From b5988111398bf3b5a1cc58c374c1ef1cb58fe0ea Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Sat, 25 Jul 2026 22:36:52 -1000 Subject: Reorganize the tree into vendor/ and custom/ --- examples/cgitrc | 566 -------------------------- examples/hooks/post-receive.agefile | 19 - examples/hooks/post-update.update-server-info | 18 - examples/servers/apache.conf | 152 ------- examples/servers/lighttpd.conf | 132 ------ examples/servers/nginx.conf | 193 --------- 6 files changed, 1080 deletions(-) delete mode 100644 examples/cgitrc delete mode 100755 examples/hooks/post-receive.agefile delete mode 100755 examples/hooks/post-update.update-server-info delete mode 100644 examples/servers/apache.conf delete mode 100644 examples/servers/lighttpd.conf delete mode 100644 examples/servers/nginx.conf (limited to 'examples') diff --git a/examples/cgitrc b/examples/cgitrc deleted file mode 100644 index 4a36149..0000000 --- a/examples/cgitrc +++ /dev/null @@ -1,566 +0,0 @@ -# cgitrc reference configuration -# -# This file lists every cgit configuration option set to its default value. -# Options with a real default are left uncommented at that default. Options -# that are site-specific are commented out with a realistic example and their -# default noted in the comment. Copied as-is, cgit behaves as if no option -# were set. -# -# Quick start. The one thing you must set to see any repositories is where -# they live. Uncomment scan-path further down and point it at your git -# directory, or list repositories by hand in the per-repository section at -# the end of this file. -# -# About pages (markdown, man and plain-text readmes) render through the -# bundled about-render.lua about-filter, see the filter section below. Source -# syntax highlighting is optional and ships as a source-filter there too. -# -# One key=value pair per line. Lines starting with # are comments. - - -## -## Cache -## - -# Maximum number of entries in the cgit output cache. A value of 0 disables -# caching. Value is an integer. Default is 0. -cache-size=0 - -# Directory used to store cgit cache entries. Value is a filesystem path that -# may use macros. Default is /var/cache/cgit. -#cache-root=/var/cache/cgit - -# Minutes to cache the repository index page. Value is an integer number of -# minutes. Default is 5. -cache-root-ttl=5 - -# Minutes to cache the repository summary page. Value is an integer number of -# minutes. Default is 5. -cache-repo-ttl=5 - -# Minutes to cache the result of scanning a path for repositories. Value is an -# integer number of minutes. Default is 15. -cache-scanrc-ttl=15 - -# Minutes to cache repo pages requested with a fixed SHA1. A negative value -# never expires. Value is an integer number of minutes. Default is -1. -cache-static-ttl=-1 - -# Minutes to cache repo pages requested without a fixed SHA1. Value is an -# integer number of minutes. Default is 5. -cache-dynamic-ttl=5 - -# Minutes to cache the repository about page. Value is an integer number of -# minutes. Default is 15. -cache-about-ttl=15 - -# Minutes to cache snapshots. Value is an integer number of minutes. -# Default is 5. -cache-snapshot-ttl=5 - -# Expose the ls_cache page, which lists cache paths and the urls other -# visitors requested. Values are 0 or 1. Default is 0. -enable-cache-list=0 - - -## -## Site appearance -## - -# Heading text on the repository index page. Value is any text. -# Default is Git repository browser. -#root-title=Git repository browser - -# Subheading text below the index page heading. Value is any text. -# Default is a fast webinterface for the git dscm. -#root-desc=a fast webinterface for the git dscm - -# File included verbatim below the about link on the index page. Value is a -# filesystem path. Default is none. -#root-readme=/var/www/htdocs/about.html - -# Default value or values for repo.readme. The first existing file wins. Value -# is one or more [ref]path entries. Default is none. -#readme=:README.md - -# CSS document urls added to the head of every page. Value is one or more urls. -# Default is /cgit.css. -#css=/cgit.css - -# JavaScript document urls included on every page. An empty value disables it. -# Value is one or more urls. Default is /cgit.js. -#js=/cgit.js - -# Shortcut icon url for all pages. Value is a url. Default is /favicon.ico. -#favicon=/favicon.ico - -# Image url used as the logo on all pages. Value is a url. Default is /cgit.png. -#logo=/cgit.png - -# Url loaded when clicking the logo. Value is a url. Default is the index url. -#logo-link=/ - -# File included verbatim at the top of all pages. Value is a filesystem path. -# Default is none. -#header=/var/www/htdocs/cgit-header.html - -# File included verbatim at the bottom of all pages, replacing the generated-by -# line. Value is a filesystem path. Default is none. -#footer=/var/www/htdocs/cgit-footer.html - -# File included verbatim in the HTML head of all pages. Value is a filesystem -# path. Default is none. -#head-include=/var/www/htdocs/cgit-head.html - -# Content of the robots meta tag. Value is robots meta content. -# Default is index, nofollow. -robots=index, nofollow - -# Omit the standard page header when set. Values are 0 or 1. Default is 0. -noheader=0 - -# Generate an HTML fragment suitable for embedding in other pages. Values are -# 0 or 1. Default is 0. -embedded=0 - -# Root url for all cgit links, enabling virtual urls. Value is a url path. -# Default is none. -#virtual-root=/ - -# Link format string for submodules in directory listings. Value is a printf -# format string taking path and sha1. Default is none. -#module-link=/%s/commit/?id=%s - - -## -## Repository discovery -## - -# Directory scanned for git repositories at parse time. Value is a filesystem -# path that may use macros. Default is none. -#scan-path=/var/lib/git - -# When scanning, recurse into dot-directories. Must precede scan-path. -# Values are 0 or 1. Default is 0. -scan-hidden-path=0 - -# Derive default section names from N leading path elements. Must precede -# scan-path. Value is an integer that may be negative. Default is 0. -section-from-path=0 - -# Strip the .git suffix from scanned repo url and name. Must precede scan-path. -# Values are 0 or 1. Default is 0. -remove-suffix=0 - -# File listing subdirs of scan-path to load. Must precede scan-path. Value is a -# filesystem path that may use macros. Default is none. -#project-list=/var/lib/git/projects.list - -# Serve a repo only if this file exists inside it. Emulates gitweb EXPORT_OK. -# Must precede scan-path. Value is a filename. Default is none. -#strict-export=git-daemon-export-ok - -# Section heading that subsequently-defined repos inherit. Value is any section -# heading text. Default is none. -#section=main - -# Sort sections and repos within them by name rather than file order. Values -# are 0 or 1. Default is 0. -section-sort=0 - -# How repositories within a section are sorted. Values are name or age. -# Default is name. -repository-sort=name - -# Let scanned repos set cgit settings via git config using gitweb.* or cgit.* -# keys. Values are 0 or 1. Default is 0. -enable-git-config=0 - -# Include another config file before continuing to parse this one. Value is a -# filesystem path that may use macros. Default is none. -#include=/etc/cgitrc.d/extra - - -## -## Features -## - -# Provide a blame page for files and links to it. Values are 0 or 1. -# Default is 0. -enable-blame=0 - -# Print an ASCII-art commit history graph in the log page. Values are 0 or 1. -# Default is 0. -enable-commit-graph=0 - -# Allow following a file across renames in the log view. Values are 0 or 1. -# Default is 0. -enable-follow-links=0 - -# Add a help tab to the index page with a built-in guide to the interface. -# Values are 0 or 1. Default is 1. -enable-help=1 - -# Generate extra summary, commit and tree links per repo on the index. Values -# are 0 or 1. Default is 0. -enable-index-links=0 - -# Show the owner of each repo on the index page. Values are 0 or 1. -# Default is 1. -enable-index-owner=1 - -# Show the number of modified files per commit in the log. Values are 0 or 1. -# Default is 0. -enable-log-filecount=0 - -# Show added and removed line counts per commit in the log. Values are 0 or 1. -# Default is 0. -enable-log-linecount=0 - -# Display remote branches in summary and refs views. Values are 0 or 1. -# Default is 0. -enable-remote-branches=0 - -# Use the parent commit subject as link text for parent links. Values are -# 0 or 1. Default is 0. -enable-subject-links=0 - -# Allow /plain to serve HTML mimetypes instead of downgrading to text/plain. -# Values are 0 or 1. Default is 0. -enable-html-serving=0 - -# Generate line-number links for plaintext blobs in the tree view. Values are -# 0 or 1. Default is 1. -enable-tree-linenumbers=1 - -# List directories first, then files, in the tree view. Values are 0 or 1. -# Default is 0. -enable-tree-group-dirs=0 - -# Default maximum statistics period. Leaving this unset disables statistics. -# Values are week, month, quarter or year. Default is unset. -#max-stats=week - -# Enable the statistics page, with the repository overview, activity -# timeline, commit rhythm, language breakdown and commits per author. -# Values are 0 or 1. Default is 0. -enable-stats=0 - - -## -## Snapshots and cloning -## - -# Default set of snapshot archive formats to offer. Value is a space list of -# tar tar.gz tar.bz2 tar.lz tar.xz tar.zst zip, or the word all. -# Default is none. -#snapshots=tar.gz tar.xz zip - -# Act as a dumb HTTP endpoint for git clones. Values are 0 or 1. Default is 1. -enable-http-clone=1 - -# Prefixes combined with the repo url to build clone urls. Used only when -# repo.clone-url is unset. Value is space-separated url prefixes. -# Default is none. -#clone-prefix=https://example.com/git git://example.com - -# Clone-url templates used when repo.clone-url is unset. Value is -# space-separated url templates that may use macros. Default is none. -#clone-url=https://example.com/$CGIT_REPO_URL git://example.com/$CGIT_REPO_URL - - -## -## Filters -## -# -# A filter is an external command cgit runs to transform a piece of content. -# Prefix the command with lua: to run it through the built-in Lua interpreter, -# which avoids a fork per call, or with exec: to run a normal program. The -# commands below that point at /usr/share/cgit/extensions/ use scripts this -# repository ships under extensions/. The ones written as /path/to/your-command -# mark where your own command goes. - -# Allow filter settings to be overridden in per-repo cgitrc files. Values are -# 0 or 1. Default is 0. -enable-filter-overrides=0 - -# Filter command used to format about-page content. The bundled about-render.lua -# renders markdown, man pages and plain text. Value is a command optionally -# prefixed with exec or lua. Default is none. -#about-filter=lua:/usr/share/cgit/extensions/about-render.lua - -# Filter command used to format commit messages, for example to turn object -# names and issue numbers into links. Value is a command optionally prefixed -# with exec or lua. Default is none. -#commit-filter=lua:/usr/share/cgit/extensions/link-commits.lua - -# Filter command used to format author and committer