| -rw-r--r-- | AUTHORS | 12 | ||||
| -rw-r--r-- | README | 99 | ||||
| -rw-r--r-- | README.md | 85 | ||||
| -rw-r--r-- | cgit.c | 16 | ||||
| -rw-r--r-- | cgit.h | 4 | ||||
| -rw-r--r-- | cgitrc.5.txt | 28 | ||||
| -rw-r--r-- | cmd.c | 4 | ||||
| -rw-r--r-- | filter.c | 10 | ||||
| -rwxr-xr-x | filters/ci-jenkins.sh | 58 | ||||
| -rw-r--r-- | shared.c | 13 | ||||
| -rw-r--r-- | tests/t0112-ci.sh | 44 | ||||
| -rw-r--r-- | tests/t0113-ci-lua.sh | 78 | ||||
| -rw-r--r-- | tests/t0114-broken-repo.sh | 71 | ||||
| -rw-r--r-- | ui-ci.c | 31 | ||||
| -rw-r--r-- | ui-shared.c | 8 |
15 files changed, 438 insertions, 123 deletions
@@ -1,13 +1,5 @@ Maintainer: - Jason A. Donenfeld <Jason@zx2c4.com> + Saya Andy <saya.andy@posteo.com> Contributors: - Jason A. Donenfeld <Jason@zx2c4.com> - Lukas Fleischer <cgit@cryptocrack.de> - Johan Herland <johan@herland.net> - Lars Hjemli <hjemli@gmail.com> - Ferry Huberts <ferry.huberts@pelagic.nl> - John Keeping <john@keeping.me.uk> - -Previous Maintainer: - Lars Hjemli <hjemli@gmail.com> + Saya Andy <saya.andy@posteo.com> @@ -1,99 +0,0 @@ -cgit - CGI for Git -================== - -This is an attempt to create a fast web interface for the Git SCM, using a -built-in cache to decrease server I/O pressure. - -Installation ------------- - -Building cgit involves building a proper version of Git. How to do this -depends on how you obtained the cgit sources: - -a) If you're working in a cloned cgit repository, you first need to -initialize and update the Git submodule: - - $ git submodule init # register the Git submodule in .git/config - $ $EDITOR .git/config # if you want to specify a different url for git - $ git submodule update # clone/fetch and checkout correct git version - -b) If you're building from a cgit tarball, you can download a proper git -version like this: - - $ make get-git - -When either a) or b) has been performed, you can build and install cgit like -this: - - $ make - $ sudo make install - -This will install `cgit.cgi` and `cgit.css` into `/var/www/htdocs/cgit`. You -can configure this location (and a few other things) by providing a `cgit.conf` -file (see the Makefile for details). - -If you'd like to compile without Lua support, you may use: - - $ make NO_LUA=1 - -And if you'd like to specify a Lua implementation, you may use: - - $ make LUA_PKGCONFIG=lua5.1 - -If this is not specified, the Lua implementation will be auto-detected, -preferring LuaJIT if many are present. Acceptable values are generally "lua", -"luajit", "lua5.1", and "lua5.2". - - -Dependencies ------------- - -* libzip -* libcrypto (OpenSSL) -* libssl (OpenSSL) -* optional: luajit or lua, most reliably used when pkg-config is available - -Apache configuration --------------------- - -A new `Directory` section must probably be added for cgit, possibly something -like this: - - <Directory "/var/www/htdocs/cgit/"> - AllowOverride None - Options +ExecCGI - Order allow,deny - Allow from all - </Directory> - - -Runtime configuration ---------------------- - -The file `/etc/cgitrc` is read by cgit before handling a request. In addition -to runtime parameters, this file may also contain a list of repositories -displayed by cgit (see `cgitrc.5.txt` for further details). - -The cache ---------- - -When cgit is invoked it looks for a cache file matching the request and -returns it to the client. If no such cache file exists (or if it has expired), -the content for the request is written into the proper cache file before the -file is returned. - -If the cache file has expired but cgit is unable to obtain a lock for it, the -stale cache file is returned to the client. This is done to favour page -throughput over page freshness. - -The generated content contains the complete response to the client, including -the HTTP headers `Modified` and `Expires`. - -Online presence ---------------- - -* The cgit homepage is hosted by cgit at <https://git.zx2c4.com/cgit/about/> - -* Patches, bug reports, discussions and support should go to the cgit - mailing list: <cgit@lists.zx2c4.com>. To sign up, visit - <https://lists.zx2c4.com/mailman/listinfo/cgit> diff --git a/README.md b/README.md new file mode 100644 index 0000000..d4092ee --- /dev/null +++ b/README.md @@ -0,0 +1,85 @@ +## cgitext - CGI for Git extension by Saya Andy + +This is a custom expansion to cgit. Its most prominent changes by now are: + +* CI/CD tab, linking to an external service on ref pages by using template. The Jenkins plugin is added to support a scenario when a ref lacks a pipeline. + +The original cgit project is hosted at [git.zx2c4.com](https://git.zx2c4.com/cgit/about/) + +## cgit - CGI for Git + +This is an attempt to create a fast web interface for the Git SCM, using a built-in cache to decrease server I/O pressure. + +### Installation + +Building cgit involves building a proper version of Git. How to do this depends on how you obtained the cgit sources: + +1. If you're working in a cloned cgit repository, you first need to initialize and update the Git submodule: + + $ git submodule init # register the Git submodule in .git/config + $ $EDITOR .git/config # if you want to specify a different url for git + $ git submodule update # clone/fetch and checkout correct git version + +2. If you're building from a cgit tarball, you can download a proper git version like this: + + $ make get-git + +When either `1.` or `2.` has been performed, you can build and install cgit like +this: +``` +make +sudo make install +``` + +This will install `cgit.cgi` and `cgit.css` into `/var/www/htdocs/cgit`. You can configure this location (and a few other things) by providing a `cgit.conf` file (see the Makefile for details). + +If you'd like to compile without Lua support, you may use: +``` +make NO_LUA=1 +``` + +And if you'd like to specify a Lua implementation, you may use: +``` +make LUA_PKGCONFIG=lua5.1 +``` + +If this is not specified, the Lua implementation will be auto-detected, preferring LuaJIT if many are present. Acceptable values are generally "lua", "luajit", "lua5.1", and "lua5.2". + + +### Dependencies + +* libzip +* libcrypto (OpenSSL) +* libssl (OpenSSL) +* optional: luajit or lua, most reliably used when pkg-config is available + +### Apache configuration + +A new `Directory` section must probably be added for cgit, possibly something like this: + +``` +<Directory "/var/www/htdocs/cgit/"> + AllowOverride None + Options +ExecCGI + Order allow,deny + Allow from all +</Directory> +``` + +### Runtime configuration + +The file `/etc/cgitrc` is read by cgit before handling a request. In addition to runtime parameters, this file may also contain a list of repositories displayed by cgit (see `cgitrc.5.txt` for further details). + +### The cache + +When cgit is invoked it looks for a cache file matching the request and returns it to the client. If no such cache file exists (or if it has expired), the content for the request is written into the proper cache file before the file is returned. + +If the cache file has expired but cgit is unable to obtain a lock for it, the stale cache file is returned to the client. This is done to favour page throughput over page freshness. + +The generated content contains the complete response to the client, including the HTTP headers `Modified` and `Expires`. + +### Online presence + +* The cgit homepage is hosted by cgit at [git.zx2c4.com](https://git.zx2c4.com/cgit/about/) + +* Patches, bug reports, discussions and support should go to the cgit mailing list: [cgit@lists.zx2c4.com](mailto:cgit@lists.zx2c4.com). To