git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[BUG] `git instaweb` and `gitweb`

From
Wwindwiny <windwiny.ubt@gmail.com>
Date
Nov 24, 2025, 13:04 UTC
Message-ID
<CAJ_pojYchJyC4GgPGXnPV+DvVmsHYXycEWVF5GF-1pUEM1mbug@mail.gmail.com>
Hi,
 When i run `git instaweb` on a code dir, it generate .git/gitweb/ dir
and some .conf/.perl files,
and lighttpd+fastcgi read/exec those files  to serve git repo access via http.
 When dir name include `@` char ,then instaweb run ok, but gitweb.cgi
will get incorrect dir name.
 In Perl, the array variable @xx is interpolated (its value is
inserted into the string) inside a "" (double-quoted) string, but not
inside a '' (single-quoted) string.
 i write a simple patch can fix when dir include `@` char.
    --- git-instaweb.ori    Tue Sep 30 05:50:42 2025
    +++ git-instaweb        Mon Nov 24 20:53:13 2025
    @@ -716,10 +716,10 @@
     gitweb_conf() {
            cat > "$fqgitdir/gitweb/gitweb_config.perl" <<EOF
     #!/usr/bin/perl
    -our \$projectroot = "$(dirname "$fqgitdir")";
    -our \$git_temp = "$fqgitdir/gitweb/tmp";
    +our \$projectroot = '$(dirname "$fqgitdir")';
    +our \$git_temp = '$fqgitdir/gitweb/tmp';
     our \$projects_list = \$projectroot;
     \$feature{'remote_heads'}{'default'} = [1];
     EOF
Than fixed, those code still has bug:  if dir name include `'` or `"`,
 instaweb run failed.

OTHER, the instaweb generated an .perl script, gitweb exec it to read vars define, this method may cause CVE security vulnerability issues. Probably should replaced by .ini/.conf/.json

Message 1 of 1 in “[BUG] `git instaweb` and `gitweb`”
  1. windwinyNov 24, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.