git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] gitweb: Improve repository verification

From
JHJunio C Hamano <jch@google.com>
Date
Apr 19, 2012, 18:30 UTC
Message-ID
<xmqq397zwp4c.fsf@junio.mtv.corp.google.com>
In-Reply-To
<201204191807.32410.jnareb@gmail.com>
Jakub Narebski <jnareb@gmail.com> writes:
Show 25 quoted lines
> Bring repository verification in check_export_ok() to standards of
> is_git_directory function from setup.c (core git), and validate_headref()
> to standards of the same function in path.c,... and a bit more.
>
> validate_headref() replaces check_head_link(); note that the former
> requires path to HEAD file, while the late latter path to repository.
>
> Issues of note:
> * is_git_directory() in gitweb is a bit stricter: it checks that
>   "/objects" and "/refs" are directories, and not only 'executable'
>   permission,
> * validate_headref() in gitweb is a bit stricter: it checks that
>   reference symlink or symref points to starts with "refs/heads/",
>   and not only with "refs/",
> * calls to check_head_link(), all of which were meant to check if
>   given directory can be a git repository, were replaced by newly
>   introduced is_git_directory().
>
> This change is preparation for removing "Last change" column from list
> of projects, which is currently used also for validating repository.
>
> Suggested-by: Kacper Kornet <draenog@pld-linux.org>
> Signed-off-by: Jakub Narebski <jnareb@gmail.com>
> ---
> Here is how such first step could look like...

Do you mean by "could look like" that this is still an RFC, or is this something we want to apply and see how well it makes people's lives in the field?

By the way, I wonder (1) if it is worth adding support for the textual ".git" file that contains "gitdir: $path", and (2) if so how big a change would we need to do so.

Show 77 quoted lines
>  gitweb/gitweb.perl |   52 ++++++++++++++++++++++++++++++++++++++++++----------
>  1 files changed, 42 insertions(+), 10 deletions(-)
>
> diff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl
> index 098e527..767d7a5 100755
> --- a/gitweb/gitweb.perl
> +++ b/gitweb/gitweb.perl
> @@ -621,19 +621,51 @@ sub feature_avatar {
>  	return @val ? @val : @_;
>  }
>  
> -# checking HEAD file with -e is fragile if the repository was
> -# initialized long time ago (i.e. symlink HEAD) and was pack-ref'ed
> -# and then pruned.
> -sub check_head_link {
> -	my ($dir) = @_;
> -	my $headfile = "$dir/HEAD";
> -	return ((-e $headfile) ||
> -		(-l $headfile && readlink($headfile) =~ /^refs\/heads\//));
> +# Test if it looks like we're at a git directory.
> +# We want to see:
> +#
> +#  - an objects/ directory,
> +#  - a refs/ directory,
> +#  - either a HEAD symlink or a HEAD file that is formatted as
> +#    a proper "ref:", or a regular file HEAD that has a properly
> +#    formatted sha1 object name.
> +#
> +# See is_git_directory() in setup.c
> +sub is_git_directory {
> +	my $dir = shift;
> +	return
> +		-x "$dir/objects" && -d _ &&
> +		-x "$dir/refs"    && -d _ &&
> +		validate_headref("$dir/HEAD");
> +}
> +
> +# Check HEAD file, that it is either
> +#
> +#  - a "refs/heads/.." symlink, or
> +#  - a symbolic ref to "refs/heads/..", or
> +#  - a detached HEAD.
> +#
> +# See validate_headref() in path.c
> +sub validate_headref {
> +	my $headfile = shift;
> +	if (-l $headfile) {
> +		return readlink($headfile) =~ m!^refs/heads/!;
> +
> +	} elsif (-e _) {
> +		open my $fh, '<', $headfile or return;
> +		my $line = <$fh>;
> +		close $fh or return;
> +
> +		return
> +			$line =~ m!^ref:\s*refs/heads/! ||  # symref
> +			$line =~ m!^[0-9a-z]{40}$!i;        # detached HEAD
> +	}
> +	return;
>  }
>  
>  sub check_export_ok {
>  	my ($dir) = @_;
> -	return (check_head_link($dir) &&
> +	return (is_git_directory($dir) &&
>  		(!$export_ok || -e "$dir/$export_ok") &&
>  		(!$export_auth_hook || $export_auth_hook->($dir)));
>  }
> @@ -842,7 +874,7 @@ sub evaluate_path_info {
>  	# find which part of PATH_INFO is project
>  	my $project = $path_info;
>  	$project =~ s,/+$,,;
> -	while ($project && !check_head_link("$projectroot/$project")) {
> +	while ($project && !is_git_directory("$projectroot/$project")) {
>  		$project =~ s,/*[^/]*$,,;
>  	}
>  	return unless $project;
Previous: Jakub NarebskiNext: Jakub Narebski
Message 12 of 23 in “gitweb: Option to omit column with time of the last change”
  1. gitweb: Option to omit column with time of the last changeKacper Kornet, Apr 3, 2012
  2. Jakub NarebskiApr 3, 2012
  3. Kacper KornetApr 4, 2012
  4. Jakub NarebskiApr 4, 2012
  5. Kacper KornetApr 4, 2012
  6. Jakub NarebskiApr 14, 2012
  7. Kacper KornetApr 16, 2012
  8. Jakub NarebskiApr 16, 2012
  9. Kacper KornetApr 16, 2012
  10. Jakub NarebskiApr 17, 2012
  11. gitweb: Improve repository verificationJakub Narebski, Apr 19, 2012
  12. Junio C HamanoApr 19, 2012
  13. Jakub NarebskiApr 19, 2012
  14. Jakub NarebskiApr 21, 2012
  15. 1/2 gitweb: Option to omit column with time of the last changeKacper Kornet, Apr 24, 2012
  16. 2/2 gitweb: Option to not display information about ownerKacper Kornet, Apr 24, 2012
  17. Junio C HamanoApr 26, 2012
  18. Kacper KornetApr 26, 2012
  19. Junio C HamanoApr 26, 2012
  20. Kacper KornetApr 26, 2012
  21. 2/2 gitweb: Option to not display information about ownerKacper Kornet, Apr 26, 2012
  22. Kacper KornetApr 24, 2012
  23. Junio C HamanoApr 4, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.