commit b5162388d5ee344d126d07bd84f528459812e1e8
parent 2d314ea1199dd8310984ddbc28f8704cba8ada67
Author: Christian Grothoff <christian@grothoff.org>
Date: Fri, 7 Aug 2026 16:41:45 +0200
build system cleanups
Diffstat:
19 files changed, 360 insertions(+), 158 deletions(-)
diff --git a/.gitignore b/.gitignore
@@ -1,23 +1,14 @@
**~
-.version
-INSTALL
+
+# Written by ./configure
Makefile
-aclocal.m4
-autom4te.cache/
-compile
-config.guess
-config.sub
-depcomp
-install-sh
-ltmain.sh
-m4/
-missing
-paivana_config.h.in
-config.log
config.status
-libtool
-paivana_config.h
-stamp-h1
-Makefile.in
-contrib/paywall.en.must
+
+# Written by scripts/get_version.sh, shipped inside dist tarballs
+.version
+
+# Default meson build tree (--mesonbuilddir= can move it)
build/
+
+# 'nix build' result symlink
+result
diff --git a/Makefile.in b/Makefile.in
@@ -23,11 +23,6 @@ uninstall:
dist:
$(MESON) dist -C $(mesonbuilddir) --no-tests --formats gztar
-# Make doxygen
-.PHONY: doxygen
-doxygen:
- $(NINJA) -C $(mesonbuilddir) doxygen
-
# Run tests
.PHONY: check
check:
@@ -41,6 +36,7 @@ installcheck:
integrationtests:
$(MESON) test -C $(mesonbuilddir) --suite=integrationtests
+.PHONY: format
format:
$(MESON) fmt -i -r .
#find ./src -name "*.[h,c]" | uncrustify -l c -c contrib/conf/uncrustify.cfg -F - --replace --no-backup
diff --git a/configure b/configure
@@ -1,8 +1,8 @@
#!/bin/sh
pkg_name="paivana"
-pkg_default_features=""
-pkg_optional_features="coverage logging only-doc install-rpath"
+pkg_default_features="doc logging"
+pkg_optional_features="coverage only-doc install-rpath"
pkg_optional_dependencies=""
# DO NOT EDIT BELOW THIS LINE
@@ -190,12 +190,36 @@ mesonfeatopts=""
for feat in $pkg_optional_features $pkg_default_features; do
ft=$(echo $feat | tr - _)
eval "echo \"enable_$ft=\${enable_$ft}\" >> Makefile"
- if [ "coverage" = $feat ]; then
- mfeat="b_$feat"
- else
- mfeat=$feat
- fi
- eval "mesonfeatopts=\"$mesonfeatopts -D$mfeat=\${enable_$ft}\""
+ eval "mval=\${enable_$ft}"
+ # Not every switch maps onto an identically named boolean meson
+ # option: coverage is a meson built-in, doc is expressed as its
+ # negation, and logging is a four-valued choice. A switch that
+ # falls through to a meson option that does not exist, or to a
+ # value that option does not accept, is silently ignored, so keep
+ # this in sync with meson.options.
+ case "$feat" in
+ coverage)
+ mfeat="b_coverage"
+ ;;
+ doc)
+ mfeat="disable-doc"
+ case "$mval" in
+ true) mval=false ;;
+ false) mval=true ;;
+ esac
+ ;;
+ logging)
+ mfeat="logging"
+ case "$mval" in
+ true) mval=yes ;;
+ false) mval=no ;;
+ esac
+ ;;
+ *)
+ mfeat="$feat"
+ ;;
+ esac
+ mesonfeatopts="$mesonfeatopts -D$mfeat=$mval"
done
for dep in $pkg_optional_dependencies; do
eval "echo \"with_$dep=\${with_$dep}\" >> Makefile"
diff --git a/debian/etc/paivana/secrets/paivana.secret.conf b/debian/etc/paivana/secrets/paivana.secret.conf
@@ -0,0 +1,36 @@
+# Secrets for paivana-httpd.
+#
+# This file is inlined into the [paivana] section of
+# /etc/paivana/paivana.conf via "@inline-secret@" and is deliberately
+# NOT world-readable: dpkg-statoverride restricts it to the
+# paivana-httpd account (see the package's postinst). Do not move
+# either setting back into the main configuration file, and do not
+# relax the mode.
+#
+# Both values below are, in different ways, complete control:
+#
+# - MERCHANT_ACCESS_TOKEN is the bearer credential for the merchant
+# backend instance, i.e. authority over its orders and templates.
