AgeCommit message (Collapse)AuthorLines
Use standard HTTP reason phrasesBryce Kwon-5/+5
Resolve submodule links from `.gitmodules`Bryce Kwon-0/+5
Log scan lock failures that are not contentionBryce Kwon-1/+6
Give up a scan or slot whose lock file was renamedBryce Kwon-0/+13
Let a crashed scan's lock expire with its processBryce Kwon-9/+40
Cache id-pinned pages and snapshots as staticBryce Kwon-3/+27
Keep error pages out of the cacheBryce Kwon-3/+2
Drop the Last-Modified, Expires and ETag headersBryce Kwon-11/+0
Remove the repository homepage featureBryce Kwon-4/+0
Restyle the sources and fix the audit's findingsBryce Kwon-637/+712
Bound the search and cache key a request can askBryce Kwon-1/+8
Gather page output into one bufferBryce Kwon-0/+3
Settle the names, types and layout of the sourcesBryce Kwon-59/+59
Isolate the git environment without a constructorBryce Kwon-8/+13
Update the bundled Git to 2.55.0Bryce Kwon-1/+1
Give empty repositories their own pageBryce Kwon-18/+7
Add `enable-relative-dates` and `date-format`Bryce Kwon-0/+6
Drop the help tab and its built-in guideBryce Kwon-3/+0
Replace the browser markdown renderer with a filterBryce Kwon-3/+0
The readme is now escaped plain text unless `about-filter` points at the new `about-render.lua`, which renders markdown, man pages and plain text server-side. `enable-markdown` goes away with the renderer.
Add `max-patch-count` to bound the patch viewBryce Kwon-0/+3
Gate the stats page and add a language breakdownBryce Kwon-0/+6
`max-stats` only bounds the selectable periods now and no longer doubles as the enable switch. The tree walk runs before the history walk on purpose. Releasing commit memory while walking history resets each commit slab index, and a commit graph lookup afterwards would read another commit slot and walk the wrong tree. The stats fixture writes a commit graph so the tests cover that path. The history walk bounds the window in process rather than passing a formatted since date to `setup_revisions`, and parses each commit once.
Remove the owner filter hookBryce Kwon-6/+0
Stat oversized diffs instead of inlining themBryce Kwon-0/+6
Cap and paginate the ref listingsBryce Kwon-0/+3
Add a help page with common workflowsBryce Kwon-0/+3
Point the fork's links and credits at itselfBryce Kwon-2/+2
AUTHORS now records the upstream developers as the project's history rather than as maintainers of the fork.
Drop unused config and query fieldsBryce Kwon-4/+0
Key the cache on scheme and hostBryce Kwon-2/+15
Clone urls and atom links are built from the request scheme and Host, but the cache key left them out, so a request with a spoofed Host could cache a page carrying a bogus clone url and serve it to other visitors.
Bound the authenticate-post length safelyBryce Kwon-3/+4
The POST length was clamped with a signed comparison, so a very large Content-Length could turn negative and slip past the limit into the fixed-size buffer.
Respect the cgitrc order of sectionsBryce Kwon-1/+1
The default sorted the sections and the repositories within them by name, so the order written in the cgitrc file was ignored.
Keep snapshots working under a global git configBryce Kwon-1/+7
cgit unsets HOME to isolate git from the calling user, but git still finds the global config through its getpwuid fallback and then dies expanding a `~` in `core.excludesfile`. That die happened after the snapshot headers and the gzip filter were already in place, so the error page was compressed into the archive and every snapshot came out undecompressable.
Clamp the log offset to bound history walksBryce Kwon-1/+11
A crafted `ofs` could send cgit walking most of the history for one request.
Check `max-blob-size` before reading, default 10 MBBryce Kwon-1/+1
Only the tree view honoured the limit, and only after loading the whole object. The raw blob, plain, blame and readme paths now check the size before reading, and the default moves from unlimited to 10 MB so a fresh install never buffers a huge object whole, with zero still the opt-out.
Render README markdown in the browserBryce Kwon-0/+3
cgit had no markdown support of its own, so a readme was rendered through an external python filter or not at all. Escaping the source and formatting it in cgit.js keeps the work in the browser like the blob highlighter, and the page stays readable as plain text without scripting.
Add `enable-tree-group-dirs` to list dirs firstBryce Kwon-0/+2
Gate the cache listing behind `enable-cache-list`Bryce Kwon-0/+2
The `ls_cache` page printed the cache directory path and the urls other visitors had requested, with no gate at all.
Reorganize into source, assets and librariesBryce Kwon-0/+0
The C sources move to source/, the served files to assets/, the bundled Git submodule to libraries/git and the filter scripts to extensions/. Everything the build generates now lands in build/, so a clean is a single remove and the tree stays clean.
