Skip to content

Commit 3b1687a

Browse files
authored
Merge branch 'main' into lunny/allow_agit_force_push
2 parents 9eafc49 + 0fe5e2b commit 3b1687a

File tree

5 files changed

+108
-11
lines changed

5 files changed

+108
-11
lines changed

routers/api/packages/container/blob.go

Lines changed: 18 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -10,20 +10,18 @@ import (
1010
"fmt"
1111
"os"
1212
"strings"
13-
"sync"
1413

1514
"code.gitea.io/gitea/models/db"
1615
packages_model "code.gitea.io/gitea/models/packages"
1716
container_model "code.gitea.io/gitea/models/packages/container"
17+
"code.gitea.io/gitea/modules/globallock"
1818
"code.gitea.io/gitea/modules/log"
1919
packages_module "code.gitea.io/gitea/modules/packages"
2020
container_module "code.gitea.io/gitea/modules/packages/container"
2121
"code.gitea.io/gitea/modules/util"
2222
packages_service "code.gitea.io/gitea/services/packages"
2323
)
2424

25-
var uploadVersionMutex sync.Mutex
26-
2725
// saveAsPackageBlob creates a package blob from an upload
2826
// The uploaded blob gets stored in a special upload version to link them to the package/image
2927
func saveAsPackageBlob(ctx context.Context, hsr packages_module.HashedSizeReader, pci *packages_service.PackageCreationInfo) (*packages_model.PackageBlob, error) { //nolint:unparam
@@ -90,13 +88,20 @@ func mountBlob(ctx context.Context, pi *packages_service.PackageInfo, pb *packag
9088
})
9189
}
9290

91+
func containerPkgName(piOwnerID int64, piName string) string {
92+
return fmt.Sprintf("pkg_%d_container_%s", piOwnerID, strings.ToLower(piName))
93+
}
94+
9395
func getOrCreateUploadVersion(ctx context.Context, pi *packages_service.PackageInfo) (*packages_model.PackageVersion, error) {
9496
var uploadVersion *packages_model.PackageVersion
9597

96-
// FIXME: Replace usage of mutex with database transaction
97-
// https://github.com/go-gitea/gitea/pull/21862
98-
uploadVersionMutex.Lock()
99-
err := db.WithTx(ctx, func(ctx context.Context) error {
98+
releaser, err := globallock.Lock(ctx, containerPkgName(pi.Owner.ID, pi.Name))
99+
if err != nil {
100+
return nil, err
101+
}
102+
defer releaser()
103+
104+
err = db.WithTx(ctx, func(ctx context.Context) error {
100105
created := true
101106
p := &packages_model.Package{
102107
OwnerID: pi.Owner.ID,
@@ -140,7 +145,6 @@ func getOrCreateUploadVersion(ctx context.Context, pi *packages_service.PackageI
140145

141146
return nil
142147
})
143-
uploadVersionMutex.Unlock()
144148

145149
return uploadVersion, err
146150
}
@@ -173,6 +177,12 @@ func createFileForBlob(ctx context.Context, pv *packages_model.PackageVersion, p
173177
}
174178

175179
func deleteBlob(ctx context.Context, ownerID int64, image, digest string) error {
180+
releaser, err := globallock.Lock(ctx, containerPkgName(ownerID, image))
181+
if err != nil {
182+
return err
183+
}
184+
defer releaser()
185+
176186
return db.WithTx(ctx, func(ctx context.Context) error {
177187
pfds, err := container_model.GetContainerBlobs(ctx, &container_model.BlobSearchOptions{
178188
OwnerID: ownerID,

routers/web/repo/pull.go

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -887,8 +887,6 @@ func viewPullFiles(ctx *context.Context, specifiedStartCommit, specifiedEndCommi
887887
}
888888

