diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Trim the comments and dead code across the tree
Diffstat (limited to '')
-rwxr-xr-xtools/release-build.sh27
-rwxr-xr-xtools/serve.py23
2 files changed, 29 insertions, 21 deletions
diff --git a/tools/release-build.sh b/tools/release-build.sh
index 12f4260..0d9008f 100755
--- a/tools/release-build.sh
+++ b/tools/release-build.sh
@@ -1,17 +1,13 @@
#!/bin/sh
-# Build cgit for a release with Linux hardening flags. These are ELF and GCC
-# or Clang specific, so this targets a Linux deploy rather than local macOS
-# development, where a plain make is enough. The flags add a stack protector,
-# fortified libc calls, a position independent executable, and full RELRO. By
-# default Lua is pinned off so the binary needs no Lua at runtime, and running
-# it as ./tools/release-build.sh lua links in the backend behind the "lua:"
-# filter prefix instead, which needs a Lua dev package installed.
+# Build cgit for a release with Linux hardening flags, which are ELF and GCC or
+# Clang specific. The flags add a stack protector, fortified libc calls, a
+# position independent executable, and full RELRO. By default Lua is pinned off
+# so the binary needs no Lua at runtime, and running it as
+# ./tools/release-build.sh lua links in the backend behind the "lua:" filter
+# prefix instead, which needs a Lua dev package installed.
set -eu
-# The argument is checked rather than assumed, since anything unrecognised
-# would otherwise fall through to a quiet Lua-less build that looks like it
-# worked.
if [ "$#" -gt 1 ]; then
echo "usage: $0 [lua]" >&2
exit 2
@@ -23,8 +19,7 @@ lua) set -- ;;
exit 2 ;;
esac
-# Every make target below is written relative to the repository root, so go
-# there rather than requiring the caller to.
+# Every make target below is written relative to the repository root.
cd "$(dirname "$0")/.."
CC=${CC:-cc}
@@ -68,11 +63,9 @@ LDFLAGS="-pie \
# These reach only the cgit objects, so git's own sources are not held to them.
# -Wformat-security is an error because a non-literal format with no arguments
-# is never intentional. The shape that let a repository supply its own format
-# string through module-link was the other one, a non-literal that does take
-# arguments, and only -Wformat-nonliteral reports that, and that one is left out because it also fires
-# on forwarding a va_list and on local format constants, so it cannot be an
-# error without false positives. It is still worth running by hand when
+# is never intentional. -Wformat-nonliteral would catch the module-link shape,
+# a non-literal that does take arguments, but it also fires on va_list
+# forwarding and on local format constants, so it is left to manual runs when
# touching anything that formats.
#
# make cgit CGIT_EXTRA_CFLAGS=-Wformat-nonliteral
diff --git a/tools/serve.py b/tools/serve.py
index 2b2f045..a39d03f 100755
--- a/tools/serve.py
+++ b/tools/serve.py
@@ -29,8 +29,20 @@ REPO_ROOT = Path(__file__).resolve().parent.parent
MAX_BODY_BYTES = 8 * 1024 * 1024
CGI_TIMEOUT = 60
-STATIC_SUFFIXES = (".css", ".js", ".png", ".ico", ".gif", ".jpg", ".jpeg",
- ".svg", ".webp", ".txt", ".woff", ".woff2")
+STATIC_SUFFIXES = (
+ ".css",
+ ".js",
+ ".png",
+ ".ico",
+ ".gif",
+ ".jpg",
+ ".jpeg",
+ ".svg",
+ ".webp",
+ ".txt",
+ ".woff",
+ ".woff2",
+)
# The request headers cgit looks at, paired with the CGI variable each one
# has to arrive as.
@@ -273,8 +285,11 @@ def main() -> None:
config = Path(options.config).resolve()
cgit = Path(options.cgit).resolve()
data_dir = Path(options.data).resolve()
- for label, path in (("config", config), ("cgit binary", cgit),
- ("data directory", data_dir)):
+ for label, path in (
+ ("config", config),
+ ("cgit binary", cgit),
+ ("data directory", data_dir),
+ ):
if not path.exists():
sys.exit(f"error: {label} not found: {path}")