emails, for example to -# add avatar images. Value is a command optionally prefixed with exec or lua. -# Default is none. -#email-filter=lua:/usr/share/cgit/extensions/email-gravatar.lua - -# Filter command used to format plaintext blobs in the tree view. Without it -# cgit serves the text plain. For syntax highlighting, the shipped filter -# below uses the Scintillua lexers and needs the lpeg module installed too, -# on Debian that is "apt install lua-lpeg". Missing either dependency means -# plain uncolored text, not an error. See the comments in that file. Value -# is a command optionally prefixed with exec or lua. Default is none. -#source-filter=lua:/usr/share/cgit/extensions/syntax-highlight.lua - -# Filter command invoked to authenticate access, gating repositories behind a -# login. See extensions/auth-inline.lua and extensions/auth-file.lua. Value -# is a command optionally prefixed with exec or lua. Default is none. -#auth-filter=lua:/usr/share/cgit/extensions/auth-inline.lua - - -## -## Limits and safety -## - -# Number of items to display in atom feeds. Value is an integer. Default is 10. -max-atom-items=10 - -# Max commit message characters shown in the log view. Value is an integer. -# Default is 80. -max-message-length=80 - -# Max repo description characters shown on the index page. Value is an integer. -# Default is 80. -max-repodesc-length=80 - -# Max blob size in KBytes read into memory for html, plain and blob output. -# A value of 0 disables the limit. Value is an integer. Default is 10240. -max-blob-size=10240 - -# Number of repos listed per page on the index. A value of 0 or negative shows -# all repos. Value is an integer. Default is 50. -max-repo-count=50 - -# Number of log entries listed per page in the log view. Value is an integer. -# Default is 50. -max-commit-count=50 - -# Maximum number of commits the patch view emits as a series for an explicit -# revision range. A single commit is unaffected. A value of 0 removes the -# limit. Value is an integer. Default is 50. -max-patch-count=50 - -# Commits changing more files than this render as a diffstat, where each file -# links to its own diff page. A value of 0 always renders everything inline. -# Value is an integer. Default is 200. -max-diff-files=200 - -# A file whose diff spans more lines than this is replaced by a link to its -# own diff page in whole-commit views. A value of 0 always renders it inline. -# Value is an integer. Default is 1000. -max-diff-lines=1000 - -# Branches and tags listed per section on the refs page, and per page on the -# dedicated branch and tag pages. A value of 0 lists everything on one page. -# Value is an integer. Default is 200. -max-ref-count=200 - -# Max files considered when detecting renames. A value of -1 uses the git -# compile-time value. Value is an integer. Default is -1. -renamelimit=-1 - - -## -## Presentation -## - -# Number of log entries shown in the summary view. Value is an integer. -# Default is 10. -summary-log=10 - -# Number of branches shown in the summary view. Value is an integer. -# Default is 10. -summary-branches=10 - -# Number of tags shown in the summary view. Value is an integer. Default is 10. -summary-tags=10 - -# Show side-by-side diffs instead of unidiffs by default. Values are 0 or 1. -# Default is 0. -side-by-side-diffs=0 - -# Print commit and tag times in the server timezone. Values are 0 or 1. -# Default is 0. -local-time=0 - -# Ordering of commits in the log view. Leaving this unset uses the git log -# default. Values are date or topo. Default is unset. -#commit-sort=date - -# Ordering of the branch ref list. Values are name or age. Default is name. -branch-sort=name - -# Sort items in the repo list case-sensitively. Values are 0 or 1. Default is 1. -case-sensitive-sort=1 - -# Hide full author email addresses when set. Values are 0 or 1. Default is 0. -noplainemail=0 - -# File giving the timestamp of the youngest commit. Value is a path relative to -# the repo. Default is info/web/last-modified. -#agefile=info/web/last-modified - -# Fallback mimetype lookup file for plain output. Value is a filesystem path. -# Default is none. -#mimetype-file=/etc/mime.types - -# Mimetype for a given filename extension, used by plain output. Value is a -# mimetype string keyed by extension. Default is none. -#mimetype.gif=image/gif -#mimetype.html=text/html -#mimetype.jpg=image/jpeg -#mimetype.pdf=application/pdf -#mimetype.png=image/png -#mimetype.svg=image/svg+xml - - -## -## Per-repository overrides -## -# -# Each repository is introduced by a repo.url line, which must be the first -# setting of the block. All following repo.* settings apply to that repo until -# the next repo.url line. When repos are discovered via scan-path the repo. -# prefix is dropped inside each repo cgitrc and repo.url and repo.path are not -# allowed there. - -# Relative url for a repo. Must be the first setting of each repo block. Value -# is a relative url path. Default is none. -#repo.url=example - -# Absolute path to the repository. For a non-bare repo this is the .git dir. -# Value is an absolute filesystem path. Default is none. -#repo.path=/var/lib/git/example.git - -# Display name of the repository. Value is any text. Default is the repo url. -#repo.name=example - -# Repository description. Value is any text. Default is none. -#repo.desc=An example repository - -# Repository owner identifier. Value is any text. Default is none. -#repo.owner=Jane Doe - -# Repository homepage value. Value is a url or text. Default is none. -#repo.homepage=https://example.com/ - -# Urls used to clone this