AgeCommit message (Collapse)AuthorLines
End a request quietly when the client has goneBryce Kwon-0/+5
A write that failed with EPIPE on an uncached page died into an error page, which died again at exit when the page could not be sent either, and git logged a recursion warning on every dropped connection. A filter that exits early fails a write the same way, so the quiet exit is kept for writes that reach the client itself.
Keep the Lua-less build compilingBryce Kwon-0/+6
`cgit_abort_filters` unhooks the Lua write interposer under NO_LUA too, where neither the hook nor its state exists, so `make NO_LUA=1` and the default mode of `tools/release-build.sh` have not compiled since the die path learned to take stdout back from a filter. The suite now builds that variant into `build/nolua` and runs it, and a `lua:` filter in such a build is refused with a message naming the cause instead of an unknown filter type.
Harden the request path, scan and error recoveryBryce Kwon-13/+43
Fail cleanly when a filter cannot runBryce Kwon-5/+17
A filter program that could not be run answered with two responses, and a filter that exited without reading its input ended cgit with the page half written.
Split trailers out of the commit messageBryce Kwon-0/+3
Clean up the whole treeBryce Kwon-32/+16
Harden the lua filter failure pathsBryce Kwon-5/+9
Trim the comments and dead code across the treeBryce Kwon-36/+17
Restyle the sources and fix the audit's findingsBryce Kwon-146/+178
Gather page output into one bufferBryce Kwon-0/+10
Settle the names, types and layout of the sourcesBryce Kwon-9/+9
Remove the owner filter hookBryce Kwon-6/+0
Point the fork's links and credits at itselfBryce Kwon-1/+1
AUTHORS now records the upstream developers as the project's history rather than as maintainers of the fork.
Reorganize into source, assets and librariesBryce Kwon-0/+0
The C sources move to source/, the served files to assets/, the bundled Git submodule to libraries/git and the filter scripts to extensions/. Everything the build generates now lands in build/, so a clean is a single remove and the tree stays clean.
global: fix libc constness warningsJason A. Donenfeld-1/+1
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
cgit: truncate all config values at the newlineJason A. Donenfeld-2/+2
These would be largely invalid anyway (save, I suppose, for Linux file paths that technically can contain new lines). The actual problem is that these get printed back out into cached -- and trusted -- cgitrc files, and if the fields have newlines, the git-config way of less trusted users configuring repos on a shared system can be abused to inject newlines, which then can be used to smuggle global options (including filters, which execute code) into the cached cgitrc. So now, only ever duplicate up to the newline, when dealing with these inputs. Reported-by: Adrian Denkiewicz <adrian@doyensec.com> Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
fix building with clangDenis Pronin-3/+3
fix error that is given because of macro overlapping cgit_filter member: ../filter.c:388:10: error: no member named '__fprintf_chk' in 'struct cgit_filter' 388 | filter->fprintf(filter, f, prefix); | ~~~~~~ ^ /usr/include/bits/stdio2.h:92:3: note: expanded from macro 'fprintf' 92 | __fprintf_chk (stream, __USE_FORTIFY_LEVEL - 1, __VA_ARGS__) | ^ 1 error generated. Signed-off-by: Denis Pronin <dannftk@yandex.ru> Signed-off-by: Christian Hesse <mail@eworm.de>
filter: pipe_fh should be localJason A. Donenfeld-6/+7
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
filter: don't use dlsym unnecessarilyJohn Keeping-36/+42
We only need to hook write() if Lua filter's are in use. If support has been disabled, remove the dependency on dlsym(). Signed-off-by: John Keeping <john@keeping.me.uk>
Remove redundant includesJohn Keeping-6/+0
These are all included in git-compat-util.h (when necessary), which we include in cgit.h. Signed-off-by: John Keeping <john@keeping.me.uk>
Avoid non-ANSI function declarationsJohn Keeping-1/+1
Sparse says things like: warning: non-ANSI function declaration of function 'calc_ttl' Signed-off-by: John Keeping <john@keeping.me.uk>
repolist: add owner-filterChris Burroughs-0/+6
This allows custom links to be used for repository owners by configuring a filter to be applied in the "Owner" column in the repository list.
