1 # Copyright (C) 2014-2021 all contributors <meta@public-inbox.org>
2 # License: GPLv2 or later <https://www.gnu.org/licenses/gpl-2.0.txt>
4 # Used to read files from a git repository without excessive forking.
5 # Used in our web interfaces as well as our -nntpd server.
6 # This is based on code in Git.pm which is GPLv2+, but modified to avoid
7 # dependence on environment variables for compatibility with mod_perl.
8 # There are also API changes to simplify our usage and data set.
9 package PublicInbox::Git;
12 use parent qw(Exporter);
14 use IO::Handle; # ->autoflush
15 use Errno qw(EINTR EAGAIN ENOENT);
16 use File::Glob qw(bsd_glob GLOB_NOSORT);
18 use Time::HiRes qw(stat);
19 use PublicInbox::Spawn qw(popen_rd spawn);
20 use PublicInbox::Tmpfile;
21 use IO::Poll qw(POLLIN);
24 use PublicInbox::DS qw(dwaitpid);
25 our @EXPORT_OK = qw(git_unquote git_quote);
26 our $PIPE_BUFSIZ = 65536; # Linux default
28 our $RDTIMEO = 60_000; # milliseconds
30 use constant MAX_INFLIGHT => (POSIX::PIPE_BUF * 3) /
31 65; # SHA-256 hex size + "\n" in preparation for git using non-SHA1
44 my %ESC_GIT = map { $GIT_ESC{$_} => $_ } keys %GIT_ESC;
47 # unquote pathnames used by git, see quote.c::unquote_c_style.c in git.git
49 return $_[0] unless ($_[0] =~ /\A"(.*)"\z/);
51 $_[0] =~ s!\\([\\"abfnrtv]|[0-3][0-7]{2})!$GIT_ESC{$1}//chr(oct($1))!ge;
56 if ($_[0] =~ s/([\\"\a\b\f\n\r\t\013]|[^[:print:]])/
57 '\\'.($ESC_GIT{$1}||sprintf("%03o",ord($1)))/egs) {
64 my ($class, $git_dir) = @_;
66 $git_dir =~ s!/*\z!!s;
67 # may contain {-tmp} field for File::Temp::Dir
68 bless { git_dir => $git_dir, alt_st => '', -git_path => {} }, $class
72 my ($self, $path) = @_;
73 $self->{-git_path}->{$path} ||= do {
75 chomp(my $str = $self->qx(qw(rev-parse --git-path), $path));
77 # git prior to 2.5.0 did not understand --git-path
78 if ($str eq "--git-path\n$path") {
79 $str = "$self->{git_dir}/$path";
85 sub alternates_changed {
87 my $alt = git_path($self, 'objects/info/alternates');
88 my @st = stat($alt) or return 0;
90 # can't rely on 'q' on some 32-bit builds, but `d' works
91 my $st = pack('dd', $st[10], $st[7]); # 10: ctime, 7: size
92 return 0 if $self->{alt_st} eq $st;
93 $self->{alt_st} = $st; # always a true value
98 my $fh = $self->{err_c} or return;
99 sysseek($fh, 0, 0) or $self->fail("sysseek failed: $!");
100 defined(sysread($fh, my $buf, -s $fh)) or
101 $self->fail("sysread failed: $!");
106 my ($self, $batch, $in, $out, $pid, $err) = @_;
108 if (defined $err) { # "err_c"
109 my $fh = $self->{$err};
110 sysseek($fh, 0, 0) or $self->fail("sysseek failed: $!");
111 truncate($fh, 0) or $self->fail("truncate failed: $!");
115 pipe(my ($out_r, $out_w)) or $self->fail("pipe failed: $!");
116 my $rdr = { 0 => $out_r };
117 my $gd = $self->{git_dir};
118 if ($gd =~ s!/([^/]+/[^/]+)\z!/!) {
122 my @cmd = (qw(git), "--git-dir=$gd",
123 qw(-c core.abbrev=40 cat-file), $batch);
125 my $id = "git.$self->{git_dir}$batch.err";
126 my $fh = tmpfile($id) or $self->fail("tmpfile($id): $!");
130 my ($in_r, $p) = popen_rd(\@cmd, undef, $rdr);
