diff --git a/hooks/sai.sh b/hooks/sai.sh
index 22df6d8..0ab44e6 100755
--- a/hooks/sai.sh
+++ b/hooks/sai.sh
@@ -1,6 +1,13 @@
-#!/bin/sh
+#!/bin/bash
+
+# this is a hook to run on your gitolite server when you push a branch
+# it usually goes in ./local/VREF in your gitohashi config
+
+REPO_URL_BASE="https://libwebsockets.org"
+REPO_FETCH_URL_BASE="${REPO_URL_BASE}/repo"
+REPO_WEB_URL_BASE="${REPO_URL_BASE}/git"
+SAI_SERVER_BASE="https://libwebsockets.org:4444/sai/update-hook"
-REPO_FETCH_URL_BASE="https://libwebsockets.org/repo"
# json_escape <string>: emit a JSON string literal body with \, ", and control
# bytes escaped. Git ref names and repository names can legally contain ", \,
@@ -8,6 +15,7 @@ REPO_FETCH_URL_BASE="https://libwebsockets.org/repo"
# would allow JSON injection (a pushed branch named foo","extra":"... could
# inject fields). The whole payload is HMAC-signed afterwards, but escaping
# here keeps the structure unambiguous regardless of parser quirks.
+
json_escape() {
printf '%s' "$1" | sed \
-e 's/\\/\\\\/g' \
@@ -26,45 +34,48 @@ fi
RN=${RN%.git}
-echo sai update hook $RN...
-rm -f .sai.json .sai.json.b64
-git show $3 -- .sai.json | patch -p1 --merge
-cat .sai.json
-cat .sai.json | base64 -w0 > .sai.json.b64
-SJL=`stat .sai.json.b64 -c %s`
+# Pre-escape attacker-influenced fields once. RN is derived from the repo
+# directory name; $1 is the git ref; $3 is the new commit hash.
+
+RN_E=$(json_escape "$RN")
+REF_E=$(json_escape "$1")
+HASH_E=$(json_escape "$3")
+
-if [ -z $SJL -o $SJL = "0" ] ; then
- cat /home/sai/.sai.json | base64 -w0 > .sai.json.b64
- SJL=`stat .sai.json.b64 -c %s`
+
+pwd
+
+echo sai update hook $1 $RN_E...
+if [ ! -z "`echo $1 | grep /_`" ] ; then
+ echo "Detected temp ref starting with _, not passing to Sai"
+ exit 0
fi
+rm -f .sai.json .sai.json.b64
+git show $3:.sai.json | base64 -w0 > .sai.json.b64
+SJL=`stat .sai.json.b64 -c %s`
TF=`mktemp`
-# Pre-escape attacker-influenced fields once. RN is derived from the repo
-# directory name; $1 is the git ref; $3 is the new commit hash.
-RN_E=$(json_escape "$RN")
-REF_E=$(json_escape "$1")
-HASH_E=$(json_escape "$3")
-
echo "{\"schema\":\"com-warmcat-sai-notification\"," > $TF
echo " \"action\":\"repo-update\"," >> $TF
echo " \"repository\":{" >> $TF
-echo " \"name\":\"$RN_E\"" >> $TF
-echo " \"fetchurl\":\"$REPO_FETCH_URL_BASE\"" >> $TF
+echo " \"name\":\"${RN_E}\"," >> $TF
+echo " \"fetchurl\":\"$REPO_FETCH_URL_BASE/${RN_E}\"," >> $TF
+echo " \"weburl\":\"$REPO_WEB_URL_BASE/${RN_E}\"" >> $TF
echo " }," >> $TF
echo " \"nonce\":\"`dd if=/dev/urandom bs=32 count=1 | sha256sum | cut -d' ' -f1`\"," >> $TF
echo " \"ref\":\"$REF_E\"," >> $TF
echo " \"hash\":\"$HASH_E\"," >> $TF
-echo " \"saifile_len\":$SJL," >> $TF
+echo " \"saifile_len\":${SJL}," >> $TF
echo -n " \"saifile\":\"" >> $TF
# disallow any nested JSON monkey business by base64-encoding it
cat .sai.json.b64 >> $TF
echo "\"" >> $TF
echo "}" >> $TF
-HM=`cat $TF | sha256hmac -k /etc/sai/private/lws-sai-notification-token | cut -d' ' -f1`
+HM=`cat $TF | openssl dgst -sha256 -hmac $(cat /etc/sai/private/lws-sai-notification-token2) | cut -d' ' -f2`
if [ $SJL = "0" ] ; then
echo "No saifile"
@@ -73,14 +84,15 @@ fi
cat $TF
echo $HM
+echo badline: -F"file=@${TF};type=application/json"
curl --header "authorization: sai sha256=$HM" \
- -F"file=@$TF;type=application/json" \
- -A "sai-notifier" \
- https://warmcat.com/sai/update-hook
-#curl --header "X-Sai-Signature: sha256=$HM" -F"file=@$TF;name=notification;type=application/json" -A "sai-notifier" http://127.0.0.1:4444
+ -F"file=@${TF};type=application/json" \
+ -A "sai-notifier" -m 30 \
+ ${SAI_SERVER_BASE}
rm -f $TF
exit 0
+