sign up, visit [lists.zx2c4.com](https://lists.zx2c4.com/mailman/listinfo/cgit) @@ -1,6 +1,10 @@ /* cgit.c: cgi for the git scm * * Copyright (C) 2006-2014 cgit Development Team <cgit@lists.zx2c4.com> + * Copyright (C) 2026 Saya Andy <saya.andy@posteo.com> + * + * Modified 2026 by Saya Andy: + * Always check there is git repo on repo.path * * Licensed under GNU General Public License v2 * (see COPYING for full license text) @@ -58,6 +62,10 @@ void cgit_repo_config(struct cgit_repo *repo, const char *name, const char *valu repo->homepage = strdup_first_line(value); else if (!strcmp(name, "ci-url")) { repo->ci_url = strdup_first_line(value); + /* An explicit repo.ci-url would otherwise never be used + * when the more specific urls are inherited from the + * global settings, so discard those. + */ if (repo->ci_branch_url == ctx.cfg.ci_branch_url) repo->ci_branch_url = NULL; if (repo->ci_tag_url == ctx.cfg.ci_tag_url) @@ -132,6 +140,8 @@ void cgit_repo_config(struct cgit_repo *repo, const char *name, const char *valu repo->email_filter = cgit_new_filter(value, EMAIL); else if (!strcmp(name, "owner-filter")) repo->owner_filter = cgit_new_filter(value, OWNER); + else if (!strcmp(name, "ci-filter")) + repo->ci_filter = cgit_new_filter(value, CI); } } @@ -249,6 +259,8 @@ static void config_cb(const char *name, const char *value) ctx.cfg.owner_filter = cgit_new_filter(value, OWNER); else if (!strcmp(name, "auth-filter")) ctx.cfg.auth_filter = cgit_new_filter(value, AUTH); + else if (!strcmp(name, "ci-filter")) + ctx.cfg.ci_filter = cgit_new_filter(value, CI); else if (!strcmp(name, "embedded")) ctx.cfg.embedded = atoi(value); else if (!strcmp(name, "max-atom-items")) @@ -859,6 +871,8 @@ static void print_repo(FILE *f, struct cgit_repo *repo) cgit_fprintf_filter(repo->email_filter, f, "repo.email-filter="); if (repo->owner_filter && repo->owner_filter != ctx.cfg.owner_filter) cgit_fprintf_filter(repo->owner_filter, f, "repo.owner-filter="); + if (repo->ci_filter && repo->ci_filter != ctx.cfg.ci_filter) + cgit_fprintf_filter(repo->ci_filter, f, "repo.ci-filter="); if (repo->snapshots != ctx.cfg.snapshots) { char *tmp = build_snapshot_setting(repo->snapshots); fprintf(f, "repo.snapshots=%s\n", tmp ? tmp : ""); @@ -987,7 +1001,7 @@ static void cgit_parse_args(int argc, const char **argv) for (i = 1; i < argc; i++) { if (!strcmp(argv[i], "--version")) { - printf("CGit %s | https://git.zx2c4.com/cgit/\n\nCompiled in features:\n", CGIT_VERSION); + printf("CGit %s | https://sayag.it/cgitext.git | https://git.zx2c4.com/cgit/\n\nCompiled in features:\n", CGIT_VERSION); #ifdef NO_LUA printf("[-] "); #else @@ -63,7 +63,7 @@ typedef enum { } diff_type; typedef enum { - ABOUT, COMMIT, SOURCE, EMAIL, AUTH, OWNER + ABOUT, COMMIT, SOURCE, EMAIL, AUTH, OWNER, CI } filter_type; struct cgit_filter { @@ -119,6 +119,7 @@ struct cgit_repo { struct cgit_filter *source_filter; struct cgit_filter *email_filter; struct cgit_filter *owner_filter; + struct cgit_filter *ci_filter; struct string_list submodules; int hide; int ignore; @@ -280,6 +281,7 @@ struct cgit_config { struct cgit_filter *email_filter; struct cgit_filter *owner_filter; struct cgit_filter *auth_filter; + struct cgit_filter *ci_filter; }; struct cgit_page { diff --git a/cgitrc.5.txt b/cgitrc.5.txt index 145a17e..76b2085 100644 --- a/cgitrc.5.txt +++ b/cgitrc.5.txt @@ -105,6 +105,11 @@ ci-branch-url:: unspecified, `ci-url` is used instead. Default value: none. See also: "CI URL EXPANSION". +ci-filter:: + Specifies a command which decides whether the "ci" tab is shown for + the ref currently being viewed, which is useful when only some refs + have a pipeline. Default value: none. See also: "FILTER API". + ci-tag-url:: Url template used by the "ci" tab when a tag is being