Avoid SEGFAULT on invalid requests
When an unknown page is requested, either on the querystring or via PATH_INFO, we end up with a null-referencing cgit_cmd. This null- pointer is then used as argument to the hc() function (which decides what tab to render as 'active'), but this function failed to check if a valid cmd was specified and a SEGFAULT would occur. This patch fixes the issue by introducing a 'fallback-cmd' which specifies what tab to render as 'active' when no valid cmd is requested. While at it, we now also keep track of the active repository even if an invalid cmd was requested since we want to show the error message about the invalid request in the correct context. Noticed-by: Robin Redeker <elmex@ta-sa.org> Signed-off-by: Lars Hjemli <hjemli@gmail.com>
このコミットが含まれているのは:
コミット
eb14609dc4
1
cgit.c
1
cgit.c
@ -289,7 +289,6 @@ static void process_request(void *cbdata)
|
|||||||
cmd = cgit_get_cmd(ctx);
|
cmd = cgit_get_cmd(ctx);
|
||||||
if (!cmd) {
|
if (!cmd) {
|
||||||
ctx->page.title = "cgit error";
|
ctx->page.title = "cgit error";
|
||||||
ctx->repo = NULL;
|
|
||||||
cgit_print_http_headers(ctx);
|
cgit_print_http_headers(ctx);
|
||||||
cgit_print_docstart(ctx);
|
cgit_print_docstart(ctx);
|
||||||
cgit_print_pageheader(ctx);
|
cgit_print_pageheader(ctx);
|
||||||
|
@ -577,15 +577,20 @@ void add_hidden_formfields(int incl_head, int incl_search, char *page)
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const char *fallback_cmd = "repolist";
|
||||||
|
|
||||||
char *hc(struct cgit_cmd *cmd, const char *page)
|
char *hc(struct cgit_cmd *cmd, const char *page)
|
||||||
{
|
{
|
||||||
return (strcmp(cmd->name, page) ? NULL : "active");
|
return (strcmp(cmd ? cmd->name : fallback_cmd, page) ? NULL : "active");
|
||||||
}
|
}
|
||||||
|
|
||||||
void cgit_print_pageheader(struct cgit_context *ctx)
|
void cgit_print_pageheader(struct cgit_context *ctx)
|
||||||
{
|
{
|
||||||
struct cgit_cmd *cmd = cgit_get_cmd(ctx);
|
struct cgit_cmd *cmd = cgit_get_cmd(ctx);
|
||||||
|
|
||||||
|
if (!cmd && ctx->repo)
|
||||||
|
fallback_cmd = "summary";
|
||||||
|
|
||||||
html("<table id='header'>\n");
|
html("<table id='header'>\n");
|
||||||
html("<tr>\n");
|
html("<tr>\n");
|
||||||
html("<td class='logo' rowspan='2'><a href='");
|
html("<td class='logo' rowspan='2'><a href='");
|
||||||
|
読み込み中…
新しいイシューから参照
ユーザーをブロックする