cgit with patches for sandboxing using qssb
Go to file
Jason A. Donenfeld 989d251384 CGIT-0.9.2
Features:
- update to git v1.8.3.
- expanded set of default filters to include markdown, restructuredtext, and
  man pages.
- better sample configuration file in man page.
- "readme" may now be specified multiple times, and cgit will choose the first
  one it finds.
- "readme" no longer needs a branch name. If prefixed with simply ":" it will
  use the default branch.
- "branch-sort" allowing branches to be sorted either by "age" or "name", for
  kernel.org.
- "enable-index-owner" allowing the owner column to be disabled in the index
  page.
- print submodule revision next to submodule link.
- integrate more closely with git apis, such as strbuf.
- rely on git test harness and git makefiles.
- more robust test suite.
- more rebust makefile dependency accounting.
- pager navigation is now unordered list.
- span tag wraps commit directions.

Behavior changes:
- HOME is no longer passed as an environment variable to any filter api
  scripts.
- "about-filter" now receives the filename being filtered as argv[1]. This may
  disrupt existing scripts, so adjust accordingly.
- gitconfig and gitattributes are no longer loaded from any system directories
  or home directories.

Security:
- CVE-2013-2117: disallow directory traversal when readme is set to filesystem
  path.

Bug fixes:
- ssdiff now correctly manages tab expansion.
- support unannotated tags in http git clone.
- lots of cleanups of global variables and memory leaks.
- do not rely on gettext/libintl.
- better C standard compliance.
- make several functions and variables static.
- improved constification.
- remove unused functions.
- fix colspan values to correct width.
- fix out-of-bounds memory accesses with virtual_root="".
- cache repo config more precisely.
- die when write fails.

Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
2013-05-27 22:18:09 +02:00
filters filters: import more modern scripts 2013-05-27 21:54:16 +02:00
git@edca415256 git: update to 1.8.3 2013-05-25 13:10:14 +02:00
tests cache.c: cache ls_cache output properly 2013-05-22 12:53:06 +02:00
.gitignore tests/.gitignore: update for using Git's test infrastructure 2013-04-08 22:27:53 +02:00
.gitmodules Delete submodules.sh and prepare for using git-submodule 2007-09-03 22:54:51 +02:00
cache.c cache.c: cache ls_cache output properly 2013-05-22 12:53:06 +02:00
cache.h use __attribute__ to catch printf format mistakes 2010-09-04 11:11:40 -04:00
cgit-doc.css Add cgit-doc.css 2009-02-12 10:24:25 +01:00
cgit.c readme: use string_list instead of space deliminations 2013-05-26 16:30:03 +02:00
cgit.css filters: import more modern scripts 2013-05-27 21:54:16 +02:00
cgit.h readme: use string_list instead of space deliminations 2013-05-26 16:30:03 +02:00
cgit.mk cgit.mk: fix dependency handling 2013-04-08 15:43:17 +02:00
cgit.png Use transparent background for the cgit logo 2011-02-19 14:41:39 +01:00
cgitrc.5.txt cgitrc.5: improve example config 2013-05-27 21:54:16 +02:00
cmd.c readme: use string_list instead of space deliminations 2013-05-26 16:30:03 +02:00
cmd.h Add is_clone flag to available commands 2011-02-19 14:57:48 +01:00
configfile.c Mark several functions/variables static 2013-03-04 19:50:39 -05:00
configfile.h Move function for configfile parsing into configfile.[ch] 2008-03-28 00:09:11 +01:00
COPYING Add license file and copyright notices 2006-12-10 22:41:14 +01:00
gen-version.sh gen-version.sh: don't sed the output from git describe 2007-10-01 12:09:41 +02:00
html.c html.c: die when write fails 2013-05-22 12:53:06 +02:00
html.h html.c: add various strbuf and varadic helpers 2013-04-08 16:10:11 +02:00
Makefile CGIT-0.9.2 2013-05-27 22:18:09 +02:00
parsing.c Mark several functions/variables static 2013-03-04 19:50:39 -05:00
README README: add trailing slash to homepage 2013-05-27 21:56:57 +02:00
scan-tree.c readme: use string_list instead of space deliminations 2013-05-26 16:30:03 +02:00
scan-tree.h Add support for 'project-list' option 2010-08-04 03:09:32 +02:00
shared.c shared.c: use die_errno() where appropriate 2013-05-22 12:53:06 +02:00
ui-atom.c Always #include corresponding .h in .c files 2013-04-08 15:45:34 +02:00
ui-atom.h Add atom-support 2008-08-01 22:12:34 +02:00
ui-blob.c readme: use string_list instead of space deliminations 2013-05-26 16:30:03 +02:00
ui-blob.h readme: use string_list instead of space deliminations 2013-05-26 16:30:03 +02:00
ui-clone.c Always #include corresponding .h in .c files 2013-04-08 15:45:34 +02:00
ui-clone.h Add support for cloning over http 2008-08-06 11:21:09 +02:00
ui-commit.c Do not load user or system gitconfig and gitattributes 2013-04-08 21:43:26 +02:00
ui-commit.h ui-commit: Limit diff based on path limit in qry.path 2010-06-19 10:40:23 +02:00
ui-diff.c Convert cgit_print_error to a variadic function 2013-04-08 16:11:29 +02:00
ui-diff.h Always #include corresponding .h in .c files 2013-04-08 15:45:34 +02:00
ui-log.c ui-log: add <span/> around commit decorations 2013-05-22 12:53:06 +02:00
ui-log.h ui-log: Add "commit-sort" option for controlling commit ordering 2012-10-17 16:30:29 +02:00
ui-patch.c Convert cgit_print_error to a variadic function 2013-04-08 16:11:29 +02:00
ui-patch.h ui-patch: Apply path limit to generated patch 2010-06-19 10:40:23 +02:00
ui-plain.c use struct strbuf instead of static buffers 2013-04-08 16:12:52 +02:00
ui-plain.h Implement plain view 2008-08-06 11:21:30 +02:00
ui-refs.c Add branch-sort and repo.branch-sort options. 2013-04-10 14:48:26 +02:00
ui-refs.h Add separate header-files for each page/view 2008-03-24 16:38:47 +01:00
ui-repolist.c ui-summary: Pass filename to about-filter 2013-05-25 20:33:28 +02:00
ui-repolist.h Prepare for 'about site' page / add 'root-readme' option to cgitrc 2008-04-29 01:06:30 +02:00
ui-shared.c readme: use string_list instead of space deliminations 2013-05-26 16:30:03 +02:00
ui-shared.h Convert cgit_print_error to a variadic function 2013-04-08 16:11:29 +02:00
ui-snapshot.c cgit.c: Do not reset HOME after unsetting it. 2013-05-25 20:33:28 +02:00
ui-snapshot.h Set prefix in snapshots when using dwimmery 2008-11-30 13:39:53 +01:00
ui-ssdiff.c Always #include corresponding .h in .c files 2013-04-08 15:45:34 +02:00
ui-ssdiff.h ui-ssdiff: move LCS table away from the stack 2012-01-03 15:16:01 +00:00
ui-stats.c Convert cgit_print_error to a variadic function 2013-04-08 16:11:29 +02:00
ui-stats.h Add and use cgit_find_stats_periodname() in print_repo() 2009-08-24 11:02:48 +02:00
ui-summary.c readme: use string_list instead of space deliminations 2013-05-26 16:30:03 +02:00
ui-summary.h readme: use string_list instead of space deliminations 2013-05-26 16:30:03 +02:00
ui-tag.c use struct strbuf instead of static buffers 2013-04-08 16:12:52 +02:00
ui-tag.h Add separate header-files for each page/view 2008-03-24 16:38:47 +01:00
ui-tree.c use struct strbuf instead of static buffers 2013-04-08 16:12:52 +02:00
ui-tree.h Add separate header-files for each page/view 2008-03-24 16:38:47 +01:00
vector.c Add vector utility functions 2010-11-10 00:22:41 +01:00
vector.h Add vector utility functions 2010-11-10 00:22:41 +01:00

