Blob


1 /*
2 * Copyright (c) 2016, 2019, 2020-2022 Tracey Emery <tracey@traceyemery.net>
3 * Copyright (c) 2015 Mike Larkin <mlarkin@openbsd.org>
4 * Copyright (c) 2014 Reyk Floeter <reyk@openbsd.org>
5 * Copyright (c) 2013 David Gwynne <dlg@openbsd.org>
6 * Copyright (c) 2013 Florian Obser <florian@openbsd.org>
7 *
8 * Permission to use, copy, modify, and distribute this software for any
9 * purpose with or without fee is hereby granted, provided that the above
10 * copyright notice and this permission notice appear in all copies.
11 *
12 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
13 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
14 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
15 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
16 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
17 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
18 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
19 */
20 #include "got_compat.h"
22 #include <net/if.h>
23 #include <netinet/in.h>
24 #include <sys/queue.h>
25 #include <sys/stat.h>
26 #include <sys/types.h>
28 #include <ctype.h>
29 #include <dirent.h>
30 #include <errno.h>
31 #include <event.h>
32 #include <fcntl.h>
33 #include <imsg.h>
34 #include <stdio.h>
35 #include <stdlib.h>
36 #include <string.h>
37 #include <unistd.h>
39 #include "got_error.h"
40 #include "got_object.h"
41 #include "got_reference.h"
42 #include "got_repository.h"
43 #include "got_path.h"
44 #include "got_cancel.h"
45 #include "got_worktree.h"
46 #include "got_diff.h"
47 #include "got_commit_graph.h"
48 #include "got_blame.h"
49 #include "got_privsep.h"
51 #include "proc.h"
52 #include "gotwebd.h"
53 #include "tmpl.h"
55 static const struct querystring_keys querystring_keys[] = {
56 { "action", ACTION },
57 { "commit", COMMIT },
58 { "file", RFILE },
59 { "folder", FOLDER },
60 { "headref", HEADREF },
61 { "index_page", INDEX_PAGE },
62 { "path", PATH },
63 { "page", PAGE },
64 };
66 static const struct action_keys action_keys[] = {
67 { "blame", BLAME },
68 { "blob", BLOB },
69 { "blobraw", BLOBRAW },
70 { "briefs", BRIEFS },
71 { "commits", COMMITS },
72 { "diff", DIFF },
73 { "error", ERR },
74 { "index", INDEX },
75 { "summary", SUMMARY },
76 { "tag", TAG },
77 { "tags", TAGS },
78 { "tree", TREE },
79 { "rss", RSS },
80 };
82 static const struct got_error *gotweb_init_querystring(struct querystring **);
83 static const struct got_error *gotweb_parse_querystring(struct querystring **,
84 char *);
85 static const struct got_error *gotweb_assign_querystring(struct querystring **,
86 char *, char *);
87 static int gotweb_render_index(struct template *);
88 static const struct got_error *gotweb_init_repo_dir(struct repo_dir **,
89 const char *);
90 static const struct got_error *gotweb_load_got_path(struct request *c,
91 struct repo_dir *);
92 static const struct got_error *gotweb_get_repo_description(char **,
93 struct server *, const char *, int);
94 static const struct got_error *gotweb_get_clone_url(char **, struct server *,
95 const char *, int);
97 static void gotweb_free_querystring(struct querystring *);
98 static void gotweb_free_repo_dir(struct repo_dir *);
100 struct server *gotweb_get_server(const char *);
102 static int
103 gotweb_reply(struct request *c, int status, const char *ctype,
104 struct gotweb_url *location)
106 const char *csp;
108 if (status != 200 && tp_writef(c->tp, "Status: %d\r\n", status) == -1)
109 return -1;
111 if (location) {
112 if (tp_writes(c->tp, "Location: ") == -1 ||
113 gotweb_render_url(c, location) == -1 ||
114 tp_writes(c->tp, "\r\n") == -1)
115 return -1;
118 csp = "Content-Security-Policy: default-src 'self'; "
119 "script-src 'none'; object-src 'none';\r\n";
120 if (tp_writes(c->tp, csp) == -1)
121 return -1;
123 if (ctype && tp_writef(c->tp, "Content-Type: %s\r\n", ctype) == -1)
124 return -1;
126 return tp_writes(c->tp, "\r\n");
129 static int
130 gotweb_reply_file(struct request *c, const char *ctype, const char *file,
131 const char *suffix)
133 int r;
135 r = tp_writef(c->tp, "Content-Disposition: attachment; "
136 "filename=%s%s\r\n", file, suffix ? suffix : "");
137 if (r == -1)
138 return -1;
139 return gotweb_reply(c, 200, ctype, NULL);
142 void
143 gotweb_process_request(struct request *c)
145 const struct got_error *error = NULL;
146 struct server *srv = NULL;
147 struct querystring *qs = NULL;
148 struct repo_dir *repo_dir = NULL;
149 const char *rss_ctype = "application/rss+xml;charset=utf-8";
150 const uint8_t *buf;
151 size_t len;
152 int r, binary = 0;
154 /* init the transport */
155 error = gotweb_init_transport(&c->t);
156 if (error) {
157 log_warnx("%s: %s", __func__, error->msg);
158 return;
160 /* don't process any further if client disconnected */
161 if (c->sock->client_status == CLIENT_DISCONNECT)
162 return;
163 /* get the gotwebd server */
164 srv = gotweb_get_server(c->server_name);
165 if (srv == NULL) {
166 log_warnx("%s: error server is NULL", __func__);
167 goto err;
169 c->srv = srv;
170 /* parse our querystring */
171 error = gotweb_init_querystring(&qs);
172 if (error) {
173 log_warnx("%s: %s", __func__, error->msg);
174 goto err;
176 c->t->qs = qs;
177 error = gotweb_parse_querystring(&qs, c->querystring);
178 if (error) {
179 log_warnx("%s: %s", __func__, error->msg);
180 goto err;
183 /*
184 * certain actions require a commit id in the querystring. this stops
185 * bad actors from exploiting this by manually manipulating the
186 * querystring.