viewed. If unspecified, `ci-url' is used instead. Default value: none. See also: @@ -489,6 +494,10 @@ repo.ci-branch-url:: Override the global setting `ci-branch-url' for this repository. Default value: <ci-branch-url>. See also: "CI URL EXPANSION". +repo.ci-filter:: + Override the default ci-filter. Default value: none. See also: + "enable-filter-overrides". See also: "FILTER API". + repo.ci-tag-url:: Override the global setting `ci-tag-url' for this repository. Default value: <ci-tag-url>. See also: "CI URL EXPANSION". @@ -739,6 +748,20 @@ auth filter:: Please see `filters/simple-authentication.lua` for a clear example script that may be modified. +ci filter:: + This filter is given three parameters: the name of the branch or tag + being viewed, the string "branch" or "tag" to say which of the two it + is, and the ci url that the "ci" tab would redirect to. It decides + whether that tab is shown at all, by returning zero from the exit code + / close function to show it and non-zero to hide it. Nothing is written + to its standard input, and it must not write to standard output, since + that would land in the middle of the page being rendered. + + The filter is consulted while rendering every page of the repository, + not only ref pages, so a filter which contacts the ci system should + cache its verdict and use a short timeout. Please see + `filters/ci-jenkins.sh` for an example. + commit filter:: This filter is given no arguments. The commit message text that is to be filtered is available on standard input and the filtered text is @@ -840,6 +863,10 @@ otherwise inherit from the global `ci-branch-url' and `ci-tag-url', so that a single repository can be pointed at a different ci system without having to override both of them. +Note that cgit itself never contacts the ci system, so a tab shown for a +ref which has no pipeline only reveals that after being followed. Use +`ci-filter' to suppress the tab in that case. + CACHE ----- @@ -1090,3 +1117,4 @@ AUTHOR ------ Lars Hjemli <hjemli@gmail.com> Jason A. Donenfeld <Jason@zx2c4.com> +Saya Andy <saya.andy@posteo.com> @@ -1,6 +1,10 @@ /* cmd.c: the cgit command dispatcher * * Copyright (C) 2006-2017 cgit Development Team <cgit@lists.zx2c4.com> + * Copyright (C) 2026 Saya Andy <saya.andy@posteo.com> + * + * Modified 2026 by Saya Andy: + * Include ci ui element * * Licensed under GNU General Public License v2 * (see COPYING for full license text) @@ -1,6 +1,10 @@ /* filter.c: filter framework functions * * Copyright (C) 2006-2014 cgit Development Team <cgit@lists.zx2c4.com> + * Copyright (C) 2026 Saya Andy <saya.andy@posteo.com> + * + * Modified 2026 by Saya Andy: + * Integrate ci filter * * Licensed under GNU General Public License v2 * (see COPYING for full license text) @@ -30,12 +34,14 @@ void cgit_cleanup_filters(void) reap_filter(ctx.cfg.email_filter); reap_filter(ctx.cfg.owner_filter); reap_filter(ctx.cfg.auth_filter); + reap_filter(ctx.cfg.ci_filter); for (i = 0; i < cgit_repolist.count; ++i) { reap_filter(cgit_repolist.repos[i].about_filter); reap_filter(cgit_repolist.repos[i].commit_filter); reap_filter(cgit_repolist.repos[i].source_filter); reap_filter(cgit_repolist.repos[i].email_filter); reap_filter(cgit_repolist.repos[i].owner_filter); + reap_filter(cgit_repolist.repos[i].ci_filter); } } @@ -424,6 +430,10 @@ struct cgit_filter *cgit_new_filter(const char *cmd, filter_type filtertype) argument_count = 12; break; + case CI: + argument_count = 3; + break; + case EMAIL: argument_count = 2; break; diff --git a/filters/ci-jenkins.sh b/filters/ci-jenkins.sh new file mode 100755 index 0000000..842af21 --- /dev/null +++ b/filters/ci-jenkins.sh @@ -0,0 +1,58 @@ +#!