remove trailing whitespaces from source filesChristian Hesse-1/+1
filter: don't forget to reap the auth filterJason A. Donenfeld-0/+1
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
auth: have cgit calculate login addressJason A. Donenfeld-1/+1
This way we're sure to use virtual root, or any other strangeness encountered. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
auth: add basic authentication filter frameworkJason A. Donenfeld-0/+11
This leverages the new lua support. See filters/simple-authentication.lua for explaination of how this works. There is also additional documentation in cgitrc.5.txt. Though this is a cookie-based approach, cgit's caching mechanism is preserved for authenticated pages. Very plugable and extendable depending on user needs. The sample script uses an HMAC-SHA1 based cookie to store the currently logged in user, with an expiration date. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
filter: allow returning exit code from filterJason A. Donenfeld-5/+9
Filters can now indicate a status back to cgit by means of the exit code for exec, or the return value from close for Lua. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
filter: style tweaksJason A. Donenfeld-11/+11
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
filter: add page source to email filterJason A. Donenfeld-0/+3
Since the email filter is called from lots of places, the script might benefit from knowing the origin. That way it can modify its contents and/or size depending. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
filter: add support for email filterJason A. Donenfeld-0/+3
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
filter: return on null filter from open and closeJason A. Donenfeld-0/+4
So that we don't have to include the if(filter) open_filter(filter) block everywhere, we introduce the guard in the function itself. This should simplify quite a bit of code. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
filter: add lua supportJason A. Donenfeld-0/+186
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
filter: basic write hooking infrastructureJason A. Donenfeld-21/+60
Filters can now call hook_write and unhook_write if they want to redirect writing to stdout to a different function. This saves us from potential file descriptor pipes and other less efficient mechanisms. We do this instead of replacing the call in html_raw because some places stdlib's printf functions are used (ui-patch or within git itself), which has its own internal buffering, which makes it difficult to interlace our function calls. So, we dlsym libc's write and then override it in the link stage. While we're at it, we move considerations of argument count into the generic new filter handler. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
filter: allow for cleanup hook for filter typesJason A. Donenfeld-27/+63
At some point, we're going to want to do lazy deallocation of filters. For example, if we implement lua, we'll want to load the lua runtime once for each filter, even if that filter is called many times. Similarly, for persistent exec filters, we'll want to load it once, despite many open_filter and close_filter calls, and only reap the child process at the end of the cgit process. For this reason, we add here a cleanup function that is called at the end of cgit's main(). Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
filter: introduce "filter type" prefixJohn Keeping-2/+31
This allows different filter implementations to be specified in the configuration file. Currently only "exec" is supported, but it may now be specified either with or without the "exec:" prefix. Signed-off-by: John Keeping <john@keeping.me.uk>
filter: add interface layerJohn Keeping-16/+50
Change the existing cgit_{open,close,fprintf}_filter functions to delegate to filter-specific implementations accessed via function pointers on the cgit_filter object. We treat the "exec" filter type slightly specially here by putting its structure definition in the header file and providing an "init" function to set up the function pointers. This is required so that the ui-snapshot.c code that applies a compression filter can continue to use the filter interface to do so. Signed-off-by: John Keeping <john@keeping.me.uk>
filter: add fprintf_filter functionJohn Keeping-0/+5
This stops the code in cgit.c::print_repo needing to inspect the cgit_filter structure, meaning that we can abstract out different filter types that will have different fields that need to be printed. Signed-off-by: John Keeping <john@keeping.me.uk>
filter: pass extra arguments via cgit_open_filterJohn Keeping-11/+24
This avoids poking into the filter data structure at various points in the code. We rely on the fact that the number of arguments is fixed based on the filter type (set in cgit_new_filter) and that the call sites all know which filter type they're using. Signed-off-by: John Keeping <john@keeping.me.uk>
filter: split filter functions into their own fileJason A. Donenfeld-0/+82
A first step for more interesting things. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>