+# - SECRET keys the MAC on the access cookie. Whoever holds it can
+# mint a valid cookie for any visitor, any URL and any expiry --
+# an undetectable, permanent bypass of the paywall.
+
+[paivana]
+
+# Bearer token for every call to the merchant backend. RFC 8959
+# requires the "secret-token:" prefix.
+# MERCHANT_ACCESS_TOKEN = secret-token:CHANGE-ME
+
+# Key for the access cookie's MAC. The package generates a random one
+# on first install; paivana-httpd refuses to start without it, because
+# a per-start random key would invalidate every access already paid
+# for on every restart -- and the shipped unit restarts hourly.
+#
+# Keep it stable, and keep it identical across every paivana-httpd that
+# serves the same site: the cookie one of them issues has to verify on
+# the next. To replace it by hand:
+#
+# gpg --gen-random 0 32 | base64
+#
+# Note that changing it invalidates all outstanding access cookies.
+# SECRET = CHANGE-ME
diff --git a/debian/examples/apache2-paivana.conf b/debian/examples/apache2-paivana.conf
@@ -0,0 +1,43 @@
+# Make sure to enable the following Apache modules before
+# integrating this into your configuration:
+#
+# a2enmod proxy
+# a2enmod proxy_http
+# a2enmod headers
+#
+# Apache's configuration language has no XML comments: '<!--' parses as
+# the opening of a container directive named "!--", so a block comment
+# here made `apachectl configtest' fail and the site impossible to
+# enable.
+
+<Location "/">
+# paivana-httpd is started with -f (see paivana-httpd.service), so it
+# takes the client address for the access cookie from the forwarding
+# headers. mod_proxy's ProxyAddHeaders (on by default) *appends* the
+# real client to any X-Forwarded-For the client itself sent, which
+# would leave the client in control of the leftmost entry -- and thus
+# of its own identity. Drop the client's copies first so that what
+# mod_proxy adds is the only thing paivana-httpd sees.
+#
+# If this Apache is itself behind another proxy, remove these and
+# configure mod_remoteip (RemoteIPHeader / RemoteIPInternalProxy) for
+# that hop instead.
+RequestHeader unset X-Forwarded-For
+RequestHeader unset X-Forwarded-Proto
+RequestHeader unset X-Forwarded-Host
+RequestHeader unset X-Forwarded-Port
+RequestHeader unset Forwarded
+
+# RFC 7239, which paivana-httpd prefers over the X-Forwarded-* headers
+# mod_proxy adds. Apache emits no Forwarded of its own, so build the
+# element here. "set" rather than "append": this is the outermost hop,
+# so a client-supplied element must not survive. Note that
+# %{REMOTE_ADDR}e yields an unbracketed IPv6 address where RFC 7239 §6
+# asks for for="[...]"; paivana-httpd accepts both.
+RequestHeader set Forwarded "for=%{REMOTE_ADDR}e;proto=%{REQUEST_SCHEME}e;host=%{HTTP_HOST}e"
+
+# The path paivana-httpd.socket actually listens on, and that the
+# tmpfiles snippet creates. /var/lib/paivana/httpd/paivana.sock was
+# a socket nothing anywhere creates.
+ProxyPass "unix:/run/paivana/httpd/paivana-http.sock|http://example.com/"
+</Location>
diff --git a/debian/examples/nginx-paivana b/debian/examples/nginx-paivana
@@ -0,0 +1,47 @@
+# RFC 7239 node identifier for the peer we accepted from. nginx has
+# no built-in variable for this: an IPv6 address has to be bracketed
+# and therefore quoted (RFC 7239 §6), and a peer with no address is
+# "unknown" (§6.3).
+map $remote_addr $paivana_forwarded_elem {
+ ~^[0-9.]+$ "for=$remote_addr";
+ ~^[0-9A-Fa-f:.]+$ "for=\"[$remote_addr]\"";
+ default "for=unknown";
+}
+
+server {
+ listen 80;
+ listen [::]:80;
+
+ # server_name example.com
+
+ location / {
+ proxy_pass http://unix:/run/paivana/httpd/paivana-http.sock;
+ proxy_redirect off;
+ proxy_set_header Host $host;
+
+ # paivana-httpd is started with -f (see paivana-httpd.service), so
+ # it takes the client address for the access cookie from the
+ # headers set here. That is only sound because this server is the
+ # outermost hop and *overwrites* them: $remote_addr is the peer we
+ # actually accepted, whereas $proxy_add_x_forwarded_for would
+ # append it to whatever the client claimed, leaving the client in
+ # control of the leftmost entry -- and thus of its own identity.