repo. Value is space-separated urls that may use -# macros. Default is none. -#repo.clone-url=https://example.com/example.git git://example.com/example.git - -# Default branch for the repo. Falls back to the first sorted branch. Value is -# a branch name. Default is the HEAD branch, or master. -#repo.defbranch=master - -# Override the current section name for this repo. Value is a section name. -# Default is none. -#repo.section=main - -# Prefix for snapshot filenames instead of the repo basename. Value is a prefix -# string. Default is none. -#repo.snapshot-prefix=example - -# Extra content added verbatim to the head of each page for this repo. Value is -# an HTML fragment. Default is none. -#repo.extra-head-content= - -# File included verbatim as the repo About page. A colon-prefixed value uses -# the head or defbranch. Value is a [ref]path entry. Default is the global -# readme value. -#repo.readme=:README.md - -# Per-repo logo image url. Value is a url. Default is the global logo value. -#repo.logo=/cgit.png - -# Per-repo logo link target url. Value is a url. Default is the global -# logo-link value. -#repo.logo-link=/ - -# Per-repo submodule link format string. Value is a printf format string taking -# path and sha1. Default is the global module-link value. -#repo.module-link=/%s/commit/?id=%s - -# Submodule link format for a specific submodule path. Value is a printf format -# string taking sha1. Default is none. -#repo.module-link.path/to/sub=https://example.com/sub/commit/?id=%s - -# Snapshot formats offered for this repo, restricted by the global mask. A -# value of 0 disables snapshots. Value is snapshot formats. Default is the -# global snapshots value. -#repo.snapshots=tar.gz zip - -# Hide the repo from the index but still allow direct access. Values are -# 0 or 1. Default is 0. -#repo.hide=0 - -# Ignore the repo entirely so it is not indexed and not directly accessible. -# Values are 0 or 1. Default is 0. -#repo.ignore=0 - -# Per-repo override of enable-blame. Values are 0 or 1. Default is the global -# enable-blame value. -#repo.enable-blame=0 - -# Per-repo override of enable-commit-graph. Values are 0 or 1. Default is the -# global enable-commit-graph value. -#repo.enable-commit-graph=0 - -# Per-repo override of enable-follow-links. Values are 0 or 1. Default is the -# global enable-follow-links value. -#repo.enable-follow-links=0 - -# Per-repo override of enable-log-filecount. Values are 0 or 1. Default is the -# global enable-log-filecount value. -#repo.enable-log-filecount=0 - -# Per-repo override of enable-log-linecount. Values are 0 or 1. Default is the -# global enable-log-linecount value. -#repo.enable-log-linecount=0 - -# Per-repo override of enable-remote-branches. Values are 0 or 1. Default is -# the global enable-remote-branches value. -#repo.enable-remote-branches=0 - -# Per-repo override of enable-subject-links. Values are 0 or 1. Default is the -# global enable-subject-links value. -#repo.enable-subject-links=0 - -# Per-repo override of enable-html-serving. Values are 0 or 1. Default is the -# global enable-html-serving value. -#repo.enable-html-serving=0 - -# Per-repo branch ref list ordering. Values are name or age. Default is name. -#repo.branch-sort=name - -# Per-repo commit log ordering. Leaving this unset uses the git log default. -# Values are date or topo. Default is unset. -#repo.commit-sort=date - -# Per-repo maximum statistics period. Values are week, month, quarter or year. -# Default is the global max-stats value. -#repo.max-stats=week - -# Per-repo override of the about-filter. Allowed in a repo cgitrc only when -# enable-filter-overrides is 1. Value is a command. Default is the global -# about-filter value. -#repo.about-filter=exec:/path/to/your-command - -# Per-repo override of the commit-filter. Allowed in a repo cgitrc only when -# enable-filter-overrides is 1. Value is a command. Default is the global -# commit-filter value. -#repo.commit-filter=lua:/usr/share/cgit/extensions/link-commits.lua - -# Per-repo override of the source-filter. Allowed in a repo cgitrc only when -# enable-filter-overrides is 1. Value is a command. Default is the global -# source-filter value. -#repo.source-filter=exec:/path/to/your-command - -# Per-repo override of the email-filter. Allowed in a repo cgitrc only when -# enable-filter-overrides is 1. Value is a command. Default is the global -# email-filter value. -#repo.email-filter=lua:/usr/share/cgit/extensions/email-gravatar.lua diff --git a/examples/hooks/post-receive.agefile b/examples/hooks/post-receive.agefile deleted file mode 100755 index 2f72ae9..0000000 --- a/examples/hooks/post-receive.agefile +++ /dev/null @@ -1,19 +0,0 @@ -#!/bin/sh -# -# An example hook to update the "agefile" for CGit's idle time calculation. -# -# This hook assumes that you are using the default agefile location of -# "info/web/last-modified". If you change the value in your cgitrc then you -# must also change it here. -# -# To install the hook, copy (or link) it to the file "hooks/post-receive" in -# each of your repositories. -# - -agefile="$(git rev-parse --git-dir)"/info/web/last-modified - -mkdir -p "$(dirname "$agefile")" && -git for-each-ref \ - --sort=-authordate --count=1 \ - --format='%(authordate:iso8601)' \ - >"$agefile" diff --git a/examples/hooks/post-update.update-server-info b/examples/hooks/post-update.update-server-info deleted file mode 100755 index d499ce5..0000000 --- a/examples/hooks/post-update.update-server-info +++ /dev/null @@ -1,18 +0,0 @@ -#!