Go rejects scp-style addresses like `git@host:owner/repo.git` in the
go-import meta tag because they have no URL scheme, so
GO_GET_CLONE_URL_PROTOCOL=ssh did not work with the default SSH port
unless USE_COMPAT_SSH_URI was set. Always use the ssh:// form for
go-get.
When DISABLE_HTTP_GIT is enabled, the https clone URL can never work, so
GO_GET_CLONE_URL_PROTOCOL now defaults to ssh in that case.
---------
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
Only extracted shared code, removed unnecessary code, and use
form-fetch-action to replace RenderWithErrDeprecated, slightly
refactored JS to use data-global-init
Nothing else is changed, although there are still many problems.
Written by AI
Diff with hiding spaces:
https://github.com/go-gitea/gitea/pull/39672/changes?w=1
* Fix#5796
Global shortcuts can be easily introduced by adding "data-shortcut-keys"
to the elements
---------
Signed-off-by: wxiaoguang <wxiaoguang@gmail.com>
Reject the breaking marker `!` on `build`, `chore`, `ci`, `docs`,
`style` and `test` PR titles, since these types never change user-facing
behavior. The check runs in `lint-pr-title`, so it fails before labels
are synced and such PRs never get `pr/breaking`.
Co-authored-by: silverwind <me@silverwind.io>
Creating a repository with an initial commit, via `auto_init` or a
template with git content, pushed that commit through receive-pack and
three server-side hooks that do nothing for this internal push except
refresh server info. Fetching it into the bare repository instead makes
such repository creation about 3.7x faster locally (median 790ms to
214ms). E2E tests that create initialized repositories get about
0.2-0.3s faster each.
1. Run `update-server-info` after template content generation, which the
push's `post-receive` hook did before.
2. Remove the now unused `InternalPushingEnvironment` and
`PushOptions.LocalRefName`.
Fixes#39598
The AGit update path in `services/agit` moved `refs/pull/N/head` without
recomputing commits_behind.
The AGit update path now calls `syncCommitDivergence` in
`UpdateRefForAgit`, the same as AGit PR creation (`NewPullRequest`)
already does.
---------
Signed-off-by: dziulatex <paweldziurasoftware@yahoo.com>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
Introduce second list of addresses which are classified as dialable if
explicitly allowed when in Lax mode.
Restricted pool now includes: link-local, site local, private (including
ULA), CGNAT, discard, dummy, documentation and test addreses.
Reserved pool shrinks to: this network, wireserver embedding/translation
ranges and multicasts
Rationale for the choice is that while items in restricted pool can be
dangerous to allow they could be a legitimate target in some
deployments. Ranges left in reserved list are ranges which make no sense
to dial, are public (wireserver) or are 6to4 embedding which cannot be
reasonably verified to be safe. To unlock those a proxy should be used
instead
fixes: https://github.com/go-gitea/gitea/issues/39557
---------
Signed-off-by: TheFox0x7 <thefox0x7@gmail.com>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
Automate release tagging as proposed in
https://github.com/go-gitea/gitea/pull/39544#issuecomment-5955939142,
part of https://github.com/go-gitea/gitea/issues/39550.
A maintainer selects a release branch and version in the
`release-create-tag` workflow. After approval through the
`release-signing` environment, it pushes a GPG-signed tag. The tag
starts the existing release build, which generates GitHub release notes
with git-cliff from commits since the previous release, skipping `chore`
and `ci` commits.
`CHANGELOG.md` and release-candidate releases are removed. The workflow
reuses the existing `GPGSIGN_KEY`, `GPGSIGN_PASSPHRASE`, and
`RELEASE_TOKEN` repository secrets.