+ #
+ # If this nginx is itself behind another proxy, switch to
+ # $proxy_add_x_forwarded_for and set real_ip_header /
+ # set_real_ip_from for that hop.
+ proxy_set_header X-Forwarded-For $remote_addr;
+ proxy_set_header X-Forwarded-Proto $scheme;
+ proxy_set_header X-Forwarded-Host $host;
+ proxy_set_header X-Forwarded-Port $server_port;
+
+ # RFC 7239. paivana-httpd prefers this over the X-Forwarded-*
+ # headers above, which are kept for origins that only speak those.
+ # Again a plain "set": nginx offers no $proxy_add_forwarded, and at
+ # the outermost hop we would not want one -- a client-supplied
+ # element must not survive. Behind another proxy, replace this
+ # with the appending form from nginx.org's "Using the Forwarded
+ # header", which validates $http_forwarded before extending it.
+ proxy_set_header Forwarded "$paivana_forwarded_elem;proto=$scheme;host=$host";
+ }
+}
diff --git a/debian/paivana-httpd.examples b/debian/paivana-httpd.examples
@@ -0,0 +1,2 @@
+debian/examples/nginx-paivana
+debian/examples/apache2-paivana.conf
diff --git a/flake.nix b/flake.nix
@@ -56,6 +56,9 @@
pkgs.meson
pkgs.ninja
pkgs.pkg-config
+ # src/frontend/generate-paywall.py renders the paywall
+ # template at build time and needs jinja2.
+ (pkgs.python3.withPackages (ps: [ ps.jinja2 ]))
];
buildInputs = [
pkgs.libtool
@@ -70,7 +73,7 @@
merchantpkgs.merchant
];
preConfigure = ''
- patchShebangs --build contrib/check-prebuilt
+ patchShebangs --build bootstrap configure scripts src/frontend src/tests
./bootstrap
'';
};
@@ -90,6 +93,8 @@
in
{
default = pkgs.mkShell {
+ # Keep this in step with the buildInputs above: a shell
+ # that cannot get past ./configure is worse than no shell.
packages = [
pkgs.gcc
pkgs.meson
@@ -98,8 +103,11 @@
pkgs.pkg-config
pkgs.libtool
pkgs.jansson
+ pkgs.libmicrohttpd
+ pkgs.libgcrypt
pkgs.git
pkgs.curlWithGnuTls
+ (pkgs.python3.withPackages (ps: [ ps.jinja2 ]))
gnunetpkgs.gnunet
pkgs.codespell
pkgs.clang-tools
diff --git a/meson-dist-script b/meson-dist-script
@@ -1,3 +1,11 @@
#!/bin/sh
+# Ship a .version in the tarball, so that a build from it does not need
+# git. A checkout without reachable tags has no .version to copy, so
+# fall back to the version meson resolved for this dist run.
+set -eu
-cp $MESON_SOURCE_ROOT/.version $MESON_DIST_ROOT
+if [ -f "$MESON_SOURCE_ROOT/.version" ]; then
+ cp "$MESON_SOURCE_ROOT/.version" "$MESON_DIST_ROOT/.version"
+else
+ echo "$MESON_PROJECT_VERSION" > "$MESON_DIST_ROOT/.version"
+fi
diff --git a/meson.build b/meson.build
@@ -9,13 +9,9 @@ project(
cc = meson.get_compiler('c')
incdir = include_directories('src/include')
-# Used to populate gnunet_private_config.h
+# Used to populate paivana_config.h
private_config = configuration_data()
-
-plugindir = get_option('libdir') / 'paivana'
-pkgdatadir = get_option('datadir') / 'paivana'
-pkgcfgdir = pkgdatadir / 'config.d'
docdir = get_option('datadir') / 'doc' / 'paivana'
if get_option('install-rpath')
@@ -27,55 +23,49 @@ endif
install_emptydir(docdir)
install_data('README', 'COPYING', install_dir: docdir)
-gnunet_user = false
-dpkg_architecture_bin = find_program(
- 'dpkg-architecture',
- '/usr/bin/dpkg-architecture',
- required: false,
-)
-if dpkg_architecture_bin.found()
- private_config.set(
- 'MULTIARCH',
- dpkg_architecture_bin.full_path() + ' -qDEB_HOST_MULTIARCH',
- )
-endif
-
-TALER_PLUGIN_LDFLAGS = [
- '-export-dynamic',
- '-avoid-version',
- '-module',
- '--no-undefined',
-]
-
-cdata = configuration_data()
if not get_option('only-doc')
add_project_arguments(
'-Wall',
'-Wno-address-of-packed-member',
language: 'c',
)
- taler_lib_ldflags = '-export-dynamic -no-undefined'
- check_headers = ['stdint.h', 'stdlib.h', 'string.h', 'unistd.h']
+ # Every header that src/include/platform.h includes behind a
+ # `#if HAVE_..._H' guard has to be probed here. A guard whose macro
+ # is never defined is silently false, so the #include simply does not
+ # happen; keep this list and the guards in platform.h in sync.
