From 969e9554a31385b2d2c09695dab984d585dc2693 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Mon, 21 Sep 2026 06:42:39 -1000 Subject: Harden the request path, scan and error recovery --- MANUAL.txt | 41 +++++------ custom/cgitrc | 12 ++-- source/cache.c | 71 +++++++++++++------ source/cache.h | 18 ++--- source/cgit.c | 177 ++++++++++++++++++++++++++++++++++-------------- source/cgit.h | 17 ++++- source/cgit.mk | 28 ++++---- source/cmd.c | 2 +- source/cmd.h | 4 +- source/config.c | 2 +- source/filter.c | 56 +++++++++++---- source/filter.h | 10 ++- source/html.c | 32 +++++++-- source/html.h | 12 ++-- source/parsing.c | 16 ++--- source/parsing.h | 6 +- source/scan-tree.c | 117 +++++++++++++++++++++++++------- source/shared.c | 105 +++++++++++++++++++++------- source/shared.h | 26 +++++-- tests/t0205-config.sh | 6 +- tests/t0301-security.sh | 31 +++++++-- 21 files changed, 565 insertions(+), 224 deletions(-) diff --git a/MANUAL.txt b/MANUAL.txt index f032512..0fbce91 100644 --- a/MANUAL.txt +++ b/MANUAL.txt @@ -178,9 +178,9 @@ enable-git-config:: settings. The keys gitweb.owner, gitweb.category, and gitweb.description will map to the cgit keys repo.owner, repo.section, and repo.desc respectively. All git config keys that begin with "cgit." will be mapped - to the corresponding "repo." key in cgit, with the filter keys among - them waiting on "trust-scan-filters". Default value: "0". See also: - scan-path, section-from-path, trust-scan-filters. + to the corresponding "repo." key in cgit, subject to "trust-scan-config" + the way a repository's cgitrc is. Default value: "0". See also: + scan-path, section-from-path, trust-scan-config. enable-gitmodules-links:: Flag which, when set to "1", makes submodule listings derive a link from @@ -538,14 +538,16 @@ trailer-filter:: URL values ships as custom/extensions/link-trailers.lua. Default value: none. See also: "Filter API". -trust-scan-filters:: - Flag which, when set to "1", honours the filter settings in a - repository's own cgitrc file and git config found by "scan-path". Those - files belong to whoever can push to the repository, and a filter is a - command cgit runs, so they are ignored with a warning unless the - repositories under the scan are trusted. Filter settings in the main - cgitrc, the "repo." form included, never need this. Default - value: "0". See also: "scan-path", "enable-git-config". +trust-scan-config:: + Flag which, when set to "1", honours every setting in a repository's + own cgitrc file and git config found by "scan-path". Those files belong + to whoever can push to the repository, so without it the settings that + run a command, put raw markup on the page, place a link or read a file + off the disk are ignored with a warning. Those are the filters, + head-content, module-link, logo, logo-link, clone-url and a readme that + names a file rather than a git object. Settings in the main cgitrc, the + "repo.