/bin/sh -# -# Example hook that keeps cgit's dumb HTTP clone data current. -# -# cgit can serve "git clone" over HTTP by itself using the dumb protocol, -# which is on by default through enable-http-clone. The dumb protocol -# reads a few static files that git refreshes only when you run -# "git update-server-info", so without this hook a fresh push can leave a -# clone unable to see the new refs and objects. -# -# You do not need this when you clone through git-http-backend (the smart -# protocol) or over ssh or git://. It matters only when cgit itself is the -# clone endpoint. -# -# To install it, copy or link this file to "hooks/post-update" in each -# repository and make sure it is executable. -# -exec git update-server-info diff --git a/examples/servers/apache.conf b/examples/servers/apache.conf deleted file mode 100644 index d042dd9..0000000 --- a/examples/servers/apache.conf +++ /dev/null @@ -1,152 +0,0 @@ -# Apache httpd 2.4 configuration for cgit. -# -# Apache runs the cgit.cgi binary directly through mod_cgid, so no FastCGI -# bridge is needed. Drop this file in your vhost directory, for example -# /etc/apache2/sites-available/cgit.conf on Debian and Ubuntu or -# /etc/httpd/conf.d/cgit.conf on RHEL and Fedora, then enable it and reload. -# -# Paths assumed below, edit them to match your install. -# cgit CGI binary /usr/lib/cgit/cgit.cgi -# static assets /usr/share/cgit (cgit.css cgit.js cgit.png favicon.ico robots.txt) -# cgit config /etc/cgitrc -# public URL https://git.example.org/ (cgit at the domain root) -# -# cgit is one CGI executable. It learns the repository and the page from -# PATH_INFO and reads page options such as h= and id= from QUERY_STRING. -# ScriptAlias runs the binary and forwards the trailing path as PATH_INFO, so -# no extra path tuning is needed. cgit builds its own link base from -# SCRIPT_NAME. The five static assets are served straight off disk. mod_alias -# resolves Alias and ScriptAlias in order and the first match wins, so the -# static Alias lines come before the catch-all ScriptAlias to stop the two -# routes from shadowing each other. - - -# --- Required modules ------------------------------------------------------- -# mod_cgid suits the threaded MPMs that ship by default. Use mod_cgi instead -# only on the old prefork MPM. mod_alias provides Alias and ScriptAlias and -# mod_env provides SetEnv. On Debian and Ubuntu run a2enmod cgid alias env -# rather than editing these lines. The guards make double-loading harmless. - - LoadModule cgid_module modules/mod_cgid.so - - - LoadModule alias_module modules/mod_alias.so - - - LoadModule env_module modules/mod_env.so - - - LoadModule headers_module modules/mod_headers.so - - - -# --- Plain HTTP virtual host ------------------------------------------------ -# This vhost only bounces plain HTTP up to HTTPS. It serves no cgit itself, -# every cgit directive lives in the HTTPS vhost below. To run without TLS for -# now, convert the HTTPS vhost to port 80 and delete this whole block rather -# than editing it, since deleting only the Redirect line would leave a vhost -# that serves nothing. - - ServerName git.example.org - - ErrorLog /var/log/apache2/cgit_error.log - CustomLog /var/log/apache2/cgit_access.log combined - - Redirect permanent / https://git.example.org/ - - - -# --- HTTPS virtual host, this one serves cgit ------------------------------- -# To run without TLS for now, change this opening line to , -# delete the three SSL lines, and delete the port 80 vhost above so there is -# only one vhost. Everything else stays the same. - - ServerName git.example.org - - ErrorLog /var/log/apache2/cgit_ssl_error.log - CustomLog /var/log/apache2/cgit_ssl_access.log combined - - # TLS needs mod_ssl (a2enmod ssl). Point these at your certificate. - SSLEngine on - SSLCertificateFile /etc/ssl/certs/git.example.org.crt - SSLCertificateKeyFile /etc/ssl/private/git.example.org.key - - # Which config cgit reads. It falls back to the compiled-in /etc/cgitrc, - # the same path used here, but setting it makes the location explicit and - # lets you point at a per-vhost file later. - SetEnv CGIT_CONFIG /etc/cgitrc - - # --- Security headers (needs mod_headers, a2enmod headers) -------------- - # Set here, not in cgit, so they also cover the static assets Apache - # serves. script-src stays self because cgit loads only its own cgit.js, - # and style-src allows inline for the diffstat bars. If you enable the - # gravatar or libravatar avatar filter, add its host to img-src, for - # example https://www.gravatar.com. - Header always set Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'" - Header always set X-Content-Type-Options "nosniff" - Header always set Referrer-Policy "no-referrer" - # Enable only once you serve HTTPS exclusively, since it is hard to undo. - #Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains" - - # --- Static assets, served directly by Apache --------------------------- - # These five files are the only things served off disk. Each Alias maps - # one URL to one file. Because they come before the ScriptAlias below, a - # request for /cgit.css is answered from disk and never reaches cgit. - # cgit.css and cgit.js are the paths cgit's HTML points at by default, so - # if you relocate the assets update both these Alias targets and the css, - # js, logo and favicon settings in cgitrc to agree. - Alias /cgit.css /usr/share/cgit/cgit.css - Alias /cgit.js /usr/share/cgit/cgit.js - Alias /cgit.png /usr/share/cgit/cgit.png - Alias /favicon.ico /usr/share/cgit/favicon.ico - Alias /robots.txt /usr/share/cgit/robots.txt - - # Apache 2.4 denies filesystem access by default, so open the asset - # directory for reading. - - Options None - AllowOverride None - Require all granted - - # Optional. These assets rarely change, so let browsers cache them. - # Needs mod_expires (a2enmod expires). Safe to delete this block. - - ExpiresActive On - ExpiresDefault "access plus 30 days" - - - - # --- cgit, the catch-all ------------------------------------------------ - # ScriptAlias maps a URL prefix to a path, marks it executable, and - # forwards the rest of the URL as PATH_INFO. Mapping / makes cgit the - # handler for every URL the static Aliases above did not already claim. - # - # The trailing slash on cgit.cgi/ is load bearing. It tells Apache that - # cgit.cgi is the program and the rest of the URL is PATH_INFO. So a - # request for /torvalds/linux/tree/kernel?h=next runs the binary with - # PATH_INFO set to /torvalds/linux/tree/kernel and QUERY_STRING set to - # h=next. cgit derives its link base from SCRIPT_NAME, which at the domain - # root is / and needs no tuning. For a sub-path install see the note below. - ScriptAlias / /usr/lib/cgit/cgit.cgi/ - - - # Allow CGI execution here. ScriptAlias implies it, stating it makes - # the intent clear. - Options +ExecCGI - # Run cgit.cgi as a CGI even if it is ever reached through a plain - # Alias rather than ScriptAlias. - SetHandler cgi-script - AllowOverride None - Require all granted - - - - -# --- Sub-path install, only if cgit is not at the domain root --------------- -# To serve cgit at https://git.example.org/cgit/ instead of the root, change -# the ScriptAlias to -# ScriptAlias /cgit/ /usr/lib/cgit/cgit.cgi/ -# and move the static assets under the same prefix, for example -# Alias /cgit/cgit.css /usr/share/cgit/cgit.css -# SCRIPT_NAME then becomes /cgit and cgit auto-detects it. If links come out -# wrong, pin the base in cgitrc with virtual-root=/cgit. diff --git a/examples/servers/lighttpd.conf b/examples/servers/lighttpd.conf deleted file mode 100644 index 3111ed0..0000000 --- a/examples/servers/lighttpd.conf +++ /dev/null @@ -1,132 +0,0 @@ -# lighttpd configuration for cgit. -# -# lighttpd runs the cgit.cgi binary directly through mod_cgi, so no FastCGI -# bridge is needed. This is cgit's classic reference deployment, mod_cgi with -# mod_alias and mod_setenv. -# -# Paths assumed below, edit them to match your install. -# cgit CGI binary /usr/lib/cgit/cgit.cgi -# static assets /usr/share/cgit (cgit.css cgit.js cgit.png favicon.ico robots.txt) -# cgit config /etc/cgitrc -# public URL https://git.example.org/ (cgit at the domain root) -# -# cgit is one CGI executable. It learns the repository and the page from -# PATH_INFO and reads page options such as h= and id= from QUERY_STRING. cgit -# builds its own link base from SCRIPT_NAME. The five static assets are served -# straight off disk and must never be routed through cgit. - - -# --- Modules ---------------------------------------------------------------- -# Append the three modules cgit needs so the distro's base config is kept. -# mod_alias maps URL paths onto files, mod_setenv injects CGIT_CONFIG, and -# mod_cgi runs cgit.cgi. -server.modules += ( "mod_alias", "mod_setenv", "mod_cgi" ) - - -# --- Server basics ---------------------------------------------------------- -server.port = 80 -server.username = "http" # Debian and Ubuntu use www-data -server.groupname = "http" -server.document-root = "/usr/share/cgit" # a valid docroot must exist, the - # alias rules below do the routing -server.errorlog = "/var/log/lighttpd/error.log" -# Access logging needs mod_accesslog. Load it and uncomment to enable. -#server.modules += ( "mod_accesslog" ) -#accesslog.filename = "/var/log/lighttpd/access.log" - - -# --- MIME types for the static assets --------------------------------------- -# mod_alias serves the assets off disk, so lighttpd must know their content -# types. Without this the stylesheet is sent as application/octet-stream and -# the browser ignores it. -mimetype.assign = ( - ".css" => "text/css", - ".js" => "text/javascript", - ".png" => "image/png", - ".ico" => "image/vnd.microsoft.icon", - ".txt" => "text/plain", -) - - -# --- Virtual host, git.example.org ------------------------------------------ -# A top-level conditional, so it matches on both the port 80 socket and the -# optional TLS socket at the end of this file. -$HTTP["host"] == "git.example.org" { - - # Which config cgit reads. It falls back to the compiled-in /etc/cgitrc, - # the same path used here, but setting it makes the location explicit. - setenv.add-environment = ( "CGIT_CONFIG" => "/etc/cgitrc" ) - - # --- Security headers --------------------------------------------------- - # Set here, not in cgit, so they also cover the static assets lighttpd - # serves. script-src stays self because cgit loads only its own cgit.js, - # and style-src allows inline for the diffstat bars. If you enable the - # gravatar or libravatar avatar filter, add its host to img-src. - setenv.add-response-header = ( - "Content-Security-Policy" => "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'", - "X-Content-Type-Options" => "nosniff", - "Referrer-Policy" => "no-referrer" - ) - # Enable only once you serve HTTPS exclusively, since it is hard to undo. - #setenv.add-response-header += ( "Strict-Transport-Security" => "max-age=63072000; includeSubDomains" ) - - # Register the cgit binary as a CGI program. The key cgit.cgi matches the - # binary's name and the empty value means the file is itself the program, - # with no interpreter in front of it. This is what makes lighttpd split - # the trailing path off as PATH_INFO, so never drop