Closes https://github.com/go-gitea/gitea/issues/39550
---------
Co-authored-by: bircni <bircni@users.noreply.github.com>
Co-authored-by: silverwind <me@silverwind.io>
* Fix#39610
* Regression of #39262
Also, the old code is very fragile: `#branch_target` is from translation
string, so refactored it together
---------
Co-authored-by: silverwind <me@silverwind.io>
Creating a PR fetches the head commit into the base repo, then pushes
the same objects into `refs/pull/N/head`. Since git 2.54, background
repacks race that push:
1. The push can be rejected with "unable to migrate objects to permanent
storage", see
https://github.com/go-gitea/gitea/actions/runs/37171442185/job/111345034829.
2. For heads with 100+ new objects, the repack can delete the reused
pack, leaving the PR ref pointing at missing objects.
Fetching the head commit with `FetchRemoteTempCommit` and setting the PR
ref with `UpdateRef` avoids both, as the fetch transfers nothing when
the objects exist. Fork PR refs are now updated like AGit PR refs
already are, without going through receive hooks.
Also syncs the PR ref when a PR is reopened again.
https://github.com/go-gitea/gitea/pull/37077 inverted that condition, so
a reopened PR kept a stale ref.
---------
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
Co-authored-by: bircni <bircni@icloud.com>
Closes https://github.com/go-gitea/gitea/issues/39287
Security key nicknames could only be set at registration, so a skipped
nickname left an auto-generated hex name until the key was
re-registered. Each key now has a Rename button opening a dialog with
the current nickname. A nickname used by another of the user's keys
(case-insensitive) or a blank nickname is rejected. Renames are recorded
as `user:webauth:rename` audit events.
Co-authored-by: silverwind <me@silverwind.io>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
The SSH integration tests read the user's `~/.ssh/config`, so options
like `ControlMaster` reused a connection authenticated with another
test's key and the tests failed with "Cannot find key". Pass `-F none`
so ssh reads no config files.
Rendering a CITATION.cff could use memory far out of proportion to the
file, as every YAML alias copies its target into the formatted citation
and the parser copies `%TAG` prefixes into every node. Files past these
limits show no citation, like unparseable ones do today.
- Skip files over 256 KiB, largest real-world file found is 80 KiB
- Skip files with `%TAG` directives
- Skip files whose aliases add more than 64 Ki nodes and value bytes
- Skip self-referencing anchors, except a sequence listing itself
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
## Summary
When an Actions runner's registration has been deleted (or the
UUID/token is invalid), `FetchTask` and other authenticated runner RPCs
currently return **HTTP 500**
## Change
- Return `connect.NewError(connect.CodeUnauthenticated, ...)` via a
small `unregisteredRunnerError()` helper for both unregistered /
bad-token paths in the interceptor.
- Leave Internal `status.Error` paths unchanged (those should remain
5xx).
- Add a unit test asserting `connect.CodeOf(err) ==
connect.CodeUnauthenticated`.
Fixes#39576
---------
Signed-off-by: Alex Mitre <mitre88@users.noreply.github.com>
Co-authored-by: Alex Mitre <mitre88@users.noreply.github.com>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
The labels page shows open issue counts, but "Most issues" and "Least
issues" sorted by the total including closed issues, so a label with no
open issues could land in the middle of the list.
- Sort repository and organization labels by their open issue count
- Sort organization labels on a repository's labels page by their open
issues in that repository, which is the count they display
Fixes: https://github.com/go-gitea/gitea/issues/39346
---------
Signed-off-by: piyush295 <mr.piyush295@gmail.com>
Co-authored-by: silverwind <me@silverwind.io>
Raise the minimum git version to 2.34, the version in Ubuntu 22.04,
Debian 12 and RHEL 8 ship newer, and remove the fallbacks it makes
obsolete.
- Always enable AGit
- Use `diff --skip-to` and `apply -3` unconditionally
- Set the default branch of new repos and wikis via `git init
--initial-branch`
- Detect rebase conflicts via `REBASE_HEAD`
Fixes#39572
The shared user cards template calls the User-only `IsTypeBot` method.
The profile organizations tab passed `*organization.Organization` values
to that template, so `/{username}?tab=organizations` returned a 500
error.