187 */
189 if (qs->action == BLAME || qs->action == BLOB ||
190 qs->action == BLOBRAW || qs->action == DIFF) {
191 if (qs->commit == NULL) {
192 error = got_error(GOT_ERR_BAD_QUERYSTRING);
193 goto err;
197 if (qs->action != INDEX) {
198 error = gotweb_init_repo_dir(&repo_dir, qs->path);
199 if (error)
200 goto err;
201 error = gotweb_load_got_path(c, repo_dir);
202 c->t->repo_dir = repo_dir;
203 if (error && error->code != GOT_ERR_LONELY_PACKIDX)
204 goto err;
207 if (qs->action == BLOBRAW || qs->action == BLOB) {
208 error = got_get_repo_commits(c, 1);
209 if (error)
210 goto err;
212 error = got_open_blob_for_output(&c->t->blob, &c->t->fd,
213 &binary, c);
214 if (error)
215 goto err;
218 switch(qs->action) {
219 case BLAME:
220 error = got_get_repo_commits(c, 1);
221 if (error) {
222 log_warnx("%s: %s", __func__, error->msg);
223 goto err;
225 if (gotweb_reply(c, 200, "text/html", NULL) == -1)
226 return;
227 gotweb_render_page(c->tp, gotweb_render_blame);
228 return;
229 case BLOB:
230 if (binary) {
231 struct gotweb_url url = {
232 .index_page = -1,
233 .page = -1,
234 .action = BLOBRAW,
235 .path = qs->path,
236 .commit = qs->commit,
237 .folder = qs->folder,
238 .file = qs->file,
239 };
241 gotweb_reply(c, 302, NULL, &url);
242 return;
245 if (gotweb_reply(c, 200, "text/html", NULL) == -1)
246 return;
247 gotweb_render_page(c->tp, gotweb_render_blob);
248 return;
249 case BLOBRAW:
250 if (binary)
251 r = gotweb_reply_file(c, "application/octet-stream",
252 qs->file, NULL);
253 else
254 r = gotweb_reply(c, 200, "text/plain", NULL);
255 if (r == -1)
256 return;
257 if (template_flush(c->tp) == -1)
258 return;
260 for (;;) {
261 error = got_object_blob_read_block(&len, c->t->blob);
262 if (error)
263 break;
264 if (len == 0)
265 break;
266 buf = got_object_blob_get_read_buf(c->t->blob);
267 if (fcgi_write(c, buf, len) == -1)
268 break;
270 return;
271 case BRIEFS:
272 error = got_get_repo_commits(c, srv->max_commits_display);
273 if (error)
274 goto err;
275 if (gotweb_reply(c, 200, "text/html", NULL) == -1)
276 return;
277 gotweb_render_page(c->tp, gotweb_render_briefs);
278 return;
279 case COMMITS:
280 error = got_get_repo_commits(c, srv->max_commits_display);
281 if (error) {
282 log_warnx("%s: %s", __func__, error->msg);
283 goto err;
285 if (gotweb_reply(c, 200, "text/html", NULL) == -1)
286 return;
287 gotweb_render_page(c->tp, gotweb_render_commits);
288 return;
289 case DIFF:
290 error = got_get_repo_commits(c, 1);
291 if (error) {
292 log_warnx("%s: %s", __func__, error->msg);
293 goto err;
295 error = got_open_diff_for_output(&c->t->fp, c);
296 if (error) {
297 log_warnx("%s: %s", __func__, error->msg);
298 goto err;
300 if (gotweb_reply(c, 200, "text/html", NULL) == -1)
301 return;
302 gotweb_render_page(c->tp, gotweb_render_diff);
303 return;
304 case INDEX:
305 c->t->nrepos = scandir(srv->repos_path, &c->t->repos, NULL,
306 alphasort);
307 if (c->t->nrepos == -1) {
308 c->t->repos = NULL;
309 error = got_error_from_errno2("scandir",
310 srv->repos_path);
311 goto err;
313 if (gotweb_reply(c, 200, "text/html", NULL) == -1)
314 return;
315 gotweb_render_page(c->tp, gotweb_render_index);
316 return;
317 case RSS:
318 error = got_get_repo_tags(c, D_MAXSLCOMMDISP);
319 if (error)
320 goto err;
321 if (gotweb_reply_file(c, rss_ctype, repo_dir->name, ".rss")
322 == -1)
323 return;
324 gotweb_render_rss(c->tp);
325 return;
326 case SUMMARY:
327 error = got_ref_list(&c->t->refs, c->t->repo, "refs/heads",
328 got_ref_cmp_by_name, NULL);
329 if (error) {
330 log_warnx("%s: got_ref_list: %s", __func__,
331 error->msg);
332 goto err;
334 error = got_get_repo_commits(c, D_MAXSLCOMMDISP);
335 if (error)
336 goto err;
337 qs->action = TAGS;
338 error = got_get_repo_tags(c, D_MAXSLCOMMDISP);
339 if (error) {
