Project homepage Mailing List  Warmcat.com  API Docs  Github Mirror 
    npro  
 Modern all-safe Rust Network Protocol library supporting h1, h2, h3, ws, wt sans-IO and with socket IO + tls
git clone https://npro.rs/repo/npro
 
root / assets / OpenSans-Light.ttf
Author[]Andy Green <andy@warmcat.com> 2026-08-23 17:58 UTC
Committer[]Andy Green <andy@warmcat.com> 2026-08-23 18:06 UTC
Tree89ef3c164b6d1fec344423601ea901f356fff0ba   Raw Patch
 
REPO_FETCH_URL_BASE="https://libwebsockets.org/repo" REPO_WEBURL_BASE="...
REPO_FETCH_URL_BASE="https://libwebsockets.org/repo"
REPO_WEBURL_BASE="https://libwebsockets.org/git"

json_escape() {
    printf '%s' "$1" | sed \
        -e 's/\\/\\\\/g' \
        -e 's/"/\\"/g' \
        -e 's/	/\\t/g' \
        -e ':a' -e 'N' -e '$!ba' -e 's/\n/\\n/g' \
        -e 's/\r/\\r/g'
}

if [ $(git rev-parse --is-bare-repository) = true ]
then
    RN=$(basename "$PWD")
else
    RN=$(basename $(readlink -nf "$PWD"/..))
fi

RN=${RN%.git}

echo sai update hook $RN...
rm -f .sai.json .sai.json.b64
git show $3 -- .sai.json | patch -p1 --merge
cat .sai.json
cat .sai.json | base64 -w0 > .sai.json.b64
SJL=`stat .sai.json.b64 -c %s`

if [ -z $SJL -o $SJL = "0" ] ; then
    cat /home/sai/.sai.json | base64 -w0 > .sai.json.b64
    SJL=`stat .sai.json.b64 -c %s`
fi



TF=`mktemp`

RN_E=$(json_escape "$RN")
REF_E=$(json_escape "$1")
HASH_E=$(json_escape "$3")

echo "{\"schema\":\"com-warmcat-sai-notification\"," > $TF
echo " \"action\":\"repo-update\"," >> $TF
echo " \"repository\":{" >> $TF
echo "  \"name\":\"$RN_E\"," >> $TF
echo "  \"fetchurl\":\"$REPO_FETCH_URL_BASE/$RN_E\"," >> $TF
echo "  \"weburl\":\"$REPO_WEBURL_BASE/$RN_E\"" >> $TF
echo " }," >> $TF
echo " \"nonce\":\"`dd if=/dev/urandom bs=32 count=1 | sha256sum | cut -d' ' -f1`\"," >> $TF
echo " \"ref\":\"$REF_E\"," >> $TF
echo " \"hash\":\"$HASH_E\"," >> $TF
echo " \"saifile_len\":$SJL," >> $TF
echo -n " \"saifile\":\"" >> $TF
cat .sai.json.b64 >> $TF
echo "\"" >> $TF
echo "}" >> $TF

HM=`cat $TF | sha256hmac -k /etc/sai/private/lws-sai-notification-token | cut -d' ' -f1`

if [ $SJL = "0" ] ; then
	echo "No saifile"
	exit 0
fi

cat $TF
echo $HM

curl --header "authorization: sai sha256=$HM" \
    -F"file=@$TF;type=application/json" \
    -A "sai-notifier" \
     https://warmcat.com/sai/update-hook

