"); + else if (repo->commit_sort == 2) + fprintf(f, "repo.commit-sort=topo\n"); + } + fprintf(f, "repo.hide=%d\n", repo->hide); + fprintf(f, "repo.ignore=%d\n", repo->ignore); + fprintf(f, "\n"); +} + +static void print_repolist(FILE *f, struct cgit_repolist *list, int start) +{ + int i; + + for (i = start; i < list->count; i++) + print_repo(f, &list->repos[i]); +} + +static void parse_args(int argc, const char **argv) +{ + int i; + const char *arg; + int scanned = 0; + + for (i = 1; i < argc; i++) { + if (!strcmp(argv[i], "--version")) { + print_version(); + exit(0); + } + if (skip_prefix(argv[i], "--cache=", &arg)) { + ctx.cfg.cache_root = xstrdup(arg); + } else if (!strcmp(argv[i], "--nohttp")) { + ctx.env.no_http = "1"; + } else if (skip_prefix(argv[i], "--query=", &arg)) { + ctx.qry.raw = xstrdup(arg); + } else if (skip_prefix(argv[i], "--repo=", &arg)) { + ctx.qry.repo = xstrdup(arg); + } else if (skip_prefix(argv[i], "--page=", &arg)) { + ctx.qry.page = xstrdup(arg); + } else if (skip_prefix(argv[i], "--head=", &arg)) { + ctx.qry.head = xstrdup(arg); + ctx.qry.has_symref = 1; + } else if (skip_prefix(argv[i], "--oid=", &arg)) { + ctx.qry.oid = xstrdup(arg); + ctx.qry.has_oid = 1; + } else if (skip_prefix(argv[i], "--ofs=", &arg)) { + ctx.qry.ofs = atoi(arg); + } else if (skip_prefix(argv[i], "--scan-tree=", &arg) || + skip_prefix(argv[i], "--scan-path=", &arg)) { + // A repository's own snapshots setting is masked with + // the global one, which normally comes from cgitrc. + // That has not been read yet here, so an empty mask + // would discard whatever the repository asked for. + ctx.cfg.snapshots = ALL_SNAPSHOT_FORMATS; + scanned++; + scan_tree(arg); + } + } + if (scanned) { + qsort(cgit_repolist.repos, cgit_repolist.count, + sizeof(struct cgit_repo), cmp_repos); + print_repolist(stdout, &cgit_repolist, 0); + exit(0); + } +} + +static int generate_cached_repolist(const char *path, const char *cached_rc) +{ + struct strbuf locked_rc = STRBUF_INIT; + int err = 0; + int first; + FILE *f; + + strbuf_addf(&locked_rc, "%s.lock", cached_rc); + f = fopen(locked_rc.buf, "wx"); + if (!f) { + // An existing lock file only means concurrent requests, which + // is not worth a line in the server log. + err = errno; + if (err != EEXIST) + fprintf(stderr, "[cgit] Error opening %s: %s (%d)\n", + locked_rc.buf, strerror(err), err); + goto out; + } + first = cgit_repolist.count; + if (ctx.cfg.project_list) + scan_projects(path, ctx.cfg.project_list); + else + scan_tree(path); + print_repolist(f, &cgit_repolist, first); + // Closed before the rename, because print_repolist writes through stdio + // and a rename over the live file would otherwise publish a repolist + // that stops wherever the buffer happened to end. + if (fclose(f)) { + err = errno; + fprintf(stderr, "[cgit] Error writing %s: %s (%d)\n", + locked_rc.buf, strerror(err), err); + unlink(locked_rc.buf); + goto out; + } + if (rename(locked_rc.buf, cached_rc)) { + err = errno; + fprintf(stderr, "[cgit] Error renaming %s to %s: %s (%d)\n", + locked_rc.buf, cached_rc, strerror(err), err); + unlink(locked_rc.buf); + } +out: + strbuf_release(&locked_rc); + return err; +} + +// A cached repolist is itself a config file, so these two call each other. +static void apply_config(const char *name, const char *value); + +static void process_cached_repolist(const char *path) +{ + struct stat st; + struct strbuf cached_rc = STRBUF_INIT; + time_t age; + unsigned long hash; + int devnull; + + hash = cache_hash_str(path); + if (ctx.cfg.project_list) + hash += cache_hash_str(ctx.cfg.project_list); + strbuf_addf(&cached_rc, "%s/rc-%8lx", ctx.cfg.cache_root, hash); + + if (stat(cached_rc.buf, &st)) { + // Nothing is cached yet, so this request scans in its own + // process, leaving no copy behind when it cannot take the lock. + if (generate_cached_repolist(path, cached_rc.buf)) { + if (ctx.cfg.project_list) + scan_projects(path, ctx.cfg.project_list); + else + scan_tree(path); + } + goto out; + } + + config_file_parse(cached_rc.buf, apply_config); + + age = time(NULL) - st.st_mtime; + if (age <= (ctx.cfg.cache_scanrc_ttl * 60)) + goto out; + + // The list just parsed is stale but usable, so a child rebuilds it + // while this request answers from what it already has. + if (fork()) + goto out; + + // The child inherits the descriptors of the request, and the web server + // reads stdout until every holder of it is gone, so leaving them in + // place would keep the visitor waiting for the whole scan after their + // page was written. Anything the scan prints would land on that + // response as well. + devnull = open("/dev/null", O_RDWR); + if (devnull >= 0) { + dup2(devnull, STDIN_FILENO); + dup2(devnull, STDOUT_FILENO); + dup2(devnull, STDERR_FILENO); + if (devnull > STDERR_FILENO) + close(devnull); } + // _exit rather than exit, so the handlers the request registered do + // not run a second time in the child. + _exit(generate_cached_repolist(path, cached_rc.buf)); +out: + strbuf_release(&cached_rc); } -static void config_cb(const char *name, const char *value) +static void add_mimetype(const char *name, const char *value) +{ + struct string_list_item *item; + + item = string_list_insert(&ctx.cfg.mimetypes, name); + item->util = xstrdup(value); +} + +static void apply_config(const char *name, const char *value) { const char *arg; @@ -282,7 +597,7 @@ static void config_cb(const char *name, const char *value) ctx.cfg.max_patch_count = atoi(value); else if (!strcmp(name, "project-list")) ctx.cfg.project_list = cgit_strdup_first_line(cgit_expand_macros(value)); - else if (!strcmp(name, "scan-path")) + else if (!strcmp(name, "scan-path")) { if (ctx.cfg.cache_size) process_cached_repolist(cgit_expand_macros(value)); else if (ctx.cfg.project_list) @@ -290,7 +605,7 @@ static void config_cb(const char *name, const char *value) ctx.cfg.project_list); else scan_tree(cgit_expand_macros(value)); - else if (!strcmp(name, "scan-hidden-path")) + } else if (!strcmp(name, "scan-hidden-path")) ctx.cfg.scan_hidden_path = atoi(value); else if (!strcmp(name, "section-from-path")) ctx.cfg.section_from_path = atoi(value); @@ -339,10 +654,27 @@ static void config_cb(const char *name, const char *value) } else if (skip_prefix(name, "mimetype.", &arg)) add_mimetype(arg, value); else if (!strcmp(name, "include")) - parse_configfile(cgit_expand_macros(value), config_cb); + config_file_parse(cgit_expand_macros(value), apply_config); +} + +/* + * Read a whole number a request supplied, clamped into the range the caller + * accepts. strtol rather than atoi, because atoi has no defined behaviour once + * the digits overflow and every value here arrives straight from the query + * string. + */ +static int query_int(const char *value, int min, int max) +{ + long number = strtol(value, NULL, 10); + + if (number < min) + return min; + if (number > max) + return max; + return number; } -static void querystring_cb(const char *name, const char *value) +static void apply_query_param(const char *name, const char *value) { if (!value) value = ""; @@ -353,19 +685,19 @@ static void querystring_cb(const char *name, const char *value) } else if (!strcmp(name, "p")) { ctx.qry.page = xstrdup(value); } else if (!strcmp(name, "url")) { - if (*value == '/') + // Every leading slash goes, not just one. What is left is + // joined onto the virtual root, so a value like //example.com + // would otherwise survive as /example.com and make that join a + // scheme-relative link to another host. + while (*value == '/') value++; ctx.qry.url = xstrdup(value); cgit_parse_url(value); } else if (!strcmp(name, "qt")) { ctx.qry.grep = xstrdup(value); } else if (!strcmp(name, "q")) { - /* A query is matched against every repository, ref or commit - * the page lists, so bound what one request can ask to be - * compared. Nothing legible reaches this length, and the value - * also lands in the cache key. */ - if (strlen(value) > CGIT_MAX_SEARCH_LEN) - ctx.qry.search = xstrndup(value, CGIT_MAX_SEARCH_LEN); + if (strlen(value) > MAX_SEARCH_LEN) + ctx.qry.search = xstrndup(value, MAX_SEARCH_LEN); else ctx.qry.search = xstrdup(value); } else if (!strcmp(name, "h")) { @@ -378,165 +710,178 @@ static void querystring_cb(const char *name, const char *value) ctx.qry.oid2 = xstrdup(value); ctx.qry.has_oid = 1; } else if (!strcmp(name, "ofs")) { - /* Bound the upper end so a crafted value cannot force a walk - * over the whole history (and strtol avoids the atoi overflow). - * Only clamp the upper end: ofs is overloaded, the stats page - * submits -1 for "all authors", and the log skip loop already - * floors negatives at zero. */ - long ofs = strtol(value, NULL, 10); - if (ofs > 100000) - ofs = 100000; - else if (ofs < -1) - ofs = -1; - ctx.qry.ofs = ofs; + // Bounded above so a crafted value cannot force a walk over the + // whole history. Negatives stop at -1 rather than at zero, + // because the offset is overloaded, the stats page submits -1 + // for all authors, and the log skip loop floors a negative + // itself. + ctx.qry.ofs = query_int(value, -1, MAX_QUERY_OFFSET); } else if (!strcmp(name, "path")) { ctx.qry.path = cgit_trim_end(value, '/'); } else if (!strcmp(name, "s")) { ctx.qry.sort = xstrdup(value); } else if (!strcmp(name, "showmsg")) { - ctx.qry.showmsg = atoi(value); + ctx.qry.showmsg = query_int(value, INT_MIN, INT_MAX); } else if (!strcmp(name, "period")) { ctx.qry.period = xstrdup(value); } else if (!strcmp(name, "dt")) { - ctx.qry.difftype = atoi(value); + ctx.qry.difftype = query_int(value, INT_MIN, INT_MAX); ctx.qry.has_difftype = 1; } else if (!strcmp(name, "ss")) { - /* No longer generated, but there may be links out there. */ - ctx.qry.difftype = atoi(value) ? DIFF_SSDIFF : DIFF_UNIFIED; + // No longer generated, but old links still carry it. + ctx.qry.difftype = query_int(value, INT_MIN, INT_MAX) ? + DIFF_SSDIFF : DIFF_UNIFIED; ctx.qry.has_difftype = 1; } else if (!strcmp(name, "all")) { - ctx.qry.show_all = atoi(value); + ctx.qry.show_all = query_int(value, INT_MIN, INT_MAX); } else if (!strcmp(name, "context")) { - ctx.qry.context = atoi(value); + // Context lines are not counted against max-diff-lines, so an + // unbounded width turns a whole blob into context and renders + // it in full however small the change was. + ctx.qry.context = query_int(value, 0, MAX_DIFF_CONTEXT_LINES); } else if (!strcmp(name, "ignorews")) { - ctx.qry.ignorews = atoi(value); + ctx.qry.ignorews = query_int(value, INT_MIN, INT_MAX); } else if (!strcmp(name, "follow")) { - ctx.qry.follow = atoi(value); + ctx.qry.follow = query_int(value, INT_MIN, INT_MAX); } } -static void prepare_context(void) +static void open_auth_filter(const char *action) { - memset(&ctx, 0, sizeof(ctx)); - ctx.cfg.agefile = "info/web/last-modified"; - ctx.cfg.cache_size = 0; - ctx.cfg.cache_root = CGIT_CACHE_ROOT; - ctx.cfg.cache_about_ttl = 15; - ctx.cfg.cache_snapshot_ttl = 5; - ctx.cfg.cache_repo_ttl = 5; - ctx.cfg.cache_root_ttl = 5; - ctx.cfg.cache_scanrc_ttl = 15; - ctx.cfg.cache_dynamic_ttl = 5; - ctx.cfg.cache_static_ttl = -1; - ctx.cfg.case_sensitive_sort = 1; - ctx.cfg.branch_sort = 0; - ctx.cfg.commit_sort = 0; - ctx.cfg.logo = "/cgit.png"; - ctx.cfg.favicon = "/favicon.ico"; - ctx.cfg.local_time = 0; - ctx.cfg.date_mode = date_mode_from_type(DATE_SHORT); - ctx.cfg.enable_relative_dates = 1; - ctx.cfg.enable_http_clone = 1; - ctx.cfg.enable_index_owner = 1; - ctx.cfg.enable_tree_linenumbers = 1; - ctx.cfg.enable_git_config = 0; - ctx.cfg.max_repo_count = 50; - ctx.cfg.max_commit_count = 50; - ctx.cfg.max_patch_count = 50; - ctx.cfg.max_diff_files = 200; /* larger commits render stat only */ - ctx.cfg.max_diff_lines = 1000; /* larger file diffs link out */ - ctx.cfg.max_msg_len = 80; - ctx.cfg.max_ref_count = 200; /* refs beyond this paginate */ - ctx.cfg.max_repodesc_len = 80; - ctx.cfg.max_blob_size = 10 * 1024; /* 10 MB; bounds per-request memory */ - ctx.cfg.max_stats = 0; - ctx.cfg.project_list = NULL; - ctx.cfg.renamelimit = -1; - ctx.cfg.remove_suffix = 0; - ctx.cfg.robots = "index, nofollow"; - ctx.cfg.root_title = "Git repository browser"; - ctx.cfg.root_desc = "a fast webinterface for the git dscm"; - ctx.cfg.scan_hidden_path = 0; - ctx.cfg.script_name = CGIT_SCRIPT_NAME; - ctx.cfg.section = ""; - ctx.cfg.repository_sort = "name"; - ctx.cfg.section_sort = 0; - ctx.cfg.summary_branches = 10; - ctx.cfg.summary_log = 10; - ctx.cfg.summary_tags = 10; - ctx.cfg.max_atom_items = 10; - ctx.cfg.difftype = DIFF_UNIFIED; - ctx.env.cgit_config = getenv("CGIT_CONFIG"); - ctx.env.http_host = getenv("HTTP_HOST"); - ctx.env.https = getenv("HTTPS"); - ctx.env.no_http = getenv("NO_HTTP"); - ctx.env.path_info = getenv("PATH_INFO"); - ctx.env.query_string = getenv("QUERY_STRING"); - ctx.env.request_method = getenv("REQUEST_METHOD"); - ctx.env.script_name = getenv("SCRIPT_NAME"); - ctx.env.server_name = getenv("SERVER_NAME"); - ctx.env.server_port = getenv("SERVER_PORT"); - ctx.env.http_cookie = getenv("HTTP_COOKIE"); - ctx.env.http_referer = getenv("HTTP_REFERER"); - ctx.env.content_length = getenv("CONTENT_LENGTH") ? strtoul(getenv("CONTENT_LENGTH"), NULL, 10) : 0; - ctx.env.authenticated = 0; - ctx.page.mimetype = "text/html"; - ctx.page.charset = PAGE_ENCODING; - ctx.page.filename = NULL; - ctx.page.size = 0; - ctx.page.modified = time(NULL); - ctx.page.expires = ctx.page.modified; - ctx.page.etag = NULL; - string_list_init_dup(&ctx.cfg.mimetypes); - if (ctx.env.script_name) - ctx.cfg.script_name = xstrdup(ctx.env.script_name); - if (ctx.env.query_string) - ctx.qry.raw = xstrdup(ctx.env.query_string); - if (!ctx.env.cgit_config) - ctx.env.cgit_config = CGIT_CONFIG; + cgit_open_filter(ctx.cfg.auth_filter, action, + ctx.env.http_cookie ? ctx.env.http_cookie : "", + ctx.env.request_method ? ctx.env.request_method : "", + ctx.env.query_string ? ctx.env.query_string : "", + ctx.env.http_referer ? ctx.env.http_referer : "", + ctx.env.path_info ? ctx.env.path_info : "", + ctx.env.http_host ? ctx.env.http_host : "", + ctx.env.https ? ctx.env.https : "", + ctx.qry.repo ? ctx.qry.repo : "", + ctx.qry.page ? ctx.qry.page : "", + cgit_currentfullurl(), + cgit_loginurl()); } -struct refmatch { - char *req_ref; - char *first_ref; - int match; -}; +/* + * The filter answers the login POST itself, writing the status line and every + * header, so nothing here prints any and the process ends before this returns. + */ +static void authenticate_post(void) +{ + char buffer[MAX_AUTHENTICATION_POST_BYTES]; + size_t len; + ssize_t got; + + open_auth_filter("authenticate-post"); + len = ctx.env.content_length; + if (len > MAX_AUTHENTICATION_POST_BYTES) + len = MAX_AUTHENTICATION_POST_BYTES; + if ((got = read(STDIN_FILENO, buffer, len)) < 0) + die_errno("Could not read POST from stdin"); + if (write(STDOUT_FILENO, buffer, got) < 0) + die_errno("Could not write POST to stdout"); + cgit_close_filter(ctx.cfg.auth_filter); + exit(0); +} + +static void authenticate_cookie(void) +{ + if (!ctx.cfg.auth_filter) { + ctx.env.authenticated = 1; + return; + } + + if (ctx.env.request_method && ctx.qry.page && !ctx.repo && + !strcmp(ctx.env.request_method, "POST") && + !strcmp(ctx.qry.page, "login")) { + authenticate_post(); + return; + } + + open_auth_filter("authenticate-cookie"); + ctx.env.authenticated = cgit_close_filter(ctx.cfg.auth_filter); +} + +// Every cache-*-ttl setting is written in minutes, and so is this. +static int calc_ttl(void) +{ + if (!ctx.repo) + return ctx.cfg.cache_root_ttl; + + if (!ctx.qry.page) + return ctx.cfg.cache_repo_ttl; + + if (!strcmp(ctx.qry.page, "about")) + return ctx.cfg.cache_about_ttl; + + if (!strcmp(ctx.qry.page, "snapshot")) + return ctx.cfg.cache_snapshot_ttl; + + if (ctx.qry.has_oid) + return ctx.cfg.cache_static_ttl; + + if (ctx.qry.has_symref) + return ctx.cfg.cache_dynamic_ttl; + + return ctx.cfg.cache_repo_ttl; +} -static int find_current_ref(const struct reference *ref, void *cb_data) +/* + * The scheme and the host are folded in because the absolute urls a page + * carries, its clone urls and atom links, are built from them, so a request + * arriving with a spoofed Host must not poison the page served to a visitor + * who came in on the real one. + */ +static void build_cache_key(struct strbuf *key) { - struct refmatch *info; + char *hosturl = cgit_hosturl(); + const char *parts[] = { + cgit_httpscheme(), + hosturl ? hosturl : "", + ctx.env.path_info ? ctx.env.path_info : "", + ctx.env.query_string ? ctx.env.query_string : "", + }; + size_t i; - info = (struct refmatch *)cb_data; - if (!strcmp(ref->name, info->req_ref)) - info->match = 1; - if (!info->first_ref) - info->first_ref = xstrdup(ref->name); - return info->match; + // Each part is written behind its own length, so nothing a value + // contains can make two different requests spell one key. The path and + // the query come from the environment rather than the query string cgit + // rebuilds, since that rebuild folds the two together and would let the + // PATH_INFO and QUERY_STRING forms of one request share a slot. + for (i = 0; i < ARRAY_SIZE(parts); i++) + strbuf_addf(key, "%zu|%s", strlen(parts[i]), parts[i]); + free(hosturl); } -static void free_refmatch_inner(struct refmatch *info) +// Returning non-zero ends git's walk, so the search stops at the first hit. +static int find_current_ref(const struct reference *ref, void *data) { - if (info->first_ref) - free(info->first_ref); + struct refmatch *match = data; + + if (!strcmp(ref->name, match->wanted)) + match->found = 1; + if (!match->first) + match->first = xstrdup(ref->name); + return match->found; } static char *find_default_branch(struct cgit_repo *repo) { - struct refmatch info; + struct refmatch match; char *ref; - info.req_ref = repo->defbranch; - info.first_ref = NULL; - info.match = 0; + match.wanted = repo->defbranch; + match.first = NULL; + match.found = 0; refs_for_each_branch_ref(get_main_ref_store(the_repository), - find_current_ref, &info); - if (info.match) - ref = info.req_ref; + find_current_ref, &match); + if (match.found) + ref = match.wanted; else - ref = info.first_ref; + ref = match.first; if (ref) ref = xstrdup(ref); - free_refmatch_inner(&info); + free(match.first); return ref; } @@ -553,8 +898,12 @@ static char *guess_defbranch(void) return xstrdup(refname); } -/* The caller must free filename and ref after calling this. */ -static inline void parse_readme(const char *readme, char **filename, char **ref, struct cgit_repo *repo) +/* + * Split one readme setting into the file it names and the ref that file is + * read from, leaving the ref NULL for a file on disk. The caller frees both. + */ +static void parse_readme(const char *readme, char **filename, char **ref, + struct cgit_repo *repo) { const char *colon; @@ -564,11 +913,10 @@ static inline void parse_readme(const char *readme, char **filename, char **ref, if (!readme || !readme[0]) return; - /* Check if the readme is tracked in the git repo. */ + // A colon separates a ref from a path, so a setting carrying one names + // a file tracked in the repository rather than one on disk. colon = strchr(readme, ':'); if (colon && strlen(colon) > 1) { - /* If it starts with a colon, we want to use head given - * from query or the default branch */ if (colon == readme && ctx.qry.head) *ref = xstrdup(ctx.qry.head); else if (colon == readme && repo->defbranch) @@ -578,12 +926,12 @@ static inline void parse_readme(const char *readme, char **filename, char **ref, readme = colon + 1; } - /* Prepend repo path to relative readme path unless tracked. */ if (!