+ check_headers = [
+ 'endian.h',
+ 'ifaddrs.h',
+ 'malloc.h',
+ 'netinet/in.h',
+ 'netinet/in_systm.h',
+ 'netinet/ip.h',
+ 'stdint.h',
+ 'stdlib.h',
+ 'string.h',
+ 'sys/endian.h',
+ 'sys/param.h',
+ 'sys/resource.h',
+ 'sys/time.h',
+ 'sys/types.h',
+ 'sys/ucred.h',
+ 'ucred.h',
+ 'unistd.h',
+ 'vfork.h',
+ ]
foreach h : check_headers
if cc.check_header(h)
- define = 'HAVE_' + h.underscorify().to_upper()
- message(define)
- private_config.set(define, 1)
+ private_config.set('HAVE_' + h.underscorify().to_upper(), 1)
endif
endforeach
- zlib_dep = dependency('zlib', required: false)
- if not zlib_dep.found()
- zlib_dep = cc.find_library('zlib', required: true)
- endif
- m_dep = cc.find_library('m', required: false)
- if m_dep.found()
- private_config.set('HAVE_LIBM', 1)
+ # platform.h declares atoll() itself when this is missing.
+ if cc.has_function('atoll', prefix: '#include <stdlib.h>')
+ private_config.set('HAVE_ATOLL', 1)
endif
-
mhd_dep = dependency('libmicrohttpd', required: false)
if not mhd_dep.found()
mhd_dep = cc.find_library('microhttpd', required: true)
@@ -86,13 +76,26 @@ if not get_option('only-doc')
json_dep = cc.find_library('jansson', required: true)
endif
- gcrypt_dep = dependency('libgcrypt', required: false)
+ gcrypt_dep = dependency('libgcrypt', version: '>=1.6.1', required: false)
if not gcrypt_dep.found()
gcrypt_dep = cc.find_library('gcrypt', required: true)
+ gcrypt_version_check = '''#include <gcrypt.h>
+ int main(int argc, char **argv) {
+ #if GCRYPT_VERSION_NUMBER < 0x010601
+ #error "libgcrypt version >= 1.6.1 required"
+ #endif
+ return 0;
+ }
+ '''
+ if not cc.compiles(
+ gcrypt_version_check,
+ name: 'libgcrypt version check',
+ dependencies: gcrypt_dep,
+ )
+ error('libgcrypt version >=1.6.1 required')
+ endif
endif
- private_config.set_quoted('NEED_LIBGCRYPT_VERSION', '1.6.1')
-
gnunetutil_dep = dependency('gnunetutil', required: false)
if not gnunetutil_dep.found()
gnunetutil_dep = cc.find_library('gnunetutil', required: true)
@@ -153,7 +156,6 @@ if not get_option('only-doc')
required: true,
dependencies: [talerutil_dep],
)
- private_config.set10('HAVE_TALERUTIL', talerutil_dep.found())
talertemplating_dep = dependency('talertemplating', required: false)
if not talertemplating_dep.found()
talertemplating_dep = cc.find_library('talertemplating', required: true)
@@ -168,7 +170,6 @@ if not get_option('only-doc')
required: true,
dependencies: [talermhd_dep],
)
- private_config.set10('HAVE_TALERMHD', talermhd_dep.found())
talerjson_dep = dependency('talerjson', required: false)
if not talerjson_dep.found()
@@ -180,7 +181,6 @@ if not get_option('only-doc')
required: true,
dependencies: [talerjson_dep],
)
- private_config.set10('HAVE_TALERJSON', talerjson_dep.found())
talermerchant_dep = dependency('talermerchant', required: false)
if not talermerchant_dep.found()
@@ -192,65 +192,31 @@ if not get_option('only-doc')
required: true,
dependencies: [talermerchant_dep],
)
- private_config.set10('HAVE_TALERMERCHANT', talermerchant_dep.found())
+ # GNUNET_CULL_LOGGING removes every log statement at compile time;
+ # GNUNET_EXTRA_LOGGING gates the GNUNET_log_from() DEBUG level, with
+ # the same 0/1/2 scale GNUnet itself uses. Both have to be handed to
+ # the compiler -- computing a verbosity and never passing it on left
+ # 'verbose' and 'veryverbose' doing nothing at all.
