AgeCommit message (Collapse)AuthorLines
Gate html serving behind trust-scan-configBryce Kwon-11/+15
`enable-html-serving` makes the plain page send a repository file as text/html on the site's own origin, with no nosniff and no policy, so a scanned repository could switch it on from its git config or cgitrc without `trust-scan-config` and run script against every visitor. The warning for a key read from git config also named a null repository, because `repo->path` was set only after that file had been read.
Align with spaces instead of tabsBryce Kwon-7/+7
Harden the request path, scan and error recoveryBryce Kwon-23/+94
Gate scanned filters with `trust-scan-filters`Bryce Kwon-2/+14
Clean up the whole treeBryce Kwon-20/+10
Trim the comments and dead code across the treeBryce Kwon-5/+6
Log scan lock failures that are not contentionBryce Kwon-7/+7
Remove the repository homepage featureBryce Kwon-2/+0
Restyle the sources and fix the audit's findingsBryce Kwon-118/+136
Settle the names, types and layout of the sourcesBryce Kwon-10/+11
Hide git's default repository descriptionBryce Kwon-0/+10
Strip the trailing slash before matching `/.git`Bryce Kwon-2/+5
Point the fork's links and credits at itselfBryce Kwon-1/+1
AUTHORS now records the upstream developers as the project's history rather than as maintainers of the fork.
Avoid an out-of-bounds read on short scan pathsBryce Kwon-1/+1
A relative path shorter than five bytes made the `/.git` suffix test read before the buffer.
Reorganize into source, assets and librariesBryce Kwon-0/+0
The C sources move to source/, the served files to assets/, the bundled Git submodule to libraries/git and the filter scripts to extensions/. Everything the build generates now lands in build/, so a clean is a single remove and the tree stays clean.
cgit: truncate all config values at the newlineJason A. Donenfeld-4/+4
These would be largely invalid anyway (save, I suppose, for Linux file paths that technically can contain new lines). The actual problem is that these get printed back out into cached -- and trusted -- cgitrc files, and if the fields have newlines, the git-config way of less trusted users configuring repos on a shared system can be abused to inject newlines, which then can be used to smuggle global options (including filters, which execute code) into the cached cgitrc. So now, only ever duplicate up to the newline, when dealing with these inputs. Reported-by: Adrian Denkiewicz <adrian@doyensec.com> Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
cgit: devirtualize repo_configJason A. Donenfeld-17/+15
There's no reason to pass around function pointers. It was never used for anything beyond one function. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
scan-tree: fix error caused by missing parameter nameKian Kasad-1/+2
This fixes an error which was introduced by 2f50b47c72cbc4270bbd12ae7f520486d5f42736. Git 2.42.0 added a new argument to config_fn_t, and it was added to gitconfig_config(), but not named. This causes compile warnings/errors. This commit fixes that by naming the new parameter, and marking it unused. Signed-off-by: Christian Hesse <mail@eworm.de>
git: update to v2.42.0Christian Hesse-1/+1
Update to git version v2.42.0, this requires changes for these upstream commits: * bc5c5ec0446895f5c4139cd470066beb3c4ac6d5 cache.h: remove this no-longer-used header * aba070683295a20bdf4f49146384984961c794b2 path: move related function to path * a4e7e317f8f27f861321e6eb08b9c8c0f3ab570c config: add ctx arg to config_fn_t Signed-off-by: Christian Hesse <mail@eworm.de>
git: update to v2.14Jeff Smith-2/+3
Numerous changes were made to git functions to use an object_id structure rather than sending sha1 hashes as raw unsigned character arrays. The functions that affect cgit are: parse_object, lookup_commit_reference, lookup_tag, lookup_tree, parse_tree_indirect, diff_root_tree_sha1, diff_tree_sha1, and format_display_notes. Commit b2141fc (config: don't include config.h by default) made it necessary to that config.h be explicitly included when needed. Commit 07a3d41 (grep: remove regflags from the public grep_opt API) removed one way of specifying the ignore-case grep option. Signed-off-by: Jeff Smith <whydoubt@gmail.com>
Use skip_prefix() to get rid of magic constantsLukas Fleischer-2/+4
Signed-off-by: Lukas Fleischer <lfleischer@lfos.de>
git: update to v2.8.2Christian Hesse-1/+1
Update to git version v2.8.2. * Upstream commit 1a0c8dfd89475d6bb09ddee8c019cf0ae5b3bdc2 (strbuf: give strbuf_getline() to the "most text friendly" variant) changed API. Signed-off-by: Christian Hesse <mail@eworm.de>
ui-shared: add homepage to tabsJason A. Donenfeld-0/+2
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
scan-tree: remove useless strdup()John Keeping-1/+1
parse_configfile() takes a "const char *" and doesn't hold any references to it after it returns; there is no reason to pass it a duplicate. Coverity-id: 13941 Signed-off-by: John Keeping <john@keeping.me.uk>
scan-tree: make some variables 'static'John Keeping-2/+2
These are not used outside this file and are not declared. Signed-off-by: John Keeping <john@keeping.me.uk>
Remove trailing slash after remove-suffixLukas Fleischer-3/+6
When removing the ".git" suffix of a non-bare repository, also remove the trailing slash for compatibility with cgit_repobasename(). Signed-off-by: Lukas Fleischer <cgit@cryptocrack.de>
remove debug fprinf() calls that sneaked in with commit 79c985Christian Hesse-4/+0
git: update for git 2.0Christian Hesse-3/+7
prefixcmp() and suffixcmp() have been remove, functionality is now provided by starts_with() and ends_with(). Retrurn values have been changed, so instead of just renaming we have to fix logic. Everything else looks just fine.