340 log_warnx("%s: got_get_repo_tags: %s", __func__,
341 error->msg);
342 goto err;
344 qs->action = SUMMARY;
345 if (gotweb_reply(c, 200, "text/html", NULL) == -1)
346 return;
347 gotweb_render_page(c->tp, gotweb_render_summary);
348 return;
349 case TAG:
350 error = got_get_repo_tags(c, 1);
351 if (error) {
352 log_warnx("%s: %s", __func__, error->msg);
353 goto err;
355 if (c->t->tag_count == 0) {
356 error = got_error_msg(GOT_ERR_BAD_OBJ_ID,
357 "bad commit id");
358 goto err;
360 if (gotweb_reply(c, 200, "text/html", NULL) == -1)
361 return;
362 gotweb_render_page(c->tp, gotweb_render_tag);
363 return;
364 case TAGS:
365 error = got_get_repo_tags(c, srv->max_commits_display);
366 if (error) {
367 log_warnx("%s: %s", __func__, error->msg);
368 goto err;
370 if (gotweb_reply(c, 200, "text/html", NULL) == -1)
371 return;
372 gotweb_render_page(c->tp, gotweb_render_tags);
373 return;
374 case TREE:
375 error = got_get_repo_commits(c, 1);
376 if (error) {
377 log_warnx("%s: %s", __func__, error->msg);
378 goto err;
380 if (gotweb_reply(c, 200, "text/html", NULL) == -1)
381 return;
382 gotweb_render_page(c->tp, gotweb_render_tree);
383 return;
384 case ERR:
385 default:
386 error = got_error(GOT_ERR_BAD_QUERYSTRING);
389 err:
390 c->t->error = error;
391 if (gotweb_reply(c, 400, "text/html", NULL) == -1)
392 return;
393 gotweb_render_page(c->tp, gotweb_render_error);
396 struct server *
397 gotweb_get_server(const char *server_name)
399 struct server *srv;
401 /* check against the server name first */
402 if (*server_name != '\0')
403 TAILQ_FOREACH(srv, &gotwebd_env->servers, entry)
404 if (strcmp(srv->name, server_name) == 0)
405 return srv;
407 /* otherwise, use the first server */
408 return TAILQ_FIRST(&gotwebd_env->servers);
409 };
411 const struct got_error *
412 gotweb_init_transport(struct transport **t)
414 const struct got_error *error = NULL;
416 *t = calloc(1, sizeof(**t));
417 if (*t == NULL)
418 return got_error_from_errno2(__func__, "calloc");
420 TAILQ_INIT(&(*t)->repo_commits);
421 TAILQ_INIT(&(*t)->repo_tags);
422 TAILQ_INIT(&(*t)->refs);
424 (*t)->fd = -1;
426 return error;
429 static const struct got_error *
430 gotweb_init_querystring(struct querystring **qs)
432 const struct got_error *error = NULL;
434 *qs = calloc(1, sizeof(**qs));
435 if (*qs == NULL)
436 return got_error_from_errno2(__func__, "calloc");
438 (*qs)->headref = strdup("HEAD");
439 if ((*qs)->headref == NULL) {
440 free(*qs);
441 *qs = NULL;
442 return got_error_from_errno2(__func__, "strdup");
445 (*qs)->action = INDEX;
446 (*qs)->commit = NULL;
447 (*qs)->file = NULL;
448 (*qs)->folder = NULL;
449 (*qs)->index_page = 0;
450 (*qs)->path = NULL;
452 return error;
455 static const struct got_error *
456 gotweb_parse_querystring(struct querystring **qs, char *qst)
458 const struct got_error *error = NULL;
459 char *tok1 = NULL, *tok1_pair = NULL, *tok1_end = NULL;
460 char *tok2 = NULL, *tok2_pair = NULL, *tok2_end = NULL;
462 if (qst == NULL)
463 return error;
465 tok1 = strdup(qst);
466 if (tok1 == NULL)
467 return got_error_from_errno2(__func__, "strdup");
469 tok1_pair = tok1;
470 tok1_end = tok1;
472 while (tok1_pair != NULL) {
473 strsep(&tok1_end, "&");
475 tok2 = strdup(tok1_pair);
476 if (tok2 == NULL) {
477 free(tok1);
478 return got_error_from_errno2(__func__, "strdup");
481 tok2_pair = tok2;
482 tok2_end = tok2;
484 while (tok2_pair != NULL) {
485 strsep(&tok2_end, "=");
486 if (tok2_end) {
487 error = gotweb_assign_querystring(qs, tok2_pair,
488 tok2_end);
489 if (error)
490 goto err;
492 tok2_pair = tok2_end;
494 free(tok2);
495 tok1_pair = tok1_end;
497 free(tok1);
498 return error;
499 err:
500 free(tok2);
501 free(tok1);
502 return error;
505 /*
506 * Adapted from usr.sbin/httpd/httpd.c url_decode.
