1 ;;; GNU Guix --- Functional package management for GNU
2 ;;; Copyright © 2016 Nikita <nikita@n0.is>
3 ;;; Copyright © 2016 Sou Bunnbu <iyzsong@member.fsf.org>
4 ;;; Copyright © 2017 Oleg Pykhalov <go.wigust@gmail.com>
5 ;;; Copyright © 2017 Clément Lassieur <clement@lassieur.org>
6 ;;; Copyright © 2018 Christopher Baines <mail@cbaines.net>
7 ;;; Copyright © 2021 Julien Lepiller <julien@lepiller.eu>
9 ;;; This file is part of GNU Guix.
11 ;;; GNU Guix is free software; you can redistribute it and/or modify it
12 ;;; under the terms of the GNU General Public License as published by
13 ;;; the Free Software Foundation; either version 3 of the License, or (at
14 ;;; your option) any later version.
16 ;;; GNU Guix is distributed in the hope that it will be useful, but
17 ;;; WITHOUT ANY WARRANTY; without even the implied warranty of
18 ;;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
19 ;;; GNU General Public License for more details.
21 ;;; You should have received a copy of the GNU General Public License
22 ;;; along with GNU Guix. If not, see <http://www.gnu.org/licenses/>.
24 (define-module (gnu services version-control)
25 #:use-module (gnu services)
26 #:use-module (gnu services base)
27 #:use-module (gnu services shepherd)
28 #:use-module (gnu services web)
29 #:use-module (gnu system shadow)
30 #:use-module (gnu packages version-control)
31 #:use-module (gnu packages admin)
32 #:use-module (guix records)
33 #:use-module (guix gexp)
34 #:use-module (guix store)
35 #:use-module (srfi srfi-1)
36 #:use-module (srfi srfi-26)
37 #:use-module (ice-9 format)
38 #:use-module (ice-9 match)
39 #:export (git-daemon-service
40 git-daemon-service-type
41 git-daemon-configuration
42 git-daemon-configuration?
44 git-http-configuration
45 git-http-configuration?
46 git-http-nginx-location-configuration
48 <gitolite-configuration>
49 gitolite-configuration
50 gitolite-configuration-package
51 gitolite-configuration-user
52 gitolite-configuration-rc-file
53 gitolite-configuration-admin-pubkey
57 gitolite-rc-file-local-code
58 gitolite-rc-file-umask
59 gitolite-rc-file-unsafe-pattern
60 gitolite-rc-file-git-config-keys
61 gitolite-rc-file-roles
62 gitolite-rc-file-enable
67 gitile-configuration-package
68 gitile-configuration-host
69 gitile-configuration-port
70 gitile-configuration-database
71 gitile-configuration-repositories
72 gitile-configuration-git-base-url
73 gitile-configuration-index-title
74 gitile-configuration-intro
75 gitile-configuration-footer
76 gitile-configuration-nginx
82 ;;; Version Control related services.
91 (define-record-type* <git-daemon-configuration>
92 git-daemon-configuration
93 make-git-daemon-configuration
94 git-daemon-configuration?
95 (package git-daemon-configuration-package ;file-like
97 (export-all? git-daemon-configuration-export-all ;boolean
99 (base-path git-daemon-configuration-base-path ;string | #f
100 (default "/srv/git"))
101 (user-path git-daemon-configuration-user-path ;string | #f
103 (listen git-daemon-configuration-listen ;list of string
105 (port git-daemon-configuration-port ;number | #f
107 (whitelist git-daemon-configuration-whitelist ;list of string
109 (extra-options git-daemon-configuration-extra-options ;list of string
112 (define git-daemon-shepherd-service
114 (($ <git-daemon-configuration>
115 package export-all? base-path user-path
116 listen port whitelist extra-options)
117 (let* ((git (file-append package "/bin/git"))
119 "daemon" "--syslog" "--reuseaddr"
124 `(,(string-append "--base-path=" base-path))
127 `(,(string-append "--user-path=" user-path))
129 ,@(map (cut string-append "--listen=" <>) listen)
132 "--port=" (number->string port)))
136 (list (shepherd-service
137 (documentation "Run the git-daemon.")
138 (requirement '(networking))
139 (provision '(git-daemon))
140 (start #~(make-forkexec-constructor '#$command
142 #:group "git-daemon"))
143 (stop #~(make-kill-destructor))))))))
145 (define %git-daemon-accounts
146 ;; User account and group for git-daemon.
154 (comment "Git daemon user")
155 (home-directory "/var/empty")
156 (shell (file-append shadow "/sbin/nologin")))))
158 (define (git-daemon-activation config)
159 "Return the activation gexp for git-daemon using CONFIG."
160 (let ((base-path (git-daemon-configuration-base-path config)))
162 (use-modules (guix build utils))
163 ;; Create the 'base-path' directory when it's not '#f'.
