AgeCommit message (Collapse)AuthorLines
Keep clone files and oversized responses out of the cacheBryce Kwon-0/+1
The dumb transport reads files that already sit on the disk, so a pack copied into a slot cost that disk twice and the request a second write of every byte. A snapshot took a slot whatever its size, so a visitor naming distinct refs and ids could fill the cache root with archives. `cache-max-slot-size`, 64 MB unless set, now serves a larger response from the lock file and drops it, along with any expired copy it would have replaced.
Rename enable-trailers to enable-commit-trailersBryce Kwon-2/+2
Harden the request path, scan and error recoveryBryce Kwon-3/+14
Gate scanned filters with `trust-scan-filters`Bryce Kwon-1/+1
Apply the mailmap at HEAD to every identBryce Kwon-0/+2
Split trailers out of the commit messageBryce Kwon-0/+4
Clean up the whole treeBryce Kwon-2/+1
Trim the comments and dead code across the treeBryce Kwon-2/+1
Rename the inconsistent config keysBryce Kwon-6/+6
noplainemail enable-plain-email noheader enable-header cache-root-ttl cache-index-ttl cache-repo-ttl cache-summary-ttl cache-scanrc-ttl cache-scan-ttl agefile age-file renamelimit rename-limit extra-head-content head-content
Fold `enable-stats` back into `max-stats`Bryce Kwon-2/+0
A `max-stats` period enables the page again, as it did before v2.2.0, so one key does both jobs.
Resolve submodule links from `.gitmodules`Bryce Kwon-0/+2
Print the raw-content headers with the restBryce Kwon-0/+1
Drop the Last-Modified, Expires and ETag headersBryce Kwon-3/+0
Remove the repository homepage featureBryce Kwon-1/+0
Restyle the sources and fix the audit's findingsBryce Kwon-143/+43
Bound the search and cache key a request can askBryce Kwon-0/+8
Settle the names, types and layout of the sourcesBryce Kwon-12/+12
Give empty repositories their own pageBryce Kwon-0/+3
Add `enable-relative-dates` and `date-format`Bryce Kwon-0/+4
Drop the help tab and its built-in guideBryce Kwon-1/+0
Replace the browser markdown renderer with a filterBryce Kwon-1/+0
The readme is now escaped plain text unless `about-filter` points at the new `about-render.lua`, which renders markdown, man pages and plain text server-side. `enable-markdown` goes away with the renderer.
Add `max-patch-count` to bound the patch viewBryce Kwon-0/+1
Gate the stats page and add a language breakdownBryce Kwon-0/+2
`max-stats` only bounds the selectable periods now and no longer doubles as the enable switch. The tree walk runs before the history walk on purpose. Releasing commit memory while walking history resets each commit slab index, and a commit graph lookup afterwards would read another commit slot and walk the wrong tree. The stats fixture writes a commit graph so the tests cover that path. The history walk bounds the window in process rather than passing a formatted since date to `setup_revisions`, and parses each commit once.
Remove the owner filter hookBryce Kwon-3/+1
Stat oversized diffs instead of inlining themBryce Kwon-0/+2
Cap and paginate the ref listingsBryce Kwon-0/+1
Add a help page with common workflowsBryce Kwon-0/+1
Drop unused config and query fieldsBryce Kwon-3/+0
Render README markdown in the browserBryce Kwon-0/+1
cgit had no markdown support of its own, so a readme was rendered through an external python filter or not at all. Escaping the source and formatting it in cgit.js keeps the work in the browser like the blob highlighter, and the page stays readable as plain text without scripting.
Add `enable-tree-group-dirs` to list dirs firstBryce Kwon-0/+1
Gate the cache listing behind `enable-cache-list`Bryce Kwon-0/+1
The `ls_cache` page printed the cache directory path and the urls other visitors had requested, with no gate at all.
Reorganize into source, assets and librariesBryce Kwon-0/+0
The C sources move to source/, the served files to assets/, the bundled Git submodule to libraries/git and the filter scripts to extensions/. Everything the build generates now lands in build/, so a clean is a single remove and the tree stays clean.
