John Keeping b1f17f168b Fix out-of-bounds memory accesses with virtual_root=""
The CGit configuration variable virtual_root is normalized so that it
does not have a trailing '/' character, but it is allowed to be empty
(the empty string and NULL have different meanings here) and there is
code that is insufficiently cautious when checking if it ends in a '/':

	if (virtual_root[strlen(virtual_root) - 1] != '/')

Clearly this check is redundant, but rather than simply removing it we
get a slight efficiency improvement by switching the normalization so
that the virtual_root variable always ends in '/'.  Do this with a new
"ensure_end" helper.

Signed-off-by: John Keeping <john@keeping.me.uk>
2013-04-08 15:59:46 +02:00
2013-04-08 15:41:38 +02:00
2009-02-12 10:24:25 +01:00
2013-04-08 15:43:17 +02:00
2013-03-04 09:12:54 -05:00
2011-02-19 14:57:48 +01:00
2006-12-10 22:41:14 +01:00
2013-04-08 15:45:34 +02:00
2013-04-08 15:41:38 +02:00
2012-10-09 13:21:30 +02:00
2008-08-01 22:12:34 +02:00
2010-08-20 18:57:30 +02:00
2008-08-06 11:21:09 +02:00
2008-08-06 11:21:30 +02:00
2013-04-08 15:45:34 +02:00
2010-11-10 00:22:41 +01:00
2010-11-10 00:22:41 +01:00

                       cgit - cgi for git


This is an attempt to create a fast web interface for the git scm, using a
builtin cache to decrease server io-pressure.


Installation

Building cgit involves building a proper version of git. How to do this
depends on how you obtained the cgit sources:

a) If you're working in a cloned cgit repository, you first need to
initialize and update the git submodule:

  $ git submodule init     # register the git submodule in .git/config
  $ $EDITOR .git/config    # if you want to specify a different url for git
  $ git submodule update   # clone/fetch and checkout correct git version

b) If you're building from a cgit tarball, you can download a proper git
version like this:

  $ make get-git


When either a) or b) has been performed, you can build and install cgit like
this:

  $ make
  $ sudo make install

This will install cgit.cgi and cgit.css into "/var/www/htdocs/cgit". You can
configure this location (and a few other things) by providing a "cgit.conf"
file (see the Makefile for details).


Dependencies:
  -git 1.7.4
  -zip lib
  -crypto lib
  -openssl lib


Apache configuration

A new Directory-section must probably be added for cgit, possibly something
like this:

  <Directory "/var/www/htdocs/cgit/">
      AllowOverride None
      Options +ExecCGI
      Order allow,deny
      Allow from all
  </Directory>


Runtime configuration

The file /etc/cgitrc is read by cgit before handling a request. In addition
to runtime parameters, this file may also contain a list of repositories
displayed by cgit (see cgitrc.5.txt for further details).


The cache

When cgit is invoked it looks for a cachefile matching the request and
returns it to the client. If no such cachefile exist (or if it has expired),
the content for the request is written into the proper cachefile before the
file is returned.

If the cachefile has expired but cgit is unable to obtain a lock for it, the
stale cachefile is returned to the client. This is done to favour page
throughput over page freshness.

The generated content contains the complete response to the client, including
the http-headers "Modified" and "Expires".


Online presence

* The cgit homepage is hosted by cgit at http://git.zx2c4.com/cgit/about

* Patches, bugreports, discussions and support should go to the cgit
  mailing list: cgit@hjemli.net
Description
cgit with patches for sandboxing using qssb
Readme 2.8 MiB
Languages
C 74.2%
Shell 8%
Lua 7.9%
CSS 4%
Python 3.3%
Other 2.6%