/bin/sh +# This script may be used with the ci-filter or repo.ci-filter setting in +# cgitrc to hide the "ci" tab for refs which have no pipeline on a Jenkins +# instance. +# +# Arguments: +# $1 the name of the branch or tag being viewed +# $2 "branch" or "tag" +# $3 the ci url which the "ci" tab would redirect to +# +# Exit with a zero status to show the tab, non-zero to hide it. This script +# must not write anything to standard output, as that would end up in the +# middle of the page cgit is rendering. +# +# The filter is consulted while rendering every repository page, so the +# verdict is cached on disk to keep Jenkins from being hammered, and the +# probe is given a short timeout so that an unreachable Jenkins degrades +# into a missing tab rather than a hanging web server. +# +# Set CI_NETRC to a netrc(5) file if the Jenkins instance requires +# authentication; without it a private job answers 403 and the tab is +# hidden even though the pipeline exists. + +CI_CACHE_DIR="${CI_CACHE_DIR:-/var/cache/cgit/ci-filter}" +CI_CACHE_TTL_MINUTES="${CI_CACHE_TTL_MINUTES:-5}" +CI_TIMEOUT="${CI_TIMEOUT:-2}" + +url="$3" +test -n "$url" || exit 1 + +# Jenkins job pages are often not readable anonymously, so query the REST +# API rather than the page the tab points at. +probe="$url/api/json?tree=name" + +key="$(printf '%s' "$url" | cksum | tr -cd '0-9')" +cache="$CI_CACHE_DIR/$key" + +mkdir -p "$CI_CACHE_DIR" 2>/dev/null + +if test -f "$cache" && + test -z "$(find "$cache" -mmin "+$CI_CACHE_TTL_MINUTES" 2>/dev/null)" +then + exit "$(cat "$cache")" +fi + +status=0 +curl --silent --fail --head --output /dev/null \ + --max-time "$CI_TIMEOUT" \ + ${CI_NETRC:+--netrc-file "$CI_NETRC"} \ + "$probe" >/dev/null 2>&1 || status=1 + +if test -d "$CI_CACHE_DIR" +then + printf '%s\n' "$status" >"$cache.$$" 2>/dev/null && + mv "$cache.$$" "$cache" 2>/dev/null +fi + +exit "$status" @@ -1,6 +1,11 @@ /* shared.c: global vars + some callback functions * * Copyright (C) 2006-2014 cgit Development Team <cgit@lists.zx2c4.com> + * Copyright (C) 2026 Saya Andy <saya.andy@posteo.com> + * + * Modified 2026 by Saya Andy: + * Add cgit_have_repository() + * Add ci filter configuration * * Licensed under GNU General Public License v2 * (see COPYING for full license text) @@ -13,13 +18,6 @@ struct cgit_repolist cgit_repolist; struct cgit_context ctx; -/* Returns true when the git repository belonging to this request was opened - * successfully. Some requests print a page for a repository which could not - * be opened, e.g. because repo.path is wrong, and the object database and - * ref stores must not be touched in that case: they would abort with - * "reference backend is unknown" or dereference the not yet known hash - * algorithm. - */ int cgit_have_repository(void) { return startup_info->have_repository; @@ -95,6 +93,7 @@ struct cgit_repo *cgit_add_repo(const char *url) ret->source_filter = ctx.cfg.source_filter; ret->email_filter = ctx.cfg.email_filter; ret->owner_filter = ctx.cfg.owner_filter; + ret->ci_filter = ctx.cfg.ci_filter; ret->clone_url = ctx.cfg.clone_url; ret->submodules.strdup_strings = 1; ret->hide = ret->ignore = 0; diff --git a/tests/t0112-ci.sh b/tests/t0112-ci.sh index d8673e4..33609d6 100644 --- a/tests/t0112-ci.sh +++ b/tests/t0112-ci.sh @@ -10,6 +10,7 @@ cat >cgitrc.ci <<EOF virtual-root=/ cache-root=$PWD/cache cache-size=0 +enable-filter-overrides=1 repo.url=tagonly repo.path=$PWD/repos/foo/.git @@ -27,8 +28,20 @@ repo.path=$PWD/repos/foo/.git repo.url=override repo.path=$PWD/repos/foo/.git repo.ci-url=https://ci.example.org/override/\$repo/\$\$/\$ref + +repo.url=filtered +repo.path=$PWD/repos/foo/.git +repo.ci-filter=exec:$PWD/ci-filter.sh EOF +# Records its arguments and only accepts tags. +cat >ci-filter.sh <<EOF +#!