                       cgit - cgi for git


This is an attempt to create a fast web interface for the git scm, using a
builtin cache to decrease server io-pressure.


Installation

Building cgit involves building a proper version of git. How to do this
depends on how you obtained the cgit sources:

a) If you're working in a cloned cgit repository, you first need to
initialize and update the git submodule:

  $ git submodule init     # register the git submodule in .git/config
  $ $EDITOR .git/config    # if you want to specify a different url for git
  $ git submodule update   # clone/fetch and checkout correct git version

b) If you're building from a cgit tarball, you can download a proper git
version like this:

  $ make get-git


When either a) or b) has been performed, you can build and install cgit like
this:

  $ make
  $ sudo make install

This will install cgit.cgi and cgit.css into "/var/www/htdocs/cgit". You can
configure this location (and a few other things) by providing a "cgit.conf"
file (see the Makefile for details).


Dependencies:
  -git 1.7.4
  -zip lib
  -crypto lib
  -openssl lib


Apache configuration

A new Directory-section must probably be added for cgit, possibly something
like this:

  <Directory "/var/www/htdocs/cgit/">
      AllowOverride None
      Options +ExecCGI
      Order allow,deny
      Allow from all
  </Directory>


Runtime configuration

The file /etc/cgitrc is read by cgit before handling a request. In addition
to runtime parameters, this file may also contain a list of repositories
displayed by cgit (see cgitrc.5.txt for further details).


The cache

When cgit is invoked it looks for a cachefile matching the request and
returns it to the client. If no such cachefile exist (or if it has expired),
the content for the request is written into the proper cachefile before the
file is returned.

If the cachefile has expired but cgit is unable to obtain a lock for it, the
stale cachefile is returned to the client. This is done to favour page
throughput over page freshness.

The generated content contains the complete response to the client, including
the http-headers "Modified" and "Expires".


Online presence

* The cgit homepage is hosted by cgit at <http://git.zx2c4.com/cgit/about/>

* Patches, bugreports, discussions and support should go to the cgit
  mailing list: <cgit@lists.zx2c4.com>. To sign up, visit 
  <http://lists.zx2c4.com/mailman/listinfo/cgit>