132 $self->{"$pid.owner"} = $$;
133 $out_w->autoflush(1);
134 if ($^O eq 'linux') { # 1031: F_SETPIPE_SZ
135 fcntl($out_w, 1031, 4096);
136 fcntl($in_r, 1031, 4096) if $batch eq '--batch-check';
138 $self->{$out} = $out_w;
139 $self->{$in} = $in_r;
142 sub poll_in ($) { IO::Poll::_poll($RDTIMEO, fileno($_[0]), my $ev = POLLIN) }
145 my ($fh, $rbuf, $len) = @_;
146 my $left = $len - length($$rbuf);
149 $r = sysread($fh, $$rbuf, $PIPE_BUFSIZ, length($$rbuf));
152 } elsif (defined($r)) { # EOF
155 next if ($! == EAGAIN and poll_in($fh));
156 next if $! == EINTR; # may be set by sysread or poll_in
157 return; # unrecoverable error
160 \substr($$rbuf, 0, $len, '');
163 sub my_readline ($$) {
164 my ($fh, $rbuf) = @_;
166 if ((my $n = index($$rbuf, "\n")) >= 0) {
167 return substr($$rbuf, 0, $n + 1, '');
169 my $r = sysread($fh, $$rbuf, $PIPE_BUFSIZ, length($$rbuf))
172 # return whatever's left on EOF
173 return substr($$rbuf, 0, length($$rbuf)+1, '') if defined($r);
175 next if ($! == EAGAIN and poll_in($fh));
176 next if $! == EINTR; # may be set by sysread or poll_in
177 return; # unrecoverable error
181 sub cat_async_retry ($$$$$) {
182 my ($self, $inflight, $req, $cb, $arg) = @_;
184 # {inflight} may be non-existent, but if it isn't we delete it
185 # here to prevent cleanup() from waiting:
186 delete $self->{inflight};
189 $self->{inflight} = $inflight;
190 batch_prepare($self);
192 for (my $i = 0; $i < @$inflight; $i += 3) {
193 $buf .= "$inflight->[$i]\n";
195 print { $self->{out} } $buf or $self->fail("write error: $!");
196 unshift(@$inflight, \$req, $cb, $arg); # \$ref to indicate retried
198 cat_async_step($self, $inflight); # take one step
201 sub cat_async_step ($$) {
202 my ($self, $inflight) = @_;
203 die 'BUG: inflight empty or odd' if scalar(@$inflight) < 3;
204 my ($req, $cb, $arg) = splice(@$inflight, 0, 3);
205 my $rbuf = delete($self->{cat_rbuf}) // \(my $new = '');
206 my ($bref, $oid, $type, $size);
207 my $head = my_readline($self->{in}, $rbuf);
208 # ->fail may be called via Gcf2Client.pm
209 if ($head =~ /^([0-9a-f]{40,}) (\S+) ([0-9]+)$/) {
210 ($oid, $type, $size) = ($1, $2, $3 + 0);
211 $bref = my_read($self->{in}, $rbuf, $size + 1) or
212 $self->fail(defined($bref) ? 'read EOF' : "read: $!");
213 chop($$bref) eq "\n" or $self->fail('LF missing after blob');
214 } elsif ($head =~ s/ missing\n//s) {
216 # ref($req) indicates it's already been retried
217 # -gcf2 retries internally, so it never hits this path:
218 if (!ref($req) && !$in_cleanup && $self->alternates_changed) {
219 return cat_async_retry($self, $inflight,
223 $oid = ref($req) ? $$req : $req if $oid eq '';
225 my $err = $! ? " ($!)" : '';
226 $self->fail("bad result from async cat-file: $head$err");
228 $self->{cat_rbuf} = $rbuf if $$rbuf ne '';
229 eval { $cb->($bref, $oid, $type, $size, $arg) };
230 warn "E: $oid: $@\n" if $@;
233 sub cat_async_wait ($) {
235 my $inflight = $self->{inflight} or return;
236 while (scalar(@$inflight)) {
237 cat_async_step($self, $inflight);
241 sub batch_prepare ($) {
242 _bidi_pipe($_[0], qw(--batch in out pid));