Replace most uses of strncmp() with prefixcmp()Lukas Fleischer-1/+1
This is a preparation for replacing all prefix checks with either strip_prefix() or starts_with() when Git 1.8.6 is released. Signed-off-by: Lukas Fleischer <cgit@cryptocrack.de>
Update copyright informationLukas Fleischer-3/+2
* Name "cgit Development Team" as copyright holder to avoid listing every single developer. * Update copyright ranges. Signed-off-by: Lukas Fleischer <cgit@crytocrack.de>
scan-tree.c: Remove unused macroLukas Fleischer-2/+0
This is no longer needed since commit fb3655df (use struct strbuf instead of static buffers, 2013-04-06). Signed-off-by: Lukas Fleischer <cgit@cryptocrack.de>
Fix section-from-path > 1Lukas Fleischer-4/+4
When having found the first path separator occurrence at position i, we invoked strchr() on the same position i in subsequent iterations resulting in the same path separator being returned by strchr() over and over again. Increase the position by one to skip the occurrence that has just been found and advance to the next separator. Reported-by: Konstantin Ryabitsev <mricon@kernel.org> Signed-off-by: Lukas Fleischer <cgit@cryptocrack.de>
readme: use string_list instead of space deliminationsJason A. Donenfeld-7/+1
Now this is possible in cgitrc - readme=:README.md readme=:readme.md readme=:README.mkd readme=:readme.mkd readme=:README.rst readme=:readme.rst readme=:README.html readme=:readme.html readme=:README.htm readme=:readme.htm readme=:README.txt readme=:readme.txt readme=:README readme=:readme readme=:INSTALL.txt readme=:install.txt readme=:INSTALL readme=:install Suggested-by: John Keeping <john@keeping.me.uk> Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
scan-tree: fix regression in section-from-path=-1John Keeping-0/+2
Commit fb3655d (use struct strbuf instead of static buffers - 2013-04-06) introduced a regression in the "section-from-path" handling when the configured value is negative. By changing the "rel" variable so that it includes a trailing slash, counting slashes from the end of the string no longer gives the same answer as it did before. Fix this by ensuring that "rel" does not have a trailing slash. Reported-by: Julius Plenz <plenz@cis.fu-berlin.de> Signed-off-by: John Keeping <john@keeping.me.uk>
use struct strbuf instead of static buffersJohn Keeping-71/+89
Use "struct strbuf" from Git to remove the limit on file path length. Notes on scan-tree: This is slightly involved since I decided to pass the strbuf into add_repo() and modify if whenever a new file name is required, which should avoid any extra allocations within that function. The pattern there is to append the filename, use it and then reset the buffer to its original length (retaining a trailing '/'). Notes on ui-snapshot: Since write_archive modifies the argv array passed to it we copy the argv_array values into a new array of char* and then free the original argv_array structure and the new array without worrying about what the values now look like. Signed-off-by: John Keeping <john@keeping.me.uk>
Remove redundant calls to fmt("%s", ...)John Keeping-2/+2
After this change there is one remaining call 'fmt("%s", delim)' in ui-shared.c but is needed as delim is stack allocated and so cannot be returned from the function. Signed-off-by: John Keeping <john@keeping.me.uk>
Always #include corresponding .h in .c filesJohn Keeping-0/+1
While doing this, remove declarations from header files where the corresponding definition is declared "static" in order to avoid build errors. Also re-order existing headers in ui-*.c so that the file-specific header always comes immediately after "cgit.h", helping with future consistency. Signed-off-by: John Keeping <john@keeping.me.uk>
White space around control verbs.Jason A. Donenfeld-1/+1
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Fix several whitespace errorsLukas Fleischer-2/+2
* Remove whitespace at the end of lines. * Replace space indentation by tabs. * Add whitespace before/after several operators ("+", "-", "*", ...) * Add whitespace to assignments ("foo = bar;"). * Fix whitespace in parameter lists ("foobar(foo, bar, 42)"). Signed-off-by: Lukas Fleischer <cgit@cryptocrack.de>
scan-tree: Unify gitweb.* and cgit.* settings into one config option.Jason A. Donenfeld-29/+19
After some back and forth with Jamie and René, it looks like the git config semantics are going to be like this: - gitweb.category maps to the cgit repo config key "section" - gitweb.description maps to the cgit repo config key "desc" - gitweb.owner maps to the cgit repo config key "owner" - cgit.* maps to all cgit repo config keys This option can be enabled with "enable-git-config=1", and replaces all previous "enable-gitweb-*" config keys. The order of operations is as follows: - git config settings are applied in the order that they exist in the git config file - if the owner is not set from git config, get the owner using the usual getpwuid call - if the description is not set from git config, look inside the static $path/description file - if section-from-path=1, override whatever previous settings were inside of git config using the section-from-path logic - parse $path/cgitrc for local repo.* settings, that override all previous settings
Update copyright headers to have latest dates.Jason A. Donenfeld-1/+1
scan-tree: Support gitweb.category.Jason A. Donenfeld-0/+6
Use gitweb.category from git config to determine repo's section, if option is enabled.