507 */
508 static const struct got_error *
509 gotweb_urldecode(char *url)
511 char *p, *q;
512 char hex[3];
513 unsigned long x;
515 hex[2] = '\0';
516 p = q = url;
518 while (*p != '\0') {
519 switch (*p) {
520 case '%':
521 /* Encoding character is followed by two hex chars */
522 if (!isxdigit((unsigned char)p[1]) ||
523 !isxdigit((unsigned char)p[2]) ||
524 (p[1] == '0' && p[2] == '0'))
525 return got_error(GOT_ERR_BAD_QUERYSTRING);
527 hex[0] = p[1];
528 hex[1] = p[2];
530 /*
531 * We don't have to validate "hex" because it is
532 * guaranteed to include two hex chars followed by nul.
533 */
534 x = strtoul(hex, NULL, 16);
535 *q = (char)x;
536 p += 2;
537 break;
538 default:
539 *q = *p;
540 break;
542 p++;
543 q++;
545 *q = '\0';
547 return NULL;
550 static const struct got_error *
551 gotweb_assign_querystring(struct querystring **qs, char *key, char *value)
553 const struct got_error *error = NULL;
554 const char *errstr;
555 int a_cnt, el_cnt;
557 error = gotweb_urldecode(value);
558 if (error)
559 return error;
561 for (el_cnt = 0; el_cnt < QSELEM__MAX; el_cnt++) {
562 if (strcmp(key, querystring_keys[el_cnt].name) != 0)
563 continue;
565 switch (querystring_keys[el_cnt].element) {
566 case ACTION:
567 for (a_cnt = 0; a_cnt < ACTIONS__MAX; a_cnt++) {
568 if (strcmp(value, action_keys[a_cnt].name) != 0)
569 continue;
570 else if (strcmp(value,
571 action_keys[a_cnt].name) == 0){
572 (*qs)->action =
573 action_keys[a_cnt].action;
574 goto qa_found;
577 (*qs)->action = ERR;
578 qa_found:
579 break;
580 case COMMIT:
581 (*qs)->commit = strdup(value);
582 if ((*qs)->commit == NULL) {
583 error = got_error_from_errno2(__func__,
584 "strdup");
585 goto done;
587 break;
588 case RFILE:
589 (*qs)->file = strdup(value);
590 if ((*qs)->file == NULL) {
591 error = got_error_from_errno2(__func__,
592 "strdup");
593 goto done;
595 break;
596 case FOLDER:
597 (*qs)->folder = strdup(value);
598 if ((*qs)->folder == NULL) {
599 error = got_error_from_errno2(__func__,
600 "strdup");
601 goto done;
603 break;
604 case HEADREF:
605 free((*qs)->headref);
606 (*qs)->headref = strdup(value);
607 if ((*qs)->headref == NULL) {
608 error = got_error_from_errno2(__func__,
609 "strdup");
610 goto done;
612 break;
613 case INDEX_PAGE:
614 if (*value == '\0')
615 break;
616 (*qs)->index_page = strtonum(value, INT64_MIN,
617 INT64_MAX, &errstr);
618 if (errstr) {
619 error = got_error_from_errno3(__func__,
620 "strtonum", errstr);
621 goto done;
623 if ((*qs)->index_page < 0)
624 (*qs)->index_page = 0;
625 break;
626 case PATH:
627 (*qs)->path = strdup(value);
628 if ((*qs)->path == NULL) {
629 error = got_error_from_errno2(__func__,
630 "strdup");
631 goto done;
633 break;
634 case PAGE:
635 if (*value == '\0')
636 break;
637 (*qs)->page = strtonum(value, INT64_MIN,
638 INT64_MAX, &errstr);
639 if (errstr) {
640 error = got_error_from_errno3(__func__,
641 "strtonum", errstr);
642 goto done;
644 if ((*qs)->page < 0)
645 (*qs)->page = 0;
646 break;
647 default:
648 break;
651 done:
652 return error;
655 void
656 gotweb_free_repo_tag(struct repo_tag *rt)
658 if (rt != NULL) {
659 free(rt->commit_id);
660 free(rt->tag_name);
661 free(rt->tag_commit);
662 free(rt->commit_msg);
663 free(rt->tagger);
665 free(rt);
668 void
669 gotweb_free_repo_commit(struct repo_commit *rc)
671 if (rc != NULL) {
672 free(rc->path);
673 free(rc->refs_str);
674 free(rc->commit_id);
675 free(rc->parent_id);
676 free(rc->tree_id);
677 free(rc->author);
678 free(rc->committer);
679 free(rc->commit_msg);
681 free(rc);
684 static void
685 gotweb_free_querystring(struct querystring *qs)
687 if (qs != NULL) {
688 free(qs->commit);
689 free(qs->file);
690 free(qs->folder);
691 free(qs->headref);
692 free(qs->path);
694 free(qs);
697 static void
698 gotweb_free_repo_dir(struct repo_dir *repo_dir)
700 if (repo_dir != NULL) {
701 free(repo_dir->name);
702 free(repo_dir->owner);
703 free(repo_dir->description);
704 free(repo_dir->url);
705 free(repo_dir->path);
707 free(repo_dir);
710 void
711 gotweb_free_transport(struct transport *t)
713 const struct got_error *err;
714 struct repo_commit *rc = NULL, *trc = NULL;
