mirror of
https://github.com/go-gitea/gitea.git
synced 2026-10-01 15:54:49 +00:00
1b1274486c
Introduces gitproxy module which spawns a small forward proxy as scanner for git calls Replaces hostmatcher with matchlist which supports port rules Deprecates ALLOWED_DOMAINS/BLOCKED_DOMAINS and ALLOW_LOCALNETWORKS settings in migration in favor of full names we have in security configs. Removes `external` preset in favor of lax/strict modes, strict mode requiring explicit ports if they aren't standard http/s ones. Breaking changes: - `external` preset no longer works as deny rule. To enforce that, use `strict` mode and allow ranges to connect to - Wildcards are no longer accepted in IP addresses - `*` is no longer allowed as entry in lists - domain rules now use curl like syntax `*.example.com` matching subdomains but not `example.com`, `example.com` matching itself and all subdomains. `example.*` is not a valid rule - In the default `lax` mode, `[security] ALLOWED_HOST_LIST` no longer restricts public hosts, set `EGRESS_MODE = strict` to keep an exclusive list. A startup warning flags this - Invalid list entries are logged at startup, invalid `BLOCKED_HOST_LIST`/`BLOCKED_DOMAINS` entries stop it Docs: https://gitea.com/gitea/docs/pulls/557 Signed-off-by: wxiaoguang <wxiaoguang@gmail.com> Co-authored-by: silverwind <me@silverwind.io> Co-authored-by: bircni <bircni@icloud.com> Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
49 lines
1.6 KiB
Go
49 lines
1.6 KiB
Go
// Copyright 2025 The Gitea Authors. All rights reserved.
|
|
// SPDX-License-Identifier: MIT
|
|
|
|
package gitcmd
|
|
|
|
import (
|
|
"fmt"
|
|
"os/exec"
|
|
"sync/atomic"
|
|
|
|
"gitea.dev/modules/log"
|
|
"gitea.dev/modules/setting"
|
|
)
|
|
|
|
var GitExecutable = "git" // the command name of git, will be updated to an absolute path during initialization
|
|
|
|
var extraEnvs atomic.Pointer[[]string]
|
|
|
|
// SetExtraEnvs adds envs to every git command, the git proxy routes git's network remotes with them
|
|
func SetExtraEnvs(envs []string) {
|
|
extraEnvs.Store(&envs)
|
|
}
|
|
|
|
// SetExecutablePath changes the path of git executable and checks the file permission and version.
|
|
func SetExecutablePath(path string) error {
|
|
// If path is empty, we use the default value of GitExecutable "git" to search for the location of git.
|
|
if path != "" {
|
|
GitExecutable = path
|
|
}
|
|
absPath, err := exec.LookPath(GitExecutable)
|
|
if err != nil {
|
|
return fmt.Errorf("git not found: %w", err)
|
|
}
|
|
GitExecutable = absPath
|
|
return nil
|
|
}
|
|
|
|
// HomeDir is the home dir for git to store the global config file used by Gitea internally
|
|
func HomeDir() string {
|
|
if setting.Git.HomePath == "" {
|
|
// strict check, make sure the git module is initialized correctly.
|
|
// attention: when the git module is called in gitea sub-command (serv/hook), the log module might not obviously show messages to users/developers.
|
|
// for example: if there is gitea git hook code calling NewCommand before git.InitXxx, the integration test won't show the real failure reasons.
|
|
log.Fatal("Unable to init Git's HomeDir, incorrect initialization of the setting and git modules")
|
|
return ""
|
|
}
|
|
return setting.Git.HomePath
|
|
}
|