it. - cgi.assign = ( "cgit.cgi" => "" ) - - # Routing. lighttpd's alias.url is first-match in declaration order, not - # longest prefix, so the five static entries must come before the / entry. - # If / came first it would swallow every request and recent lighttpd - # refuses to start. The static entries are served off disk and the / entry - # hands everything else to cgit. - # - # The trailing slash on cgit.cgi/ is load bearing. lighttpd builds the - # physical path by stripping the matched key off the front of the URL and - # appending the rest to the value. For the key / the remainder carries no - # leading slash, so without the trailing slash a request for - # /linux/tree/kernel/sched.c glues onto the binary name as - # /usr/lib/cgit/cgit.cgilinux/tree/... and 404s. The trailing slash - # restores the separator, giving cgit SCRIPT_FILENAME /usr/lib/cgit/cgit.cgi - # and PATH_INFO /linux/tree/kernel/sched.c. - alias.url = ( - "/cgit.css" => "/usr/share/cgit/cgit.css", - "/cgit.js" => "/usr/share/cgit/cgit.js", - "/cgit.png" => "/usr/share/cgit/cgit.png", - "/favicon.ico" => "/usr/share/cgit/favicon.ico", - "/robots.txt" => "/usr/share/cgit/robots.txt", - "/" => "/usr/lib/cgit/cgit.cgi/", - ) - - # Served at / the SCRIPT_NAME is empty and cgit derives its link base - # correctly. For a sub-path install use a key without a trailing slash - # mapped to the binary without a trailing slash, for example - # "/git" => "/usr/lib/cgit/cgit.cgi" - # so /git/linux/tree resolves to /usr/lib/cgit/cgit.cgi/linux/tree, giving - # SCRIPT_NAME /git and PATH_INFO /linux/tree. cgit auto-detects the prefix. - # If links come out wrong, pin it in cgitrc with virtual-root=/git. -} - - -# --- Optional HTTPS on 443 -------------------------------------------------- -# Uncomment this whole block to enable TLS. The host block above is socket -# independent, so it serves cgit over this socket too once the crypto is set. -#server.modules += ( "mod_openssl" ) -# -#$SERVER["socket"] == ":443" { -# ssl.engine = "enable" -# ssl.pemfile = "/etc/lighttpd/certs/git.example.org.crt" -# ssl.privkey = "/etc/lighttpd/certs/git.example.org.key" -# ssl.ca-file = "/etc/lighttpd/certs/git.example.org.chain.pem" -# ssl.openssl.ssl-conf-cmd = ( "MinProtocol" => "TLSv1.2" ) -#} -# -# Redirect plain HTTP to HTTPS, scoped to the port 80 socket. Needs -# mod_redirect. -#server.modules += ( "mod_redirect" ) -#$SERVER["socket"] == ":80" { -# $HTTP["host"] == "git.example.org" { -# url.redirect = ( "^/(.*)" => "https://git.example.org/$1" ) -# } -#} diff --git a/examples/servers/nginx.conf b/examples/servers/nginx.conf deleted file mode 100644 index 76ac260..0000000 --- a/examples/servers/nginx.conf +++ /dev/null @@ -1,193 +0,0 @@ -# nginx configuration for cgit. -# -# nginx cannot run CGI programs itself, so a small bridge called fcgiwrap -# runs the cgit.cgi binary and speaks FastCGI to nginx. Starting fcgiwrap is -# covered in the notes at the end of this file. -# -# Paths assumed below, edit them to match your install. -# cgit CGI binary /usr/lib/cgit/cgit.cgi -# static assets /usr/share/cgit (cgit.css cgit.js cgit.png favicon.ico robots.txt) -# cgit config /etc/cgitrc -# public URL https://git.example.org/ (cgit at the domain root) -# -# cgit is one CGI executable. It learns the repository and the page from -# PATH_INFO and reads page options such as h= and id= from QUERY_STRING, so -# nginx must pass PATH_INFO through to the binary. cgit builds its own link -# base from SCRIPT_NAME. The five static assets are served straight off disk -# and must never be routed through cgit. Passing PATH_INFO through is the -# single most important part of the config below. - - -# --- Optional HTTP to HTTPS redirect ---------------------------------------- -# Delete this whole server block if you serve plain HTTP only. -server { - listen 80; - listen [::]:80; - server_name git.example.org; - - # ACME http-01 challenge files, if you use certbot in webroot mode. - location ^~ /.well-known/acme-challenge/ { - root /var/www/html; - } - - # Everything else moves to HTTPS. - location / { - return 301 https://$host$request_uri; - } -} - - -# --- Main site -------------------------------------------------------------- -# Written for TLS on 443. For a quick plain-HTTP test, change the two listen -# lines to port 80, delete the redirect block above, and delete the four ssl -# lines below. Everything else stays the same. -server { - listen 443 ssl; - listen [::]:443 ssl; - http2 on; - server_name git.example.org; - - ssl_certificate /etc/letsencrypt/live/git.example.org/fullchain.pem; - ssl_certificate_key /etc/letsencrypt/live/git.example.org/privkey.pem; - ssl_protocols TLSv1.2 TLSv1.3; - ssl_ciphers HIGH:!aNULL:!MD5; - - # --- Security headers --------------------------------------------------- - # These sit here, not in cgit, because they must also cover the static - # assets nginx serves directly. cgit loads only its own /cgit.js and uses - # inline style on the diffstat bars, so script-src stays self while - # style-src allows inline. always applies them to error responses too. If - # you enable the gravatar or libravatar avatar filter, add its host to - # img-src, for example https://www.gravatar.com or https://seccdn.libravatar.org. - add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'" always; - add_header X-Content-Type-Options "nosniff" always; - add_header Referrer-Policy "no-referrer" always; - # Enable only once you serve HTTPS exclusively, since it is hard to undo. - #add_header Strict-Transport-Security "max-age=63072000; includeSubDomains" always; - - # The