Project homepage Mailing List  Warmcat.com  API Docs  Github Mirror 
    npro  
 Modern all-safe Rust Network Protocol library supporting h1, h2, h3, ws, wt sans-IO and with socket IO + tls
git clone https://npro.rs/repo/npro
Author[]Andy Green <andy@warmcat.com> 2026-08-23 17:53 UTC
Committer[]Andy Green <andy@warmcat.com> 2026-08-23 17:53 UTC
Treef397766ba92b34f63b409ac10f5056ba9d154695   Raw Patch
 
hook: update to what is in use
hook: update to what is in use
diff --git a/hooks/sai.sh b/hooks/sai.sh index 22df6d8..0ab44e6 100755 --- a/hooks/sai.sh +++ b/hooks/sai.sh @@ -1,6 +1,13 @@ -#!/bin/sh +#!/bin/bash + +# this is a hook to run on your gitolite server when you push a branch +# it usually goes in ./local/VREF in your gitohashi config + +REPO_URL_BASE="https://libwebsockets.org" +REPO_FETCH_URL_BASE="${REPO_URL_BASE}/repo" +REPO_WEB_URL_BASE="${REPO_URL_BASE}/git" +SAI_SERVER_BASE="https://libwebsockets.org:4444/sai/update-hook" -REPO_FETCH_URL_BASE="https://libwebsockets.org/repo" # json_escape <string>: emit a JSON string literal body with \, ", and control # bytes escaped. Git ref names and repository names can legally contain ", \, @@ -8,6 +15,7 @@ REPO_FETCH_URL_BASE="https://libwebsockets.org/repo" # would allow JSON injection (a pushed branch named foo","extra":"... could # inject fields). The whole payload is HMAC-signed afterwards, but escaping # here keeps the structure unambiguous regardless of parser quirks. + json_escape() { printf '%s' "$1" | sed \ -e 's/\\/\\\\/g' \ @@ -26,45 +34,48 @@ fi RN=${RN%.git} -echo sai update hook $RN... -rm -f .sai.json .sai.json.b64 -git show $3 -- .sai.json | patch -p1 --merge -cat .sai.json -cat .sai.json | base64 -w0 > .sai.json.b64 -SJL=`stat .sai.json.b64 -c %s` +# Pre-escape attacker-influenced fields once. RN is derived from the repo +# directory name; $1 is the git ref; $3 is the new commit hash. + +RN_E=$(json_escape "$RN") +REF_E=$(json_escape "$1") +HASH_E=$(json_escape "$3") + -if [ -z $SJL -o $SJL = "0" ] ; then - cat /home/sai/.sai.json | base64 -w0 > .sai.json.b64 - SJL=`stat .sai.json.b64 -c %s` + +pwd + +echo sai update hook $1 $RN_E... +if [ ! -z "`echo $1 | grep /_`" ] ; then + echo "Detected temp ref starting with _, not passing to Sai" + exit 0 fi +rm -f .sai.json .sai.json.b64 +git show $3:.sai.json | base64 -w0 > .sai.json.b64 +SJL=`stat .sai.json.b64 -c %s` TF=`mktemp` -# Pre-escape attacker-influenced fields once. RN is derived from the repo -# directory name; $1 is the git ref; $3 is the new commit hash. -RN_E=$(json_escape "$RN") -REF_E=$(json_escape "$1") -HASH_E=$(json_escape "$3") - echo "{\"schema\":\"com-warmcat-sai-notification\"," > $TF echo " \"action\":\"repo-update\"," >> $TF echo " \"repository\":{" >> $TF -echo " \"name\":\"$RN_E\"" >> $TF -echo " \"fetchurl\":\"$REPO_FETCH_URL_BASE\"" >> $TF +echo " \"name\":\"${RN_E}\"," >> $TF +echo " \"fetchurl\":\"$REPO_FETCH_URL_BASE/${RN_E}\"," >> $TF +echo " \"weburl\":\"$REPO_WEB_URL_BASE/${RN_E}\"" >> $TF echo " }," >> $TF echo " \"nonce\":\"`dd if=/dev/urandom bs=32 count=1 | sha256sum | cut -d' ' -f1`\"," >> $TF echo " \"ref\":\"$REF_E\"," >> $TF echo " \"hash\":\"$HASH_E\"," >> $TF -echo " \"saifile_len\":$SJL," >> $TF +echo " \"saifile_len\":${SJL}," >> $TF echo -n " \"saifile\":\"" >> $TF # disallow any nested JSON monkey business by base64-encoding it cat .sai.json.b64 >> $TF echo "\"" >> $TF echo "}" >> $TF -HM=`cat $TF | sha256hmac -k /etc/sai/private/lws-sai-notification-token | cut -d' ' -f1` +HM=`cat $TF | openssl dgst -sha256 -hmac $(cat /etc/sai/private/lws-sai-notification-token2) | cut -d' ' -f2` if [ $SJL = "0" ] ; then echo "No saifile" @@ -73,14 +84,15 @@ fi cat $TF echo $HM +echo badline: -F"file=@${TF};type=application/json" curl --header "authorization: sai sha256=$HM" \ - -F"file=@$TF;type=application/json" \ - -A "sai-notifier" \ - https://warmcat.com/sai/update-hook -#curl --header "X-Sai-Signature: sha256=$HM" -F"file=@$TF;name=notification;type=application/json" -A "sai-notifier" http://127.0.0.1:4444 + -F"file=@${TF};type=application/json" \ + -A "sai-notifier" -m 30 \ + ${SAI_SERVER_BASE} rm -f $TF exit 0 +
Page fetched 0s ago, creation time: 8ms (vhost etag hits: 0%, cache hits: 0%)