release.go 9.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370
  1. package database
  2. import (
  3. "fmt"
  4. "sort"
  5. "strings"
  6. "time"
  7. "github.com/cockroachdb/errors"
  8. "github.com/gogs/git-module"
  9. api "github.com/gogs/go-gogs-client"
  10. "gorm.io/gorm"
  11. log "unknwon.dev/clog/v2"
  12. "gogs.io/gogs/internal/errutil"
  13. "gogs.io/gogs/internal/process"
  14. )
  15. // Release represents a release of repository.
  16. type Release struct {
  17. ID int64
  18. RepoID int64
  19. Repo *Repository `gorm:"-" json:"-"`
  20. PublisherID int64
  21. Publisher *User `gorm:"-" json:"-"`
  22. TagName string
  23. LowerTagName string
  24. Target string
  25. Title string
  26. Sha1 string `gorm:"type:varchar(40)"`
  27. NumCommits int64
  28. NumCommitsBehind int64 `gorm:"-" json:"-"`
  29. Note string `gorm:"type:text"`
  30. IsDraft bool `gorm:"not null;default:false"`
  31. IsPrerelease bool
  32. Created time.Time `gorm:"-" json:"-"`
  33. CreatedUnix int64
  34. Attachments []*Attachment `gorm:"-" json:"-"`
  35. }
  36. func (r *Release) BeforeCreate(tx *gorm.DB) error {
  37. if r.CreatedUnix == 0 {
  38. r.CreatedUnix = tx.NowFunc().Unix()
  39. }
  40. return nil
  41. }
  42. func (r *Release) AfterFind(tx *gorm.DB) error {
  43. r.Created = time.Unix(r.CreatedUnix, 0).Local()
  44. return nil
  45. }
  46. func (r *Release) loadAttributes(e *gorm.DB) (err error) {
  47. if r.Repo == nil {
  48. r.Repo, err = getRepositoryByID(e, r.RepoID)
  49. if err != nil {
  50. return errors.Newf("getRepositoryByID [repo_id: %d]: %v", r.RepoID, err)
  51. }
  52. }
  53. if r.Publisher == nil {
  54. r.Publisher, err = getUserByID(e, r.PublisherID)
  55. if err != nil {
  56. if IsErrUserNotExist(err) {
  57. r.PublisherID = -1
  58. r.Publisher = NewGhostUser()
  59. } else {
  60. return errors.Newf("getUserByID.(Publisher) [publisher_id: %d]: %v", r.PublisherID, err)
  61. }
  62. }
  63. }
  64. if r.Attachments == nil {
  65. r.Attachments, err = getAttachmentsByReleaseID(e, r.ID)
  66. if err != nil {
  67. return errors.Newf("getAttachmentsByReleaseID [%d]: %v", r.ID, err)
  68. }
  69. }
  70. return nil
  71. }
  72. func (r *Release) LoadAttributes() error {
  73. return r.loadAttributes(db)
  74. }
  75. // This method assumes some fields assigned with values:
  76. // Required - Publisher
  77. func (r *Release) APIFormat() *api.Release {
  78. return &api.Release{
  79. ID: r.ID,
  80. TagName: r.TagName,
  81. TargetCommitish: r.Target,
  82. Name: r.Title,
  83. Body: r.Note,
  84. Draft: r.IsDraft,
  85. Prerelease: r.IsPrerelease,
  86. Author: r.Publisher.APIFormat(),
  87. Created: r.Created,
  88. }
  89. }
  90. // IsReleaseExist returns true if release with given tag name already exists.
  91. func IsReleaseExist(repoID int64, tagName string) (bool, error) {
  92. if tagName == "" {
  93. return false, nil
  94. }
  95. var count int64
  96. err := db.Model(&Release{}).Where("repo_id = ? AND lower_tag_name = ?", repoID, strings.ToLower(tagName)).Count(&count).Error
  97. return count > 0, err
  98. }
  99. func createTag(gitRepo *git.Repository, r *Release) error {
  100. // Only actual create when publish.
  101. if !r.IsDraft {
  102. if !gitRepo.HasTag(r.TagName) {
  103. commit, err := gitRepo.BranchCommit(r.Target)
  104. if err != nil {
  105. return errors.Newf("get branch commit: %v", err)
  106. }
  107. // 🚨 SECURITY: Trim any leading '-' to prevent command line argument injection.
