Commit Graph
21734 Commits
Author SHA1 Message Date
Roland Singerandwxiaoguang a0b9ce05c4 fix: go get fails with GO_GET_CLONE_URL_PROTOCOL=ssh on the default SSH port (#39674)
Go rejects scp-style addresses like `git@host:owner/repo.git` in the
go-import meta tag because they have no URL scheme, so
GO_GET_CLONE_URL_PROTOCOL=ssh did not work with the default SSH port
unless USE_COMPAT_SSH_URI was set. Always use the ssh:// form for
go-get.

When DISABLE_HTTP_GIT is enabled, the https clone URL can never work, so
GO_GET_CLONE_URL_PROTOCOL now defaults to ssh in that case.

---------

Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-10-08 08:52:24 +00:00
wxiaoguang cc623c5f2f refactor: clean up git migration forms (#39672)
Only extracted shared code, removed unnecessary code, and use
form-fetch-action to replace RenderWithErrDeprecated, slightly
refactored JS to use data-global-init

Nothing else is changed, although there are still many problems.

Written by AI

Diff with hiding spaces:
https://github.com/go-gitea/gitea/pull/39672/changes?w=1
2026-10-08 10:36:08 +02:00
GiteaBot 89ec271d9c [skip ci] Updated translations via Crowdin 2026-10-08 01:00:05 +00:00
wxiaoguang c8fc705632 fix: correct change password page and redirection (#39671)
Backport fix is #39670
2026-10-07 19:34:47 +00:00
wxiaoguang 21cf3f774d refactor: clean ui modal component (#39654)
1. use "button" element for the modal close button
2. remove "ui modal" width hacks
2026-10-07 11:49:50 -07:00
Nico Schlömerandsilverwind 5bcb0ce0fc fix(markup): display MathML has no space below it (#39663)
Co-authored-by: silverwind <me@silverwind.io>
2026-10-07 16:45:07 +00:00
wxiaoguang 5a529ffd58 fix: various bugs (#39661)
1. fix #39660: relax email validation
2. fix #39658: use "int64" instead of time.Duration (for JSON v2)
2026-10-08 00:33:55 +08:00
wxiaoguang 4cba1e18ed feat: global shortcut support (#39604)
* Fix #5796

Global shortcuts can be easily introduced by adding "data-shortcut-keys"
to the elements

---------

Signed-off-by: wxiaoguang <wxiaoguang@gmail.com>
2026-10-07 13:35:38 +08:00
bircniandsilverwind 9b1d6f47f1 ci: reject breaking marker on non-breaking PR types (#39584)
Reject the breaking marker `!` on `build`, `chore`, `ci`, `docs`,
`style` and `test` PR titles, since these types never change user-facing
behavior. The check runs in `lint-pr-title`, so it fails before labels
are synced and such PRs never get `pr/breaking`.

Co-authored-by: silverwind <me@silverwind.io>
2026-10-07 03:08:08 +02:00
wxiaoguang 26475404d4 fix: show "merge" form for empty PR (#39640)
fix #39637
2026-10-06 17:28:28 +00:00
silverwind 20ea3e204d perf(repo): fetch the initial commit instead of pushing it (#39628)
Creating a repository with an initial commit, via `auto_init` or a
template with git content, pushed that commit through receive-pack and
three server-side hooks that do nothing for this internal push except
refresh server info. Fetching it into the bare repository instead makes
such repository creation about 3.7x faster locally (median 790ms to
214ms). E2E tests that create initialized repositories get about
0.2-0.3s faster each.

1. Run `update-server-info` after template content generation, which the
push's `post-receive` hook did before.
2. Remove the now unused `InternalPushingEnvironment` and
`PushOptions.LocalRefName`.
2026-10-06 14:39:36 +00:00
KShotandwxiaoguang a835fd78d1 fix(models): chunk commit status queries to avoid SQLite expression depth limit (#39611)
Fixes https://github.com/go-gitea/gitea/issues/39606

Refactor GetLatestCommitStatusForRepoCommitIDs to 
query commit IDs by batch to avoid generating a large SQL

---------

Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-10-06 15:50:41 +02:00
wxiaoguang 1065f03454 refactor: clarify GOOS detection (#39620)
Introduce `consts.IsWindows`, now it's clearer to see how Windows build works
2026-10-06 08:22:36 +00:00
Sergio Benitezandwxiaoguang 052f660ba5 fix(web): normalize content for edit history diff and fix comment history dropdown (#39616)
Signed-off-by: wxiaoguang <wxiaoguang@gmail.com>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-10-06 08:03:06 +00:00
wxiaoguang fc1f0dbec4 fix: correct RemoveWithRetry error handling (#39619)
* Fix #39618
* Follow up #38588
* Remove unrelated errors
2026-10-06 07:45:31 +00:00
dziulatexandwxiaoguang 1264072754 fix(pull): refresh commits behind when an AGit pull request is updated (#39613)
Fixes #39598

The AGit update path in `services/agit` moved `refs/pull/N/head` without
recomputing commits_behind.