246 my ($bref, $oid, $type, $size, $result) = @_;
247 @$result = ($bref, $oid, $type, $size);
251 my ($self, $oid) = @_;
253 cat_async($self, $oid, \&_cat_file_cb, $result);
254 cat_async_wait($self);
255 wantarray ? @$result : $result->[0];
258 sub check_async_step ($$) {
259 my ($self, $inflight_c) = @_;
260 die 'BUG: inflight empty or odd' if scalar(@$inflight_c) < 3;
261 my ($req, $cb, $arg) = splice(@$inflight_c, 0, 3);
262 my $rbuf = delete($self->{chk_rbuf}) // \(my $new = '');
263 chomp(my $line = my_readline($self->{in_c}, $rbuf));
264 my ($hex, $type, $size) = split(/ /, $line);
266 # Future versions of git.git may have type=ambiguous, but for now,
267 # we must handle 'dangling' below (and maybe some other oddball
269 # https://public-inbox.org/git/20190118033845.s2vlrb3wd3m2jfzu@dcvr/T/
270 if ($hex eq 'dangling' || $hex eq 'notdir' || $hex eq 'loop') {
271 my $ret = my_read($self->{in_c}, $rbuf, $type + 1);
272 $self->fail(defined($ret) ? 'read EOF' : "read: $!") if !$ret;
274 $self->{chk_rbuf} = $rbuf if $$rbuf ne '';
275 eval { $cb->($hex, $type, $size, $arg, $self) };
276 warn "E: check($req) $@\n" if $@;
279 sub check_async_wait ($) {
281 my $inflight_c = $self->{inflight_c} or return;
282 while (scalar(@$inflight_c)) {
283 check_async_step($self, $inflight_c);
287 sub check_async_begin ($) {
289 cleanup($self) if alternates_changed($self);
290 _bidi_pipe($self, qw(--batch-check in_c out_c pid_c err_c));
291 die 'BUG: already in async check' if $self->{inflight_c};
292 $self->{inflight_c} = [];
295 sub check_async ($$$$) {
296 my ($self, $oid, $cb, $arg) = @_;
297 my $inflight_c = $self->{inflight_c} // check_async_begin($self);
298 while (scalar(@$inflight_c) >= MAX_INFLIGHT) {
299 check_async_step($self, $inflight_c);
301 print { $self->{out_c} } $oid, "\n" or $self->fail("write error: $!");
302 push(@$inflight_c, $oid, $cb, $arg);
305 sub _check_cb { # check_async callback
306 my ($hex, $type, $size, $result) = @_;
307 @$result = ($hex, $type, $size);
311 my ($self, $oid) = @_;
313 check_async($self, $oid, \&_check_cb, $result);
314 check_async_wait($self);
315 my ($hex, $type, $size) = @$result;
317 # Future versions of git.git may show 'ambiguous', but for now,
318 # we must handle 'dangling' below (and maybe some other oddball
320 # https://public-inbox.org/git/20190118033845.s2vlrb3wd3m2jfzu@dcvr/T/
321 return if $type eq 'missing' || $type eq 'ambiguous';
322 return if $hex eq 'dangling' || $hex eq 'notdir' || $hex eq 'loop';
323 ($hex, $type, $size);
327 my ($self, $rbuf, $in, $out, $pid, $err) = @_;
328 delete @$self{($rbuf, $in, $out)};
329 delete $self->{$err} if $err; # `err_c'
331 # GitAsyncCat::event_step may delete {pid}
332 my $p = delete $self->{$pid} or return;
333 dwaitpid($p) if $$ == $self->{"$pid.owner"};
336 sub cat_async_abort ($) {
338 if (my $inflight = $self->{inflight}) {
340 my ($req, $cb, $arg) = splice(@$inflight, 0, 3);
341 $req =~ s/ .*//; # drop git_dir for Gcf2Client
342 eval { $cb->(undef, $req, undef, undef, $arg) };
343 warn "E: $req: $@ (in abort)\n" if $@;