  108. r.TagName = strings.TrimLeft(r.TagName, "-")
  109. if err = gitRepo.CreateTag(r.TagName, commit.ID.String()); err != nil {
  110. if strings.Contains(err.Error(), "is not a valid tag name") {
  111. return ErrInvalidTagName{r.TagName}
  112. }
  113. return err
  114. }
  115. } else {
  116. commit, err := gitRepo.TagCommit(r.TagName)
  117. if err != nil {
  118. return errors.Newf("get tag commit: %v", err)
  119. }
  120. r.Sha1 = commit.ID.String()
  121. r.NumCommits, err = commit.CommitsCount()
  122. if err != nil {
  123. return errors.Newf("count commits: %v", err)
  124. }
  125. }
  126. }
  127. return nil
  128. }
  129. func (r *Release) preparePublishWebhooks() {
  130. if err := PrepareWebhooks(r.Repo, HookEventTypeRelease, &api.ReleasePayload{
  131. Action: api.HOOK_RELEASE_PUBLISHED,
  132. Release: r.APIFormat(),
  133. Repository: r.Repo.APIFormatLegacy(nil),
  134. Sender: r.Publisher.APIFormat(),
  135. }); err != nil {
  136. log.Error("PrepareWebhooks: %v", err)
  137. }
  138. }
  139. // NewRelease creates a new release with attachments for repository.
  140. func NewRelease(gitRepo *git.Repository, r *Release, uuids []string) error {
  141. isExist, err := IsReleaseExist(r.RepoID, r.TagName)
  142. if err != nil {
  143. return err
  144. } else if isExist {
  145. return ErrReleaseAlreadyExist{r.TagName}
  146. }
  147. if err = createTag(gitRepo, r); err != nil {
  148. return err
  149. }
  150. r.LowerTagName = strings.ToLower(r.TagName)
  151. err = db.Transaction(func(tx *gorm.DB) error {
  152. if err := tx.Create(r).Error; err != nil {
  153. return errors.Newf("insert: %v", err)
  154. }
  155. if len(uuids) > 0 {
  156. if err := tx.Model(&Attachment{}).Where("uuid IN ?", uuids).Update("release_id", r.ID).Error; err != nil {
  157. return errors.Newf("link attachments: %v", err)
  158. }
  159. }
  160. return nil
  161. })
  162. if err != nil {
  163. return err
  164. }
  165. // Only send webhook when actually published, skip drafts
  166. if r.IsDraft {
  167. return nil
  168. }
  169. r, err = GetReleaseByID(r.ID)
  170. if err != nil {
  171. return errors.Newf("GetReleaseByID: %v", err)
  172. }
  173. r.preparePublishWebhooks()
  174. return nil
  175. }
  176. var _ errutil.NotFound = (*ErrReleaseNotExist)(nil)
  177. type ErrReleaseNotExist struct {
  178. args map[string]any
  179. }
  180. func IsErrReleaseNotExist(err error) bool {
  181. _, ok := err.(ErrReleaseNotExist)
  182. return ok
  183. }
  184. func (err ErrReleaseNotExist) Error() string {
  185. return fmt.Sprintf("release does not exist: %v", err.args)
  186. }
  187. func (ErrReleaseNotExist) NotFound() bool {
  188. return true
  189. }
  190. // GetRelease returns release by given ID.
  191. func GetRelease(repoID int64, tagName string) (*Release, error) {
  192. isExist, err := IsReleaseExist(repoID, tagName)
  193. if err != nil {
  194. return nil, err
  195. } else if !isExist {
  196. return nil, ErrReleaseNotExist{args: map[string]any{"tag": tagName}}
  197. }
  198. r := &Release{}
  199. if err = db.Where("repo_id = ? AND lower_tag_name = ?", repoID, strings.ToLower(tagName)).First(r).Error; err != nil {
  200. return nil, errors.Newf("get: %v", err)
  201. }
  202. return r, r.LoadAttributes()
  203. }
  204. // GetReleaseByID returns release with given ID.
  205. func GetReleaseByID(id int64) (*Release, error) {
  206. r := new(Release)
  207. err := db.Where("id = ?", id).First(r).Error
  208. if err != nil {
  209. if errors.Is(err, gorm.ErrRecordNotFound) {
  210. return nil, ErrReleaseNotExist{args: map[string]any{"releaseID": id}}
  211. }
  212. return nil, err
  213. }
  214. return r, r.LoadAttributes()
  215. }
  216. // GetPublishedReleasesByRepoID returns a list of published releases of repository.
  217. // If matches is not empty, only published releases in matches will be returned.
  218. // In any case, drafts won't be returned by this function.