889889
if pull.HeadRepo != nil {
890-
ctx.Data["SourcePath"] = pull.HeadRepo.Link() + "/src/commit/" + endCommitID
891-
892890
if !pull.HasMerged && ctx.Doer != nil {
893891
perm, err := access_model.GetUserRepoPermission(ctx, pull.HeadRepo, ctx.Doer)
894892
if err != nil {

services/context/permission.go

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -58,6 +58,9 @@ func RequireRepoWriterOr(unitTypes ...unit.Type) func(ctx *Context) {
5858
func RequireRepoReader(unitType unit.Type) func(ctx *Context) {
5959
return func(ctx *Context) {
6060
if !ctx.Repo.CanRead(unitType) {
61+
if unitType == unit.TypeCode && canWriteAsMaintainer(ctx) {
62+
return
63+
}
6164
if log.IsTrace() {
6265
if ctx.IsSigned {
6366
log.Trace("Permission Denied: User %-v cannot read %-v in Repo %-v\n"+

services/context/repo.go

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -374,7 +374,7 @@ func repoAssignment(ctx *Context, repo *repo_model.Repository) {
374374
return
375375
}
376376

377-
if !ctx.Repo.Permission.HasAnyUnitAccessOrEveryoneAccess() {
377+
if !ctx.Repo.Permission.HasAnyUnitAccessOrEveryoneAccess() && !canWriteAsMaintainer(ctx) {
378378
if ctx.FormString("go-get") == "1" {
379379
EarlyResponseForGoGetMeta(ctx)
380380
return
@@ -1058,3 +1058,11 @@ func GitHookService() func(ctx *Context) {
10581058
}
10591059
}
10601060
}
1061+
1062+
// canWriteAsMaintainer check if the doer can write to a branch as a maintainer
1063+
func canWriteAsMaintainer(ctx *Context) bool {
1064+
branchName := getRefNameFromPath(ctx.Repo, ctx.PathParam("*"), func(branchName string) bool {
1065+
return issues_model.CanMaintainerWriteToBranch(ctx, ctx.Repo.Permission, branchName, ctx.Doer)
1066+
})
1067+
return len(branchName) > 0
1068+
}

tests/integration/pull_compare_test.go

Lines changed: 78 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,7 @@ import (
1414
repo_model "code.gitea.io/gitea/models/repo"
1515
"code.gitea.io/gitea/models/unittest"
1616
user_model "code.gitea.io/gitea/models/user"
17+
"code.gitea.io/gitea/modules/test"
1718
repo_service "code.gitea.io/gitea/services/repository"
1819
"code.gitea.io/gitea/tests"
1920

