gitea源码

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428
  1. // Copyright 2019 The Gitea Authors. All rights reserved.
  2. // SPDX-License-Identifier: MIT
  3. package release
  4. import (
  5. "context"
  6. "errors"
  7. "fmt"
  8. "strings"
  9. "code.gitea.io/gitea/models/db"
  10. git_model "code.gitea.io/gitea/models/git"
  11. repo_model "code.gitea.io/gitea/models/repo"
  12. user_model "code.gitea.io/gitea/models/user"
  13. "code.gitea.io/gitea/modules/container"
  14. "code.gitea.io/gitea/modules/git"
  15. "code.gitea.io/gitea/modules/git/gitcmd"
  16. "code.gitea.io/gitea/modules/gitrepo"
  17. "code.gitea.io/gitea/modules/graceful"
  18. "code.gitea.io/gitea/modules/log"
  19. "code.gitea.io/gitea/modules/repository"
  20. "code.gitea.io/gitea/modules/storage"
  21. "code.gitea.io/gitea/modules/timeutil"
  22. "code.gitea.io/gitea/modules/util"
  23. notify_service "code.gitea.io/gitea/services/notify"
  24. )
  25. // ErrInvalidTagName represents a "InvalidTagName" kind of error.
  26. type ErrInvalidTagName struct {
  27. TagName string
  28. }
  29. // IsErrInvalidTagName checks if an error is a ErrInvalidTagName.
  30. func IsErrInvalidTagName(err error) bool {
  31. _, ok := err.(ErrInvalidTagName)
  32. return ok
  33. }
  34. func (err ErrInvalidTagName) Error() string {
  35. return fmt.Sprintf("release tag name is not valid [tag_name: %s]", err.TagName)
  36. }
  37. func (err ErrInvalidTagName) Unwrap() error {
  38. return util.ErrInvalidArgument
  39. }
  40. // ErrProtectedTagName represents a "ProtectedTagName" kind of error.
  41. type ErrProtectedTagName struct {
  42. TagName string
  43. }
  44. // IsErrProtectedTagName checks if an error is a ErrProtectedTagName.
  45. func IsErrProtectedTagName(err error) bool {
  46. _, ok := err.(ErrProtectedTagName)
  47. return ok
  48. }
  49. func (err ErrProtectedTagName) Error() string {
  50. return fmt.Sprintf("release tag name is protected [tag_name: %s]", err.TagName)
  51. }
  52. func (err ErrProtectedTagName) Unwrap() error {
  53. return util.ErrPermissionDenied
  54. }
  55. func createTag(ctx context.Context, gitRepo *git.Repository, rel *repo_model.Release, msg string) (bool, error) {
  56. err := rel.LoadAttributes(ctx)
  57. if err != nil {
  58. return false, err
  59. }
  60. err = rel.Repo.MustNotBeArchived()
  61. if err != nil {
  62. return false, err
  63. }
  64. var created bool
  65. // Only actual create when publish.
  66. if !rel.IsDraft {
  67. if !gitrepo.IsTagExist(ctx, rel.Repo, rel.TagName) {
  68. if err := rel.LoadAttributes(ctx); err != nil {
  69. log.Error("LoadAttributes: %v", err)
  70. return false, err
  71. }
  72. protectedTags, err := git_model.GetProtectedTags(ctx, rel.Repo.ID)
  73. if err != nil {
  74. return false, fmt.Errorf("GetProtectedTags: %w", err)
  75. }
  76. // Trim '--' prefix to prevent command line argument vulnerability.
