diff options
context:
space:
mode:
Diffstat (limited to '')
-rw-r--r--source/cgit.c91
1 file changed, 37 insertions, 54 deletions
diff --git a/source/cgit.c b/source/cgit.c
index 730e2c6..dc56a0e 100644
--- a/source/cgit.c
+++ b/source/cgit.c
@@ -59,12 +59,10 @@ struct refmatch {
const char *cgit_version = CGIT_VERSION;
/*
- * Isolate git from the calling user's configuration, so a snapshot cannot be
- * broken by something like a core.excludesfile pointing at a "~" path that git
- * can no longer expand once HOME is unset below. Called from cmd_main rather
- * than from a constructor attribute, because git-compat-util.h defines
- * __attribute__ away on a compiler that does not support it, which would leave
- * this silently never running.
+ * Isolate git from the calling user's configuration, which could otherwise
+ * break once HOME is unset below. Called from cmd_main rather than from a
+ * constructor attribute, because git-compat-util.h defines __attribute__
+ * away on a compiler without it, which would leave this silently unrun.
*/
static void isolate_git_environment(void)
{
@@ -173,7 +171,8 @@ static void prepare_context(void)
static void print_version(void)
{
- printf("CGit %s | https://github.com/brycekwon/cgit\n\nCompiled in features:\n", CGIT_VERSION);
+ printf("CGit %s | https://github.com/brycekwon/cgit\n\n"
+ "Compiled in features:\n", CGIT_VERSION);
#ifdef NO_LUA
printf("[-] ");
#else
@@ -319,10 +318,9 @@ static void parse_args(int argc, const char **argv)
ctx.qry.ofs = atoi(arg);
} else if (skip_prefix(argv[i], "--scan-tree=", &arg) ||
skip_prefix(argv[i], "--scan-path=", &arg)) {
- // A repository's own snapshots setting is masked with
- // the global one, which normally comes from cgitrc.
- // That has not been read yet here, so an empty mask
- // would discard whatever the repository asked for.
+ // A repository's snapshots setting is masked with the
+ // global one, and cgitrc has not been read here, so an
+ // empty mask would discard what the repository set.
ctx.cfg.snapshots = ALL_SNAPSHOT_FORMATS;
scanned++;
scan_tree(arg);
@@ -338,9 +336,8 @@ static void parse_args(int argc, const char **argv)
/*
* The lock is a fcntl lock rather than the mere existence of the lock file,
- * because a lock the kernel drops with its process cannot outlive a scan that
- * was killed mid-run. A leftover lock file used to count as a scan in
- * progress, and one crash would silently freeze the repolist for good.
+ * because a lock the kernel drops with its process cannot outlive a scan
+ * killed mid-run. A leftover file would count as a scan forever in progress.
*/
static int generate_cached_repolist(const char *path, const char *cached_rc)
{
@@ -379,10 +376,8 @@ static int generate_cached_repolist(const char *path, const char *cached_rc)
}
// The lock landed on whatever inode the path named at open. A holder
// finishing in between renames that inode into place as the live
- // list, so truncating it on the strength of the stale descriptor
- // would tear down the list other requests are reading. Once the path
- // is confirmed to still name this file the rename can no longer
- // happen, because doing so takes the lock now held here.
+ // list, and once the path is confirmed to still name this file that
+ // rename can no longer happen, because it takes the lock held here.
if (fstat(fd, &held) || stat(locked_rc.buf, &named) ||
held.st_ino != named.st_ino || held.st_dev != named.st_dev) {
err = EAGAIN;
@@ -469,11 +464,10 @@ static void process_cached_repolist(const char *path)
if (fork())
goto out;
- // The child inherits the descriptors of the request, and the web server
- // reads stdout until every holder of it is gone, so leaving them in
- // place would keep the visitor waiting for the whole scan after their
- // page was written. Anything the scan prints would land on that
- // response as well.
+ // The child inherits the request's descriptors, and the web server
+ // reads stdout until every holder is gone, so left in place they
+ // would keep the visitor waiting on the scan and let its output
+ // land on the response.
devnull = open("/dev/null", O_RDWR);
if (devnull >= 0) {
dup2(devnull, STDIN_FILENO);
@@ -703,9 +697,8 @@ static void apply_config(const char *name, const char *value)
/*
* Read a whole number a request supplied, clamped into the range the caller
- * accepts. strtol rather than atoi, because atoi has no defined behaviour once
- * the digits overflow and every value here arrives straight from the query
- * string.
+ * accepts. strtol rather than atoi, because atoi is undefined on overflow
+ * and every value here arrives straight from the query string.
*/
static int query_int(const char *value, int min, int max)
{
@@ -729,10 +722,9 @@ static void apply_query_param(const char *name, const char *value)
} else if (!strcmp(name, "p")) {
ctx.qry.page = xstrdup(value);
} else if (!strcmp(name, "url")) {
- // Every leading slash goes, not just one. What is left is
- // joined onto the virtual root, so a value like //example.com
- // would otherwise survive as /example.com and make that join a
- // scheme-relative link to another host.