715 struct repo_tag *rt = NULL, *trt = NULL;
716 int i;
718 got_ref_list_free(&t->refs);
719 TAILQ_FOREACH_SAFE(rc, &t->repo_commits, entry, trc) {
720 TAILQ_REMOVE(&t->repo_commits, rc, entry);
721 gotweb_free_repo_commit(rc);
723 TAILQ_FOREACH_SAFE(rt, &t->repo_tags, entry, trt) {
724 TAILQ_REMOVE(&t->repo_tags, rt, entry);
725 gotweb_free_repo_tag(rt);
727 gotweb_free_repo_dir(t->repo_dir);
728 gotweb_free_querystring(t->qs);
729 free(t->more_id);
730 free(t->next_id);
731 free(t->prev_id);
732 if (t->blob)
733 got_object_blob_close(t->blob);
734 if (t->fp) {
735 err = got_gotweb_closefile(t->fp);
736 if (err)
737 log_warnx("%s: got_gotweb_closefile failure: %s",
738 __func__, err->msg);
740 if (t->fd != -1 && close(t->fd) == -1)
741 log_warn("%s: close", __func__);
742 if (t->repos) {
743 for (i = 0; i < t->nrepos; ++i)
744 free(t->repos[i]);
745 free(t->repos);
747 free(t);
750 void
751 gotweb_get_navs(struct request *c, struct gotweb_url *prev, int *have_prev,
752 struct gotweb_url *next, int *have_next)
754 struct transport *t = c->t;
755 struct querystring *qs = t->qs;
756 struct server *srv = c->srv;
758 *have_prev = *have_next = 0;
760 switch(qs->action) {
761 case INDEX:
762 if (qs->index_page > 0) {
763 *have_prev = 1;
764 *prev = (struct gotweb_url){
765 .action = -1,
766 .index_page = qs->index_page - 1,
767 .page = -1,
768 };
770 if (t->next_disp == srv->max_repos_display &&
771 t->repos_total != (qs->index_page + 1) *
772 srv->max_repos_display) {
773 *have_next = 1;
774 *next = (struct gotweb_url){
775 .action = -1,
776 .index_page = qs->index_page + 1,
777 .page = -1,
778 };
780 break;
781 case TAGS:
782 if (t->prev_id && qs->commit != NULL &&
783 strcmp(qs->commit, t->prev_id) != 0) {
784 *have_prev = 1;
785 *prev = (struct gotweb_url){
786 .action = TAGS,
787 .index_page = -1,
788 .page = qs->page - 1,
789 .path = qs->path,
790 .commit = t->prev_id,
791 .headref = qs->headref,
792 };
794 if (t->next_id) {
795 *have_next = 1;
796 *next = (struct gotweb_url){
797 .action = TAGS,
798 .index_page = -1,
799 .page = qs->page + 1,
800 .path = qs->path,
801 .commit = t->next_id,
802 .headref = qs->headref,
803 };
805 break;
809 static int
810 gotweb_render_index(struct template *tp)
812 const struct got_error *error = NULL;
813 struct request *c = tp->tp_arg;
814 struct server *srv = c->srv;
815 struct transport *t = c->t;
816 struct querystring *qs = t->qs;
817 struct repo_dir *repo_dir = NULL;
818 struct dirent **sd_dent = t->repos;
819 unsigned int d_i, d_disp = 0;
820 unsigned int d_skipped = 0;
821 int type, r;
823 if (gotweb_render_repo_table_hdr(c->tp) == -1)
824 return -1;
826 for (d_i = 0; d_i < t->nrepos; d_i++) {
827 if (srv->max_repos > 0 && t->prev_disp == srv->max_repos)
828 break;
830 if (strcmp(sd_dent[d_i]->d_name, ".") == 0 ||
831 strcmp(sd_dent[d_i]->d_name, "..") == 0) {
832 d_skipped++;
833 continue;
836 error = got_path_dirent_type(&type, srv->repos_path,
837 sd_dent[d_i]);
838 if (error)
839 continue;
840 if (type != DT_DIR) {
841 d_skipped++;
842 continue;
845 if (qs->index_page > 0 && (qs->index_page *
846 srv->max_repos_display) > t->prev_disp) {
847 t->prev_disp++;
848 continue;
851 error = gotweb_init_repo_dir(&repo_dir, sd_dent[d_i]->d_name);
852 if (error)
853 continue;
855 error = gotweb_load_got_path(c, repo_dir);
856 if (error && error->code != GOT_ERR_LONELY_PACKIDX) {
857 if (error->code != GOT_ERR_NOT_GIT_REPO)
858 log_warnx("%s: %s: %s", __func__,
859 sd_dent[d_i]->d_name, error->msg);
860 gotweb_free_repo_dir(repo_dir);
861 repo_dir = NULL;
862 d_skipped++;
863 continue;
866 d_disp++;
867 t->prev_disp++;
869 r = gotweb_render_repo_fragment(c->tp, repo_dir);
870 gotweb_free_repo_dir(repo_dir);
871 if (r == -1)
872 return -1;
874 t->next_disp++;
875 if (d_disp == srv->max_repos_display)
876 break;
878 t->repos_total = t->nrepos - d_skipped;
880 if (srv->max_repos_display == 0)
881 return 0;
882 if (srv->max_repos > 0 && srv->max_repos < srv->max_repos_display)
883 return 0;
884 if (t->repos_total <= srv->max_repos ||
885 t->repos_total <= srv->max_repos_display)
886 return 0;
888 if (gotweb_render_navs(c->tp) == -1)
889 return -1;
891 return 0;