  77. rel.TagName = strings.TrimPrefix(rel.TagName, "--")
  78. isAllowed, err := git_model.IsUserAllowedToControlTag(ctx, protectedTags, rel.TagName, rel.PublisherID)
  79. if err != nil {
  80. return false, err
  81. }
  82. if !isAllowed {
  83. return false, ErrProtectedTagName{
  84. TagName: rel.TagName,
  85. }
  86. }
  87. commit, err := gitRepo.GetCommit(rel.Target)
  88. if err != nil {
  89. return false, err
  90. }
  91. if len(msg) > 0 {
  92. if err = gitRepo.CreateAnnotatedTag(rel.TagName, msg, commit.ID.String()); err != nil {
  93. if strings.Contains(err.Error(), "is not a valid tag name") {
  94. return false, ErrInvalidTagName{
  95. TagName: rel.TagName,
  96. }
  97. }
  98. return false, err
  99. }
  100. } else if err = gitRepo.CreateTag(rel.TagName, commit.ID.String()); err != nil {
  101. if strings.Contains(err.Error(), "is not a valid tag name") {
  102. return false, ErrInvalidTagName{
  103. TagName: rel.TagName,
  104. }
  105. }
  106. return false, err
  107. }
  108. created = true
  109. rel.LowerTagName = strings.ToLower(rel.TagName)
  110. objectFormat := git.ObjectFormatFromName(rel.Repo.ObjectFormatName)
  111. commits := repository.NewPushCommits()
  112. commits.HeadCommit = repository.CommitToPushCommit(commit)
  113. commits.CompareURL = rel.Repo.ComposeCompareURL(objectFormat.EmptyObjectID().String(), commit.ID.String())
  114. refFullName := git.RefNameFromTag(rel.TagName)
  115. notify_service.PushCommits(
  116. ctx, rel.Publisher, rel.Repo,
  117. &repository.PushUpdateOptions{
  118. RefFullName: refFullName,
  119. OldCommitID: objectFormat.EmptyObjectID().String(),
  120. NewCommitID: commit.ID.String(),
  121. }, commits)
  122. notify_service.CreateRef(ctx, rel.Publisher, rel.Repo, refFullName, commit.ID.String())
  123. rel.CreatedUnix = timeutil.TimeStampNow()
  124. }
  125. commit, err := gitRepo.GetTagCommit(rel.TagName)
  126. if err != nil {
  127. return false, fmt.Errorf("GetTagCommit: %w", err)
  128. }
  129. rel.Sha1 = commit.ID.String()
  130. rel.NumCommits, err = commit.CommitsCount()
  131. if err != nil {
  132. return false, fmt.Errorf("CommitsCount: %w", err)
  133. }
  134. if rel.PublisherID <= 0 {
  135. u, err := user_model.GetUserByEmail(ctx, commit.Author.Email)
  136. if err == nil {
  137. rel.PublisherID = u.ID
  138. }
  139. }
  140. } else {
  141. rel.CreatedUnix = timeutil.TimeStampNow()
  142. }
  143. return created, nil
  144. }
  145. // CreateRelease creates a new release of repository.
  146. func CreateRelease(gitRepo *git.Repository, rel *repo_model.Release, attachmentUUIDs []string, msg string) error {
  147. has, err := repo_model.IsReleaseExist(gitRepo.Ctx, rel.RepoID, rel.TagName)
  148. if err != nil {
  149. return err
  150. } else if has {
  151. return repo_model.ErrReleaseAlreadyExist{
  152. TagName: rel.TagName,
  153. }
  154. }
  155. if _, err = createTag(gitRepo.Ctx, gitRepo, rel, msg); err != nil {
  156. return err
  157. }
  158. rel.Title = util.EllipsisDisplayString(rel.Title, 255)
  159. rel.LowerTagName = strings.ToLower(rel.TagName)
  160. if err = db.Insert(gitRepo.Ctx, rel); err != nil {
  161. return err
  162. }
  163. if err = repo_model.AddReleaseAttachments(gitRepo.Ctx, rel.ID, attachmentUUIDs); err != nil {
  164. return err
  165. }
  166. if !rel.IsDraft {
  167. notify_service.NewRelease(gitRepo.Ctx, rel)
  168. }
  169. return nil
  170. }
  171. // ErrTagAlreadyExists represents an error that tag with such name already exists.
  172. type ErrTagAlreadyExists struct {
  173. TagName string
  174. }
  175. // IsErrTagAlreadyExists checks if an error is an ErrTagAlreadyExists.
