| Age | Commit message (Collapse) | Author | Lines |
|
The dumb transport reads files that already sit on the disk, so a pack
copied into a slot cost that disk twice and the request a second write
of every byte. A snapshot took a slot whatever its size, so a visitor
naming distinct refs and ids could fill the cache root with archives.
`cache-max-slot-size`, 64 MB unless set, now serves a larger response
from the lock file and drops it, along with any expired copy it would
have replaced.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
noplainemail enable-plain-email
noheader enable-header
cache-root-ttl cache-index-ttl
cache-repo-ttl cache-summary-ttl
cache-scanrc-ttl cache-scan-ttl
agefile age-file
renamelimit rename-limit
extra-head-content head-content
|
|
A `max-stats` period enables the page again, as it did before
v2.2.0, so one key does both jobs.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
The readme is now escaped plain text unless `about-filter` points at
the new `about-render.lua`, which renders markdown, man pages and plain
text server-side. `enable-markdown` goes away with the renderer.
|
|
|
|
`max-stats` only bounds the selectable periods now and no longer
doubles as the enable switch.
The tree walk runs before the history walk on purpose. Releasing
commit memory while walking history resets each commit slab index,
and a commit graph lookup afterwards would read another commit slot
and walk the wrong tree. The stats fixture writes a commit graph so
the tests cover that path. The history walk bounds the window in
process rather than passing a formatted since date to
`setup_revisions`, and parses each commit once.
|
|
|
|
|
|
|
|
|
|
AUTHORS now records the upstream developers as the project's history
rather than as maintainers of the fork.
|
|
|
|
Clone urls and atom links are built from the request scheme and Host,
but the cache key left them out, so a request with a spoofed Host
could cache a page carrying a bogus clone url and serve it to other
visitors.
|
|
The POST length was clamped with a signed comparison, so a very large
Content-Length could turn negative and slip past the limit into the
fixed-size buffer.
|
|
The default sorted the sections and the repositories within them by
name, so the order written in the cgitrc file was ignored.
|
|
cgit unsets HOME to isolate git from the calling user, but git still
finds the global config through its getpwuid fallback and then dies
expanding a `~` in `core.excludesfile`. That die happened after the
snapshot headers and the gzip filter were already in place, so the
error page was compressed into the archive and every snapshot came
out undecompressable.
|
|
A crafted `ofs` could send cgit walking most of the history for one
request.
|
|
Only the tree view honoured the limit, and only after loading the
whole object. The raw blob, plain, blame and readme paths now check
the size before reading, and the default moves from unlimited to
10 MB so a fresh install never buffers a huge object whole, with zero
still the opt-out.
|
|
cgit had no markdown support of its own, so a readme was rendered
through an external python filter or not at all. Escaping the source
and formatting it in cgit.js keeps the work in the browser like the
blob highlighter, and the page stays readable as plain text without
scripting.
|
|
|
|
The `ls_cache` page printed the cache directory path and the urls other
visitors had requested, with no gate at all.
|
|
The C sources move to source/, the served files to assets/, the bundled
Git submodule to libraries/git and the filter scripts to extensions/.
Everything the build generates now lands in build/, so a clean is a
single remove and the tree stays clean.
|