The AGit update path now calls `syncCommitDivergence` in
`UpdateRefForAgit`, the same as AGit PR creation (`NewPullRequest`)
already does.

---------

Signed-off-by: dziulatex <paweldziurasoftware@yahoo.com>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-10-06 07:21:43 +00:00
TheFox0x7andwxiaoguang bd2a6c40d7 fix(egress): expose more ranges as restricted rather than reserved (#39560)
Introduce second list of addresses which are classified as dialable if
explicitly allowed when in Lax mode.
Restricted pool now includes: link-local, site local, private (including
ULA), CGNAT, discard, dummy, documentation and test addreses.
Reserved pool shrinks to: this network, wireserver embedding/translation
ranges and multicasts

Rationale for the choice is that while items in restricted pool can be
dangerous to allow they could be a legitimate target in some
deployments. Ranges left in reserved list are ranges which make no sense
to dial, are public (wireserver) or are 6to4 embedding which cannot be
reasonably verified to be safe. To unlock those a proxy should be used
instead

fixes: https://github.com/go-gitea/gitea/issues/39557

---------

Signed-off-by: TheFox0x7 <thefox0x7@gmail.com>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-10-06 14:36:06 +08:00
43fedd662a ci(release): automate signed release tags and release notes (#39544)
Automate release tagging as proposed in
https://github.com/go-gitea/gitea/pull/39544#issuecomment-5955939142,
part of https://github.com/go-gitea/gitea/issues/39550.

A maintainer selects a release branch and version in the
`release-create-tag` workflow. After approval through the
`release-signing` environment, it pushes a GPG-signed tag. The tag
starts the existing release build, which generates GitHub release notes
with git-cliff from commits since the previous release, skipping `chore`
and `ci` commits.

`CHANGELOG.md` and release-candidate releases are removed. The workflow
reuses the existing `GPGSIGN_KEY`, `GPGSIGN_PASSPHRASE`, and
`RELEASE_TOKEN` repository secrets.


Closes https://github.com/go-gitea/gitea/issues/39550

---------

Co-authored-by: bircni <bircni@users.noreply.github.com>
Co-authored-by: silverwind <me@silverwind.io>
2026-10-06 05:21:07 +00:00
GiteaBot 6e7de91f99 [skip ci] Updated translations via Crowdin 2026-10-06 00:58:27 +00:00
wxiaoguangandsilverwind b1726adebb fix: make "edit pr title & target branch" get correct branch (#39612)
* Fix #39610
* Regression of #39262

Also, the old code is very fragile: `#branch_target` is from translation
string, so refactored it together

---------

Co-authored-by: silverwind <me@silverwind.io>
2026-10-05 20:29:33 +00:00
4e2c3e43f2 fix(pull): fetch PR head refs instead of pushing them (#39603)
Creating a PR fetches the head commit into the base repo, then pushes
the same objects into `refs/pull/N/head`. Since git 2.54, background
repacks race that push:

1. The push can be rejected with "unable to migrate objects to permanent
storage", see
https://github.com/go-gitea/gitea/actions/runs/37171442185/job/111345034829.
2. For heads with 100+ new objects, the repack can delete the reused
pack, leaving the PR ref pointing at missing objects.

Fetching the head commit with `FetchRemoteTempCommit` and setting the PR
ref with `UpdateRef` avoids both, as the fetch transfers nothing when
the objects exist. Fork PR refs are now updated like AGit PR refs
already are, without going through receive hooks.

Also syncs the PR ref when a PR is reopened again.
https://github.com/go-gitea/gitea/pull/37077 inverted that condition, so
a reopened PR kept a stale ref.

---------

Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
Co-authored-by: bircni <bircni@icloud.com>
2026-10-05 20:31:21 +02:00
d16b20b972 feat(user): allow renaming security keys (webauthn/passkey) (#39413)
Closes https://github.com/go-gitea/gitea/issues/39287

Security key nicknames could only be set at registration, so a skipped
nickname left an auto-generated hex name until the key was
re-registered. Each key now has a Rename button opening a dialog with
the current nickname. A nickname used by another of the user's keys
(case-insensitive) or a blank nickname is rejected. Renames are recorded
as `user:webauth:rename` audit events.