rm -f $TF

exit 0
diff --git a/hooks/sai.sh b/hooks/sai.sh index 0ab44e6..9bd9cec 100755 --- a/hooks/sai.sh +++ b/hooks/sai.sh @@ -1,13 +1,7 @@ -#!/bin/bash - -# this is a hook to run on your gitolite server when you push a branch -# it usually goes in ./local/VREF in your gitohashi config - -REPO_URL_BASE="https://libwebsockets.org" -REPO_FETCH_URL_BASE="${REPO_URL_BASE}/repo" -REPO_WEB_URL_BASE="${REPO_URL_BASE}/git" -SAI_SERVER_BASE="https://libwebsockets.org:4444/sai/update-hook" +#!/bin/sh +REPO_FETCH_URL_BASE="https://libwebsockets.org/repo" +REPO_WEBURL_BASE="https://libwebsockets.org/git" # json_escape <string>: emit a JSON string literal body with \, ", and control # bytes escaped. Git ref names and repository names can legally contain ", \, @@ -15,7 +9,6 @@ SAI_SERVER_BASE="https://libwebsockets.org:4444/sai/update-hook" # would allow JSON injection (a pushed branch named foo","extra":"... could # inject fields). The whole payload is HMAC-signed afterwards, but escaping # here keeps the structure unambiguous regardless of parser quirks. - json_escape() { printf '%s' "$1" | sed \ -e 's/\\/\\\\/g' \ @@ -34,48 +27,46 @@ fi RN=${RN%.git} -# Pre-escape attacker-influenced fields once. RN is derived from the repo -# directory name; $1 is the git ref; $3 is the new commit hash. - -RN_E=$(json_escape "$RN") -REF_E=$(json_escape "$1") -HASH_E=$(json_escape "$3") - - - -pwd +echo sai update hook $RN... +rm -f .sai.json .sai.json.b64 +git show $3 -- .sai.json | patch -p1 --merge +cat .sai.json +cat .sai.json | base64 -w0 > .sai.json.b64 +SJL=`stat .sai.json.b64 -c %s` -echo sai update hook $1 $RN_E... -if [ ! -z "`echo $1 | grep /_`" ] ; then - echo "Detected temp ref starting with _, not passing to Sai" - exit 0 +if [ -z $SJL -o $SJL = "0" ] ; then + cat /home/sai/.sai.json | base64 -w0 > .sai.json.b64 + SJL=`stat .sai.json.b64 -c %s` fi -rm -f .sai.json .sai.json.b64 -git show $3:.sai.json | base64 -w0 > .sai.json.b64 -SJL=`stat .sai.json.b64 -c %s` TF=`mktemp` +# Pre-escape attacker-influenced fields once. RN is derived from the repo +# directory name; $1 is the git ref; $3 is the new commit hash. +RN_E=$(json_escape "$RN") +REF_E=$(json_escape "$1") +HASH_E=$(json_escape "$3") + echo "{\"schema\":\"com-warmcat-sai-notification\"," > $TF echo " \"action\":\"repo-update\"," >> $TF echo " \"repository\":{" >> $TF -echo " \"name\":\"${RN_E}\"," >> $TF -echo " \"fetchurl\":\"$REPO_FETCH_URL_BASE/${RN_E}\"," >> $TF -echo " \"weburl\":\"$REPO_WEB_URL_BASE/${RN_E}\"" >> $TF +echo " \"name\":\"$RN_E\"," >> $TF +echo " \"fetchurl\":\"$REPO_FETCH_URL_BASE/$RN_E\"," >> $TF +echo " \"weburl\":\"$REPO_WEBURL_BASE/$RN_E\"" >> $TF echo " }," >> $TF echo " \"nonce\":\"`dd if=/dev/urandom bs=32 count=1 | sha256sum | cut -d' ' -f1`\"," >> $TF echo " \"ref\":\"$REF_E\"," >> $TF echo " \"hash\":\"$HASH_E\"," >> $TF -echo " \"saifile_len\":${SJL}," >> $TF +echo " \"saifile_len\":$SJL," >> $TF echo -n " \"saifile\":\"" >> $TF # disallow any nested JSON monkey business by base64-encoding it cat .sai.json.b64 >> $TF echo "\"" >> $TF echo "}" >> $TF -HM=`cat $TF | openssl dgst -sha256 -hmac $(cat /etc/sai/private/lws-sai-notification-token2) | cut -d' ' -f2` +HM=`cat $TF | sha256hmac -k /etc/sai/private/lws-sai-notification-token | cut -d' ' -f1` if [ $SJL = "0" ] ; then echo "No saifile" @@ -84,15 +75,14 @@ fi cat $TF echo $HM -echo badline: -F"file=@${TF};type=application/json" curl --header "authorization: sai sha256=$HM" \ - -F"file=@${TF};type=application/json" \ - -A "sai-notifier" -m 30 \ - ${SAI_SERVER_BASE} + -F"file=@$TF;type=application/json" \ + -A "sai-notifier" \ + https://warmcat.com/sai/update-hook +#curl --header "X-Sai-Signature: sha256=$HM" -F"file=@$TF;name=notification;type=application/json" -A "sai-notifier" http://127.0.0.1:4444 rm -f $TF exit 0 - diff --git a/src/builder/b-nspawn.c b/src/builder/b-nspawn.c index 6e06f27..b27286d 100644 --- a/src/builder/b-nspawn.c +++ b/src/builder/b-nspawn.c @@ -369,7 +369,7 @@ sai_lsp_reap_cb(void *opaque, const lws_spawn_resource_us_t *res, siginfo_t *si, if (saib_srv_queue_json_fragments_helper(ns->spm->ss, lsm_schema_map_build_metric, - LWS_ARRAY_SIZE(lsm_schema_build_metric), &m)) + LWS_ARRAY_SIZE(lsm_schema_map_build_metric), &m)) return; skip: diff --git a/src/common/include/private.h b/src/common/include/private.h index ccec1a6..ef1ce91 100644 --- a/src/common/include/private.h +++ b/src/common/include/private.h @@ -878,7 +878,7 @@ extern const lws_struct_map_t lsm_schema_sq3_map_artifact[1], lsm_schema_map_ta[1], lsm_schema_map_plat_simple[1], - lsm_event[12], + lsm_event[13], lsm_task[32], lsm_log[8], lsm_artifact[9], @@ -901,11 +901,10 @@ extern const lws_struct_map_t lsm_schema_ptydata[1], lsm_rebuild[1], lsm_schema_rebuild[1], - lsm_schema_build_metric[1], lsm_schema_map_build_metric[1], lsm_schema_sq3_map_build_metric[1], lsm_load_report_members[9], - lsm_schema_json_task_rej[5], + lsm_schema_json_task_rej[1], lsm_stay_state_update[2], lsm_schema_stay_state_update[1], lsm_build_metric[14], @@ -923,7 +922,7 @@ extern const lws_struct_map_t lsm_watcher_rule[6], lsm_watcher_ui_rule[4], lsm_watcher_service[6], - lsm_watcher[9], + lsm_watcher[8], lsm_schema_sq3_map_watcher[1], lsm_schema_json_map_watcher[1], lsm_watcher_conf[1],
Page fetched 0s ago, creation time: 3ms (vhost etag hits: 0%, cache hits: 0%)