| Age | Commit message (Collapse) | Author | Lines |
|
|
|
|
|
|
|
AUTHORS now records the upstream developers as the project's history
rather than as maintainers of the fork.
|
|
|
|
Clone urls and atom links are built from the request scheme and Host,
but the cache key left them out, so a request with a spoofed Host
could cache a page carrying a bogus clone url and serve it to other
visitors.
|
|
The stat-only diff path returned before the closing call, so the
content wrapper, footer and closing tags were never emitted.
|
|
The feed-level element was written only inside the commit loop, so a
feed with no commits omitted an element the atom format requires.
|
|
The diffstat divided by zero when a commit changed no lines, and a
submodule change was printed with a hardcoded length that dropped a
digit of a sha-1 and most of a sha-256.
|
|
The pager html-escaped its search and sort values instead of
url-encoding them, so a term with a hash or ampersand broke the link
and dropped the active filter on the next page.
|
|
The POST length was clamped with a signed comparison, so a very large
Content-Length could turn negative and slip past the limit into the
fixed-size buffer.
|
|
The idle-sort comparator returned a 64-bit time difference truncated
to int, which could flip sign and leave the ordering inconsistent.
|
|
The index derived a repository's age from `refs/heads/master` alone,
so a repository on any other default branch showed no age. HEAD is
repo-controlled and the age stat walks under `refs/heads`, so a branch
name carrying a parent-directory component is rejected.
|
|
The default sorted the sections and the repositories within them by
name, so the order written in the cgitrc file was ignored.
|
|
cgit unsets HOME to isolate git from the calling user, but git still
finds the global config through its getpwuid fallback and then dies
expanding a `~` in `core.excludesfile`. That die happened after the
snapshot headers and the gzip filter were already in place, so the
error page was compressed into the archive and every snapshot came
out undecompressable.
|
|
The log page passed the `id` query parameter to git's revision parser
without resolving it and ahead of the end-of-options marker. A value
like `id=--output=/path` was then parsed as an option, so an
unauthenticated request could create or truncate any file the server
user could write. No valid ref or object name begins with a dash.
|
|
A crafted `ofs` could send cgit walking most of the history for one
request.
|
|
The about subpath was confined to the readme directory with a plain
byte-prefix match, so a sibling directory sharing the base name as a
prefix passed the check and its files were served.
|
|
The line-number gutter did one allocation and one write per line.
|
|
Only the tree view honoured the limit, and only after loading the
whole object. The raw blob, plain, blame and readme paths now check
the size before reading, and the default moves from unlimited to
10 MB so a fresh install never buffers a huge object whole, with zero
still the opt-out.
|
|
A blob requested by ref with an unknown path fell through to the
commit object and was served with a 200 instead of a 404, two error
pages passed a null pointer to a %s format when the request carried
no object id, and the error pages left the layout open.
|
|
`fmt()` aborts the request rather than truncate, so a very long path
fed into a context-sensitive tab title took down page rendering.
|
|
The year period rendered without its label, and a commit with no
author line crashed the view.
|
|
A plain char is undefined in the ctype functions for negative values,
which a high byte produces wherever char is signed.
|
|
A relative path shorter than five bytes made the `/.git` suffix test
read before the buffer.
|
|
`read_in_full` returns a signed -1 on error, which became SIZE_MAX once
stored in the size_t length and then wrote a terminator far out of
bounds.
|
|
`trim_end()` returns NULL when a repo url is empty or all slashes and
the later newline trim dereferenced it. The legacy `r=` and `p=about`
path also read the last byte of the url without checking it was set.
|
|
A readme that is not markdown was written to the about page as raw
HTML when no about-filter was configured, so an untrusted repository
could inject script.
|
|
cgit had no markdown support of its own, so a readme was rendered
through an external python filter or not at all. Escaping the source
and formatting it in cgit.js keeps the work in the browser like the
blob highlighter, and the page stays readable as plain text without
scripting.
|
|
Highlighting previously required a source filter shelling out to
something like Pygments. A configured source filter still takes
precedence, every character is preserved so the line gutter stays
aligned, and large files are skipped.
|
|
On a phone the description, owner and shortcut columns crowded the
index and pushed the age off screen, and tapping the name already
opens the repository, so the index collapses to name and age.
|
|
The button is emitted hidden and only revealed by the script, so a
browser without JavaScript never shows a control that cannot work and
the page keeps tracking the system theme.
|
|
The old sheet had no overflow rules, so wide code, diff, blame and
stats blocks scrolled the whole page sideways on a phone. The classic
layout, badge colours and age shading are kept.
|
|
Without a viewport meta, mobile browsers assume a desktop-width page
and scale it down, which is the root cause of content overflowing on
small screens.
|
|
The masthead, tab bar, breadcrumb, content region and footer were HTML
tables, which cannot reflow and forced the page to scroll sideways on
small screens. Class and id names are kept so custom themes keep
matching, the tabs gain title hints and the form controls accessible
names.
|
|
|
|
The `ls_cache` page printed the cache directory path and the urls other
visitors had requested, with no gate at all.
|
|
Lua only powers the filter extensions, so it stays optional and
autodetected. `NO_LUA` yields a self-contained binary and the release
script links Lua only when asked to.
|
|
|
|
The C sources move to source/, the served files to assets/, the bundled
Git submodule to libraries/git and the filter scripts to extensions/.
Everything the build generates now lands in build/, so a clean is a
single remove and the tree stays clean.
|