{"thread":{"id":"64526","subject":"[BUG] `git instaweb` and `gitweb`","startedAt":"2025-11-24T13:04:54Z","lastAt":"2025-11-24T13:04:54Z","messageCount":1,"participants":["windwiny"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"531213","messageId":"CAJ_pojYchJyC4GgPGXnPV+DvVmsHYXycEWVF5GF-1pUEM1mbug@mail.gmail.com","threadId":"64526","inReplyTo":null,"subject":"[BUG] `git instaweb` and `gitweb`","fromName":"windwiny","fromEmail":"windwiny.ubt@gmail.com","sentAt":"2025-11-24T13:04:25Z","receivedAt":"2025-11-24T13:04:54Z","isPatch":false,"sender":{"key":"windwiny.ubt@gmail.com","avatar":null},"body":"Hi,\n\n When i run `git instaweb` on a code dir, it generate .git/gitweb/ dir\nand some .conf/.perl files,\nand lighttpd+fastcgi read/exec those files  to serve git repo access via http.\n\n When dir name include `@` char ,then instaweb run ok, but gitweb.cgi\nwill get incorrect dir name.\n In Perl, the array variable @xx is interpolated (its value is\ninserted into the string) inside a \"\" (double-quoted) string, but not\ninside a '' (single-quoted) string.\n\n i write a simple patch can fix when dir include `@` char.\n\n    --- git-instaweb.ori    Tue Sep 30 05:50:42 2025\n    +++ git-instaweb        Mon Nov 24 20:53:13 2025\n    @@ -716,10 +716,10 @@\n\n     gitweb_conf() {\n            cat > \"$fqgitdir/gitweb/gitweb_config.perl\" <<EOF\n     #!/usr/bin/perl\n    -our \\$projectroot = \"$(dirname \"$fqgitdir\")\";\n    -our \\$git_temp = \"$fqgitdir/gitweb/tmp\";\n    +our \\$projectroot = '$(dirname \"$fqgitdir\")';\n    +our \\$git_temp = '$fqgitdir/gitweb/tmp';\n     our \\$projects_list = \\$projectroot;\n\n     \\$feature{'remote_heads'}{'default'} = [1];\n     EOF\n\nThan fixed, those code still has bug:  if dir name include `'` or `\"`,\n instaweb run failed.\n\nOTHER,  the instaweb generated an .perl script, gitweb exec it to read\nvars define,\nthis method may cause CVE security vulnerability issues.\nProbably should replaced by .ini/.conf/.json\n"}]}