blob: 833c1703078b58d0cb874a3867ebd7e302f9eea2 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
/*
 * The dumb HTTP transport, which lets a client clone by fetching plain files
 * rather than by talking to a server side helper. It answers the requests
 * such a client makes, the ref listing under info, the loose objects and pack
 * files under objects, and HEAD, each written as raw bytes rather than as a
 * page. The two listings a clone starts from are built per request, so a
 * repository serves without anyone having run git update-server-info over it.
 */

#define USE_THE_REPOSITORY_VARIABLE

#include "cgit.h"
#include "html.h"
#include "ui-clone.h"
#include "ui-shared.h"

/*
 * A client reading this listing expects an annotated tag to be followed by a
 * second line, marked with ^{}, naming the object the tag peels to, the
 * format git update-server-info writes into info/refs.
 */
static int print_ref(const struct reference *ref, void *cb_data)
{
	struct object *obj;

	obj = parse_object(the_repository, ref->oid);
	if (!obj)
		return 0;

	htmlf("%s\t%s\n", oid_to_hex(ref->oid), ref->name);
	if (obj->type == OBJ_TAG) {
		obj = deref_tag(the_repository, obj, ref->name, 0);
		if (!obj)
			return 0;
		htmlf("%s\t%s^{}\n", oid_to_hex(&obj->oid), ref->name);
	}
	return 0;
}

/*
 * A path ending in a slash is handed back whole, where git's own
 * pack_basename would return the empty string.
 */
static const char *last_path_component(const char *path)
{
	const char *slash = strrchr(path, '/');

	if (slash && slash[1] != '\0')
		return slash + 1;
	return path;
}

/*
 * Only the packs this repository holds itself are listed, because one
 * borrowed from an alternate is not reachable below this URL and a client
 * told about it would come back for a file that is not there.
 */
static void print_pack_info(void)
{
	struct odb_source *source;

	ctx.page.mimetype = "text/plain";
	ctx.page.filename = "objects/info/packs";
	cgit_print_http_headers();
	odb_reprepare(the_repository->objects);
	for (source = the_repository->objects->sources; source; source = source->next) {
		struct odb_source_files *files = odb_source_files_downcast(source);
		struct packfile_list_entry *entry;
		// Asked for through the accessor rather than read off the list,
		// because a pack the multi-pack-index already covers joins that
		// list only when the accessor loads it, and reading the field
		// directly leaves those packs unfindable.
		for (entry = packfile_store_get_packs(files->packed); entry; entry = entry->next) {
			struct packed_git *pack = entry->pack;

			if (pack->pack_local)
				htmlf("P %s\n", last_path_component(pack->pack_name));
		}
	}
}

/*
 * Only the characters an object path can hold pass, and no dotdot component.
 */
static int path_is_safe(const char *path)
{
	const char *p;

	for (p = path; *p; ++p) {
		if (*p == '.' && *(p + 1) == '.')
			return 0;
		if (!isalnum((unsigned char)*p) && *p != '/' && *p != '.' && *p != '-')
			return 0;
	}
	return 1;
}

/*
 * The file is read in batches the size of the output buffer, so each one
 * goes to the client in a single write, and its size is sent ahead so the
 * client can tell a cut-off transfer from a complete one.
 */
static void send_file(const char *path)
{
	static char buf[HTML_BATCH];
	struct stat st;
	ssize_t got;
	int fd;

	fd = open(path, O_RDONLY);
	if (fd < 0) {
		switch (errno) {
		case ENOENT:
			cgit_print_error_page(404, "Not Found", "Not found");
			break;
		case EACCES:
			cgit_print_error_page(403, "Forbidden", "Forbidden");
			break;
		default:
			cgit_print_error_page(400, "Bad Request", "Bad request");
		}
		return;
	}
	// open succeeds on a directory on most systems and reads nothing from
	// it.
	if (fstat(fd, &st) || !S_ISREG(st.st_mode)) {
		close(fd);
		cgit_print_error_page(404, "Not Found", "Not found");
		return;
	}
	ctx.page.mimetype = "application/octet-stream";
	// Offer the file under its path inside the repository, so the layout
	// of the server's disk stays out of the download name.
	ctx.page.filename = path;
	skip_prefix(path, ctx.repo->path, &ctx.page.filename);
	skip_prefix(ctx.page.filename, "/", &ctx.page.filename);
	ctx.page.size = st.st_size;
	cgit_print_http_headers();
	while ((got = xread(fd, buf, sizeof(buf))) > 0)
		html_raw(buf, got);
	close(fd);
}

void cgit_clone_info(void)
{
	if (!ctx.qry.path || strcmp(ctx.qry.path, "refs")) {
		cgit_print_error_page(400, "Bad Request", "Bad request");
		return;
	}

	ctx.page.mimetype = "text/plain";
	ctx.page.filename = "info/refs";
	cgit_print_http_headers();
	refs_for_each_ref(get_main_ref_store(the_repository), print_ref, NULL);
}

void cgit_clone_objects(void)
{
	char *path;

	if (!ctx.qry.path)
		goto err;

	if (!strcmp(ctx.qry.path, "info/packs")) {
		print_pack_info();
		return;
	}

	if (!path_is_safe(ctx.qry.path))
		goto err;

	path = repo_git_path(the_repository, "objects/%s", ctx.qry.path);
	send_file(path);
	free(path);
	return;

err:
	cgit_print_error_page(400, "Bad Request", "Bad request");
}

void cgit_clone_head(void)
{
	char *path;

	path = repo_git_path(the_repository, "HEAD");
	send_file(path);
	free(path);
}