logging_opt = get_option('logging')
- logging_verbosity = 0
- if logging_opt == 'yes'
- logging_verbosity = 1
- endif
if logging_opt == 'no'
add_project_arguments('-DGNUNET_CULL_LOGGING=1', language: 'c')
+ else
+ logging_verbosity = {'yes': 0, 'verbose': 1, 'veryverbose': 2}[logging_opt]
+ add_project_arguments(
+ '-DGNUNET_EXTRA_LOGGING=@0@'.format(logging_verbosity),
+ language: 'c',
+ )
endif
- if logging_opt == 'verbose'
- logging_verbosity = 2
- endif
- if logging_opt == 'veryverbose'
- logging_verbosity = 3
- endif
-
- #add_project_arguments('-DGNUNET_EXTRA_LOGGING=@0@'.format(logging_verbosity), language: 'c')
-
-
- # todo gcov has meson builtin
-
- # Used to populate configuration file and script templates
-
-
- libltversions = [
- ['libpaivana', '0:0:0'],
- ]
-
- solibversions = {}
-
- foreach libversion : libltversions
- ltversion = libversion[1].split(':')
- current = ltversion[0].to_int()
- revision = ltversion[1].to_int()
- age = ltversion[2].to_int()
- soversion_str = '@0@'.format(current - age)
- ltversion_str = '@0@.@1@.@2@'.format(current - age, age, revision)
- solibversions = solibversions + {
- libversion[0]: {
- 'soversion': soversion_str,
- 'version': ltversion_str,
- },
- }
- endforeach
+ summary({'logging': logging_opt}, section: 'Configuration')
- private_config.set_quoted('PACKAGE', meson.project_name())
private_config.set_quoted('PACKAGE_VERSION', meson.project_version())
- # Compatibility. Used in source.
- private_config.set_quoted('VERSION', meson.project_version())
- private_config.set_quoted('PACKAGE_BUGREPORT', 'taler@gnu.org')
configure_file(output: 'paivana_config.h', configuration: private_config)
configuration_inc = include_directories('.')
- cdata.merge_from(private_config)
add_project_arguments('-DHAVE_CONFIG_H', language: 'c')
- pkg = import('pkgconfig')
subdir('contrib')
subdir('src')
if not get_option('disable-doc')
diff --git a/meson.options b/meson.options
@@ -2,4 +2,4 @@
option('only-doc', type : 'boolean', value : false, description: 'whether to compile documentation ONLY')
option('disable-doc', type : 'boolean', value : false, description: 'whether to disable documentation')
option('install-rpath', type : 'boolean', value : false, description: 'Add rpath to installed binaries if set')
-option('logging', type : 'string', value: 'yes', description: 'Log setting. Can be set to "yes" (logging, default), "no" (no logging), "verbose" (extra logging"), "veryverbose" (even more logging)')
+option('logging', type : 'combo', choices : ['yes', 'no', 'verbose', 'veryverbose'], value : 'yes', description: 'Log setting: "yes" (logging, default), "no" (no logging at all), "verbose" (extra logging), "veryverbose" (even more logging)')
diff --git a/scripts/get_version.sh b/scripts/get_version.sh
@@ -9,7 +9,13 @@ if [ -e ./.git ]; then
gitver=$(git describe --tags 2>/dev/null || echo no-git-version)
if test "$gitver" != "no-git-version"; then
VERSION=${gitver#v}
- echo "$VERSION" > .version
+ # Cache it for builds from a tarball, but only when that actually
+ # changes something: this runs on every 'meson setup', and a source
+ # tree that is read-only (distribution builds, nix) or that we would
+ # otherwise needlessly dirty must not turn into a hard failure.
+ if test "x$VERSION" != "x$(cat .version 2>/dev/null)"; then
+ echo "$VERSION" > .version 2>/dev/null || true
+ fi
fi
fi
if test "x$VERSION" = "x"; then
diff --git a/src/backend/meson.build b/src/backend/meson.build
@@ -31,8 +31,8 @@ paivana_httpd_exe = executable(
mhd_dep,
json_dep,
curl_dep,
- zlib_dep,
],
include_directories: [incdir, configuration_inc],
+ install_rpath: rpath_option,
install: true,
)
diff --git a/src/frontend/generate-paywall.py b/src/frontend/generate-paywall.py
@@ -16,7 +16,18 @@ def main():
search_dir = os.path.dirname(os.path.abspath(input_template))
# Set up jinja2 environment with custom delimiters.
- # Delimiters are changed to avoid conflict with Mustache tags like {{ merchant_backend }}.