cgit: truncate all config values at the newlineJason A. Donenfeld-1/+3
These would be largely invalid anyway (save, I suppose, for Linux file paths that technically can contain new lines). The actual problem is that these get printed back out into cached -- and trusted -- cgitrc files, and if the fields have newlines, the git-config way of less trusted users configuring repos on a shared system can be abused to inject newlines, which then can be used to smuggle global options (including filters, which execute code) into the cached cgitrc. So now, only ever duplicate up to the newline, when dealing with these inputs. Reported-by: Adrian Denkiewicz <adrian@doyensec.com> Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
cgit: devirtualize repo_configJason A. Donenfeld-4/+2
There's no reason to pass around function pointers. It was never used for anything beyond one function. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
ui-log: allow link following to be disabled per-repoJason A. Donenfeld-0/+1
This exists for other CPU heavy operations like blame, but doesn't for the follow functionality. Add it for that. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
git: update to v2.53.0Christian Hesse-2/+1
Update to git version v2.53.0, this requires changes for these upstream commits: * bdbebe5714b25dc9d215b48efbb80f410925d7dd refs: introduce wrapper struct for `each_ref_fn` * 589127caa73090040200989ff4d24c3d54f473f2 packfile: move list of packs into the packfile store * 5a5c7359f77ecd1bc4b0e172563161d602f131d3 refs: drop `current_ref_iter` hack * b6e4cc8c32850315323961659e553d1d14591f7f tag: support arbitrary repositories in parse_tag() * 84f0e60b28de69d1ccb7a51b729af6202b6cf4c8 packfile: move packfile store into object source Signed-off-by: Christian Hesse <mail@eworm.de>
git: update to v2.51.0Christian Hesse-1/+1
Update to git version v2.51.0, this requires changes for these upstream commits: * 8f49151763cb81adf4bcec53c1ae67057081b02d object-store: rename files to "odb.{c,h}" Signed-off-by: Christian Hesse <mail@eworm.de>
git: update to v2.47.0Christian Hesse-2/+2
Update to git version v2.47.0, this requires changes for these upstream commits: * e8207717f1623325fe1c95338fb03c1104ed5687 refs: add referent to each_ref_fn Signed-off-by: Christian Hesse <mail@eworm.de>
fix building with clangDenis Pronin-1/+1
fix error that is given because of macro overlapping cgit_filter member: ../filter.c:388:10: error: no member named '__fprintf_chk' in 'struct cgit_filter' 388 | filter->fprintf(filter, f, prefix); | ~~~~~~ ^ /usr/include/bits/stdio2.h:92:3: note: expanded from macro 'fprintf' 92 | __fprintf_chk (stream, __USE_FORTIFY_LEVEL - 1, __VA_ARGS__) | ^ 1 error generated. Signed-off-by: Denis Pronin <dannftk@yandex.ru> Signed-off-by: Christian Hesse <mail@eworm.de>
git: update to v2.42.0Christian Hesse-1/+1
Update to git version v2.42.0, this requires changes for these upstream commits: * bc5c5ec0446895f5c4139cd470066beb3c4ac6d5 cache.h: remove this no-longer-used header * aba070683295a20bdf4f49146384984961c794b2 path: move related function to path * a4e7e317f8f27f861321e6eb08b9c8c0f3ab570c config: add ctx arg to config_fn_t Signed-off-by: Christian Hesse <mail@eworm.de>
git: update to v2.41.0Christian Hesse-13/+17
Update to git version v2.41.0, with lots of changes... This requires changes for these upstream commits: * 60ff56f50372c1498718938ef504e744fe011ffb banned.h: mark `strtok()` and `strtok_r()` as banned * 52acddf36c8cb3778ab2098a0d95cc2e375a4069 string-list: multi-delimiter `string_list_split_in_place()` * d850b7a545fcfbd97460a921c7f7c59d933eb0f7 cocci: apply the "cache.h" part of "the_repository.pending" * cb338c23d6d518947bf6f7240bf30e2ec232bd3b cocci: apply the "commit-reach.h" part of "the_repository.pending" * ecb5091fd4301ac647db0bd2504112b38f7ee06d cocci: apply the "commit.h" part of "the_repository.pending" * 085390328f5fe1dfba67039b1fd6cc51546a4e41 cocci: apply the "diff.h" part of "the_repository.pending" * bc726bd075929aab6b3e09d4dd5c2b0726fd5350 cocci: apply the "object-store.h" part of "the_repository.pending" * bab821646a74c446370fa8d01ca851f247df5033 cocci: apply the "pretty.h" part of "the_repository.pending" * afe27c889429438829bc8818ed17e4960bd3ef02 cocci: apply the "packfile.h" part of "the_repository.pending" * 12cb1c10a64170a5d600dd1c6c8abfeec105fb6b cocci: apply the "refs.h" part of "the_repository.pending" * 035c7de9e9ea11d26df5f9e4bb117f91ed11a9fd cocci: apply the "revision.h" part of "the_repository.pending" ... and some more I missed to list 😜 - for example the move and cleanup of headers and includes (see changes in `cgit.h`) comes to mind... Signed-off-by: Christian Hesse <mail@eworm.de>
