AgeCommit message (Collapse)AuthorLines
Keep clone files and oversized responses out of the cacheBryce Kwon-2/+11
The dumb transport reads files that already sit on the disk, so a pack copied into a slot cost that disk twice and the request a second write of every byte. A snapshot took a slot whatever its size, so a visitor naming distinct refs and ids could fill the cache root with archives. `cache-max-slot-size`, 64 MB unless set, now serves a larger response from the lock file and drops it, along with any expired copy it would have replaced.
Gate html serving behind trust-scan-configBryce Kwon-7/+10
`enable-html-serving` makes the plain page send a repository file as text/html on the site's own origin, with no nosniff and no policy, so a scanned repository could switch it on from its git config or cgitrc without `trust-scan-config` and run script against every visitor. The warning for a key read from git config also named a null repository, because `repo->path` was set only after that file had been read.
Keep the Lua-less build compilingBryce Kwon-1/+2
`cgit_abort_filters` unhooks the Lua write interposer under NO_LUA too, where neither the hook nor its state exists, so `make NO_LUA=1` and the default mode of `tools/release-build.sh` have not compiled since the die path learned to take stdout back from a filter. The suite now builds that variant into `build/nolua` and runs it, and a `lua:` filter in such a build is refused with a message naming the cause instead of an unknown filter type.
Rename enable-trailers to enable-commit-trailersBryce Kwon-22/+22
Unify the docs, samples and extensionsBryce Kwon-212/+201
Harden the request path, scan and error recoveryBryce Kwon-19/+22
Gate scanned filters with `trust-scan-filters`Bryce Kwon-26/+25
Apply the mailmap at HEAD to every identBryce Kwon-0/+13
Split trailers out of the commit messageBryce Kwon-0/+38
Trim the comments and dead code across the treeBryce Kwon-2/+2
Convert the manual page to plain `MANUAL.txt`Bryce Kwon-413/+390
Beyond the format change, the documented defaults and inheritance notes now match what the code does.
Document the environment macro expansion readsBryce Kwon-2/+14
Remove the language breakdown from the stats pageBryce Kwon-3/+3
Resolve submodule links from `.gitmodules`Bryce Kwon-4/+21
Document cache directory ownershipBryce Kwon-1/+10
Cache id-pinned pages and snapshots as staticBryce Kwon-1/+3
Remove the repository homepage featureBryce Kwon-6/+3
Add `enable-relative-dates` and `date-format`Bryce Kwon-1/+20
Drop the help tab and its built-in guideBryce Kwon-6/+0
Reorganize the tree into vendor/ and custom/Bryce Kwon-3/+3
Drop the example cgitrc from the manualBryce Kwon-190/+0
Replace the browser markdown renderer with a filterBryce Kwon-13/+6
The readme is now escaped plain text unless `about-filter` points at the new `about-render.lua`, which renders markdown, man pages and plain text server-side. `enable-markdown` goes away with the renderer.
Add `max-patch-count` to bound the patch viewBryce Kwon-0/+5
Emit a conforming `rel=icon` for the favicon linkBryce Kwon-3/+4
Gate the stats page and add a language breakdownBryce Kwon-3/+14
`max-stats` only bounds the selectable periods now and no longer doubles as the enable switch. The tree walk runs before the history walk on purpose. Releasing commit memory while walking history resets each commit slab index, and a commit graph lookup afterwards would read another commit slot and walk the wrong tree. The stats fixture writes a commit graph so the tests cover that path. The history walk bounds the window in process rather than passing a formatted since date to `setup_revisions`, and parses each commit once.
Remove the owner filter hookBryce Kwon-18/+0
Move syntax highlighting to a Lua source filterBryce Kwon-5/+7
Stat oversized diffs instead of inlining themBryce Kwon-0/+12
Cap and paginate the ref listingsBryce Kwon-0/+6
Add a help page with common workflowsBryce Kwon-0/+6
Prune and rename the filter extensionsBryce Kwon-6/+7
The gentoo LDAP filter is distro specific, the owner example only restates what cgit already renders, and the about converters are superseded by the built-in markdown rendering. The two auth filters do the same job and differ only in where their accounts live, so they become `auth-inline` for accounts kept in the script and `auth-file` for accounts kept on disk.