+ #
+ # Delimiters are changed to avoid conflict with Mustache tags like
+ # {{ merchant_backend }}: the output of this step is a Mustache
+ # template rendered later by libtalertemplating, so {{ ... }} has to
+ # survive verbatim. The replacements have to be sequences that do
+ # not occur in HTML, CSS or JavaScript; '@<' and '@#' are safe, and
+ # note that CSS at-rules ('@media', '@keyframes') are not, so the
+ # single-character '@' can never become a delimiter here.
+ #
+ # StrictUndefined makes a mistyped '@@ name @@' an error rather than
+ # an empty string, and keep_trailing_newline keeps the file ending
+ # in a newline the way the source template does.
env = jinja2.Environment(
loader=jinja2.FileSystemLoader(search_dir),
variable_start_string="@@",
@@ -25,6 +36,8 @@ def main():
block_end_string=">@",
comment_start_string="@#",
comment_end_string="#@",
+ undefined=jinja2.StrictUndefined,
+ keep_trailing_newline=True,
)
template_name = os.path.basename(input_template)
@@ -32,6 +45,10 @@ def main():
rendered = template.render()
+ if not rendered.strip():
+ print(f"{input_template} rendered to nothing", file=sys.stderr)
+ sys.exit(1)
+
# Ensure parent directory of output_file exists (especially in build directories).
os.makedirs(os.path.dirname(os.path.abspath(output_file)), exist_ok=True)
diff --git a/src/frontend/meson.build b/src/frontend/meson.build
@@ -1,10 +1,22 @@
+# The paywall page is assembled from a jinja2 template at build time.
+# Asking for the module here turns a missing jinja2 into an actionable
+# 'meson setup' error instead of a Python traceback in the middle of a
+# build.
+python = import('python').find_installation(
+ 'python3',
+ modules: ['jinja2'],
+)
+
paywall_must = custom_target(
'paywall.en.must',
input: 'paywall.en.must.j2',
output: 'paywall.en.must',
command: [
- find_program('python3'),
- meson.current_source_dir() / 'generate-paywall.py',
+ python,
+ # files(), not a bare path: passing the generator as a plain
+ # string leaves meson unaware of it, so editing the generator
+ # does not regenerate the template.
+ files('generate-paywall.py'),
'@INPUT@',
'@OUTPUT@',
],
@@ -12,3 +24,13 @@ paywall_must = custom_target(
install: true,
install_dir: get_option('datadir') / 'paivana' / 'templates',
)
+
+# paywall.js is plain JavaScript, but it is type-checked with tsc in
+# checkJs mode. The script reports 'skipped' when no local TypeScript
+# compiler is installed; it deliberately never fetches one, since a
+# build must not depend on the network.
+test(
+ 'paywall_typecheck',
+ files('typecheck.sh'),
+ env: {'SRCDIR': meson.current_source_dir()},
+)
diff --git a/src/frontend/paywall.en.must.j2 b/src/frontend/paywall.en.must.j2
@@ -330,8 +330,25 @@
}
}
</style>
- <!-- download from https://cdnjs.cloudflare.com/ajax/libs/qrcodejs/1.0.0/qrcode.min.js -->
- <script integrity="sha512-CNgIRecGo7nphbeZ04Sc13ka07paqdeTu0WR1IM4kNcpmBAUSHSQX0FslNhTDadL4O5SAGapGt4FodqL8My0mA==">
+@#
+ Vendored copy of
+ https://cdnjs.cloudflare.com/ajax/libs/qrcodejs/1.0.0/qrcode.min.js
+
+ Subresource Integrity only applies to elements that fetch a
+ subresource, so an integrity= attribute on an inline <script> is never
+ checked by any browser; one used to sit here and only looked like a
+ guarantee. The digest is kept here instead, so the vendored copy can
+ still be checked against upstream by hand. It is the SHA-512 of the
+ script body below with leading and trailing whitespace stripped:
+
+ sha512-CNgIRecGo7nphbeZ04Sc13ka07paqdeTu0WR1IM4kNcpmBAUSHSQX0Fsl
+ NhTDadL4O5SAGapGt4FodqL8My0mA==
+
+ What constrains this script at runtime is the Content-Security-Policy
+ built in paivana-httpd_templates.c. This is a jinja2 comment rather
+ than an HTML one: it is for whoever maintains the template, and does
+ not need to be shipped to every visitor.