894 static inline int
895 should_urlencode(int c)
897 if (c <= ' ' || c >= 127)
898 return 1;
900 switch (c) {
901 /* gen-delim */
902 case ':':
903 case '/':
904 case '?':
905 case '#':
906 case '[':
907 case ']':
908 case '@':
909 /* sub-delims */
910 case '!':
911 case '$':
912 case '&':
913 case '\'':
914 case '(':
915 case ')':
916 case '*':
917 case '+':
918 case ',':
919 case ';':
920 case '=':
921 /* needed because the URLs are embedded into the HTML */
922 case '\"':
923 return 1;
924 default:
925 return 0;
929 static char *
930 gotweb_urlencode(const char *str)
932 const char *s;
933 char *escaped;
934 size_t i, len;
935 int a, b;
937 len = 0;
938 for (s = str; *s; ++s) {
939 len++;
940 if (should_urlencode(*s))
941 len += 2;
944 escaped = calloc(1, len + 1);
945 if (escaped == NULL)
946 return NULL;
948 i = 0;
949 for (s = str; *s; ++s) {
950 if (should_urlencode(*s)) {
951 a = (*s & 0xF0) >> 4;
952 b = (*s & 0x0F);
954 escaped[i++] = '%';
955 escaped[i++] = a <= 9 ? ('0' + a) : ('7' + a);
956 escaped[i++] = b <= 9 ? ('0' + b) : ('7' + b);
957 } else
958 escaped[i++] = *s;
961 return escaped;
964 const char *
965 gotweb_action_name(int action)
967 switch (action) {
968 case BLAME:
969 return "blame";
970 case BLOB:
971 return "blob";
972 case BLOBRAW:
973 return "blobraw";
974 case BRIEFS:
975 return "briefs";
976 case COMMITS:
977 return "commits";
978 case DIFF:
979 return "diff";
980 case ERR:
981 return "err";
982 case INDEX:
983 return "index";
984 case SUMMARY:
985 return "summary";
986 case TAG:
987 return "tag";
988 case TAGS:
989 return "tags";
990 case TREE:
991 return "tree";
992 case RSS:
993 return "rss";
994 default:
995 return NULL;
999 int
1000 gotweb_render_url(struct request *c, struct gotweb_url *url)
1002 const char *sep = "?", *action;
1003 char *tmp;
1004 int r;
1006 action = gotweb_action_name(url->action);
1007 if (action != NULL) {
1008 if (tp_writef(c->tp, "?action=%s", action) == -1)
1009 return -1;
1010 sep = "&";
1013 if (url->commit) {
1014 if (tp_writef(c->tp, "%scommit=%s", sep, url->commit) == -1)
1015 return -1;
1016 sep = "&";
1019 if (url->previd) {
1020 if (tp_writef(c->tp, "%sprevid=%s", sep, url->previd) == -1)
1021 return -1;
1022 sep = "&";
1025 if (url->prevset) {
1026 if (tp_writef(c->tp, "%sprevset=%s", sep, url->prevset) == -1)
1027 return -1;
1028 sep = "&";
1031 if (url->file) {
1032 tmp = gotweb_urlencode(url->file);
1033 if (tmp == NULL)
1034 return -1;
1035 r = tp_writef(c->tp, "%sfile=%s", sep, tmp);
1036 free(tmp);
1037 if (r == -1)
1038 return -1;
1039 sep = "&";
1042 if (url->folder) {
1043 tmp = gotweb_urlencode(url->folder);
1044 if (tmp == NULL)
1045 return -1;
1046 r = tp_writef(c->tp, "%sfolder=%s", sep, tmp);
1047 free(tmp);
1048 if (r == -1)
1049 return -1;
1050 sep = "&";
1053 if (url->headref) {
1054 tmp = gotweb_urlencode(url->headref);
1055 if (tmp == NULL)
1056 return -1;
1057 r = tp_writef(c->tp, "%sheadref=%s", sep, url->headref);
1058 free(tmp);
1059 if (r == -1)
1060 return -1;
1061 sep = "&";
1064 if (url->index_page != -1) {
1065 if (tp_writef(c->tp, "%sindex_page=%d", sep,
1066 url->index_page) == -1)
1067 return -1;
1068 sep = "&";
1071 if (url->path) {
1072 tmp = gotweb_urlencode(url->path);
1073 if (tmp == NULL)
1074 return -1;
1075 r = tp_writef(c->tp, "%spath=%s", sep, tmp);
1076 free(tmp);
1077 if (r == -1)
1078 return -1;
1079 sep = "&";
1082 if (url->page != -1) {
1083 if (tp_writef(c->tp, "%spage=%d", sep, url->page) == -1)
1084 return -1;
1085 sep = "&";
1088 return 0;
1091 int
1092 gotweb_render_absolute_url(struct request *c, struct gotweb_url *url)
1094 struct template *tp = c->tp;
1095 const char *proto = c->https ? "https" : "http";
1097 if (tp_writes(tp, proto) == -1 ||
1098 tp_writes(tp, "://") == -1 ||
1099 tp_htmlescape(tp, c->server_name) == -1 ||
1100 tp_htmlescape(tp, c->document_uri) == -1)
1101 return -1;
1103 return gotweb_render_url(c, url);
1106 static struct got_repository *
1107 find_cached_repo(struct server *srv, const char *path)
1109 int i;
1111 for (i = 0; i < srv->ncached_repos; i++) {
1112 if (strcmp(srv->cached_repos[i].path, path) == 0)
1113 return srv->cached_repos[i].repo;