/bin/sh +printf '%s|%s|%s\n' "\$1" "\$2" "\$3" >>"$PWD/ci-filter.log" +test "\$2" = tag +EOF +chmod +x ci-filter.sh + git --git-dir="$PWD/repos/foo/.git" tag v0.17.3.2 master cgit_ci() @@ -80,4 +93,35 @@ test_expect_success 'no ci tab without a ci url' ' ! grep ">ci</a>" tmp ' +test_expect_success 'ci filter accepts a tag' ' + rm -f ci-filter.log && + cgit_ci "filtered/ci&h=v0.17.3.2" >tmp && + grep "^Location: https://ci.example.org/job/filtered/view/tags/job/v0.17.3.2$" tmp && + echo "v0.17.3.2|tag|https://ci.example.org/job/filtered/view/tags/job/v0.17.3.2" >expected && + test_cmp expected ci-filter.log +' + +test_expect_success 'ci filter rejects a branch' ' + rm -f ci-filter.log && + cgit_ci "filtered/ci&h=master" >tmp && + grep "^Status: 404 Not found$" tmp && + echo "master|branch|https://ci.example.org/job/filtered/job/master" >expected && + test_cmp expected ci-filter.log +' + +test_expect_success "ci filter hides the tab and is consulted once" ' + rm -f ci-filter.log && + cgit_ci "filtered/refs&h=master" >tmp && + ! grep ">ci</a>" tmp && + test_line_count = 1 ci-filter.log && + cgit_ci "filtered/refs&h=v0.17.3.2" >tmp && + grep "href=./filtered/ci/?h=v0.17.3.2.>ci</a>" tmp +' + +test_expect_success 'ci filter is not consulted without a ci url' ' + rm -f ci-filter.log && + cgit_url "foo/refs" >tmp && + test_path_is_missing ci-filter.log +' + test_done diff --git a/tests/t0113-ci-lua.sh b/tests/t0113-ci-lua.sh new file mode 100644 index 0000000..1e095b1 --- /dev/null +++ b/tests/t0113-ci-lua.sh @@ -0,0 +1,78 @@ +#!/bin/sh + +test_description='Check ci filter written in Lua' +. ./setup.sh + +if test $CGIT_HAS_LUA -ne 1 +then + skip_all='Skipping Lua ci filter tests: Lua support not compiled in' + test_done + exit +fi + +cat >cgitrc.cilua <<EOF +virtual-root=/ +cache-root=$PWD/cache +cache-size=0 + +ci-url=https://ci.example.org/job/\$slug/job/\$ref +ci-filter=lua:$PWD/ci-filter.lua + +repo.url=foo +repo.path=$PWD/repos/foo/.git +EOF + +# Accepts tags only, and records its arguments. +cat >ci-filter.lua <<EOF +function filter_open(ref, refkind, url) + local log = io.open("$PWD/ci-filter.log", "a") + log:write(ref .. "|" .. refkind .. "|" .. url .. "\n") + log:close() + accepted = (refkind == "tag") +end + +function filter_write(buffer) +end + +function filter_close() + if accepted then + return 0 + end + return 1 +end +EOF + +git --git-dir="$PWD/repos/foo/.git" tag v1.0 master + +cgit_ci() +{ + CGIT_CONFIG="$PWD/cgitrc.cilua" QUERY_STRING="url=$1" cgit +} + +test_expect_success 'Lua ci filter accepts a tag' ' + rm -f ci-filter.log && + cgit_ci "foo/ci&h=v1.0" >tmp && + grep "^Location: https://ci.example.org/job/foo/job/v1.0$" tmp && + echo "v1.0|tag|https://ci.example.org/job/foo/job/v1.0" >expected && + test_cmp expected ci-filter.log +' + +test_expect_success 'Lua ci filter rejects a branch' ' + cgit_ci "foo/ci&h=master" >tmp && + grep "^Status: 404 Not found$" tmp +' + +test_expect_success 'Lua ci filter controls the tab' ' + cgit_ci "foo/refs&h=v1.0" >tmp && + grep "href=./foo/ci/?h=v1.0.>ci</a>" tmp && + cgit_ci "foo/refs&h=master" >tmp && + ! grep ">ci</a>" tmp +' + +test_expect_success 'page is still rendered correctly around the filter' ' + cgit_ci "foo/refs&h=v1.0" >tmp && + grep "</html>" tmp && + ! grep "|tag|" tmp +' + +test_done diff --git a/tests/t0114-broken-repo.sh b/tests/t0114-broken-repo.sh new file mode 100644 index 0000000..61367e6 --- /dev/null +++ b/tests/t0114-broken-repo.sh @@ -0,0 +1,71 @@ +#!