(*ref) && readme[0] != '/') *filename = cgit_fmtalloc("%s/%s", repo->path, readme); else *filename = xstrdup(readme); } + static void choose_readme(struct cgit_repo *repo) { int found; @@ -623,24 +971,26 @@ static void choose_readme(struct cgit_repo *repo) static void prepare_repo_env(int *nongit) { - /* The path to the git repository. */ setenv("GIT_DIR", ctx.repo->path, 1); - /* Setup the git directory and initialize the notes system. Both of these - * load local configuration from the git repository, so we do them both while - * the HOME variables are unset. */ + // Both read configuration out of the repository, with the user's own + // git configuration already stripped by isolate_git_environment. setup_git_directory_gently(the_repository, nongit); load_display_notes(NULL); } +/* + * Returns non-zero once it has written a complete response of its own, in + * which case the caller must not render a page over the top of it. + */ static int prepare_repo_cmd(int nongit) { struct object_id oid; - int rc; + int err; if (nongit) { const char *name = ctx.repo->name; - rc = errno; + err = errno; ctx.page.title = cgit_fmtalloc("%s - %s", ctx.cfg.root_title, "config error"); ctx.repo = NULL; @@ -648,7 +998,7 @@ static int prepare_repo_cmd(int nongit) cgit_print_docstart(); cgit_print_pageheader(); cgit_print_error("Failed to open %s: %s", name, - rc ? strerror(rc) : "Not a valid git repository"); + err ? strerror(err) : "Not a valid git repository"); cgit_print_docend(); return 1; } @@ -690,71 +1040,13 @@ static int prepare_repo_cmd(int nongit) return 0; } -static inline void open_auth_filter(const char *function) -{ - cgit_open_filter(ctx.cfg.auth_filter, function, - ctx.env.http_cookie ? ctx.env.http_cookie : "", - ctx.env.request_method ? ctx.env.request_method : "", - ctx.env.query_string ? ctx.env.query_string : "", - ctx.env.http_referer ? ctx.env.http_referer : "", - ctx.env.path_info ? ctx.env.path_info : "", - ctx.env.http_host ? ctx.env.http_host : "", - ctx.env.https ? ctx.env.https : "", - ctx.qry.repo ? ctx.qry.repo : "", - ctx.qry.page ? ctx.qry.page : "", - cgit_currentfullurl(), - cgit_loginurl()); -} - -/* The filter is expected to spit out "Status: " and all headers. */ -static inline void authenticate_post(void) -{ - char buffer[MAX_AUTHENTICATION_POST_BYTES]; - size_t len; - ssize_t got; - - open_auth_filter("authenticate-post"); - len = ctx.env.content_length; - if (len > MAX_AUTHENTICATION_POST_BYTES) - len = MAX_AUTHENTICATION_POST_BYTES; - if ((got = read(STDIN_FILENO, buffer, len)) < 0) - die_errno("Could not read POST from stdin"); - if (write(STDOUT_FILENO, buffer, got) < 0) - die_errno("Could not write POST to stdout"); - cgit_close_filter(ctx.cfg.auth_filter); - exit(0); -} - -static inline void authenticate_cookie(void) -{ - /* If we don't have an auth_filter, consider all cookies valid, and thus return early. */ - if (!ctx.cfg.auth_filter) { - ctx.env.authenticated = 1; - return; - } - - /* If we're having something POST'd to /login, we're authenticating POST, - * instead of the cookie, so call authenticate_post and bail out early. - * This pattern here should match /?p=login with POST. */ - if (ctx.env.request_method && ctx.qry.page && !ctx.repo && \ - !strcmp(ctx.env.request_method, "POST") && !strcmp(ctx.qry.page, "login")) { - authenticate_post(); - return; - } - - /* If we've made it this far, we're authenticating the cookie for real, so do that. */ - open_auth_filter("authenticate-cookie"); - ctx.env.authenticated = cgit_close_filter(ctx.cfg.auth_filter); -} - static void process_request(void) { - struct cgit_cmd *cmd; + const struct cgit_cmd *cmd; int nongit = 0; - /* If we're not yet authenticated, no matter what page we're on, - * display the authentication body from the auth_filter. This should - * never be cached. */ + // An unauthenticated request is answered with the filter's own body + // whatever page it asked for. if (!ctx.env.authenticated) { ctx.page.title = "Authentication Required"; cgit_print_http_headers(); @@ -788,10 +1080,6 @@ static void process_request(void) return; } - /* If cmd->want_vpath is set, assume ctx.qry.path contains a "virtual" - * in-project path limit to be made available at ctx.qry.vpath. - * Otherwise, no path limit is in effect (ctx.qry.vpath = NULL). - */ ctx.qry.vpath = cmd->want_vpath ? ctx.qry.path : NULL; if (ctx.repo && prepare_repo_cmd(nongit)) @@ -800,294 +1088,94 @@ static void process_request(void) cmd->fn(); } -static int cmp_repos(const void *a, const void *b) -{ - const struct cgit_repo *ra = a, *rb = b; - return strcmp(ra->url, rb->url); -} - -static char *build_snapshot_setting(int bitmap) -{ - const struct cgit_snapshot_format *f; - struct strbuf result = STRBUF_INIT; - - for (f = cgit_snapshot_formats; f->suffix; f++) { - if (cgit_snapshot_format_bit(f) & bitmap) { - if (result.len) - strbuf_addch(&result, ' '); - strbuf_addstr(&result, f->suffix); - } - } - return strbuf_detach(&result, NULL); -} - -static void print_repo(FILE *f, struct cgit_repo *repo) +void cgit_repo_config(struct cgit_repo *repo, const char *name, const char *value) { + const char *path; struct string_list_item *item; - fprintf(f, "repo.url=%s\n", repo->url); - fprintf(f, "repo.name=%s\n", repo->name); - fprintf(f, "repo.path=%s\n", repo->path); - if (repo->owner) - fprintf(f, "repo.owner=%s\n", repo->owner); - if (repo->desc) - fprintf(f, "repo.desc=%s\n", repo->desc); - for_each_string_list_item(item, &repo->readme) { - if (item->util) - fprintf(f, "repo.readme=%s:%s\n", (char *)item->util, item->string); - else - fprintf(f, "repo.readme=%s\n", item->string); - } - if (repo->defbranch) - fprintf(f, "repo.defbranch=%s\n", repo->defbranch); - if (repo->extra_head_content) - fprintf(f, "repo.extra-head-content=%s\n", repo->extra_head_content); - if (repo->module_link) - fprintf(f, "repo.module-link=%s\n", repo->module_link); - if (repo->section) - fprintf(f, "repo.section=%s\n", repo->section); - if (repo->homepage) - fprintf(f, "repo.homepage=%s\n", repo->homepage); - if (repo->clone_url) - fprintf(f, "repo.clone-url=%s\n", repo->clone_url); - fprintf(f, "repo.enable-blame=%d\n", - repo->enable_blame); - fprintf(f, "repo.enable-commit-graph=%d\n", - repo->enable_commit_graph); - fprintf(f, "repo.enable-follow-links=%d\n", - repo->enable_follow_links); - fprintf(f, "repo.enable-log-filecount=%d\n", - repo->enable_log_filecount); - fprintf(f, "repo.enable-log-linecount=%d\n", - repo->enable_log_linecount); - if (repo->about_filter && repo->about_filter != ctx.cfg.about_filter) - cgit_fprintf_filter(repo->about_filter, f, "repo.about-filter="); - if (repo->commit_filter && repo->commit_filter != ctx.cfg.commit_filter) - cgit_fprintf_filter(repo->commit_filter, f, "repo.commit-filter="); - if (repo->source_filter && repo->source_filter != ctx.cfg.source_filter) - cgit_fprintf_filter(repo->source_filter, f, "repo.source-filter="); - if (repo->email_filter && repo->email_filter != ctx.cfg.email_filter) - cgit_fprintf_filter(repo->email_filter, f, "repo.email-filter="); - if (repo->snapshots != ctx.cfg.snapshots) { - char *tmp = build_snapshot_setting(repo->snapshots); - fprintf(f, "repo.snapshots=%s\n", tmp ? tmp : ""); - free(tmp); - } - if (repo->snapshot_prefix) - fprintf(f, "repo.snapshot-prefix=%s\n", repo->snapshot_prefix); - if (repo->enable_stats != ctx.cfg.enable_stats) - fprintf(f, "repo.enable-stats=%d\n", repo->enable_stats); - if (repo->max_stats != ctx.cfg.max_stats) - fprintf(f, "repo.max-stats=%s\n", - cgit_find_stats_periodname(repo->max_stats)); - if (repo->logo) - fprintf(f, "repo.logo=%s\n", repo->logo); - if (repo->logo_link) - fprintf(f, "repo.logo-link=%s\n", repo->logo_link); - fprintf(f, "repo.enable-remote-branches=%d\n", repo->enable_remote_branches); - fprintf(f, "repo.enable-subject-links=%d\n", repo->enable_subject_links); - fprintf(f, "repo.enable-html-serving=%d\n", repo->enable_html_serving); - if (repo->branch_sort == 1) - fprintf(f, "repo.branch-sort=age\n"); - if (repo->commit_sort) { - if (repo->commit_sort == 1) - fprintf(f, "repo.commit-sort=date\n"); - else if (repo->commit_sort == 2) - fprintf(f, "repo.commit-sort=topo\n"); - } - fprintf(f, "repo.hide=%d\n", repo->hide); - fprintf(f, "repo.ignore=%d\n", repo->ignore); - fprintf(f, "\n"); -} - -static void print_repolist(FILE *f, struct cgit_repolist *list, int start) -{ - int i; - - for (i = start; i < list->count; i++) - print_repo(f, &list->repos[i]); -} - -/* Scan 'path' for git repositories, save the resulting repolist in 'cached_rc' - * and return 0 on success. - */ -static int generate_cached_repolist(const char *path, const char *cached_rc) -{ - struct strbuf locked_rc = STRBUF_INIT; - int result = 0; - int idx; - FILE *f; - - strbuf_addf(&locked_rc, "%s.lock", cached_rc); - f = fopen(locked_rc.buf, "wx"); - if (!f) { - /* Inform about the error unless the lockfile already existed, - * since that only means we've got concurrent requests. - */ - result = errno; - if (result != EEXIST) - fprintf(stderr, "[cgit] Error opening %s: %s (%d)\n", - locked_rc.buf, strerror(result), result); - goto out; - } - idx = cgit_repolist.count; - if (ctx.cfg.project_list) - scan_projects(path, ctx.cfg.project_list); - else - scan_tree(path); - print_repolist(f, &cgit_repolist, idx); - if (rename(locked_rc.buf, cached_rc)) - fprintf(stderr, "[cgit] Error renaming %s to %s: %s (%d)\n", - locked_rc.buf, cached_rc, strerror(errno), errno); - fclose(f); -out: - strbuf_release(&locked_rc); - return result; -} - -static void process_cached_repolist(const char *path) -{ - struct stat st; - struct strbuf cached_rc = STRBUF_INIT; - time_t age; - unsigned long hash; - - hash = cache_hash_str(path); - if (ctx.cfg.project_list) - hash += cache_hash_str(ctx.cfg.project_list); - strbuf_addf(&cached_rc, "%s/rc-%8lx", ctx.cfg.cache_root, hash); - - if (stat(cached_rc.buf, &st)) { - /* Nothing is cached, we need to scan without forking. And - * if we fail to generate a cached repolist, we need to - * invoke scan_tree manually. - */ - if (generate_cached_repolist(path, cached_rc.buf)) { - if (ctx.cfg.project_list) - scan_projects(path, ctx.cfg.project_list); - else - scan_tree(path); - } - goto out; - } - - parse_configfile(cached_rc.buf, config_cb); - - /* If the cached configfile hasn't expired, lets exit now */ - age = time(NULL) - st.st_mtime; - if (age <= (ctx.cfg.cache_scanrc_ttl * 60)) - goto out; - - /* The cached