Co-authored-by: silverwind <me@silverwind.io>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-10-05 19:12:22 +02:00
bircni 66546045b5 fix(actions): refresh reusable caller status when children are skipped (#39589) 2026-10-05 17:58:42 +02:00
64f4b5856a enhance(actions): improve matrix job titles, bump actionslib (#39485)
Bump actionslib to v1.3.0 and format matrix job titles like GitHub.

- Matrix values are listed in declaration order, nested arrays and
objects are flattened, null and empty values are skipped
- Expression-evaluated names are trimmed and fall back to the job ID
when blank
- Matrix `include` and `exclude` match keys case-insensitively and
coerce numbers like GitHub

| Matrix | Before | After |
|---|---|---|
| `v: ["a,b"]` | `job (a,b)` | `job (a,b)` |
| `v: ["a, b"]` | `job (a, b)` | `job (a, b)` |
| `v: [[a, b]]` | `job ([a b])` | `job (a, b)` |
| `os: [x], arch: [y]` | `job (y, x)` | `job (x, y)` |
| `v: [{t: a, p: "b,c"}]` | `job (map[p:b,c t:a])` | `job (a, b,c)` |
| `v: [{t: a, p: [b, c]}]` | `job (map[p:[b c] t:a])` | `job (a, b, c)`
|

---------

Co-authored-by: Zettat123 <zettat123@gmail.com>
Co-authored-by: bircni <bircni@icloud.com>
2026-10-05 10:29:49 +00:00
Giteabotandsilverwind 27d876e311 chore(deps): update dependencies, add new lint rules, fix lint (#39601)
Co-authored-by: silverwind <me@silverwind.io>
2026-10-05 10:11:50 +00:00
wxiaoguang b0d5a63e7a fix: migrate broken team authorize access mode (#39579)
* fix:  #39571
* ref: https://github.com/go-gitea/gitea/pull/38938#pullrequestreview-4945228548
* fix the bug in `assignTeamPermissionUnits` which can result in wrong team access

---------

Signed-off-by: wxiaoguang <wxiaoguang@gmail.com>
2026-10-05 09:03:34 +00:00
wxiaoguang b71967b254 fix: avoid useless "Failed authentication attempt" logs (#39602) 2026-10-05 01:45:50 -07:00
silverwind fc44404843 test: keep integration ssh independent of user ssh config (#39600)
The SSH integration tests read the user's `~/.ssh/config`, so options
like `ControlMaster` reused a connection authenticated with another
test's key and the tests failed with "Cannot find key". Pass `-F none`
so ssh reads no config files.
2026-10-05 05:25:54 +00:00
wxiaoguang 49adfd065d fix: avoid FetchRemoteTempCommit touching unnecessary resources (#39583)
Also rename FetchRemoteCommit to FetchRemoteTempCommit to clarify its
purpose
2026-10-04 22:03:18 -07:00
GiteaBot b576f5bb34 [skip ci] Updated translations via Crowdin 2026-10-05 01:04:01 +00:00
silverwindandwxiaoguang 2705abf7f3 perf(citation): optimize CITATION.cff rendering (#39575)
Rendering a CITATION.cff could use memory far out of proportion to the
file, as every YAML alias copies its target into the formatted citation
and the parser copies `%TAG` prefixes into every node. Files past these
limits show no citation, like unparseable ones do today.

- Skip files over 256 KiB, largest real-world file found is 80 KiB
- Skip files with `%TAG` directives
- Skip files whose aliases add more than 64 Ki nodes and value bytes
- Skip self-referencing anchors, except a sequence listing itself

Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-10-04 23:50:46 +00:00
KBS 9bb8751b29 fix(git): return no submodule web link when the URL cannot be parsed (#39274) 2026-10-04 13:40:27 +00:00
breken 6809ecf2d2 fix(httpcache): raw files return 304 after a change when the new commit is older (#39435) 2026-10-04 13:13:24 +00:00
brekenandwxiaoguang db7d1da28f fix(markup): link team mentions that use a different org name case (#39436)
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-10-04 14:51:46 +02:00
826c65d0ec fix(actions): return 401 for unregistered runner (#39578)
## Summary

When an Actions runner's registration has been deleted (or the
UUID/token is invalid), `FetchTask` and other authenticated runner RPCs
currently return **HTTP 500**


## Change

- Return `connect.NewError(connect.CodeUnauthenticated, ...)` via a
small `unregisteredRunnerError()` helper for both unregistered /
bad-token paths in the interceptor.
- Leave Internal `status.Error` paths unchanged (those should remain
5xx).
- Add a unit test asserting `connect.CodeOf(err) ==
connect.CodeUnauthenticated`.