Organizations are now converted to Users before rendering.
Allow bot accounts to use the API when a legacy password-change flag is
set, since bots cannot complete the interactive password-change flow.
Preserve password-change enforcement for human accounts and restrictions
for inactive or prohibited accounts.
Fixes: https://github.com/go-gitea/gitea/issues/39542
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
Co-authored-by: silverwind <me@silverwind.io>
Clean up the navbar template and styling, and fix the navbar stopwatch,
which navigated to the issue instead of opening its popup since
https://github.com/go-gitea/gitea/pull/36965.
1. Add hover background to the create and user menus
2. Simplify navbar HTML and CSS and remove Fomantic styles
3. Render the notification and stopwatch icons once instead of separate
mobile and desktop copies
4. Make the stopwatch a keyboard accessible button whose popup updates
on push and closes when the stopwatch stops
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
Co-authored-by: bircni <bircni@icloud.com>
Adds `Select All` and `Deselect All` buttons to the custom events
section of the webhook form. This is useful when you need all events but
one.
- The buttons toggle every event checkbox and keep the unsaved-changes
prompt working
- Fix the "Trigger On" radio spacing by removing a leftover Fomantic
checkbox margin
Co-authored-by: silverwind <me@silverwind.io>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
Due dates set through the API were stored inconsistently. The create
endpoints kept the raw timestamp, issue and pull request edits used end
of day in the client's offset, and only the deadline and milestone edit
endpoints normalized to end of day in the server's UI timezone like the
web UI does. All API due dates now go through
`ParseAPIDeadlineToEndOfDay`.
Editing a pull request with `unset_due_date: false` and no `due_date`
dereferenced a nil pointer and returned 500. It now shares the issue
edit logic and returns 400.
Related to https://github.com/go-gitea/gitea/issues/37620, which is
about the web sidebar and isn't fixed here.
---------
Co-authored-by: silverwind <me@silverwind.io>
`pull_request_review` runs on fork PRs, which includes all backport PRs,
get a read-only token and no secrets, so giteabot cannot write lgtm
labels and statuses there. A no-op `giteabot-review` workflow now
triggers giteabot through `workflow_run`, which gets both. This allows
retiring the legacy fly.io webhook bot.
Part of https://github.com/go-gitea/giteabot/issues/15
The API filter `head_sha` on `GET /repos/{owner}/{repo}/actions/runs`
selects runs by `commit_sha`, so `commit_sha` needs an index. For a
action_run table with 212k rows:
- Without the index: the query read 212k rows, and the API request took
35-52 s.
- With the index: the query read 94 rows in 0.14 s, and the API request
took 2-4 s.
---------
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
MSSQL's default READ COMMITTED makes reads wait on writers, so the
runner pickup deadlocks with concurrent claims, flaking
`TestCreateTaskForRunnerConcurrentClaim`.
- Enable `READ_COMMITTED_SNAPSHOT` on MSSQL so it reads like PostgreSQL
and MySQL
- Read the pickup cursor before claiming, a lost claim could skip
waiting jobs
- Add tests that fail without consistent READ COMMITTED
Performance: Writes on MSSQL now also store the previous row version in
tempdb, the same versioning cost PostgreSQL and MySQL always pay, and
Azure SQL enables it by default. Reads no longer block on writers, and a
32-runner pickup stress test ran 2.5x faster with it.
---------
Signed-off-by: wxiaoguang <wxiaoguang@gmail.com>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
Co-authored-by: Giteabot <teabot@gitea.io>
Replace citation-js with a Go port of ruby-cff, which GitHub uses for
"Cite this repository", rendering APA and BibTeX server-side and
dropping about 770KB of JS. Output matches GitHub on 1568 of 1571
real-world files, the rest are improvements over GitHub.
- `CITATION.cff` wins over `CITATION.bib`, matched case-insensitively
and through symlinks
- `CITATION.bib` is offered as-is, without APA
Signed-off-by: silverwind <me@silverwind.io>