| Age | Commit message (Collapse) | Author | Lines |
|
|
|
A checkout without tags made `git describe` fail and the empty result
overwrote the fallback, so CI release binaries carried no version at
all. The release workflow now also fetches tags so a tag build stamps
its exact version.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
AUTHORS now records the upstream developers as the project's history
rather than as maintainers of the fork.
|
|
cgit's built-in clone support speaks the dumb HTTP protocol, which
serves static files that only `git update-server-info` refreshes.
Without this hook a clone can miss refs pushed after the repository
was created.
|
|
The wiring has real pitfalls around PATH_INFO and the link base, so
these ship as working commented configs. nginx needs the fcgiwrap
bridge while apache and lighttpd run the CGI directly. The security
headers live here rather than in cgit because they must also cover
the static assets the server serves itself.
|
|
|
|
The filters signed the request url and later wrote it into a Location
header, and the signing step re-encoded a newline that the verifying
step decoded back, so a crafted url could smuggle CR and LF into the
response. The cookie HMAC was also checked with a short-circuiting
comparison and carried no SameSite attribute.
|
|
The gentoo LDAP filter is distro specific, the owner example only
restates what cgit already renders, and the about converters are
superseded by the built-in markdown rendering. The two auth filters
do the same job and differ only in where their accounts live, so they
become `auth-inline` for accounts kept in the script and `auth-file`
for accounts kept on disk.
|
|
Lua is becoming the one language for the filter extensions, and this
was the last shell filter.
|
|
|
|
Clone urls and atom links are built from the request scheme and Host,
but the cache key left them out, so a request with a spoofed Host
could cache a page carrying a bogus clone url and serve it to other
visitors.
|
|
The stat-only diff path returned before the closing call, so the
content wrapper, footer and closing tags were never emitted.
|
|
The feed-level element was written only inside the commit loop, so a
feed with no commits omitted an element the atom format requires.
|
|
The diffstat divided by zero when a commit changed no lines, and a
submodule change was printed with a hardcoded length that dropped a
digit of a sha-1 and most of a sha-256.
|
|
The pager html-escaped its search and sort values instead of
url-encoding them, so a term with a hash or ampersand broke the link
and dropped the active filter on the next page.
|
|
The POST length was clamped with a signed comparison, so a very large
Content-Length could turn negative and slip past the limit into the
fixed-size buffer.
|
|
The idle-sort comparator returned a 64-bit time difference truncated
to int, which could flip sign and leave the ordering inconsistent.
|
|
The index derived a repository's age from `refs/heads/master` alone,
so a repository on any other default branch showed no age. HEAD is
repo-controlled and the age stat walks under `refs/heads`, so a branch
name carrying a parent-directory component is rejected.
|
|
The default sorted the sections and the repositories within them by
name, so the order written in the cgitrc file was ignored.
|
|
cgit unsets HOME to isolate git from the calling user, but git still
finds the global config through its getpwuid fallback and then dies
expanding a `~` in `core.excludesfile`. That die happened after the
snapshot headers and the gzip filter were already in place, so the
error page was compressed into the archive and every snapshot came
out undecompressable.
|
|
The log page passed the `id` query parameter to git's revision parser
without resolving it and ahead of the end-of-options marker. A value
like `id=--output=/path` was then parsed as an option, so an
unauthenticated request could create or truncate any file the server
user could write. No valid ref or object name begins with a dash.
|
|
A crafted `ofs` could send cgit walking most of the history for one
request.
|
|
The about subpath was confined to the readme directory with a plain
byte-prefix match, so a sibling directory sharing the base name as a
prefix passed the check and its files were served.
|
|
The line-number gutter did one allocation and one write per line.
|
|
Only the tree view honoured the limit, and only after loading the
whole object. The raw blob, plain, blame and readme paths now check
the size before reading, and the default moves from unlimited to
10 MB so a fresh install never buffers a huge object whole, with zero
still the opt-out.
|
|
A blob requested by ref with an unknown path fell through to the
commit object and was served with a 200 instead of a 404, two error
pages passed a null pointer to a %s format when the request carried
no object id, and the error pages left the layout open.
|
|
`fmt()` aborts the request rather than truncate, so a very long path
fed into a context-sensitive tab title took down page rendering.
|
|
The year period rendered without its label, and a commit with no
author line crashed the view.
|
|
A plain char is undefined in the ctype functions for negative values,
which a high byte produces wherever char is signed.
|
|
A relative path shorter than five bytes made the `/.git` suffix test
read before the buffer.
|
|
`read_in_full` returns a signed -1 on error, which became SIZE_MAX once
stored in the size_t length and then wrote a terminator far out of
bounds.
|
|
`trim_end()` returns NULL when a repo url is empty or all slashes and
the later newline trim dereferenced it. The legacy `r=` and `p=about`
path also read the last byte of the url without checking it was set.
|
|
|
|
A readme that is not markdown was written to the about page as raw
HTML when no about-filter was configured, so an untrusted repository
could inject script.
|
|
cgit had no markdown support of its own, so a readme was rendered
through an external python filter or not at all. Escaping the source
and formatting it in cgit.js keeps the work in the browser like the
blob highlighter, and the page stays readable as plain text without
scripting.
|
|
Highlighting previously required a source filter shelling out to
something like Pygments. A configured source filter still takes
precedence, every character is preserved so the line gutter stays
aligned, and large files are skipped.
|