Fixes #39576


---------

Signed-off-by: Alex Mitre <mitre88@users.noreply.github.com>
Co-authored-by: Alex Mitre <mitre88@users.noreply.github.com>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-10-04 10:28:32 +00:00
Piyush Kumarandsilverwind a9ac8c0afd fix(label): sort labels by open issue count, not total (#39464)
The labels page shows open issue counts, but "Most issues" and "Least
issues" sorted by the total including closed issues, so a label with no
open issues could land in the middle of the list.

- Sort repository and organization labels by their open issue count
- Sort organization labels on a repository's labels page by their open
issues in that repository, which is the count they display

Fixes: https://github.com/go-gitea/gitea/issues/39346

---------

Signed-off-by: piyush295 <mr.piyush295@gmail.com>
Co-authored-by: silverwind <me@silverwind.io>
2026-10-04 08:48:18 +00:00
silverwind eb4468ff4e enhance!: raise minimum git version to 2.34 (#39565)
Raise the minimum git version to 2.34, the version in Ubuntu 22.04,
Debian 12 and RHEL 8 ship newer, and remove the fallbacks it makes
obsolete.

- Always enable AGit
- Use `diff --skip-to` and `apply -3` unconditionally
- Set the default branch of new repos and wikis via `git init
--initial-branch`
- Detect rebase conflicts via `REBASE_HEAD`
2026-10-04 16:26:14 +08:00
Zettat123 4bebd86285 fix(user): restore organizations tab on user profile (#39577)
Fixes #39572

The shared user cards template calls the User-only `IsTypeBot` method.
The profile organizations tab passed `*organization.Organization` values
to that template, so `/{username}?tab=organizations` returned a 500
error.

Organizations are now converted to Users before rendering.
2026-10-04 15:30:04 +08:00
bircni 7641fc3a8c fix(actions): restore pushes to protected branches (#39564)
Use the Actions token's loaded write permission when checking
protected-branch pushes. Preserve push and force-push allowlists and add
regression coverage.

Fixes https://github.com/go-gitea/gitea/issues/39563
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
Co-authored-by: silverwind <me@silverwind.io>
Co-authored-by: Giteabot <teabot@gitea.io>
2026-10-03 19:54:55 +02:00
cca466caae fix(api): allow bots with pending password changes (#39551)
Allow bot accounts to use the API when a legacy password-change flag is
set, since bots cannot complete the interactive password-change flow.
Preserve password-change enforcement for human accounts and restrictions
for inactive or prohibited accounts.

Fixes: https://github.com/go-gitea/gitea/issues/39542
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
Co-authored-by: silverwind <me@silverwind.io>
2026-10-03 17:22:07 +00:00
516a4883fa enhance(ui): cleanup navbar template and styling (#39554)
Clean up the navbar template and styling, and fix the navbar stopwatch,
which navigated to the issue instead of opening its popup since
https://github.com/go-gitea/gitea/pull/36965.

1. Add hover background to the create and user menus
2. Simplify navbar HTML and CSS and remove Fomantic styles
3. Render the notification and stopwatch icons once instead of separate
mobile and desktop copies
4. Make the stopwatch a keyboard accessible button whose popup updates
on push and closes when the stopwatch stops

Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
Co-authored-by: bircni <bircni@icloud.com>
2026-10-03 18:35:54 +02:00
f65e01226a enhance(webhook): add select all and deselect all buttons for custom events (#35980)
Adds `Select All` and `Deselect All` buttons to the custom events
section of the webhook form. This is useful when you need all events but
one.

- The buttons toggle every event checkbox and keep the unsaved-changes
prompt working
- Fix the "Trigger On" radio spacing by removing a leftover Fomantic
checkbox margin

Co-authored-by: silverwind <me@silverwind.io>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-10-03 14:27:17 +00:00
okxintandsilverwind ab1979bcfb fix(api): normalize all API due dates to end of day (#38677)
Due dates set through the API were stored inconsistently. The create
endpoints kept the raw timestamp, issue and pull request edits used end
of day in the client's offset, and only the deadline and milestone edit
endpoints normalized to end of day in the server's UI timezone like the
web UI does. All API due dates now go through
`ParseAPIDeadlineToEndOfDay`.