cgit: truncate all config values at the newlineJason A. Donenfeld-50/+40
These would be largely invalid anyway (save, I suppose, for Linux file paths that technically can contain new lines). The actual problem is that these get printed back out into cached -- and trusted -- cgitrc files, and if the fields have newlines, the git-config way of less trusted users configuring repos on a shared system can be abused to inject newlines, which then can be used to smuggle global options (including filters, which execute code) into the cached cgitrc. So now, only ever duplicate up to the newline, when dealing with these inputs. Reported-by: Adrian Denkiewicz <adrian@doyensec.com> Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
cgit: use strchrnul instead of open codingJason A. Donenfeld-3/+1
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
cgit: devirtualize repo_configJason A. Donenfeld-10/+9
There's no reason to pass around function pointers. It was never used for anything beyond one function. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
cgit: override die routine globallyJason A. Donenfeld-0/+7
We don't get any return value from compile_grep_patterns calling compile_regexp_failed, causing the default die routine to print to stderr and then for cgit to exit ungracefully. Instead override the default die routine to show a normal error page. Perhaps compile_grep_patterns ought to change upstream to return an error. But this commit here will handle future issues as well, so perhaps not a bad idea to do anyway. Link: https://lists.zx2c4.com/pipermail/cgit/2026-March/004982.html Link: https://lists.zx2c4.com/pipermail/cgit/2026-March/004983.html Reported-by: Adrian C. <anrxc@sysphere.org> Reported-by: Aiden Woodruff <aiden@aidenw.net> Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
ui-log: allow link following to be disabled per-repoJason A. Donenfeld-0/+4
This exists for other CPU heavy operations like blame, but doesn't for the follow functionality. Add it for that. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
git: update to v2.53.0Christian Hesse-4/+3
Update to git version v2.53.0, this requires changes for these upstream commits: * bdbebe5714b25dc9d215b48efbb80f410925d7dd refs: introduce wrapper struct for `each_ref_fn` * 589127caa73090040200989ff4d24c3d54f473f2 packfile: move list of packs into the packfile store * 5a5c7359f77ecd1bc4b0e172563161d602f131d3 refs: drop `current_ref_iter` hack * b6e4cc8c32850315323961659e553d1d14591f7f tag: support arbitrary repositories in parse_tag() * 84f0e60b28de69d1ccb7a51b729af6202b6cf4c8 packfile: move packfile store into object source Signed-off-by: Christian Hesse <mail@eworm.de>
git: update to v2.47.0Christian Hesse-2/+2
Update to git version v2.47.0, this requires changes for these upstream commits: * e8207717f1623325fe1c95338fb03c1104ed5687 refs: add referent to each_ref_fn Signed-off-by: Christian Hesse <mail@eworm.de>
git: update to v2.46.0Christian Hesse-2/+6
Update to git version v2.46.0, this requires changes for these upstream commits: * e7da9385708accf518a80a1e17969020fb361048 global: introduce `USE_THE_REPOSITORY_VARIABLE` macro * 9da95bda74cf10e1475384a71fd20914c3b99784 hash: require hash algorithm in `oidread()` and `oidclr()` * 30aaff437fddd889ba429b50b96ea4c151c502c5 refs: pass repo when peeling objects * c8f815c2083c4b340d4148a15d45c55f2fcc7d3f refs: remove functions without ref store Signed-off-by: Christian Hesse <mail@eworm.de>
git: update to v2.41.0Christian Hesse-1/+1
Update to git version v2.41.0, with lots of changes... This requires changes for these upstream commits: * 60ff56f50372c1498718938ef504e744fe011ffb banned.h: mark `strtok()` and `strtok_r()` as banned * 52acddf36c8cb3778ab2098a0d95cc2e375a4069 string-list: multi-delimiter `string_list_split_in_place()` * d850b7a545fcfbd97460a921c7f7c59d933eb0f7 cocci: apply the "cache.h" part of "the_repository.pending" * cb338c23d6d518947bf6f7240bf30e2ec232bd3b cocci: apply the "commit-reach.h" part of "the_repository.pending" * ecb5091fd4301ac647db0bd2504112b38f7ee06d cocci: apply the "commit.h" part of "the_repository.pending" * 085390328f5fe1dfba67039b1fd6cc51546a4e41 cocci: apply the "diff.h" part of "the_repository.pending" * bc726bd075929aab6b3e09d4dd5c2b0726fd5350 cocci: apply the "object-store.h" part of "the_repository.pending" * bab821646a74c446370fa8d01ca851f247df5033 cocci: apply the "pretty.h" part of "the_repository.pending" * afe27c889429438829bc8818ed17e4960bd3ef02 cocci: apply the "packfile.h" part of "the_repository.pending" * 12cb1c10a64170a5d600dd1c6c8abfeec105fb6b cocci: apply the "refs.h" part of "the_repository.pending" * 035c7de9e9ea11d26df5f9e4bb117f91ed11a9fd cocci: apply the "revision.h" part of "the_repository.pending" ... and some more I missed to list 😜 - for example the move and cleanup of headers and includes (see changes in `cgit.h`) comes to mind... Signed-off-by: Christian Hesse <mail@eworm.de>
config: add jsAndy Green-0/+2
Just like the config allows setting css URL path, add a config for setting the js URL path Signed-off-by: Andy Green <andy@warmcat.com> Reviewed-by: John Keeping <john@keeping.me.uk> Signed-off-by: Christian Hesse <mail@eworm.de>
css: change to be a listAndy Green-2/+1
Without changing the default behaviour of including /cgit.css if nothing declared, allow the "css" config to be given multiple times listing one or more alternative URL paths to be included in the document head area. Signed-off-by: Andy Green <andy@warmcat.com> Signed-off-by: Christian Hesse <mail@eworm.de>
cgitrc: handle value "0" for max-repo-countChristian Hesse-2/+4
Setting max-repo-count to "0" makes cgit loop forever generating page links. Make this a special value to show all repositories. Signed-off-by: Christian Hesse <mail@eworm.de>
about: allow to give head from queryChristian Hesse-3/+5
Reading the README from repository used to be limited to default branch or a branch given in configuration. Let's allow a branch from query if not specified explicitly. Signed-off-by: Christian Hesse <mail@eworm.de>