1116 return NULL;
1119 static const struct got_error *
1120 cache_repo(struct got_repository **new, struct server *srv,
1121 struct repo_dir *repo_dir, struct socket *sock)
1123 const struct got_error *error = NULL;
1124 struct got_repository *repo;
1125 struct cached_repo *cr;
1126 int evicted = 0;
1128 if (srv->ncached_repos >= GOTWEBD_REPO_CACHESIZE) {
1129 cr = &srv->cached_repos[srv->ncached_repos - 1];
1130 error = got_repo_close(cr->repo);
1131 memset(cr, 0, sizeof(*cr));
1132 srv->ncached_repos--;
1133 if (error)
1134 return error;
1135 memmove(&srv->cached_repos[1], &srv->cached_repos[0],
1136 srv->ncached_repos * sizeof(srv->cached_repos[0]));
1137 cr = &srv->cached_repos[0];
1138 evicted = 1;
1139 } else {
1140 cr = &srv->cached_repos[srv->ncached_repos];
1143 error = got_repo_open(&repo, repo_dir->path, NULL, sock->pack_fds);
1144 if (error) {
1145 if (evicted) {
1146 memmove(&srv->cached_repos[0], &srv->cached_repos[1],
1147 srv->ncached_repos * sizeof(srv->cached_repos[0]));
1149 return error;
1152 if (strlcpy(cr->path, repo_dir->path, sizeof(cr->path))
1153 >= sizeof(cr->path)) {
1154 if (evicted) {
1155 memmove(&srv->cached_repos[0], &srv->cached_repos[1],
1156 srv->ncached_repos * sizeof(srv->cached_repos[0]));
1158 return got_error(GOT_ERR_NO_SPACE);
1161 cr->repo = repo;
1162 srv->ncached_repos++;
1163 *new = repo;
1164 return NULL;
1167 static const struct got_error *
1168 gotweb_load_got_path(struct request *c, struct repo_dir *repo_dir)
1170 const struct got_error *error = NULL;
1171 struct socket *sock = c->sock;
1172 struct server *srv = c->srv;
1173 struct transport *t = c->t;
1174 struct got_repository *repo = NULL;
1175 DIR *dt;
1176 char *dir_test;
1178 if (asprintf(&dir_test, "%s/%s/%s", srv->repos_path, repo_dir->name,
1179 GOTWEB_GIT_DIR) == -1)
1180 return got_error_from_errno("asprintf");
1182 dt = opendir(dir_test);
1183 if (dt == NULL) {
1184 free(dir_test);
1185 } else {
1186 repo_dir->path = dir_test;
1187 dir_test = NULL;
1188 goto done;
1191 if (asprintf(&dir_test, "%s/%s", srv->repos_path,
1192 repo_dir->name) == -1)
1193 return got_error_from_errno("asprintf");
1195 dt = opendir(dir_test);
1196 if (dt == NULL) {
1197 error = got_error_path(repo_dir->name, GOT_ERR_NOT_GIT_REPO);
1198 goto err;
1199 } else {
1200 repo_dir->path = dir_test;
1201 dir_test = NULL;
1204 done:
1205 if (srv->respect_exportok &&
1206 faccessat(dirfd(dt), "git-daemon-export-ok", F_OK, 0) == -1) {
1207 error = got_error_path(repo_dir->name, GOT_ERR_NOT_GIT_REPO);
1208 goto err;
1211 repo = find_cached_repo(srv, repo_dir->path);
1212 if (repo == NULL) {
1213 error = cache_repo(&repo, srv, repo_dir, sock);
1214 if (error)
1215 goto err;
1217 t->repo = repo;
1218 error = gotweb_get_repo_description(&repo_dir->description, srv,
1219 repo_dir->path, dirfd(dt));
1220 if (error)
1221 goto err;
1222 error = got_get_repo_owner(&repo_dir->owner, c);
1223 if (error)
1224 goto err;
1225 if (srv->show_repo_age) {
1226 error = got_get_repo_age(&repo_dir->age, c, NULL);
1227 if (error)
1228 goto err;
1230 error = gotweb_get_clone_url(&repo_dir->url, srv, repo_dir->path,
1231 dirfd(dt));
1232 err:
1233 free(dir_test);
1234 if (dt != NULL && closedir(dt) == EOF && error == NULL)
1235 error = got_error_from_errno("closedir");
1236 return error;
1239 static const struct got_error *
1240 gotweb_init_repo_dir(struct repo_dir **repo_dir, const char *dir)
1242 const struct got_error *error;
1244 *repo_dir = calloc(1, sizeof(**repo_dir));
1245 if (*repo_dir == NULL)
1246 return got_error_from_errno("calloc");
1248 if (asprintf(&(*repo_dir)->name, "%s", dir) == -1) {
1249 error = got_error_from_errno("asprintf");
1250 free(*repo_dir);
1251 *repo_dir = NULL;
1252 return error;
1254 (*repo_dir)->owner = NULL;
1255 (*repo_dir)->description = NULL;
1256 (*repo_dir)->url = NULL;
1257 (*repo_dir)->path = NULL;
1259 return NULL;
1262 static const struct got_error *
1263 gotweb_get_repo_description(char **description, struct server *srv,
1264 const char *dirpath, int dir)
1266 const struct got_error *error = NULL;
1267 struct stat sb;
1268 int fd = -1;
1269 off_t len;
1271 *description = NULL;