164 (and=> #$base-path mkdir-p))))
166 (define git-daemon-service-type
170 (list (service-extension shepherd-root-service-type
171 git-daemon-shepherd-service)
172 (service-extension account-service-type
173 (const %git-daemon-accounts))
174 (service-extension activation-service-type
175 git-daemon-activation)))
177 "Expose Git repositories over the insecure @code{git://} TCP-based
179 (default-value (git-daemon-configuration))))
181 (define* (git-daemon-service #:key (config (git-daemon-configuration)))
182 "Return a service that runs @command{git daemon}, a simple TCP server to
183 expose repositories over the Git protocol for anonymous access.
185 The optional @var{config} argument should be a
186 @code{<git-daemon-configuration>} object, by default it allows read-only
187 access to exported repositories under @file{/srv/git}."
188 (service git-daemon-service-type config))
192 ;;; HTTP access. Add the result of calling
193 ;;; git-http-nginx-location-configuration to an nginx-server-configuration's
194 ;;; "locations" field.
197 (define-record-type* <git-http-configuration>
198 git-http-configuration
199 make-git-http-configuration
200 git-http-configuration?
201 (package git-http-configuration-package ;file-like
203 (git-root git-http-configuration-git-root ;string
204 (default "/srv/git"))
205 (export-all? git-http-configuration-export-all? ;boolean
207 (uri-path git-http-configuration-uri-path ;string
209 (fcgiwrap-socket git-http-configuration-fcgiwrap-socket ;string
210 (default "127.0.0.1:9000")))
212 (define* (git-http-nginx-location-configuration #:optional
214 (git-http-configuration)))
216 (($ <git-http-configuration> package git-root export-all?
217 uri-path fcgiwrap-socket)
218 (nginx-location-configuration
219 (uri (string-append "~ /" (string-trim-both uri-path #\/) "(/.*)"))
222 (list "fastcgi_pass " fcgiwrap-socket ";")
223 (list "fastcgi_param SCRIPT_FILENAME "
224 package "/libexec/git-core/git-http-backend"
226 "fastcgi_param QUERY_STRING $query_string;"
227 "fastcgi_param REQUEST_METHOD $request_method;"
228 "fastcgi_param CONTENT_TYPE $content_type;"
229 "fastcgi_param CONTENT_LENGTH $content_length;"
231 "fastcgi_param GIT_HTTP_EXPORT_ALL \"\";"
233 (list "fastcgi_param GIT_PROJECT_ROOT " git-root ";")
234 "fastcgi_param PATH_INFO $1;"))))))
241 (define-record-type* <gitolite-rc-file>
242 gitolite-rc-file make-gitolite-rc-file
244 (umask gitolite-rc-file-umask
246 (local-code gitolite-rc-file-local-code
247 (default "$rc{GL_ADMIN_BASE}/local"))
248 (unsafe-pattern gitolite-rc-file-unsafe-pattern
250 (git-config-keys gitolite-rc-file-git-config-keys
252 (roles gitolite-rc-file-roles
253 (default '(("READERS" . 1)
255 (enable gitolite-rc-file-enable
266 (define-gexp-compiler (gitolite-rc-file-compiler
267 (file <gitolite-rc-file>) system target)
269 (($ <gitolite-rc-file> umask local-code unsafe-pattern git-config-keys roles enable)
270 (apply text-file* "gitolite.rc"
272 " UMASK => " ,(format #f "~4,'0o" umask) ",\n"
273 " GIT_CONFIG_KEYS => '" ,git-config-keys "',\n"
275 (simple-format #f " LOCAL_CODE => \"~A\",\n" local-code)
280 (simple-format #f " ~A => ~A,\n" role value)))
285 ,@(map (lambda (value)
286 (simple-format #f " '~A',\n" value))
292 (string-append "$UNSAFE_PATT = qr(" unsafe-pattern ");")
296 (define-record-type* <gitolite-configuration>
297 gitolite-configuration make-gitolite-configuration
298 gitolite-configuration?
299 (package gitolite-configuration-package
301 (user gitolite-configuration-user
303 (group gitolite-configuration-group
305 (home-directory gitolite-configuration-home-directory
306 (default "/var/lib/gitolite"))
307 (rc-file gitolite-configuration-rc-file
308 (default (gitolite-rc-file)))
309 (admin-pubkey gitolite-configuration-admin-pubkey))
311 (define gitolite-accounts
313 (($ <gitolite-configuration> package user group home-directory
314 rc-file admin-pubkey)
315 ;; User group and account to run Gitolite.
