diff options
| author | Bryce Kwon <bryce@brycekwon.com> | |
|---|---|---|
| committer | Bryce Kwon <bryce@brycekwon.com> | |
| commit | ||
| parent | ||
| tree | ||
| download | ||
Trim the comments and dead code across the tree
Diffstat (limited to 'tools')
| -rwxr-xr-x | tools/release-build.sh | 27 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| -rwxr-xr-x | tools/serve.py | 23 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
2 files changed, 29 insertions, 21 deletions
diff --git a/tools/release-build.sh b/tools/release-build.sh index 12f4260..0d9008f 100755 --- a/tools/release-build.sh +++ b/tools/release-build.sh @@ -1,17 +1,13 @@ #!/bin/sh -# Build cgit for a release with Linux hardening flags. These are ELF and GCC -# or Clang specific, so this targets a Linux deploy rather than local macOS -# development, where a plain make is enough. The flags add a stack protector, -# fortified libc calls, a position independent executable, and full RELRO. By -# default Lua is pinned off so the binary needs no Lua at runtime, and running -# it as ./tools/release-build.sh lua links in the backend behind the "lua:" -# filter prefix instead, which needs a Lua dev package installed. +# Build cgit for a release with Linux hardening flags, which are ELF and GCC or +# Clang specific. The flags add a stack protector, fortified libc calls, a +# position independent executable, and full RELRO. By default Lua is pinned off +# so the binary needs no Lua at runtime, and running it as +# ./tools/release-build.sh lua links in the backend behind the "lua:" filter +# prefix instead, which needs a Lua dev package installed. set -eu -# The argument is checked rather than assumed, since anything unrecognised -# would otherwise fall through to a quiet Lua-less build that looks like it -# worked. if [ "$#" -gt 1 ]; then echo "usage: $0 [lua]" >&2 exit 2 @@ -23,8 +19,7 @@ lua) set -- ;; exit 2 ;; esac -# Every make target below is written relative to the repository root, so go -# there rather than requiring the caller to. +# Every make target below is written relative to the repository root. cd "$(dirname "$0")/.." CC=${CC:-cc} @@ -68,11 +63,9 @@ LDFLAGS="-pie \ # These reach only the cgit objects, so git's own sources are not held to them. # -Wformat-security is an error because a non-literal format with no arguments -# is never intentional. The shape that let a repository supply its own format -# string through module-link was the other one, a non-literal that does take -# arguments, and only -Wformat-nonliteral reports that, and that one is left out because it also fires -# on forwarding a va_list and on local format constants, so it cannot be an -# error without false positives. It is still worth running by hand when +# is never intentional. -Wformat-nonliteral would catch the module-link shape, +# a non-literal that does take arguments, but it also fires on va_list +# forwarding and on local format constants, so it is left to manual runs when # touching anything that formats. # # make cgit CGIT_EXTRA_CFLAGS=-Wformat-nonliteral diff --git a/tools/serve.py b/tools/serve.py index 2b2f045..a39d03f 100755 --- a/tools/serve.py +++ b/tools/serve.py @@ -29,8 +29,20 @@ REPO_ROOT = Path(__file__).resolve().parent.parent MAX_BODY_BYTES = 8 * 1024 * 1024 CGI_TIMEOUT = 60 -STATIC_SUFFIXES = (".css", ".js", ".png", ".ico", ".gif", ".jpg", ".jpeg", - ".svg", ".webp", ".txt", ".woff", ".woff2") +STATIC_SUFFIXES = ( + ".css", + ".js", + ".png", + ".ico", + ".gif", + ".jpg", + ".jpeg", + ".svg", + ".webp", + ".txt", + ".woff", + ".woff2", +) # The request headers cgit looks at, paired with the CGI variable each one # has to arrive as. @@ -273,8 +285,11 @@ def main() -> None: config = Path(options.config).resolve() cgit = Path(options.cgit).resolve() data_dir = Path(options.data).resolve() - for label, path in (("config", config), ("cgit binary", cgit), - ("data directory", data_dir)): + for label, path in ( + ("config", config), + ("cgit binary", cgit), + ("data directory", data_dir), + ): if not path.exists(): sys.exit(f"error: {label} not found: {path}") |