1272 if (srv->show_repo_description == 0)
1273 return NULL;
1275 fd = openat(dir, "description", O_RDONLY);
1276 if (fd == -1) {
1277 if (errno != ENOENT && errno != EACCES) {
1278 error = got_error_from_errno_fmt("openat %s/%s",
1279 dirpath, "description");
1281 goto done;
1284 if (fstat(fd, &sb) == -1) {
1285 error = got_error_from_errno_fmt("fstat %s/%s",
1286 dirpath, "description");
1287 goto done;
1290 len = sb.st_size;
1291 if (len > GOTWEBD_MAXDESCRSZ - 1)
1292 len = GOTWEBD_MAXDESCRSZ - 1;
1294 *description = calloc(len + 1, sizeof(**description));
1295 if (*description == NULL) {
1296 error = got_error_from_errno("calloc");
1297 goto done;
1300 if (read(fd, *description, len) == -1)
1301 error = got_error_from_errno("read");
1302 done:
1303 if (fd != -1 && close(fd) == -1 && error == NULL)
1304 error = got_error_from_errno("close");
1305 return error;
1308 static const struct got_error *
1309 gotweb_get_clone_url(char **url, struct server *srv, const char *dirpath,
1310 int dir)
1312 const struct got_error *error = NULL;
1313 struct stat sb;
1314 int fd = -1;
1315 off_t len;
1317 *url = NULL;
1318 if (srv->show_repo_cloneurl == 0)
1319 return NULL;
1321 fd = openat(dir, "cloneurl", O_RDONLY);
1322 if (fd == -1) {
1323 if (errno != ENOENT && errno != EACCES) {
1324 error = got_error_from_errno_fmt("openat %s/%s",
1325 dirpath, "cloneurl");
1327 goto done;
1330 if (fstat(fd, &sb) == -1) {
1331 error = got_error_from_errno_fmt("fstat %s/%s",
1332 dirpath, "cloneurl");
1333 goto done;
1336 len = sb.st_size;
1337 if (len > GOTWEBD_MAXCLONEURLSZ - 1)
1338 len = GOTWEBD_MAXCLONEURLSZ - 1;
1340 *url = calloc(len + 1, sizeof(**url));
1341 if (*url == NULL) {
1342 error = got_error_from_errno("calloc");
1343 goto done;
1346 if (read(fd, *url, len) == -1)
1347 error = got_error_from_errno("read");
1348 done:
1349 if (fd != -1 && close(fd) == -1 && error == NULL)
1350 error = got_error_from_errno("close");
1351 return error;
1354 int
1355 gotweb_render_age(struct template *tp, time_t committer_time, int ref_tm)
1357 struct request *c = tp->tp_arg;
1358 struct tm tm;
1359 long long diff_time;
1360 const char *years = "years ago", *months = "months ago";
1361 const char *weeks = "weeks ago", *days = "days ago";
1362 const char *hours = "hours ago", *minutes = "minutes ago";
1363 const char *seconds = "seconds ago", *now = "right now";
1364 char *s;
1365 char datebuf[64];
1366 size_t r;
1368 switch (ref_tm) {
1369 case TM_DIFF:
1370 diff_time = time(NULL) - committer_time;
1371 if (diff_time > 60 * 60 * 24 * 365 * 2) {
1372 if (tp_writef(c->tp, "%lld %s",
1373 (diff_time / 60 / 60 / 24 / 365), years) == -1)
1374 return -1;
1375 } else if (diff_time > 60 * 60 * 24 * (365 / 12) * 2) {
1376 if (tp_writef(c->tp, "%lld %s",
1377 (diff_time / 60 / 60 / 24 / (365 / 12)),
1378 months) == -1)
1379 return -1;
1380 } else if (diff_time > 60 * 60 * 24 * 7 * 2) {
1381 if (tp_writef(c->tp, "%lld %s",
1382 (diff_time / 60 / 60 / 24 / 7), weeks) == -1)
1383 return -1;
1384 } else if (diff_time > 60 * 60 * 24 * 2) {
1385 if (tp_writef(c->tp, "%lld %s",
1386 (diff_time / 60 / 60 / 24), days) == -1)
1387 return -1;
1388 } else if (diff_time > 60 * 60 * 2) {
1389 if (tp_writef(c->tp, "%lld %s",
1390 (diff_time / 60 / 60), hours) == -1)
1391 return -1;
1392 } else if (diff_time > 60 * 2) {
1393 if (tp_writef(c->tp, "%lld %s", (diff_time / 60),
1394 minutes) == -1)
1395 return -1;
1396 } else if (diff_time > 2) {
1397 if (tp_writef(c->tp, "%lld %s", diff_time,
1398 seconds) == -1)
1399 return -1;
1400 } else {
1401 if (tp_writes(tp, now) == -1)
1402 return -1;
1404 break;
1405 case TM_LONG:
1406 if (gmtime_r(&committer_time, &tm) == NULL)
1407 return -1;
1409 s = asctime_r(&tm, datebuf);
1410 if (s == NULL)
1411 return -1;
1413 if (tp_writes(tp, datebuf) == -1 ||
1414 tp_writes(tp, " UTC") == -1)
1415 return -1;
1416 break;
1417 case TM_RFC822:
1418 if (gmtime_r(&committer_time, &tm) == NULL)
1419 return -1;
1421 r = strftime(datebuf, sizeof(datebuf),
1422 "%a, %d %b %Y %H:%M:%S GMT", &tm);
1423 if (r == 0)
1424 return -1;
1426 if (tp_writes(tp, datebuf) == -1)
1427 return -1;
1428 break;
1430 return 0;