316 (list (user-group (name user) (system? #t))
321 (comment "Gitolite user")
322 (home-directory home-directory))))))
324 (define gitolite-activation
326 (($ <gitolite-configuration> package user group home
327 rc-file admin-pubkey)
329 (use-modules (ice-9 match)
332 (let* ((user-info (getpwnam #$user))
333 (admin-pubkey #$admin-pubkey)
334 (pubkey-file (string-append
337 (strip-store-file-name admin-pubkey))))
338 (rc-file #$(string-append home "/.gitolite.rc")))
340 ;; activate-users+groups in (gnu build activation) sets the
341 ;; permission flags of home directories to #o700 and mentions that
342 ;; services needing looser permissions should chmod it during
343 ;; service activation. We also want the git group to be able to
344 ;; read from the gitolite home directory, so a chmod'ing we will
348 (simple-format #t "guix: gitolite: installing ~A\n" #$rc-file)
349 (copy-file #$rc-file rc-file)
350 ;; ensure gitolite's user can read the configuration
352 (passwd:uid user-info)
353 (passwd:gid user-info))
355 ;; The key must be writable, so copy it from the store
356 (copy-file admin-pubkey pubkey-file)
358 (chmod pubkey-file #o500)
360 (passwd:uid user-info)
361 (passwd:gid user-info))
363 ;; Set the git configuration, to avoid gitolite trying to use
364 ;; the hostname command, as the network might not be up yet
365 (with-output-to-file #$(string-append home "/.gitconfig")
369 email = guix@localhost
371 ;; Run Gitolite setup, as this updates the hooks and include the
372 ;; admin pubkey if specified. The admin pubkey is required for
373 ;; initial setup, and will replace the previous key if run after
375 (match (primitive-fork)
377 ;; Exit with a non-zero status code if an exception is thrown.
381 (setenv "HOME" (passwd:dir user-info))
382 (setenv "USER" #$user)
383 (setgid (passwd:gid user-info))
384 (setuid (passwd:uid user-info))
386 (system* #$(file-append package "/bin/gitolite")
388 "-m" "gitolite setup by GNU Guix"
391 (primitive-exit 1))))
394 (when (file-exists? pubkey-file)
395 (delete-file pubkey-file)))))))
397 (define gitolite-service-type
401 (list (service-extension activation-service-type
403 (service-extension account-service-type
405 (service-extension profile-service-type
406 ;; The Gitolite package in Guix uses
407 ;; gitolite-shell in the authorized_keys file, so
408 ;; gitolite-shell needs to be on the PATH for
412 (gitolite-configuration-package config))))))
414 "Set up @command{gitolite}, a Git hosting tool providing access over SSH.
415 By default, the @code{git} user is used, but this is configurable.
416 Additionally, Gitolite can integrate with with tools like gitweb or cgit to
417 provide a web interface to view selected repositories.")))
423 (define-record-type* <gitile-configuration>
424 gitile-configuration make-gitile-configuration gitile-configuration?
425 (package gitile-configuration-package
427 (host gitile-configuration-host
428 (default "127.0.0.1"))
429 (port gitile-configuration-port
431 (database gitile-configuration-database
432 (default "/var/lib/gitile/gitile-db.sql"))
433 (repositories gitile-configuration-repositories
434 (default "/var/lib/gitolite/repositories"))
435 (base-git-url gitile-configuration-base-git-url)
436 (index-title gitile-configuration-index-title
438 (intro gitile-configuration-intro
440 (footer gitile-configuration-footer
442 (nginx gitile-configuration-nginx))
444 (define (gitile-config-file host port database repositories base-git-url
445 index-title intro footer)
450 (database #$database)
451 (repositories #$repositories)
452 (base-git-url #$base-git-url)
453 (index-title #$index-title)
456 (open-output-file #$output)))
458 (computed-file "gitile.conf" build))
460 (define gitile-nginx-server-block
462 (($ <gitile-configuration> package host port database repositories
463 base-git-url index-title intro footer nginx)
464 (list (nginx-server-configuration
469 (nginx-location-configuration
473 #~(string-append "proxy_pass http://" #$host
474 ":" (number->string #$port)
478 (nginx-location-configuration
482 #~(string-append "root " #$package "/share/gitile/assets;")))))
483 '("/css" "/js" "/images"))
484 (nginx-server-configuration-locations nginx))))))))
486 (define gitile-shepherd-service
488 (($ <gitile-configuration> package host port database repositories
489 base-git-url index-title intro footer nginx)
490 (list (shepherd-service
491 (provision '(gitile))
492 (requirement '(loopback))
493 (documentation "gitile")
494 (start (let ((gitile (file-append package "/bin/gitile")))
495 #~(make-forkexec-constructor
496 `(,#$gitile "-c" #$(gitile-config-file
499 base-git-url index-title
503 (stop #~(make-kill-destructor)))))))
505 (define %gitile-accounts
513 (comment "Gitile user")
514 (home-directory "/var/empty")
515 (shell (file-append shadow "/sbin/nologin")))))
517 (define gitile-service-type
520 (description "Run Gitile, a small Git forge. Expose public repositories
523 (list (service-extension account-service-type
524 (const %gitile-accounts))
525 (service-extension shepherd-root-service-type
526 gitile-shepherd-service)
527 (service-extension nginx-service-type
528 gitile-nginx-server-block)))))