  219. func GetPublishedReleasesByRepoID(repoID int64, matches ...string) ([]*Release, error) {
  220. query := db.Where("repo_id = ? AND is_draft = ?", repoID, false).Order("created_unix DESC")
  221. if len(matches) > 0 {
  222. query = query.Where("tag_name IN ?", matches)
  223. }
  224. releases := make([]*Release, 0, 5)
  225. return releases, query.Find(&releases).Error
  226. }
  227. // GetReleasesByRepoID returns a list of all releases (including drafts) of given repository.
  228. func GetReleasesByRepoID(repoID int64) ([]*Release, error) {
  229. releases := make([]*Release, 0)
  230. return releases, db.Where("repo_id = ?", repoID).Find(&releases).Error
  231. }
  232. // GetDraftReleasesByRepoID returns all draft releases of repository.
  233. func GetDraftReleasesByRepoID(repoID int64) ([]*Release, error) {
  234. releases := make([]*Release, 0)
  235. return releases, db.Where("repo_id = ? AND is_draft = ?", repoID, true).Find(&releases).Error
  236. }
  237. type ReleaseSorter struct {
  238. releases []*Release
  239. }
  240. func (rs *ReleaseSorter) Len() int {
  241. return len(rs.releases)
  242. }
  243. func (rs *ReleaseSorter) Less(i, j int) bool {
  244. diffNum := rs.releases[i].NumCommits - rs.releases[j].NumCommits
  245. if diffNum != 0 {
  246. return diffNum > 0
  247. }
  248. return rs.releases[i].Created.After(rs.releases[j].Created)
  249. }
  250. func (rs *ReleaseSorter) Swap(i, j int) {
  251. rs.releases[i], rs.releases[j] = rs.releases[j], rs.releases[i]
  252. }
  253. // SortReleases sorts releases by number of commits and created time.
  254. func SortReleases(rels []*Release) {
  255. sorter := &ReleaseSorter{releases: rels}
  256. sort.Sort(sorter)
  257. }
  258. // UpdateRelease updates information of a release.
  259. func UpdateRelease(doer *User, gitRepo *git.Repository, r *Release, isPublish bool, uuids []string) (err error) {
  260. if err = createTag(gitRepo, r); err != nil {
  261. return errors.Newf("createTag: %v", err)
  262. }
  263. r.PublisherID = doer.ID
  264. err = db.Transaction(func(tx *gorm.DB) error {
  265. if err := tx.Model(r).Where("id = ?", r.ID).Updates(r).Error; err != nil {
  266. return errors.Newf("Update: %v", err)
  267. }
  268. // Unlink all current attachments and link back later if still valid
  269. if err := tx.Exec("UPDATE attachment SET release_id = 0 WHERE release_id = ?", r.ID).Error; err != nil {
  270. return errors.Newf("unlink current attachments: %v", err)
  271. }
  272. if len(uuids) > 0 {
  273. if err := tx.Model(&Attachment{}).Where("uuid IN ?", uuids).Update("release_id", r.ID).Error; err != nil {
  274. return errors.Newf("link attachments: %v", err)
  275. }
  276. }
  277. return nil
  278. })
  279. if err != nil {
  280. return err
  281. }
  282. if !isPublish {
  283. return nil
  284. }
  285. r.Publisher = doer
  286. r.preparePublishWebhooks()
  287. return nil
  288. }
  289. // DeleteReleaseOfRepoByID deletes a release and corresponding Git tag by given ID.
  290. func DeleteReleaseOfRepoByID(repoID, id int64) error {
  291. rel, err := GetReleaseByID(id)
  292. if err != nil {
  293. return errors.Newf("GetReleaseByID: %v", err)
  294. }
  295. // Mark sure the delete operation against same repository.
  296. if repoID != rel.RepoID {
  297. return nil
  298. }
  299. repo, err := GetRepositoryByID(rel.RepoID)
  300. if err != nil {
  301. return errors.Newf("GetRepositoryByID: %v", err)
  302. }
  303. _, stderr, err := process.ExecDir(-1, repo.RepoPath(),
  304. fmt.Sprintf("DeleteReleaseByID (git tag -d): %d", rel.ID),
  305. "git", "tag", "-d", rel.TagName)
  306. if err != nil && !strings.Contains(stderr, "not found") {
  307. return errors.Newf("git tag -d: %v - %s", err, stderr)
  308. }
  309. if err = db.Where("id = ?", rel.ID).Delete(new(Release)).Error; err != nil {
  310. return errors.Newf("delete: %v", err)
  311. }
  312. return nil
  313. }