repolist has been parsed, but it was old. So lets - * rescan the specified path and generate a new cached repolist - * in a child-process to avoid latency for the current request. - */ - if (fork()) - goto out; - - exit(generate_cached_repolist(path, cached_rc.buf)); -out: - strbuf_release(&cached_rc); -} - -static void cgit_parse_args(int argc, const char **argv) -{ - int i; - const char *arg; - int scan = 0; - - for (i = 1; i < argc; i++) { - if (!strcmp(argv[i], "--version")) { - printf("CGit %s | https://github.com/brycekwon/cgit\n\nCompiled in features:\n", CGIT_VERSION); -#ifdef NO_LUA - printf("[-] "); -#else - printf("[+] "); -#endif - printf("Lua scripting\n"); -#ifndef HAVE_LINUX_SENDFILE - printf("[-] "); -#else - printf("[+] "); -#endif - printf("Linux sendfile() usage\n"); - exit(0); - } - if (skip_prefix(argv[i], "--cache=", &arg)) { - ctx.cfg.cache_root = xstrdup(arg); - } else if (!strcmp(argv[i], "--nohttp")) { - ctx.env.no_http = "1"; - } else if (skip_prefix(argv[i], "--query=", &arg)) { - ctx.qry.raw = xstrdup(arg); - } else if (skip_prefix(argv[i], "--repo=", &arg)) { - ctx.qry.repo = xstrdup(arg); - } else if (skip_prefix(argv[i], "--page=", &arg)) { - ctx.qry.page = xstrdup(arg); - } else if (skip_prefix(argv[i], "--head=", &arg)) { - ctx.qry.head = xstrdup(arg); - ctx.qry.has_symref = 1; - } else if (skip_prefix(argv[i], "--oid=", &arg)) { - ctx.qry.oid = xstrdup(arg); - ctx.qry.has_oid = 1; - } else if (skip_prefix(argv[i], "--ofs=", &arg)) { - ctx.qry.ofs = atoi(arg); - } else if (skip_prefix(argv[i], "--scan-tree=", &arg) || - skip_prefix(argv[i], "--scan-path=", &arg)) { - /* - * HACK: The global snapshot bit mask defines the set - * of allowed snapshot formats, but the config file - * hasn't been parsed yet so the mask is currently 0. - * By setting all bits high before scanning we make - * sure that any in-repo cgitrc snapshot setting is - * respected by scan_tree(). - * - * NOTE: We assume that there aren't more than 8 - * different snapshot formats supported by cgit... - */ - ctx.cfg.snapshots = 0xFF; - scan++; - scan_tree(arg); - } - } - if (scan) { - qsort(cgit_repolist.repos, cgit_repolist.count, - sizeof(struct cgit_repo), cmp_repos); - print_repolist(stdout, &cgit_repolist, 0); - exit(0); + if (!strcmp(name, "name")) + repo->name = cgit_strdup_first_line(value); + else if (!strcmp(name, "clone-url")) + repo->clone_url = cgit_strdup_first_line(value); + else if (!strcmp(name, "desc")) + repo->desc = cgit_strdup_first_line(value); + else if (!strcmp(name, "owner")) + repo->owner = cgit_strdup_first_line(value); + else if (!strcmp(name, "homepage")) + repo->homepage = cgit_strdup_first_line(value); + else if (!strcmp(name, "defbranch")) + repo->defbranch = cgit_strdup_first_line(value); + else if (!strcmp(name, "extra-head-content")) + repo->extra_head_content = cgit_strdup_first_line(value); + else if (!strcmp(name, "snapshots")) + repo->snapshots = ctx.cfg.snapshots & cgit_parse_snapshots_mask(value); + else if (!strcmp(name, "enable-blame")) + repo->enable_blame = atoi(value); + else if (!strcmp(name, "enable-commit-graph")) + repo->enable_commit_graph = atoi(value); + else if (!strcmp(name, "enable-follow-links")) + repo->enable_follow_links = atoi(value); + else if (!strcmp(name, "enable-log-filecount")) + repo->enable_log_filecount = atoi(value); + else if (!strcmp(name, "enable-log-linecount")) + repo->enable_log_linecount = atoi(value); + else if (!strcmp(name, "enable-remote-branches")) + repo->enable_remote_branches = atoi(value); + else if (!strcmp(name, "enable-subject-links")) + repo->enable_subject_links = atoi(value); + else if (!strcmp(name, "enable-html-serving")) + repo->enable_html_serving = atoi(value); + else if (!strcmp(name, "enable-stats")) + repo->enable_stats = atoi(value); + else if (!strcmp(name, "branch-sort")) { + if (!strcmp(value, "age")) + repo->branch_sort = 1; + if (!strcmp(value, "name")) + repo->branch_sort = 0; + } else if (!strcmp(name, "commit-sort")) { + if (!strcmp(value, "date")) + repo->commit_sort = 1; + if (!strcmp(value, "topo")) + repo->commit_sort = 2; + } else if (!strcmp(name, "max-stats")) + repo->max_stats = cgit_find_stats_period(value, NULL); + else if (!strcmp(name, "module-link")) + repo->module_link = cgit_strdup_first_line(value); + else if (skip_prefix(name, "module-link.", &path)) { + item = string_list_append(&repo->submodules, + cgit_strdup_first_line(path)); + item->util = cgit_strdup_first_line(value); + } else if (!strcmp(name, "section")) + repo->section = cgit_strdup_first_line(value); + else if (!strcmp(name, "snapshot-prefix")) + repo->snapshot_prefix = cgit_strdup_first_line(value); + else if (!strcmp(name, "readme") && value != NULL) { + if (repo->readme.items == ctx.cfg.readme.items) + memset(&repo->readme, 0, sizeof(repo->readme)); + string_list_append(&repo->readme, cgit_strdup_first_line(value)); + } else if (!strcmp(name, "logo") && value != NULL) + repo->logo = cgit_strdup_first_line(value); + else