git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH] gitweb: do misparse nonnumeric content tag files that contain a digit

From
Jonathan Nieder <jrnieder@gmail.com>
Date
Jun 9, 2011, 07:08 UTC
Message-ID
<20110609070857.GA735@elie>
In-Reply-To
<201103071900.16126.jnareb@gmail.com>

v1.7.6-rc0~27^2~4 (gitweb: Change the way "content tags" ('ctags') are handled, 2011-04-29) tried to make gitweb's tag cloud feature more intuitive for webmasters by checking whether the ctags/<label> under a project's .git dir contains a number (representing the strength of association to <label>) before treating it as one.

So after that change, after putting '$feature{'ctags'}{'default'} = [1];' in your $GITWEB_CONFIG, you could do

	echo Linux >.git/ctags/linux

and gitweb would treat that as a request to tag the current repository with the Linux tag, instead of the previous behavior of writing an error page embedded in the projects list that triggers error messages from Chromium and Firefox about malformed XML.

Unfortunately the pattern (\d+) used to match numbers is too loose, and the "XML declaration allowed only at the start of the document" error can still be experienced if you write "Linux-2.6" in place of "Linux" in the example above. Fix it by tightening the pattern to ^\d+$.

Signed-off-by: Jonathan Nieder <jrnieder@gmail.com>
---
Hi,
Jakub Narebski wrote:
>> On Thu, Mar 03, 2011 at 01:42:15AM +0100, Jakub Narebski wrote:
>>> 1. Hardening parsing of ctags files, so that gitweb does not crash on
>>>    malformed entries, but e.g. just ignores them.
>
> Done.

Sorry for a (long-) delayed response. Based on testing rc0 today, it works well; thanks! Patch to fix a small detail noticed while trying '-1' follows.

 gitweb/gitweb.perl                     |    2 +-
 t/t9500-gitweb-standalone-no-errors.sh |    8 ++++++++
 2 files changed, 9 insertions(+), 1 deletions(-)
diff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl
index ebf2d1c..1b83a8d 100755
--- a/gitweb/gitweb.perl
+++ b/gitweb/gitweb.perl
@@ -2644,7 +2644,7 @@ sub git_get_project_ctags {
 			close $ct;
 
 			(my $ctag = $tagfile) =~ s#.*/##;
-			if ($val =~ /\d+/) {
+			if ($val =~ /^\d+$/) {
 				$ctags->{$ctag} = $val;
 			} else {
 				$ctags->{$ctag} = 1;
diff --git a/t/t9500-gitweb-standalone-no-errors.sh b/t/t9500-gitweb-standalone-no-errors.sh
index f5648a6..5329715 100755
--- a/t/t9500-gitweb-standalone-no-errors.sh
+++ b/t/t9500-gitweb-standalone-no-errors.sh
@@ -644,6 +644,14 @@ test_expect_success \
 	'ctags: search projects by non existent tag' \
 	'gitweb_run "by_tag=non-existent"'
 
+test_expect_success \
+	'ctags: malformed tag weights' \
+	'mkdir -p .git/ctags &&
+	 echo "not-a-number" > .git/ctags/nan &&
+	 echo "not-a-number-2" > .git/ctags/nan2 &&
+	 echo "0.1" >.git/ctags/floating-point &&
+	 gitweb_run'
+
 # ----------------------------------------------------------------------
 # categories
 
-- 
1.7.6.rc0
Previous: Petr BaudisNext: Jonathan Nieder
Message 13 of 16 in “gitweb: cloud tags feature produces malformed XML for errors”
  1. Jonathan NiederMar 1, 2011
  2. Jakub NarebskiMar 2, 2011
  3. Jakub NarebskiMar 2, 2011
  4. Uwe Kleine-KönigMar 2, 2011
  5. J.H.Mar 2, 2011
  6. Jakub NarebskiMar 2, 2011
  7. Uwe Kleine-KönigMar 2, 2011
  8. Jakub NarebskiMar 3, 2011
  9. Uwe Kleine-KönigMar 3, 2011
  10. gitweb: Change the way "content tags" ('ctags') are handledJakub Narebski, Mar 7, 2011
  11. 2/1 gitweb: Mark matched 'ctag' / contents tag (?by_tag=foo)Jakub Narebski, Mar 9, 2011
  12. Petr BaudisMar 9, 2011
  13. gitweb: do misparse nonnumeric content tag files that contain a digitJonathan Nieder, Jun 9, 2011
  14. Jonathan NiederJun 9, 2011
  15. Petr BaudisMar 3, 2011
  16. Jakub NarebskiMar 3, 2011

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.