scan-tree: Support gitweb.description.Jason A. Donenfeld-7/+17
Use gitweb.description instead of description file to determine description, if option is enabled.
Only guess default branch when a repo page is requestedLars Hjemli-36/+0
There's no need to invoke guess_defbranch() for each repo during scan-path, since repo.defbranch is only used when repo content is being displayed. Also, some users prefer to register their projects manually in cgitrc but they got no benefit from the new repo.defbranch handling. This patch tries to rectify these issues by only invoking guess_defbranch() when needed, regardless of how the repo was registered. Signed-off-by: Lars Hjemli <hjemli@gmail.com>
guess default branch from HEADJulius Plenz-0/+36
This is a saner alternative than hardcoding the default branch to be "master". The add_repo() function will now check for a symbolic ref in repo_path/HEAD. If there is a suitable one, overwrite repo->defbranch with it. Note that you'll need to strip the newline from the file (-> len-17). If HEAD is a symbolic link pointing directly to a branch below refs/heads/, do a readlink() instead to find the ref name. Signed-off-by: Julius Plenz <plenz@cis.fu-berlin.de> Signed-off-by: Lars Hjemli <hjemli@gmail.com>
scan-tree.c: avoid memory leakJamie Couture-0/+2
No references are kept to the memory pointed to by the 'rel' variable, so it should be free()'d before returning from add_repo(). Signed-off-by: Jamie Couture <jamie.couture@gmail.com> Signed-off-by: Lars Hjemli <larsh@hjemli.net>
Fix crash when projectsfile cannot be openedStefan Gehn-0/+1
This patch makes cgit properly abort in case the projectsfile cannot be opened. Without the added return cgit continues using the projects pointer which is NULL and thus causes a segfault.
scan_path(): Do not recurse into hidden directories by defaultJohan Herland-0/+2
Paths that start with a period ('.') are considered hidden in the Unix world. scan_path() should arguably not recurse into these directories by default. This patch makes it so, and introduces the "scan-hidden-path" config variable for overriding the new default and revert to the old behaviour (scanning _all_ directories, including hidden .directories). Signed-off-by: Johan Herland <johan@herland.net> Signed-off-by: Lars Hjemli <larsh@prediktor.no>
scan_path(): Improve handling of inaccessible directoriesJohan Herland-9/+9
When scanning a tree containing inaccessible directories (e.g. '.ssh' directories in users' homedirs, or repos with explicitly restricted access), scan_path() currently causes three lines of "Permissions denied" errors to be printed to the CGI error log per inaccessible directory: Error checking path /home/foo/.ssh: Permission denied (13) Error checking path /home/foo/.ssh/.git: Permission denied (13) Error opening directory /home/foo/.ssh: Permission denied (13) This is a side-effect of calling is_git_dir(path) and is_git_dir(fmt("%s/.git", path) _before_ we try to opendir(path). By placing the opendir(path) before the two is_git_dir() calls, we reduce the noise to a single line per inaccessible directory: Error opening directory /home/foo/.ssh: Permission denied (13) Signed-off-by: Johan Herland <johan@herland.net> Signed-off-by: Lars Hjemli <larsh@prediktor.no>
Add `strict-export` optionFelix Hanley-0/+4
This option is used to specify a filename which needs to be present in the repositories found during `scan-path` processing. By setting this option to 'git-daemon-export-ok', only repositories explicitly marked for git daemon export will be included in the cgit configuration. Signed-off-by: Felix Hanley <felix@seconddrawer.com.au> Signed-off-by: Lars Hjemli <hjemli@gmail.com>