| Age | Commit message (Collapse) | Author | Lines |
|
The dumb transport reads files that already sit on the disk, so a pack
copied into a slot cost that disk twice and the request a second write
of every byte. A snapshot took a slot whatever its size, so a visitor
naming distinct refs and ids could fill the cache root with archives.
`cache-max-slot-size`, 64 MB unless set, now serves a larger response
from the lock file and drops it, along with any expired copy it would
have replaced.
|
|
`enable-html-serving` makes the plain page send a repository file as
text/html on the site's own origin, with no nosniff and no policy, so
a scanned repository could switch it on from its git config or cgitrc
without `trust-scan-config` and run script against every visitor. The
warning for a key read from git config also named a null repository,
because `repo->path` was set only after that file had been read.
|
|
`cgit_abort_filters` unhooks the Lua write interposer under NO_LUA
too, where neither the hook nor its state exists, so `make NO_LUA=1`
and the default mode of `tools/release-build.sh` have not compiled
since the die path learned to take stdout back from a filter. The
suite now builds that variant into `build/nolua` and runs it, and a
`lua:` filter in such a build is refused with a message naming the
cause instead of an unknown filter type.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Beyond the format change, the documented defaults and inheritance
notes now match what the code does.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
The readme is now escaped plain text unless `about-filter` points at
the new `about-render.lua`, which renders markdown, man pages and plain
text server-side. `enable-markdown` goes away with the renderer.
|
|
|
|
|
|
`max-stats` only bounds the selectable periods now and no longer
doubles as the enable switch.
The tree walk runs before the history walk on purpose. Releasing
commit memory while walking history resets each commit slab index,
and a commit graph lookup afterwards would read another commit slot
and walk the wrong tree. The stats fixture writes a commit graph so
the tests cover that path. The history walk bounds the window in
process rather than passing a formatted since date to
`setup_revisions`, and parses each commit once.
|
|
|
|
|
|
|
|
|
|
|
|
The gentoo LDAP filter is distro specific, the owner example only
restates what cgit already renders, and the about converters are
superseded by the built-in markdown rendering. The two auth filters
do the same job and differ only in where their accounts live, so they
become `auth-inline` for accounts kept in the script and `auth-file`
for accounts kept on disk.
|
|
The default sorted the sections and the repositories within them by
name, so the order written in the cgitrc file was ignored.
|
|
Only the tree view honoured the limit, and only after loading the
whole object. The raw blob, plain, blame and readme paths now check
the size before reading, and the default moves from unlimited to
10 MB so a fresh install never buffers a huge object whole, with zero
still the opt-out.
|
|
cgit had no markdown support of its own, so a readme was rendered
through an external python filter or not at all. Escaping the source
and formatting it in cgit.js keeps the work in the browser like the
blob highlighter, and the page stays readable as plain text without
scripting.
|
|
Highlighting previously required a source filter shelling out to
something like Pygments. A configured source filter still takes
precedence, every character is preserved so the line gutter stays
aligned, and large files are skipped.
|
|
|
|
The `ls_cache` page printed the cache directory path and the urls other
visitors had requested, with no gate at all.
|
|
The C sources move to source/, the served files to assets/, the bundled
Git submodule to libraries/git and the filter scripts to extensions/.
Everything the build generates now lands in build/, so a clean is a
single remove and the tree stays clean.
|
|
This exists for other CPU heavy operations like blame, but doesn't for
the follow functionality. Add it for that.
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
|
|
Just like the config allows setting css URL path, add a config for
setting the js URL path
Signed-off-by: Andy Green <andy@warmcat.com>
Reviewed-by: John Keeping <john@keeping.me.uk>
Signed-off-by: Christian Hesse <mail@eworm.de>
|
|
Without changing the default behaviour of including
/cgit.css if nothing declared, allow the "css" config
to be given multiple times listing one or more
alternative URL paths to be included in the document
head area.
Signed-off-by: Andy Green <andy@warmcat.com>
Signed-off-by: Christian Hesse <mail@eworm.de>
|
|
Setting max-repo-count to "0" makes cgit loop forever generating page
links. Make this a special value to show all repositories.
Signed-off-by: Christian Hesse <mail@eworm.de>
|
|
Reading the README from repository used to be limited to default
branch or a branch given in configuration. Let's allow a branch
from query if not specified explicitly.
Signed-off-by: Christian Hesse <mail@eworm.de>
|
|
This patch adds support for zstd [0] compressed snapshots (*.tar.zst).
We enable multiple working threads (-T0), but keep default compression
level. The latter can be influenced by environment variable.
[0] https://www.zstd.net/
Signed-off-by: Christian Hesse <mail@eworm.de>
|
|
This patch adds support for lzip [1] compressed snapshots (*.tar.lz)
[1] https://www.nongnu.org/lzip/
Signed-off-by: Hanspeter Portner <dev@open-music-kontrollers.ch>
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
|
|
The blame operation can cause high cost in terms of CPU load for huge
repositories. Let's add a per repository override for enable-blame.
Signed-off-by: Christian Hesse <mail@eworm.de>
|
|
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
|
|
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
|
|
This is to support things like go-import meta tags, which are on a
per-repo basis.
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
|
|
You maybe didn't know you had OCD until you saw an
alpha sorted list that has stuff out of order in it.
Signed-off-by: Andy Green <andy@warmcat.com>
Reviewed-by: John Keeping <john@keeping.me.uk>
|