Editing a pull request with `unset_due_date: false` and no `due_date`
dereferenced a nil pointer and returned 500. It now shares the issue
edit logic and returns 400.

Related to https://github.com/go-gitea/gitea/issues/37620, which is
about the web sidebar and isn't fixed here.

---------

Co-authored-by: silverwind <me@silverwind.io>
2026-10-03 11:59:43 +00:00
silverwindandwxiaoguang ad38b60983 refactor!: remove go-git backend (#39487)
Removes the go-git backend so every build uses the git CLI backend. Its
Windows performance advantage is gone, it lacks SHA-256 support, and it
breaks repositories on Windows.

The performance changes moved to
https://github.com/go-gitea/gitea/pull/39526.

Fixes https://github.com/go-gitea/gitea/issues/38359
Fixes https://github.com/go-gitea/gitea/issues/34694

---------

Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-10-03 10:04:24 +00:00
silverwind 3932624947 ci: relay fork PR reviews to giteabot through workflow_run (#39546)
`pull_request_review` runs on fork PRs, which includes all backport PRs,
get a read-only token and no secrets, so giteabot cannot write lgtm
labels and statuses there. A no-op `giteabot-review` workflow now
triggers giteabot through `workflow_run`, which gets both. This allows
retiring the legacy fly.io webhook bot.

Part of https://github.com/go-gitea/giteabot/issues/15
2026-10-03 09:36:38 +00:00
kiaraandwxiaoguang e0e18fc286 perf(actions): index action_run.commit_sha (#39559)
The API filter `head_sha` on `GET /repos/{owner}/{repo}/actions/runs`
selects runs by `commit_sha`, so `commit_sha` needs an index. For a
action_run table with 212k rows:

- Without the index: the query read 212k rows, and the API request took
35-52 s.
- With the index: the query read 94 rows in 0.14 s, and the API request
took 2-4 s.

---------

Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-10-03 11:19:27 +02:00
457510fa09 fix: use READ_COMMITTED_SNAPSHOT on MSSQL (#39512)
MSSQL's default READ COMMITTED makes reads wait on writers, so the
runner pickup deadlocks with concurrent claims, flaking
`TestCreateTaskForRunnerConcurrentClaim`.

- Enable `READ_COMMITTED_SNAPSHOT` on MSSQL so it reads like PostgreSQL
and MySQL
- Read the pickup cursor before claiming, a lost claim could skip
waiting jobs
- Add tests that fail without consistent READ COMMITTED

Performance: Writes on MSSQL now also store the previous row version in
tempdb, the same versioning cost PostgreSQL and MySQL always pay, and
Azure SQL enables it by default. Reads no longer block on writers, and a
32-runner pickup stress test ran 2.5x faster with it.

---------

Signed-off-by: wxiaoguang <wxiaoguang@gmail.com>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
Co-authored-by: Giteabot <teabot@gitea.io>
2026-10-03 15:25:47 +08:00
silverwind 2baa5a16f8 enhance(citation): render citations server-side (#39373)
Replace citation-js with a Go port of ruby-cff, which GitHub uses for
"Cite this repository", rendering APA and BibTeX server-side and
dropping about 770KB of JS. Output matches GitHub on 1568 of 1571
real-world files, the rest are improvements over GitHub.

- `CITATION.cff` wins over `CITATION.bib`, matched case-insensitively
and through symlinks
- `CITATION.bib` is offered as-is, without APA

Signed-off-by: silverwind <me@silverwind.io>
2026-10-03 02:28:34 +00:00
silverwind fb067e1115 fix(git): tolerate concurrent repacks in go-git storage (#39536)
Since `transfer.fsckObjects` makes fetches keep a pack, git 2.54+
background maintenance repacks a mirror right after its sync fetch, and
go-git then misses objects mid-repack. Fixes these flakes:

-
https://github.com/go-gitea/gitea/actions/runs/36875305717/job/110419770196
-
https://github.com/go-gitea/gitea/actions/runs/36900439473/job/110498845882

Changes:

- Keep reindexing while the pack set changes instead of retrying once
- List packs only once their `.idx` exists and don't fail the listing on
files removed mid-repack
- Look up large objects again when their file is gone before reading
2026-10-03 03:58:36 +02:00
GiteaBot daaed0d7f4 [skip ci] Updated translations via Crowdin 2026-10-03 00:55:34 +00:00