| Age | Commit message (Collapse) | Author | Lines |
|
The dumb transport read a pack four kilobytes at a time through stdio
and sent it without a length, so a client could not tell a cut-off
transfer from a complete one.
|
|
The dumb transport reads files that already sit on the disk, so a pack
copied into a slot cost that disk twice and the request a second write
of every byte. A snapshot took a slot whatever its size, so a visitor
naming distinct refs and ids could fill the cache root with archives.
`cache-max-slot-size`, 64 MB unless set, now serves a larger response
from the lock file and drops it, along with any expired copy it would
have replaced.
|
|
Git's Makefile defaults `prefix` to `$HOME` and compiles it into
`exec-cmd.o` as the fallback runtime prefix, so each build embedded
the path of whoever ran it and no two builders could produce the same
bytes. The release script also maps the build directory out of the
debug info, which otherwise differs between checkouts.
|
|
`enable-html-serving` makes the plain page send a repository file as
text/html on the site's own origin, with no nosniff and no policy, so
a scanned repository could switch it on from its git config or cgitrc
without `trust-scan-config` and run script against every visitor. The
warning for a key read from git config also named a null repository,
because `repo->path` was set only after that file had been read.
|
|
`cgit_abort_filters` unhooks the Lua write interposer under NO_LUA
too, where neither the hook nor its state exists, so `make NO_LUA=1`
and the default mode of `tools/release-build.sh` have not compiled
since the die path learned to take stdout back from a filter. The
suite now builds that variant into `build/nolua` and runs it, and a
`lua:` filter in such a build is refused with a message naming the
cause instead of an unknown filter type.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
The newline made the charset name unknown to the converter, so a
message in another charset was left unconverted.
|
|
A parameter without a value swallowed the parameter after it.
|
|
|
|
A filter program that could not be run answered with two responses,
and a filter that exited without reading its input ended cgit with
the page half written.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
`compose_snapshot_prefix` dropped the leading v of a tag only when just
one of the names 1.2, v1.2 and V1.2 resolved as a tag, so that the
shorter snapshot name could always be traced back to one tag. Those
probes went through ref lookups, and on a case-insensitive filesystem
a lookup for V1.2 finds the loose file of v1.2, so every freshly made
tag counted as ambiguous and kept its v. Once git packed the refs the
lookups became exact and the same tag quietly changed its snapshot
names.
The claimants on a stripped name are now counted over the tag list
itself with exact string comparison, so the answer no longer depends
on how a ref is stored or on the filesystem underneath. Two tags that
really differ only by the letter's case still both keep it.
|
|
|
|
|
|
|
|
|
|
The inline handlers and the auto-submitting selects are gone, so
`script-src` no longer needs it, and t0004 now checks that the three
configs pin the same policy.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Beyond the format change, the documented defaults and inheritance
notes now match what the code does.
|
|
|
|
noplainemail enable-plain-email
noheader enable-header
cache-root-ttl cache-index-ttl
cache-repo-ttl cache-summary-ttl
cache-scanrc-ttl cache-scan-ttl
agefile age-file
renamelimit rename-limit
extra-head-content head-content
|
|
A `max-stats` period enables the page again, as it did before
v2.2.0, so one key does both jobs.
|
|
|
|
|
|
|
|
|
|
|