@@ -73,3 +74,80 @@ func TestPullCompare(t *testing.T) {
7374
assert.EqualValues(t, editButtonCount, 0, "Expected not to find a button to edit a file in the PR diff view because head repository has been deleted")
7475
})
7576
}
77+
78+
func TestPullCompare_EnableAllowEditsFromMaintainer(t *testing.T) {
79+
onGiteaRun(t, func(t *testing.T, u *url.URL) {
80+
// repo3 is private
81+
repo3 := unittest.AssertExistsAndLoadBean(t, &repo_model.Repository{ID: 3})
82+
assert.True(t, repo3.IsPrivate)
83+
84+
// user4 forks repo3
85+
user4Session := loginUser(t, "user4")
86+
forkedRepoName := "user4-forked-repo3"
87+
testRepoFork(t, user4Session, repo3.OwnerName, repo3.Name, "user4", forkedRepoName, "")
88+
forkedRepo := unittest.AssertExistsAndLoadBean(t, &repo_model.Repository{OwnerName: "user4", Name: forkedRepoName})
89+
assert.True(t, forkedRepo.IsPrivate)
90+
91+
// user4 creates a new branch and a PR
92+
testEditFileToNewBranch(t, user4Session, "user4", forkedRepoName, "master", "user4/update-readme", "README.md", "Hello, World\n(Edited by user4)\n")
93+
resp := testPullCreateDirectly(t, user4Session, repo3.OwnerName, repo3.Name, "master", "user4", forkedRepoName, "user4/update-readme", "PR for user4 forked repo3")
94+
prURL := test.RedirectURL(resp)
95+
96+
// user2 (admin of repo3) goes to the PR files page
97+
user2Session := loginUser(t, "user2")
98+
resp = user2Session.MakeRequest(t, NewRequest(t, "GET", fmt.Sprintf("%s/files", prURL)), http.StatusOK)
99+
htmlDoc := NewHTMLParser(t, resp.Body)
100+
nodes := htmlDoc.doc.Find(".diff-file-box[data-new-filename=\"README.md\"] .diff-file-header-actions .dropdown .menu a")
101+
if assert.Equal(t, 1, nodes.Length()) {
102+
// there is only "View File" button, no "Edit File" button
103+
assert.Equal(t, "View File", nodes.First().Text())
104+
viewFileLink, exists := nodes.First().Attr("href")
105+
if assert.True(t, exists) {
106+
user2Session.MakeRequest(t, NewRequest(t, "GET", viewFileLink), http.StatusOK)
107+
}
108+
}
109+
110+
// user4 goes to the PR page and enable "Allow maintainers to edit"
111+
resp = user4Session.MakeRequest(t, NewRequest(t, "GET", prURL), http.StatusOK)
112+
htmlDoc = NewHTMLParser(t, resp.Body)
113+
dataURL, exists := htmlDoc.doc.Find("#allow-edits-from-maintainers").Attr("data-url")
114+
assert.True(t, exists)
115+
req := NewRequestWithValues(t, "POST", fmt.Sprintf("%s/set_allow_maintainer_edit", dataURL), map[string]string{
116+
"_csrf": htmlDoc.GetCSRF(),
117+
"allow_maintainer_edit": "true",
118+
})
119+
user4Session.MakeRequest(t, req, http.StatusOK)
120+
121+
// user2 (admin of repo3) goes to the PR files page again
122+
resp = user2Session.MakeRequest(t, NewRequest(t, "GET", fmt.Sprintf("%s/files", prURL)), http.StatusOK)
123+
htmlDoc = NewHTMLParser(t, resp.Body)
124+
nodes = htmlDoc.doc.Find(".diff-file-box[data-new-filename=\"README.md\"] .diff-file-header-actions .dropdown .menu a")
125+
if assert.Equal(t, 2, nodes.Length()) {
126+
// there are "View File" button and "Edit File" button
127+
assert.Equal(t, "View File", nodes.First().Text())
128+
viewFileLink, exists := nodes.First().Attr("href")
129+
if assert.True(t, exists) {
130+
user2Session.MakeRequest(t, NewRequest(t, "GET", viewFileLink), http.StatusOK)
131+
}
132+
133+
assert.Equal(t, "Edit File", nodes.Last().Text())
134+
editFileLink, exists := nodes.Last().Attr("href")
135+
if assert.True(t, exists) {
136+
// edit the file
137+
resp := user2Session.MakeRequest(t, NewRequest(t, "GET", editFileLink), http.StatusOK)
138+
htmlDoc := NewHTMLParser(t, resp.Body)
139+
lastCommit := htmlDoc.GetInputValueByName("last_commit")
140+
assert.NotEmpty(t, lastCommit)
141+
req := NewRequestWithValues(t, "POST", editFileLink, map[string]string{
142+
"_csrf": htmlDoc.GetCSRF(),
143+
"last_commit": lastCommit,
144+
"tree_path": "README.md",
145+
"content": "File is edited by the maintainer user2",
146+
"commit_summary": "user2 updated the file",
147+
"commit_choice": "direct",
148+
})
149+
user2Session.MakeRequest(t, req, http.StatusSeeOther)
150+
}
151+
}
152+
})
153+
}

0 commit comments

Comments
 (0)