+#@ <script>
var QRCode;!function(){function a(a){this.mode=c.MODE_8BIT_BYTE,this.data=a,this.parsedData=[];for(var b=[],d=0,e=this.data.length;e>d;d++){var f=this.data.charCodeAt(d);f>65536?(b[0]=240|(1835008&f)>>>18,b[1]=128|(258048&f)>>>12,b[2]=128|(4032&f)>>>6,b[3]=128|63&f):f>2048?(b[0]=224|(61440&f)>>>12,b[1]=128|(4032&f)>>>6,b[2]=128|63&f):f>128?(b[0]=192|(1984&f)>>>6,b[1]=128|63&f):b[0]=f,this.parsedData=this.parsedData.concat(b)}this.parsedData.length!=this.data.length&&(this.parsedData.unshift(191),this.parsedData.unshift(187),this.parsedData.unshift(239))}function b(a,b){this.typeNumber=a,this.errorCorrectLevel=b,this.modules=null,this.moduleCount=0,this.dataCache=null,this.dataList=[]}function i(a,b){if(void 0==a.length)throw new Error(a.length+"/"+b);for(var c=0;c<a.length&&0==a[c];)c++;this.num=new Array(a.length-c+b);for(var d=0;d<a.length-c;d++)this.num[d]=a[d+c]}function j(a,b){this.totalCount=a,this.dataCount=b}function k(){this.buffer=[],this.length=0}function m(){return"undefined"!=typeof CanvasRenderingContext2D}function n(){var a=!1,b=navigator.userAgent;return/android/i.test(b)&&(a=!0,aMat=b.toString().match(/android ([0-9]\.[0-9])/i),aMat&&aMat[1]&&(a=parseFloat(aMat[1]))),a}function r(a,b){for(var c=1,e=s(a),f=0,g=l.length;g>=f;f++){var h=0;switch(b){case d.L:h=l[f][0];break;case d.M:h=l[f][1];break;case d.Q:h=l[f][2];break;case d.H:h=l[f][3]}if(h>=e)break;c++}if(c>l.length)throw new Error("Too long data");return c}function s(a){var b=encodeURI(a).toString().replace(/\%[0-9a-fA-F]{2}/g,"a");return b.length+(b.length!=a?3:0)}a.prototype={getLength:function(){return this.parsedData.length},write:function(a){for(var b=0,c=this.parsedData.length;c>b;b++)a.put(this.parsedData[b],8)}},b.prototype={addData:function(b){var c=new a(b);this.dataList.push(c),this.dataCache=null},isDark:function(a,b){if(0>a||this.moduleCount<=a||0>b||this.moduleCount<=b)throw new Error(a+","+b);return this.modules[a][b]},getModuleCount:function(){return this.moduleCount},make:function(){this.makeImpl(!1,this.getBestMaskPattern())},makeImpl:function(a,c){this.moduleCount=4*this.typeNumber+17,this.modules=new Array(this.moduleCount);for(var d=0;d<this.moduleCount;d++){this.modules[d]=new Array(this.moduleCount);for(var e=0;e<this.moduleCount;e++)this.modules[d][e]=null}this.setupPositionProbePattern(0,0),this.setupPositionProbePattern(this.moduleCount-7,0),this.setupPositionProbePattern(0,this.moduleCount-7),this.setupPositionAdjustPattern(),this.setupTimingPattern(),this.setupTypeInfo(a,c),this.typeNumber>=7&&this.setupTypeNumber(a),null==this.dataCache&&(this.dataCache=b.createData(this.typeNumber,this.errorCorrectLevel,this.dataList)),this.mapData(this.dataCache,c)},setupPositionProbePattern:function(a,b){for(var c=-1;7>=c;c++)if(!