document root is the directory that holds the static assets. cgit - # emits absolute links to /cgit.css and /cgit.png by default, so those - # files must resolve at the root of the URL space. Pointing root at the - # asset directory makes /cgit.css map to /usr/share/cgit/cgit.css. - root /usr/share/cgit; - - # Upload cap for large form posts. Snapshots are generated rather than - # uploaded, so this does not limit them. - client_max_body_size 64m; - - access_log /var/log/nginx/cgit.access.log; - error_log /var/log/nginx/cgit.error.log; - - # --- Static assets, served directly ------------------------------------- - # Match the assets by their exact root-level names, never by bare - # extension. cgit routes on PATH_INFO and a repository can hold files - # ending in .css or .png, so /myrepo/tree/style.css and /myrepo/plain/ - # logo.png are real cgit URLs. A broad extension match would capture - # those, look for them on disk, and return 404 before cgit could render - # them. Anchoring the regex at the start of the path matches /cgit.css but - # not /myrepo/tree/cgit.css, so it can never shadow a repository file. An - # nginx regex location is matched before the prefix location below, so - # these assets win for their exact URLs and cgit wins for the rest. - location ~ ^/(cgit\.css|cgit\.js|cgit\.png|favicon\.ico|robots\.txt)$ { - expires 30d; - access_log off; - try_files $uri =404; - } - - # --- cgit, the catch-all ------------------------------------------------ - # Everything that is not a static asset above is a cgit URL, the repo - # index, a repository, a page within a repository, a snapshot, a feed. - location / { - # nginx's standard FastCGI parameters, some of which are overridden - # below. A later fastcgi_param wins, so include order does not matter. - include fastcgi_params; - - # The program fcgiwrap runs. It must be the cgit binary itself, not - # $document_root$fastcgi_script_name, which would try to run a repo - # path and is the usual cause of a failed request. - fastcgi_param SCRIPT_FILENAME /usr/lib/cgit/cgit.cgi; - - # cgit builds its link base, the virtual root, from SCRIPT_NAME. The - # stock parameters set SCRIPT_NAME to the whole request path, which - # would make cgit prepend that path to every link. Served at the - # domain root the script has no prefix, so force SCRIPT_NAME empty and - # cgit uses / as its base. A sub-path install sets it instead, see the - # end of this file. - fastcgi_param SCRIPT_NAME ""; - - # How cgit learns the repository and page. At the domain root the - # whole request path is the PATH_INFO. - fastcgi_param PATH_INFO $uri; - - # Page options such as h=branch, id=sha and the snapshot format. - fastcgi_param QUERY_STRING $query_string; - - # Where the static assets live, kept consistent with root above. - fastcgi_param DOCUMENT_ROOT $document_root; - - # The browser's Host header, so cgit builds clone URLs against the - # name the visitor used rather than server_name. - fastcgi_param HTTP_HOST $http_host; - - # Which config cgit reads. It checks CGIT_CONFIG and falls back to the - # compiled-in /etc/cgitrc. Setting it makes the location explicit and - # lets you move cgitrc without recompiling. - fastcgi_param CGIT_CONFIG /etc/cgitrc; - - # The real scheme, so cgit builds correct https clone URLs. - fastcgi_param HTTPS $https if_not_empty; - - # Hand off to the fcgiwrap socket. See the notes for how to create it. - # A TCP fcgiwrap would use for example 127.0.0.1:9000 here. - fastcgi_pass unix:/run/fcgiwrap.socket; - - # Large outputs such as snapshot tarballs and blame on big files can - # take a while, so give cgit room and stream rather than buffer. - fastcgi_read_timeout 300s; - fastcgi_buffering off; - } -} - - -# --- Notes, starting fcgiwrap ----------------------------------------------- -# cgit is a CGI binary and fcgiwrap is the CGI to FastCGI bridge nginx talks -# to. On Debian and Ubuntu the packaged systemd socket provides -# /run/fcgiwrap.socket, so enabling it is enough. -# apt install fcgiwrap -# systemctl enable --now fcgiwrap.socket -# The socket must be readable by nginx's user. The packaged unit runs fcgiwrap -# as www-data, which nginx also uses on those systems. Without systemd you can -# run -# spawn-fcgi -s /run/fcgiwrap.socket -M 660 -- /usr/sbin/fcgiwrap -# or run fcgiwrap over TCP and point fastcgi_pass at 127.0.0.1:9000. - - -# --- Alternative, serving cgit under a sub-path ----------------------------- -# To serve cgit at https://git.example.org/cgit/ instead of the root, split -# the URL so SCRIPT_NAME is the prefix and PATH_INFO is the rest. -# -# location /cgit/ { -# include fastcgi_params; -# fastcgi_split_path_info ^(/cgit)(/.*)$; -# fastcgi_param SCRIPT_FILENAME /usr/lib/cgit/cgit.cgi; -# fastcgi_param SCRIPT_NAME $fastcgi_script_name; -# fastcgi_param PATH_INFO $fastcgi_path_info; -# fastcgi_param QUERY_STRING $query_string; -# fastcgi_param HTTP_HOST $http_host; -# fastcgi_param CGIT_CONFIG /etc/cgitrc; -# fastcgi_param HTTPS $https if_not_empty; -# fastcgi_pass unix:/run/fcgiwrap.socket; -# } -# -# Serve the assets from the sub-path too, again anchored to the exact names. -# -# location ~ ^/cgit/(cgit\.css|cgit\.js|cgit\.png|favicon\.ico|robots\.txt)$ { -# alias /usr/share/cgit/$1; -# expires 30d; -# access_log off; -# } -# -# cgit's default css=/cgit.css and logo=/cgit.png point at the domain root, so -# under a sub-path also set css=/cgit/cgit.css and logo=/cgit/cgit.png in -# cgitrc. cgit derives the /cgit prefix from SCRIPT_NAME. If links come out -# wrong, pin it in cgitrc with virtual-root=/cgit/. -- cgit v2.8.0