Respect the cgitrc order of sectionsBryce Kwon-3/+3
The default sorted the sections and the repositories within them by name, so the order written in the cgitrc file was ignored.
Check `max-blob-size` before reading, default 10 MBBryce Kwon-2/+4
Only the tree view honoured the limit, and only after loading the whole object. The raw blob, plain, blame and readme paths now check the size before reading, and the default moves from unlimited to 10 MB so a fresh install never buffers a huge object whole, with zero still the opt-out.
Render README markdown in the browserBryce Kwon-4/+13
cgit had no markdown support of its own, so a readme was rendered through an external python filter or not at all. Escaping the source and formatting it in cgit.js keeps the work in the browser like the blob highlighter, and the page stays readable as plain text without scripting.
Add built-in syntax highlightingBryce Kwon-4/+6
Highlighting previously required a source filter shelling out to something like Pygments. A configured source filter still takes precedence, every character is preserved so the line gutter stays aligned, and large files are skipped.
Add `enable-tree-group-dirs` to list dirs firstBryce Kwon-0/+6
Gate the cache listing behind `enable-cache-list`Bryce Kwon-0/+6
The `ls_cache` page printed the cache directory path and the urls other visitors had requested, with no gate at all.
Reorganize into source, assets and librariesBryce Kwon-1/+1
The C sources move to source/, the served files to assets/, the bundled Git submodule to libraries/git and the filter scripts to extensions/. Everything the build generates now lands in build/, so a clean is a single remove and the tree stays clean.
ui-log: allow link following to be disabled per-repoJason A. Donenfeld-0/+4
This exists for other CPU heavy operations like blame, but doesn't for the follow functionality. Add it for that. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
config: add jsAndy Green-0/+5
Just like the config allows setting css URL path, add a config for setting the js URL path Signed-off-by: Andy Green <andy@warmcat.com> Reviewed-by: John Keeping <john@keeping.me.uk> Signed-off-by: Christian Hesse <mail@eworm.de>
css: change to be a listAndy Green-1/+2
Without changing the default behaviour of including /cgit.css if nothing declared, allow the "css" config to be given multiple times listing one or more alternative URL paths to be included in the document head area. Signed-off-by: Andy Green <andy@warmcat.com> Signed-off-by: Christian Hesse <mail@eworm.de>
cgitrc: handle value "0" for max-repo-countChristian Hesse-1/+2
Setting max-repo-count to "0" makes cgit loop forever generating page links. Make this a special value to show all repositories. Signed-off-by: Christian Hesse <mail@eworm.de>
about: allow to give head from queryChristian Hesse-5/+5
Reading the README from repository used to be limited to default branch or a branch given in configuration. Let's allow a branch from query if not specified explicitly. Signed-off-by: Christian Hesse <mail@eworm.de>
ui-snapshot: add support for zstd compressionChristian Hesse-3/+6
This patch adds support for zstd [0] compressed snapshots (*.tar.zst). We enable multiple working threads (-T0), but keep default compression level. The latter can be influenced by environment variable. [0] https://www.zstd.net/ Signed-off-by: Christian Hesse <mail@eworm.de>
ui-snapshot: add support for lzip compressionHanspeter Portner-2/+2
This patch adds support for lzip [1] compressed snapshots (*.tar.lz) [1] https://www.nongnu.org/lzip/ Signed-off-by: Hanspeter Portner <dev@open-music-kontrollers.ch> Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
ui-tree: allow per repository override for enable-blameChristian Hesse-0/+4
The blame operation can cause high cost in terms of CPU load for huge repositories. Let's add a per repository override for enable-blame. Signed-off-by: Christian Hesse <mail@eworm.de>
cgitrc.5: add local tar signature exampleJason A. Donenfeld-3/+14
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
cgitrc.5: document new signature notesJason A. Donenfeld-1/+17
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
extra-head-content: introduce another option for meta tagsJason A. Donenfeld-0/+4
This is to support things like go-import meta tags, which are on a per-repo basis. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
manpage: fix sorting orderAndy Green-88/+88
You maybe didn't know you had OCD until you saw an alpha sorted list that has stuff out of order in it. Signed-off-by: Andy Green <andy@warmcat.com> Reviewed-by: John Keeping <john@keeping.me.uk>