+ // Every leading slash goes, not just one, so a value like
+ // //example.com cannot survive as /example.com and make the
+ // virtual root join a scheme-relative link to another host.
while (*value == '/')
value++;
ctx.qry.url = xstrdup(value);
@@ -754,11 +746,9 @@ static void apply_query_param(const char *name, const char *value)
ctx.qry.oid2 = xstrdup(value);
ctx.qry.has_oid = 1;
} else if (!strcmp(name, "ofs")) {
- // Bounded above so a crafted value cannot force a walk over the
- // whole history. Negatives stop at -1 rather than at zero,
- // because the offset is overloaded, the stats page submits -1
- // for all authors, and the log skip loop floors a negative
- // itself.
+ // Bounded above so a crafted value cannot force a walk over
+ // the whole history. The floor is -1 rather than 0 because
+ // the stats page submits -1 for all authors.
ctx.qry.ofs = query_int(value, -1, MAX_QUERY_OFFSET);
} else if (!strcmp(name, "path")) {
ctx.qry.path = cgit_trim_end(value, '/');
@@ -847,10 +837,9 @@ static void authenticate_cookie(void)
}
/*
- * Only a full object id names content that can never change. The id parameter
- * accepts anything git can resolve, so a ref name or an abbreviation arrives
- * here just as marked as a real id, and a page pinned to one of those must
- * not be cached under the never-expiring static ttl.
+ * Only a full object id names content that can never change. The id
+ * parameter accepts anything git can resolve, so a page pinned to a ref
+ * name or abbreviation must not be cached under the static ttl.
*/
static int is_full_oid(const char *rev)
{
@@ -895,10 +884,9 @@ static int calc_ttl(void)
}
/*
- * The scheme and the host are folded in because the absolute urls a page
- * carries, its clone urls and atom links, are built from them, so a request
- * arriving with a spoofed Host must not poison the page served to a visitor
- * who came in on the real one.
+ * The scheme and host are folded in because the page's absolute urls, its
+ * clone urls and atom links, are built from them, so a spoofed Host must
+ * not poison the page served on the real one.
*/
static void build_cache_key(struct strbuf *key)
{
@@ -911,11 +899,9 @@ static void build_cache_key(struct strbuf *key)
};
size_t i;
- // Each part is written behind its own length, so nothing a value
- // contains can make two different requests spell one key. The path and
- // the query come from the environment rather than the query string cgit
- // rebuilds, since that rebuild folds the two together and would let the
- // PATH_INFO and QUERY_STRING forms of one request share a slot.
+ // Each part is written behind its own length so no value can make two
+ // requests spell one key, and the path and query come from the
+ // environment because cgit's rebuilt query string folds them together.
for (i = 0; i < ARRAY_SIZE(parts); i++)
strbuf_addf(key, "%zu|%s", strlen(parts[i]), parts[i]);
free(hosturl);
@@ -1013,7 +999,6 @@ static void choose_readme(struct cgit_repo *repo)
for_each_string_list_item(entry, &repo->readme) {
parse_readme(entry->string, &filename, &ref, repo);
if (!filename) {
- free(filename);
free(ref);
continue;
}
@@ -1041,8 +1026,6 @@ static void prepare_repo_env(int *nongit)
{
setenv("GIT_DIR", ctx.repo->path, 1);
- // Both read configuration out of the repository, with the user's own
- // git configuration already stripped by isolate_git_environment.
setup_git_directory_gently(the_repository, nongit);
load_display_notes(NULL);
}
@@ -1230,7 +1213,8 @@ void cgit_repo_config(struct cgit_repo *repo, const char *name, const char *valu
else if (!strcmp(name, "about-filter") || !strcmp(name, "commit-filter") ||
!strcmp(name, "source-filter") || !strcmp(name, "email-filter")) {
if (!ctx.cfg.enable_filter_overrides)
- fprintf(stderr, "[cgit] Ignoring repo %s: enable-filter-overrides is not set\n", name);
+ fprintf(stderr, "[cgit] Ignoring repo %s: "
+ "enable-filter-overrides is not set\n", name);
else if (!strcmp(name, "about-filter"))
repo->about_filter = cgit_new_filter(value, ABOUT);
else if (!strcmp(name, "commit-filter"))
@@ -1275,8 +1259,7 @@ int cmd_main(int argc, const char **argv)
// string keeps it part of the cache key.
path = ctx.env.path_info;
if (!ctx.qry.url && path) {
- // Stripped like the url parameter and for the same reason, so
- // a request for //example.com cannot turn into a link off site.
+ // Stripped like the url parameter and for the same reason.
while (*path == '/')
path++;
ctx.qry.url = xstrdup(path);