  176. func IsErrTagAlreadyExists(err error) bool {
  177. _, ok := err.(ErrTagAlreadyExists)
  178. return ok
  179. }
  180. func (err ErrTagAlreadyExists) Error() string {
  181. return fmt.Sprintf("tag already exists [name: %s]", err.TagName)
  182. }
  183. func (err ErrTagAlreadyExists) Unwrap() error {
  184. return util.ErrAlreadyExist
  185. }
  186. // CreateNewTag creates a new repository tag
  187. func CreateNewTag(ctx context.Context, doer *user_model.User, repo *repo_model.Repository, commit, tagName, msg string) error {
  188. has, err := repo_model.IsReleaseExist(ctx, repo.ID, tagName)
  189. if err != nil {
  190. return err
  191. } else if has {
  192. return ErrTagAlreadyExists{
  193. TagName: tagName,
  194. }
  195. }
  196. gitRepo, closer, err := gitrepo.RepositoryFromContextOrOpen(ctx, repo)
  197. if err != nil {
  198. return err
  199. }
  200. defer closer.Close()
  201. rel := &repo_model.Release{
  202. RepoID: repo.ID,
  203. Repo: repo,
  204. PublisherID: doer.ID,
  205. Publisher: doer,
  206. TagName: tagName,
  207. Target: commit,
  208. IsDraft: false,
  209. IsPrerelease: false,
  210. IsTag: true,
  211. }
  212. if _, err = createTag(ctx, gitRepo, rel, msg); err != nil {
  213. return err
  214. }
  215. return db.Insert(ctx, rel)
  216. }
  217. // UpdateRelease updates information, attachments of a release and will create tag if it's not a draft and tag not exist.
  218. // addAttachmentUUIDs accept a slice of new created attachments' uuids which will be reassigned release_id as the created release
  219. // delAttachmentUUIDs accept a slice of attachments' uuids which will be deleted from the release
  220. // editAttachments accept a map of attachment uuid to new attachment name which will be updated with attachments.
  221. func UpdateRelease(ctx context.Context, doer *user_model.User, gitRepo *git.Repository, rel *repo_model.Release,
  222. addAttachmentUUIDs, delAttachmentUUIDs []string, editAttachments map[string]string,
  223. ) error {
  224. if rel.ID == 0 {
  225. return errors.New("UpdateRelease only accepts an exist release")
  226. }
  227. isTagCreated, err := createTag(gitRepo.Ctx, gitRepo, rel, "")
  228. if err != nil {
  229. return err
  230. }
  231. rel.LowerTagName = strings.ToLower(rel.TagName)
  232. oldRelease, err := repo_model.GetReleaseByID(ctx, rel.ID)
  233. if err != nil {
  234. return err
  235. }
  236. isConvertedFromTag := oldRelease.IsTag && !rel.IsTag
  237. if err := db.WithTx(ctx, func(ctx context.Context) error {
  238. if err = repo_model.UpdateRelease(ctx, rel); err != nil {
  239. return err
  240. }
  241. if err = repo_model.AddReleaseAttachments(ctx, rel.ID, addAttachmentUUIDs); err != nil {
  242. return fmt.Errorf("AddReleaseAttachments: %w", err)
  243. }
  244. deletedUUIDs := make(container.Set[string])
  245. if len(delAttachmentUUIDs) > 0 {
  246. // Check attachments
  247. attachments, err := repo_model.GetAttachmentsByUUIDs(ctx, delAttachmentUUIDs)
  248. if err != nil {
  249. return fmt.Errorf("GetAttachmentsByUUIDs [uuids: %v]: %w", delAttachmentUUIDs, err)
  250. }
  251. for _, attach := range attachments {
  252. if attach.ReleaseID != rel.ID {
  253. return util.NewPermissionDeniedErrorf("delete attachment of release permission denied")
  254. }
  255. deletedUUIDs.Add(attach.UUID)
  256. }
  257. if _, err := repo_model.DeleteAttachments(ctx, attachments, true); err != nil {
  258. return fmt.Errorf("DeleteAttachments [uuids: %v]: %w", delAttachmentUUIDs, err)
  259. }
  260. }
  261. if len(editAttachments) > 0 {
  262. updateAttachmentsList := make([]string, 0, len(editAttachments))
  263. for k := range editAttachments {
  264. updateAttachmentsList = append(updateAttachmentsList, k)
  265. }
  266. // Check attachments
  267. attachments, err := repo_model.GetAttachmentsByUUIDs(ctx, updateAttachmentsList)
  268. if err != nil {
  269. return fmt.Errorf("GetAttachmentsByUUIDs [uuids: %v]: %w", updateAttachmentsList, err)
  270. }
  271. for _, attach := range attachments {
  272. if attach.ReleaseID != rel.ID {
  273. return util.NewPermissionDeniedErrorf("update attachment of release permission denied")
  274. }
  275. }
  276. for uuid, newName := range editAttachments {
  277. if !deletedUUIDs.Contains(uuid) {
  278. if err = repo_model.UpdateAttachmentByUUID(ctx, &repo_model.Attachment{
  279. UUID: uuid,
  280. Name: newName,
  281. }, "name"); err != nil {
  282. return err
  283. }
  284. }
  285. }
  286. }
  287. return nil
  288. }); err != nil {
  289. return err
  290. }
  291. for _, uuid := range delAttachmentUUIDs {
  292. if err := storage.Attachments.Delete(repo_model.AttachmentRelativePath(uuid)); err != nil {
  293. // Even delete files failed, but the attachments has been removed from database, so we
  294. // should not return error but only record the error on logs.