if (!strcmp(name, "logo-link") && value != NULL) + repo->logo_link = cgit_strdup_first_line(value); + else if (!strcmp(name, "hide")) + repo->hide = atoi(value); + else if (!strcmp(name, "ignore")) + repo->ignore = atoi(value); + else if (ctx.cfg.enable_filter_overrides) { + if (!strcmp(name, "about-filter")) + repo->about_filter = cgit_new_filter(value, ABOUT); + else if (!strcmp(name, "commit-filter")) + repo->commit_filter = cgit_new_filter(value, COMMIT); + else if (!strcmp(name, "source-filter")) + repo->source_filter = cgit_new_filter(value, SOURCE); + else if (!strcmp(name, "email-filter")) + repo->email_filter = cgit_new_filter(value, EMAIL); } } -static int calc_ttl(void) -{ - if (!ctx.repo) - return ctx.cfg.cache_root_ttl; - - if (!ctx.qry.page) - return ctx.cfg.cache_repo_ttl; - - if (!strcmp(ctx.qry.page, "about")) - return ctx.cfg.cache_about_ttl; - - if (!strcmp(ctx.qry.page, "snapshot")) - return ctx.cfg.cache_snapshot_ttl; - - if (ctx.qry.has_oid) - return ctx.cfg.cache_static_ttl; - - if (ctx.qry.has_symref) - return ctx.cfg.cache_dynamic_ttl; - - return ctx.cfg.cache_repo_ttl; -} - -static NORETURN void cgit_die_routine(const char *msg, va_list params) -{ - cgit_vprint_error_page(400, "Bad request", msg, params); - exit(0); -} - int cmd_main(int argc, const char **argv) { + struct strbuf cache_key = STRBUF_INIT; const char *path; int err, ttl; @@ -1097,71 +1185,58 @@ int cmd_main(int argc, const char **argv) // Registered second so it runs first, since exit is reached from error // paths and from the HEAD shortcut with a page still buffered. atexit(html_flush); - set_die_routine(cgit_die_routine); + set_die_routine(die_routine); prepare_context(); cgit_repolist.length = 0; cgit_repolist.count = 0; cgit_repolist.repos = NULL; - cgit_parse_args(argc, argv); - parse_configfile(cgit_expand_macros(ctx.env.cgit_config), config_cb); + parse_args(argc, argv); + config_file_parse(cgit_expand_macros(ctx.env.cgit_config), apply_config); ctx.repo = NULL; - http_parse_querystring(ctx.qry.raw, querystring_cb); + http_parse_querystring(ctx.qry.raw, apply_query_param); - /* If virtual-root isn't specified in cgitrc, lets pretend - * that virtual-root equals SCRIPT_NAME, minus any possibly - * trailing slashes. - */ if (!ctx.cfg.virtual_root && ctx.cfg.script_name) ctx.cfg.virtual_root = cgit_ensure_end(ctx.cfg.script_name, '/'); - /* If no url parameter is specified on the querystring, lets - * use PATH_INFO as url. This allows cgit to work with virtual - * urls without the need for rewriterules in the webserver (as - * long as PATH_INFO is included in the cache lookup key). - */ + // Falling back to PATH_INFO lets cgit serve virtual urls without a + // rewrite rule in the web server, and folding it into the raw query + // string keeps it part of the cache key. path = ctx.env.path_info; if (!ctx.qry.url && path) { - if (path[0] == '/') + // Stripped like the url parameter and for the same reason, so + // a request for //example.com cannot turn into a link off site. + while (*path == '/') path++; ctx.qry.url = xstrdup(path); if (ctx.qry.raw) { - char *newqry = cgit_fmtalloc("%s?%s", path, ctx.qry.raw); + char *path_and_query = cgit_fmtalloc("%s?%s", path, ctx.qry.raw); free(ctx.qry.raw); - ctx.qry.raw = newqry; + ctx.qry.raw = path_and_query; } else ctx.qry.raw = xstrdup(ctx.qry.url); cgit_parse_url(ctx.qry.url); } - /* Before we go any further, we set ctx.env.authenticated by checking to see - * if the supplied cookie is valid. All cookies are valid if there is no - * auth_filter. If there is an auth_filter, the filter decides. */ authenticate_cookie(); ttl = calc_ttl(); if (ttl < 0) - ctx.page.expires += 10 * 365 * 24 * 60 * 60; /* 10 years */ + ctx.page.expires += NEVER_EXPIRES_SECONDS; else ctx.page.expires += ttl * 60; - if (!ctx.env.authenticated || (ctx.env.request_method && !strcmp(ctx.env.request_method, "HEAD"))) + // An unauthenticated request gets a body meant for one visitor, and a + // HEAD request stops after the headers. + if (!ctx.env.authenticated || + (ctx.env.request_method && !strcmp(ctx.env.request_method, "HEAD"))) ctx.cfg.cache_size = 0; - /* Fold the scheme and host into the cache key. Absolute URLs in the - * output (clone urls, atom links) are built from these, so a request - * with a spoofed Host must not poison the cached page served to a - * visitor arriving on a different host. */ - { - struct strbuf cache_key = STRBUF_INIT; - char *hosturl = cgit_hosturl(); - strbuf_addf(&cache_key, "%s%s|%s", cgit_httpscheme(), - hosturl ? hosturl : "", - ctx.qry.raw ? ctx.qry.raw : ""); - free(hosturl); - err = cache_process(ctx.cfg.cache_size, ctx.cfg.cache_root, - cache_key.buf, ttl, process_request); - strbuf_release(&cache_key); - } + + build_cache_key(&cache_key); + err = cache_process(ctx.cfg.cache_size, ctx.cfg.cache_root, + cache_key.buf, ttl, process_request); + strbuf_release(&cache_key); + cgit_cleanup_filters(); if (err) cgit_print_error("Error processing page: %s (%d)", |