345 delete $self->{cat_rbuf};
346 delete $self->{inflight};
351 sub fail { # may be augmented in subclasses
352 my ($self, $msg) = @_;
353 cat_async_abort($self);
354 croak(ref($self) . ' ' . ($self->{git_dir} // '') . ": $msg");
357 # $git->popen(qw(show f00)); # or
358 # $git->popen(qw(show f00), { GIT_CONFIG => ... }, { 2 => ... });
360 my ($self, $cmd) = splice(@_, 0, 2);
361 $cmd = [ 'git', "--git-dir=$self->{git_dir}",
362 ref($cmd) ? @$cmd : ($cmd, grep { defined && !ref } @_) ];
363 popen_rd($cmd, grep { !defined || ref } @_); # env and opt
366 # same args as popen above
371 close $fh; # caller should check $?
376 close $fh; # caller should check $?
384 substr($_, length('--max-age='), -1)
385 } $self->qx('rev-parse', map { "--since=$_" } @_);
388 # check_async and cat_async may trigger the other, so ensure they're
389 # both completely done by using this:
390 sub async_wait_all ($) {
392 while (scalar(@{$self->{inflight_c} // []}) ||
393 scalar(@{$self->{inflight} // []})) {
394 $self->check_async_wait;
395 $self->cat_async_wait;
399 # returns true if there are pending "git cat-file" processes
401 my ($self, $lazy) = @_;
402 return 1 if $lazy && (scalar(@{$self->{inflight_c} // []}) ||
403 scalar(@{$self->{inflight} // []}));
404 local $in_cleanup = 1;
405 delete $self->{async_cat};
406 async_wait_all($self);
407 delete $self->{inflight};
408 delete $self->{inflight_c};
409 _destroy($self, qw(cat_rbuf in out pid));
410 _destroy($self, qw(chk_rbuf in_c out_c pid_c err_c));
414 # assuming a well-maintained repo, this should be a somewhat
415 # accurate estimation of its size
416 # TODO: show this in the WWW UI as a hint to potential cloners
420 my $pack_dir = git_path($self, 'objects/pack');
421 foreach my $p (bsd_glob("$pack_dir/*.pack", GLOB_NOSORT)) {
427 sub DESTROY { cleanup(@_) }
432 # don't show full FS path, basename should be OK:
433 if ($self->{git_dir} =~ m!/([^/]+)(?:/*\.git/*)?\z!) {
436 wantarray ? ($ret) : $ret;
439 sub host_prefix_url ($$) {
440 my ($env, $url) = @_;
441 return $url if index($url, '//') >= 0;
442 my $scheme = $env->{'psgi.url_scheme'};
443 my $host_port = $env->{HTTP_HOST} //
444 "$env->{SERVER_NAME}:$env->{SERVER_PORT}";
445 "$scheme://$host_port". ($env->{SCRIPT_NAME} || '/') . $url;
449 my ($self, $env) = @_;
450 if (my $urls = $self->{cgit_url}) {
451 return map { host_prefix_url($env, $_) } @$urls;
456 sub cat_async_begin {
458 cleanup($self) if $self->alternates_changed;
459 $self->batch_prepare;
460 die 'BUG: already in async' if $self->{inflight};
461 $self->{inflight} = [];
464 sub cat_async ($$$;$) {
465 my ($self, $oid, $cb, $arg) = @_;
466 my $inflight = $self->{inflight} // cat_async_begin($self);
467 while (scalar(@$inflight) >= MAX_INFLIGHT) {
468 cat_async_step($self, $inflight);
470 print { $self->{out} } $oid, "\n" or $self->fail("write error: $!");
471 push(@$inflight, $oid, $cb, $arg);
474 # returns the modified time of a git repo, same as the "modified" field
475 # of a grokmirror manifest
477 # committerdate:unix is git 2.9.4+ (2017-05-05), so using raw instead