  295. // users have to delete this attachments manually or we should have a
  296. // synchronize between database attachment table and attachment storage
  297. log.Error("delete attachment[uuid: %s] failed: %v", uuid, err)
  298. }
  299. }
  300. if !rel.IsDraft {
  301. if !isTagCreated && !isConvertedFromTag {
  302. notify_service.UpdateRelease(gitRepo.Ctx, doer, rel)
  303. return nil
  304. }
  305. notify_service.NewRelease(gitRepo.Ctx, rel)
  306. }
  307. return nil
  308. }
  309. // DeleteReleaseByID deletes a release and corresponding Git tag by given ID.
  310. func DeleteReleaseByID(ctx context.Context, repo *repo_model.Repository, rel *repo_model.Release, doer *user_model.User, delTag bool) error {
  311. if delTag {
  312. protectedTags, err := git_model.GetProtectedTags(ctx, rel.RepoID)
  313. if err != nil {
  314. return fmt.Errorf("GetProtectedTags: %w", err)
  315. }
  316. isAllowed, err := git_model.IsUserAllowedToControlTag(ctx, protectedTags, rel.TagName, rel.PublisherID)
  317. if err != nil {
  318. return err
  319. }
  320. if !isAllowed {
  321. return ErrProtectedTagName{
  322. TagName: rel.TagName,
  323. }
  324. }
  325. if stdout, _, err := gitcmd.NewCommand("tag", "-d").AddDashesAndList(rel.TagName).
  326. RunStdString(ctx, &gitcmd.RunOpts{Dir: repo.RepoPath()}); err != nil && !strings.Contains(err.Error(), "not found") {
  327. log.Error("DeleteReleaseByID (git tag -d): %d in %v Failed:\nStdout: %s\nError: %v", rel.ID, repo, stdout, err)
  328. return fmt.Errorf("git tag -d: %w", err)
  329. }
  330. refName := git.RefNameFromTag(rel.TagName)
  331. objectFormat := git.ObjectFormatFromName(repo.ObjectFormatName)
  332. notify_service.PushCommits(
  333. ctx, doer, repo,
  334. &repository.PushUpdateOptions{
  335. RefFullName: refName,
  336. OldCommitID: rel.Sha1,
  337. NewCommitID: objectFormat.EmptyObjectID().String(),
  338. }, repository.NewPushCommits())
  339. notify_service.DeleteRef(ctx, doer, repo, refName)
  340. if _, err := db.DeleteByID[repo_model.Release](ctx, rel.ID); err != nil {
  341. return fmt.Errorf("DeleteReleaseByID: %w", err)
  342. }
  343. } else {
  344. rel.IsTag = true
  345. if err := repo_model.UpdateRelease(ctx, rel); err != nil {
  346. return fmt.Errorf("Update: %w", err)
  347. }
  348. }
  349. rel.Repo = repo
  350. if err := rel.LoadAttributes(ctx); err != nil {
  351. return fmt.Errorf("LoadAttributes: %w", err)
  352. }
  353. if err := repo_model.DeleteAttachmentsByRelease(ctx, rel.ID); err != nil {
  354. return fmt.Errorf("DeleteAttachments: %w", err)
  355. }
  356. for i := range rel.Attachments {
  357. attachment := rel.Attachments[i]
  358. if err := storage.Attachments.Delete(attachment.RelativePath()); err != nil {
  359. log.Error("Delete attachment %s of release %s failed: %v", attachment.UUID, rel.ID, err)
  360. }
  361. }
  362. if !rel.IsDraft {
  363. notify_service.DeleteRelease(ctx, doer, rel)
  364. }
  365. return nil
  366. }
  367. // Init start release service
  368. func Init() error {
  369. return initTagSyncQueue(graceful.GetManager().ShutdownContext())
  370. }