| Age | Commit message (Collapse) | Author | Lines |
|
Each class behind cgit's published advisories now has a check against
the current code, from a newline in a file name to shell syntax handed
to a filter. The feed also treated an ident with an empty name and an
empty address as present and wrote an empty person, which Atom forbids.
|
|
A write that failed with EPIPE on an uncached page died into an error
page, which died again at exit when the page could not be sent either,
and git logged a recursion warning on every dropped connection. A
filter that exits early fails a write the same way, so the quiet exit
is kept for writes that reach the client itself.
|
|
Archives, packs and the HEAD file went out as octet-stream or gzip
with a UTF-8 charset on the end, since only the blob page cleared it.
The headers now decide from the type itself, so the two places that
cleared the charset by hand no longer need to.
|
|
The four pages that refuse a blob over max-blob-size each said it in
their own way, two of them in lower case, and the blame page ended its
binary notice with a full stop no other error carries.
|
|
Such a name is refused as a head before git could read it as an
option, and the fallback branch already skips it, so the switcher
offered a choice that led only to an error page.
|
|
A commit whose encoding header names something iconv cannot convert,
or whose text is labelled UTF-8 without being it, reached a page
declared UTF-8 with its bytes untouched. The atom feed already
replaced them, so its UTF-8 reader moves to shared.c and every ident,
subject, message and tag text passes through it.
|
|
With both an id and a path the blob page handed back the raw object
the id named, so a commit id gave the commit text itself, while the
plain page looked the path up in that commit's tree. A tag is peeled
to its commit on the way, and the README example of a pinned commit
now uses a form the request checks accept.
|
|
The hop to the trailing-slash form of the about page, and the hop back
to the summary of a repository without a readme, were built from the
path alone, so a request for the about page of another branch landed
on the default one. The query goes into the Location line as the
client sent it, with any byte a header cannot carry percent-encoded.
|
|
It lists object directories by their path on the server, which a
client fetching over http can neither use nor needs to learn. The
http-alternates file written for such clients still goes out.
|
|
The diff and patch pages honour the path in the url, which the
parameter table documents for every page, but rawdiff never handed it
to git and answered with the whole diff.
|
|
The dumb transport read a pack four kilobytes at a time through stdio
and sent it without a length, so a client could not tell a cut-off
transfer from a complete one.
|
|
The dumb transport reads files that already sit on the disk, so a pack
copied into a slot cost that disk twice and the request a second write
of every byte. A snapshot took a slot whatever its size, so a visitor
naming distinct refs and ids could fill the cache root with archives.
`cache-max-slot-size`, 64 MB unless set, now serves a larger response
from the lock file and drops it, along with any expired copy it would
have replaced.
|
|
`enable-html-serving` makes the plain page send a repository file as
text/html on the site's own origin, with no nosniff and no policy, so
a scanned repository could switch it on from its git config or cgitrc
without `trust-scan-config` and run script against every visitor. The
warning for a key read from git config also named a null repository,
because `repo->path` was set only after that file had been read.
|
|
`cgit_abort_filters` unhooks the Lua write interposer under NO_LUA
too, where neither the hook nor its state exists, so `make NO_LUA=1`
and the default mode of `tools/release-build.sh` have not compiled
since the die path learned to take stdout back from a filter. The
suite now builds that variant into `build/nolua` and runs it, and a
`lua:` filter in such a build is refused with a message naming the
cause instead of an unknown filter type.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
The newline made the charset name unknown to the converter, so a
message in another charset was left unconverted.
|
|
A parameter without a value swallowed the parameter after it.
|
|
|
|
A filter program that could not be run answered with two responses,
and a filter that exited without reading its input ended cgit with
the page half written.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
`compose_snapshot_prefix` dropped the leading v of a tag only when just
one of the names 1.2, v1.2 and V1.2 resolved as a tag, so that the
shorter snapshot name could always be traced back to one tag. Those
probes went through ref lookups, and on a case-insensitive filesystem
a lookup for V1.2 finds the loose file of v1.2, so every freshly made
tag counted as ambiguous and kept its v. Once git packed the refs the
lookups became exact and the same tag quietly changed its snapshot
names.
The claimants on a stripped name are now counted over the tag list
itself with exact string comparison, so the answer no longer depends
on how a ref is stored or on the filesystem underneath. Two tags that
really differ only by the letter's case still both keep it.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
noplainemail enable-plain-email
noheader enable-header
cache-root-ttl cache-index-ttl
cache-repo-ttl cache-summary-ttl
cache-scanrc-ttl cache-scan-ttl
agefile age-file
renamelimit rename-limit
extra-head-content head-content
|
|
A `max-stats` period enables the page again, as it did before
v2.2.0, so one key does both jobs.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|