js: add dynamic age updateAndy Green-0/+1
This patch updates the emitted "ages" dynamically on the client side. After updating on completion of the document load, it sets a timer to update according to the smallest age it found. If there are any ages listed in minutes, then it will update again in 10s. When the most recent age is in hours, it updates every 5m. If days, then every 30m and so on. This keeps the cost of the dynamic updates at worst once per 10s. The updates are done entirely on the client side without contact with the server. To make this work reliably, since parsing datetimes is unreliable in browser js, the unix time is added as an attribute to all age spans. To make that reliable cross-platform, the unix time is treated as a uint64_t when it is formatted for printing. The rules for display conversion of the age is aligned with the existing server-side rules in ui-shared.h. If the client or server-side time are not synchronized by ntpd etc, ages shown on the client will not relate to the original ages computed at the server. The client updates the ages immediately when the DOM has finished loading, so in the case the times at the server and client are not aligned, this patch changes what the user sees on the page to reflect patch age compared to client time. If the server and client clocks are aligned, this patch makes no difference to what is seen on the page. Signed-off-by: Andy Green <andy@warmcat.com> Signed-off-by: Christian Hesse <mail@eworm.de>
config: add jsAndy Green-0/+1
Just like the config allows setting css URL path, add a config for setting the js URL path Signed-off-by: Andy Green <andy@warmcat.com> Reviewed-by: John Keeping <john@keeping.me.uk> Signed-off-by: Christian Hesse <mail@eworm.de>
css: change to be a listAndy Green-1/+1
Without changing the default behaviour of including /cgit.css if nothing declared, allow the "css" config to be given multiple times listing one or more alternative URL paths to be included in the document head area. Signed-off-by: Andy Green <andy@warmcat.com> Signed-off-by: Christian Hesse <mail@eworm.de>
global: replace references to 'sha1' with 'oid'Christian Hesse-3/+3
For some time now sha1 is considered broken and upstream is working to replace it with sha256. Replace all references to 'sha1' with 'oid', just as upstream does. Signed-off-by: Christian Hesse <mail@eworm.de>
git: update to v2.29.0Christian Hesse-1/+1
Update to git version v2.29.0, this requires changes for these upstream commits: * dbbcd44fb47347a3fdbee88ea21805b7f4ac0b98 strvec: rename files from argv-array to strvec * 873cd28a8b17ff21908c78c7929a7615f8c94992 argv-array: rename to strvec * d70a9eb611a9d242c1d26847d223b8677609305b strvec: rename struct fields * 6a67c759489e1025665adf78326e9e0d0981bab5 test-lib-functions: restrict test_must_fail usage Signed-off-by: Christian Hesse <mail@eworm.de>
ui-tree: allow per repository override for enable-blameChristian Hesse-0/+1
The blame operation can cause high cost in terms of CPU load for huge repositories. Let's add a per repository override for enable-blame. Signed-off-by: Christian Hesse <mail@eworm.de>
git: update to v2.19.1Christian Hesse-0/+1
Update to git version v2.19.1. Required changes follow upstream commits: * commit: add repository argument to get_cached_commit_buffer (3ce85f7e5a41116145179f0fae2ce6d86558d099) * commit: add repository argument to lookup_commit_reference (2122f6754c93be8f02bfb5704ed96c88fc9837a8) * object: add repository argument to parse_object (109cd76dd3467bd05f8d2145b857006649741d5c) * tag: add repository argument to deref_tag (a74093da5ed601a09fa158e5ba6f6f14c1142a3e) * tag: add repository argument to lookup_tag (ce71efb713f97f476a2d2ab541a0c73f684a5db3) * tree: add repository argument to lookup_tree (f86bcc7b2ce6cad68ba1a48a528e380c6126705e) * archive.c: avoid access to the_index (b612ee202a48f129f81f8f6a5af6cf71d1a9caef) * for_each_*_object: move declarations to object-store.h (0889aae1cd18c1804ba01c1a4229e516dfb9fe9b) Signed-off-by: Christian Hesse <mail@eworm.de>
extra-head-content: introduce another option for meta tagsJason A. Donenfeld-0/+1
This is to support things like go-import meta tags, which are on a per-repo basis. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
global: remove functionality we deprecated for cgit v1.0Christian Hesse-3/+0
The man page states these were deprecated for v1.0. We are past v1.1, so remove the functionality. Signed-off-by: Christian Hesse <mail@eworm.de> Reviewed-by: John Keeping <john@keeping.me.uk>