| Age | Commit message (Collapse) | Author | Lines |
|
It lists object directories by their path on the server, which a
client fetching over http can neither use nor needs to learn. The
http-alternates file written for such clients still goes out.
|
|
The diff and patch pages honour the path in the url, which the
parameter table documents for every page, but rawdiff never handed it
to git and answered with the whole diff.
|
|
The dumb transport read a pack four kilobytes at a time through stdio
and sent it without a length, so a client could not tell a cut-off
transfer from a complete one.
|
|
The dumb transport reads files that already sit on the disk, so a pack
copied into a slot cost that disk twice and the request a second write
of every byte. A snapshot took a slot whatever its size, so a visitor
naming distinct refs and ids could fill the cache root with archives.
`cache-max-slot-size`, 64 MB unless set, now serves a larger response
from the lock file and drops it, along with any expired copy it would
have replaced.
|
|
`enable-html-serving` makes the plain page send a repository file as
text/html on the site's own origin, with no nosniff and no policy, so
a scanned repository could switch it on from its git config or cgitrc
without `trust-scan-config` and run script against every visitor. The
warning for a key read from git config also named a null repository,
because `repo->path` was set only after that file had been read.
|
|
`cgit_abort_filters` unhooks the Lua write interposer under NO_LUA
too, where neither the hook nor its state exists, so `make NO_LUA=1`
and the default mode of `tools/release-build.sh` have not compiled
since the die path learned to take stdout back from a filter. The
suite now builds that variant into `build/nolua` and runs it, and a
`lua:` filter in such a build is refused with a message naming the
cause instead of an unknown filter type.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
`compose_snapshot_prefix` dropped the leading v of a tag only when just
one of the names 1.2, v1.2 and V1.2 resolved as a tag, so that the
shorter snapshot name could always be traced back to one tag. Those
probes went through ref lookups, and on a case-insensitive filesystem
a lookup for V1.2 finds the loose file of v1.2, so every freshly made
tag counted as ambiguous and kept its v. Once git packed the refs the
lookups became exact and the same tag quietly changed its snapshot
names.
The claimants on a stripped name are now counted over the tag list
itself with exact string comparison, so the answer no longer depends
on how a ref is stored or on the filesystem underneath. Two tags that
really differ only by the letter's case still both keep it.
|
|
|
|
|
|
The inline handlers and the auto-submitting selects are gone, so
`script-src` no longer needs it, and t0004 now checks that the three
configs pin the same policy.
|
|
|
|
|
|
|
|
|
|
|
|
A `max-stats` period enables the page again, as it did before
v2.2.0, so one key does both jobs.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
t000x the ground the suite stands on: git version, html validity,
the cache
t01xx page content, one script per page
t02xx features that cut across pages: filters, submodule links,
dates, limits
t03xx defence, the security regressions and the $HOME promise
t04xx the helper tools under tools/
|
|
|
|
A submodule row linked to a path with its trailing slash stripped,
was labelled by its path rather than its entry name, shared the
name's element with its hash, claimed a size of zero and offered a
blame button that cannot work on a gitlink.
|
|
|
|
|
|
|