git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] gitweb: filter escapes from longer commit titles that break firefox

From
Jakub Narebski <jnareb@gmail.com>
Date
Apr 20, 2009, 09:32 UTC
Message-ID
<m3r5znpt5g.fsf@localhost.localdomain>
In-Reply-To
<1239985473-666-1-git-send-email-paul.gortmaker@windriver.com>
Paul Gortmaker <paul.gortmaker@windriver.com> writes:
Show 11 quoted lines
> If there is a commit that ends in ^X and is longer in length than
> what will fit in title_short, then it doesn't get fed through
> esc_html() and so the ^X will appear as-is in the page source.
> 
> When Firefox comes across this, it will fail to display the page,
> and only display a couple lines of error messages that read like:
> 
>    XML Parsing Error: not well-formed
>    Location: http://git ....
> 
> Signed-off-by: Paul Gortmaker <paul.gortmaker@windriver.com>

This is an issue for when project doesn't follow sanity (control characters in commit message) nor commit message conventions of git (limiting length of first line of commit message to 60-70 characters).

But I do not think that the solution presented here is good solution for this problem. chop_and_escape_str is meant as _output_ filter, because it generates (can generate) fragment of HTML. It is not a good solution to use it for shortening in intermediate representation of %co{'title'}.

And I think that issue might be a bug elsewhere in gitweb if we have text output which is not passed through esc_html... or bug in CGI.pm if the error is in not escaping of -title _attribute_ (attribute escaping has slightly different rules than escaping HTML, and should be done automatically by CGI.pm).

So thanks for noticing the issue, but NAK on the solution.
Show 20 quoted lines
> ---
>  gitweb/gitweb.perl |    2 +-
>  1 files changed, 1 insertions(+), 1 deletions(-)
> 
> diff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl
> index 33ef190..e686e82 100755
> --- a/gitweb/gitweb.perl
> +++ b/gitweb/gitweb.perl
> @@ -2470,7 +2470,7 @@ sub parse_commit_text {
>  	foreach my $title (@commit_lines) {
>  		$title =~ s/^    //;
>  		if ($title ne "") {
> -			$co{'title'} = chop_str($title, 80, 5);
> +			$co{'title'} = chop_and_escape_str($title, 80, 5);
>  			# remove leading stuff of merges to make the interesting part visible
>  			if (length($title) > 50) {
>  				$title =~ s/^Automatic //;
> -- 
> 1.6.2.3
> 
-- 
Jakub Narebski
Poland
ShadeHawk on #git
Previous: Paul GortmakerNext: Paul Gortmaker
Message 2 of 7 in “gitweb: filter escapes from longer commit titles that break firefox”
  1. gitweb: filter escapes from longer commit titles that break firefoxPaul Gortmaker, Apr 17, 2009
  2. Jakub NarebskiApr 20, 2009
  3. Paul GortmakerApr 20, 2009
  4. Jakub NarebskiApr 24, 2009
  5. Paul GortmakerApr 24, 2009
  6. Jakub NarebskiApr 24, 2009
  7. Jakub NarebskiApr 25, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.