/bin/sh + +test_description='Check that a misconfigured repo.path is reported' +. ./setup.sh + +mkdir -p plaindir + +cat >cgitrc.broken <<EOF +virtual-root=/ +cache-root=$PWD/cache +cache-size=0 + +ci-branch-url=https://ci.example.org/job/\$slug/job/\$ref + +repo.url=missing +repo.path=$PWD/no/such/repo.git + +repo.url=notarepo +repo.path=$PWD/plaindir +EOF + +# cgit used to spin forever on these requests, so give it a deadline and +# report a failure rather than hanging the test suite. +cgit_broken() +{ + CGIT_CONFIG="$PWD/cgitrc.broken" QUERY_STRING="url=$1" perl -e ' + my $pid = fork(); + if ($pid == 0) { + exec("cgit") or die "exec: $!"; + } + eval { + local $SIG{ALRM} = sub { die "timeout\n" }; + alarm(20); + waitpid($pid, 0); + alarm(0); + }; + if ($@) { + kill "KILL", $pid; + print STDERR "cgit did not terminate\n"; + exit 1; + } + ' </dev/null +} + +test_expect_success 'report a repo.path that does not exist' ' + cgit_broken "missing/&h=master" >tmp && + grep "Failed to open missing" tmp +' + +test_expect_success 'report a repo.path that is not a repository' ' + cgit_broken "notarepo/&h=master" >tmp && + grep "Failed to open notarepo" tmp +' + +test_expect_success 'report an unknown page for a broken repo' ' + cgit_broken "missing/nosuchpage/&h=master" >tmp && + grep "^Status: 404 Not found$" tmp && + grep "Invalid request" tmp +' + +test_expect_success 'no ci tab for a broken repo' ' + cgit_broken "missing/nosuchpage/&h=master" >tmp && + ! grep ">ci</a>" tmp +' + +test_expect_success 'report a broken repo on the ci page' ' + cgit_broken "missing/ci/&h=master" >tmp && + grep "Failed to open missing" tmp +' + +test_done @@ -1,6 +1,6 @@ /* ui-ci.c: redirect to an external CI system * - * Copyright (C) 2006-2025 cgit Development Team <cgit@lists.zx2c4.com> + * Copyright (C) 2026 Saya Andy <saya.andy@posteo.com> * * Licensed under GNU General Public License v2 * (see COPYING for full license text) @@ -73,9 +73,24 @@ static char *expand_ci_url(const char *template) return strbuf_detach(&buf, NULL); } +/* Ask the ci filter whether the pipeline denoted by url actually exists. + * The filter must not write to stdout, and signals "yes" by exiting with + * a zero status. + */ +static int ci_filter_accepts(const char *refkind, const char *url) +{ + struct cgit_filter *filter = ctx.repo->ci_filter; + + if (!filter) + return 1; + if (cgit_open_filter(filter, ctx.qry.head, refkind, url)) + return 0; + return !cgit_close_filter(filter); +} + static void resolve_ci_url(void) { - const char *template; + const char *template, *refkind; if (ci_resolved != -1) return; @@ -84,16 +99,24 @@ static void resolve_ci_url(void) if (!ctx.repo || !ctx.qry.head || !cgit_have_repository()) return; - if (ref_is_tag(ctx.qry.head)) + if (ref_is_tag(ctx.qry.head)) { + refkind = "tag"; template = ctx.repo->ci_tag_url; - else + } else { + refkind = "branch"; template = ctx.repo->ci_branch_url; + } if (!template) template = ctx.repo->ci_url; if (!template) return; ci_url = expand_ci_url(template); + if (!ci_filter_accepts(refkind, ci_url)) { + free(ci_url); + ci_url = NULL; + return; + } ci_resolved = 1; } diff --git a/ui-shared.c b/ui-shared.c index 9a9d014..97d1839 100644 --- a/ui-shared.c +++ b/ui-shared.c @@ -1,6 +1,12 @@ /* ui-shared.c: common web output functions * * Copyright (C) 2006-2017 cgit Development Team <cgit@lists.zx2c4.com> + * Copyright (C) 2026 Saya Andy <saya.andy@posteo.com> + * + * Modified 2026 by Saya Andy: + * Implement ci link tab + * Check repo existence + * Replace memrchr() for macOS compatibility * * Licensed under GNU General Public License v2 * (see COPYING for full license text) @@ -884,7 +890,7 @@ void cgit_print_docend(void) if (ctx.cfg.footer) html_include(ctx.cfg.footer); else { - htmlf("<div class='footer'>generated by <a href='https://git.zx2c4.com/cgit/about/'>cgit %s</a> " + htmlf("<div class='footer'>generated by <a href='https://sayag.it/cgitext.git/about/'>cgitext %s</a> " "(<a href='https://git-scm.com/'>git %s</a>) at ", cgit_version, git_version_string); html_txt(show_date(time(NULL), 0, cgit_date_mode(DATE_ISO8601))); html("</div>\n"); |