Commit Briefs



Thomas Adam

initial pass over gotwebd docs

tracey is fine with gotwebd.8 but gotweb.conf.5 still needs some work


Thomas Adam

allow multiple "listen on" statements per server in gotwebd.conf

ok tracey



Thomas Adam

gotwebd: fix NULL deref on ENOMEM in gotweb_process_request

ok tracey@


Thomas Adam

gotwebd: fix memory leak introduced in d927f8c

ok tracey@


Thomas Adam

don't create signed tag objects with trailing NUL

Although Git itself did not care, the superfluous NUL at the end of the tag object was breaking GitHub's SSH signature detection. ok stsp@


Thomas Adam

portable: sockets: handle sa_len/ss_len portably

In the sockaddr_storage struct, there can be a ss_len field. This is seen on some BSDs, but not Linux. Since this isn't POSIX-specific, there's no guarantee it will be available on all systems.


Thomas Adam

gotwebd: add CSP policy

ok tracey@


Thomas Adam

gotwebd: fix for possible NULL beign passed to fcgi_printf

reported by and ok tracey@


Thomas Adam

gotwebd: make sure to escape possibly unsafe strings

this fixes only the HTML escaping of strings, the urlencode is still missig. while here also plug a memory leak in gotweb_render_branches and drop some needless ternary operators. ok tracey@


Thomas Adam

gotwebd: minor tweaks to the generated HTML

spotted by validator.w3.org: - use target="_blank" instead of `_sotd' - drop `alt' attributes in `a' tags This fixes all the errors reported; only a warning suggesting to add a `lang' attribute on the <html> tag remains.


Thomas Adam

mark functions internally used by sockets.c as static

ok tracey


Thomas Adam

fix previous: store port number in host byte order, convert for struct sockaddr

With the previous patch the listen port was correct, but the debug log output was still displaying the swapped port number. Now both listen behaviour and debug log output agree.



Thomas Adam

gotwebd: listen on localhost only by default

ok tracey



Thomas Adam

gotwebd: add fcgi_printf

instead of fcgi_gen_response which outputs only a fixed strings provide a printf-like fcgi_printf: it greatly simplifies the generation of the HTML pages. While here also (probably) fix some HTML errors: the output was verified with the W3C validator and it's correct (in the sense that the tags are properly closed, there are still some other things the validator complains about.) ok/encouragement baseprime@, ok jamsek Thanks for reading such a boring diff!


Thomas Adam

portable: configure: fix version string

Older autotools versions need extra coaxing when running external programs.


Thomas Adam

portable: ver: fix incorrect envvar


Thomas Adam

fix overflow in blame callback

spotted by noticing gotwebd crashing on some blame requests. Diff from stsp@ with a fix from tracey@, I'm committing it only because he is short on time. ok stsp@


Thomas Adam

gotwebd: initialize IPv4 and IPv6 sockets in the same way

ok tracey


Thomas Adam

gotwebd: don't listen on FCGI sockets when FCGI is not enabled

ok tracey


Thomas Adam

gotwebd: do not allocate server/socket list heads separately

ok millert@