478 my $fh = popen($_[0], qw[for-each-ref --sort=-committerdate
479 --format=%(committerdate:raw) --count=1]);
480 (split(/ /, <$fh> // time))[0] + 0; # integerize for JSON
483 # for grokmirror, which doesn't read gitweb.description
484 # templates/hooks--update.sample and git-multimail in git.git
485 # only match "Unnamed repository", not the full contents of
486 # templates/this--description in git.git
488 my ($self, $epoch, $default_desc) = @_;
489 my $fh = $self->popen('show-ref');
490 my $dig = Digest::SHA->new(1);
491 while (read($fh, my $buf, 65536)) {
494 close $fh or return; # empty, uninitialized git repo
495 undef $fh; # for open, below
496 my $git_dir = $self->{git_dir};
498 fingerprint => $dig->hexdigest,
500 modified => modified($self),
502 chomp(my $owner = $self->qx('config', 'gitweb.owner'));
503 utf8::decode($owner);
504 $ent->{owner} = $owner eq '' ? undef : $owner;
506 if (open($fh, '<', "$git_dir/description")) {
508 chomp($desc = <$fh>);
511 $desc = 'Unnamed repository' if $desc eq '';
512 if (defined $epoch && $desc =~ /\AUnnamed repository/) {
513 $desc = "$default_desc [epoch $epoch]";
515 $ent->{description} = $desc;
516 if (open($fh, '<', "$git_dir/objects/info/alternates")) {
517 # n.b.: GitPython doesn't seem to handle comments or C-quoted
518 # strings like native git does; and we don't for now, either.
520 chomp(my @alt = <$fh>);
522 # grokmirror only supports 1 alternate for "reference",
523 if (scalar(@alt) == 1) {
524 my $objdir = "$git_dir/objects";
525 my $ref = File::Spec->rel2abs($alt[0], $objdir);
526 $ref =~ s!/[^/]+/?\z!!; # basename
527 $ent->{reference} = $ref;
533 # returns true if there are pending cat-file processes
534 sub cleanup_if_unlinked {
536 return cleanup($self, 1) if $^O ne 'linux';
537 # Linux-specific /proc/$PID/maps access
538 # TODO: support this inside git.git
540 for my $fld (qw(pid pid_c)) {
541 my $pid = $self->{$fld} // next;
542 open my $fh, '<', "/proc/$pid/maps" or return cleanup($self, 1);
544 # n.b. we do not restart for unlinked multi-pack-index
545 # since it's not too huge, and the startup cost may
547 /\.(?:idx|pack) \(deleted\)$/ and
548 return cleanup($self, 1);
561 PublicInbox::Git - git wrapper
569 use PublicInbox::Git;
570 chomp(my $git_dir = `git rev-parse --git-dir`);
571 $git_dir or die "GIT_DIR= must be specified\n";
572 my $git = PublicInbox::Git->new($git_dir);
576 Unstable API outside of the L</new> method.
577 It requires L<git(1)> to be installed.
585 my $git = PublicInbox::Git->new($git_dir);
587 Initialize a new PublicInbox::Git object for use with L<PublicInbox::Import>
588 This is the only public API method we support. Everything else
589 in this module is subject to change.
593 L<Git>, L<PublicInbox::Import>
597 All feedback welcome via plain-text mail to L<mailto:meta@public-inbox.org>
599 The mail archives are hosted at L<https://public-inbox.org/meta/>
603 Copyright (C) 2016 all contributors L<mailto:meta@public-inbox.org>
605 License: AGPL-3.0+ L<http://www.gnu.org/licenses/agpl-3.0.txt>