(-1>=a+c||this.moduleCount<=a+c))for(var d=-1;7>=d;d++)-1>=b+d||this.moduleCount<=b+d||(this.modules[a+c][b+d]=c>=0&&6>=c&&(0==d||6==d)||d>=0&&6>=d&&(0==c||6==c)||c>=2&&4>=c&&d>=2&&4>=d?!0:!1)},getBestMaskPattern:function(){for(var a=0,b=0,c=0;8>c;c++){this.makeImpl(!0,c);var d=f.getLostPoint(this);(0==c||a>d)&&(a=d,b=c)}return b},createMovieClip:function(a,b,c){var d=a.createEmptyMovieClip(b,c),e=1;this.make();for(var f=0;f<this.modules.length;f++)for(var g=f*e,h=0;h<this.modules[f].length;h++){var i=h*e,j=this.modules[f][h];j&&(d.beginFill(0,100),d.moveTo(i,g),d.lineTo(i+e,g),d.lineTo(i+e,g+e),d.lineTo(i,g+e),d.endFill())}return d},setupTimingPattern:function(){for(var a=8;a<this.moduleCount-8;a++)null==this.modules[a][6]&&(this.modules[a][6]=0==a%2);for(var b=8;b<this.moduleCount-8;b++)null==this.modules[6][b]&&(this.modules[6][b]=0==b%2)},setupPositionAdjustPattern:function(){for(var a=f.getPatternPosition(this.typeNumber),b=0;b<a.length;b++)for(var c=0;c<a.length;c++){var d=a[b],e=a[c];if(null==this.modules[d][e])for(var g=-2;2>=g;g++)for(var h=-2;2>=h;h++)this.modules[d+g][e+h]=-2==g||2==g||-2==h||2==h||0==g&&0==h?!0:!1}},setupTypeNumber:function(a){for(var b=f.getBCHTypeNumber(this.typeNumber),c=0;18>c;c++){var d=!a&&1==(1&b>>c);this.modules[Math.floor(c/3)][c%3+this.moduleCount-8-3]=d}for(var c=0;18>c;c++){var d=!a&&1==(1&b>>c);this.modules[c%3+this.moduleCount-8-3][Math.floor(c/3)]=d}},setupTypeInfo:function(a,b){for(var c=this.errorCorrectLevel<<3|b,d=f.getBCHTypeInfo(c),e=0;15>e;e++){var g=!a&&1==(1&d>>e);6>e?this.modules[e][8]=g:8>e?this.modules[e+1][8]=g:this.modules[this.moduleCount-15+e][8]=g}for(var e=0;15>e;e++){var g=!a&&1==(1&d>>e);8>e?this.modules[8][this.moduleCount-e-1]=g:9>e?this.modules[8][15-e-1+1]=g:this.modules[8][15-e-1]=g}this.modules[this.moduleCount-8][8]=!a},mapData:function(a,b){for(var c=-1,d=this.moduleCount-1,e=7,g=0,h=this.moduleCount-1;h>0;h-=2)for(6==h&&h--;;){for(var i=0;2>i;i++)if(null==this.modules[d][h-i]){var j=!1;g<a.length&&(j=1==(1&a[g]>>>e));var k=f.getMask(b,d,h-i);k&&(j=!j),this.modules[d][h-i]=j,e--,-1==e&&(g++,e=7)}if(d+=c,0>d||this.moduleCount<=d){d-=c,c=-c;break}}}},b.PAD0=236,b.PAD1=17,b.createData=function(a,c,d){for(var e=j.getRSBlocks(a,c),g=new k,h=0;h<d.length;h++){var i=d[h];g.put(i.mode,4),g.put(i.getLength(),f.getLengthInBits(i.mode,a)),i.write(g)}for(var l=0,h=0;h<e.length;h++)l+=e[h].dataCount;if(g.getLengthInBits()>8*l)throw new Error("code length overflow. ("+g.getLengthInBits()+">"+8*l+")");for(g.getLengthInBits()+4<=8*l&&g.put(0,4);0!=g.getLengthInBits()%8;)g.putBit(!1);for(;;){if(g.getLengthInBits()>=8*l)break;if(g.put(b.PAD0,8),g.getLengthInBits()>=8*l)break;g.put(b.PAD1,8)}return b.createBytes(g,e)},b.createBytes=function(a,b){for(var c=0,d=0,e=0,g=new Array(b.length),h=new Array(b.length),j=0;j<b.length;j++){var k=b[j].dataCount,l=b[j].totalCount-k;d=Math.max(d,k),e=Math.max(e,l),g[j]=new Array(k);for(var m=0;m<g[j].length;m++)g[j][m]=255&a.buffer[m+c];c+=k;var n=f.getErrorCorrectPolynomial(l),o=new i(g[j],n.getLength()-1),p=o.mod(n);h[j]=new Array(n.getLength()-1);for(var m=0;m<h[j].length;m++){var q=m+p.getLength()-h[j].length;h[j][m]=q>=0?p.get(q):0}}for(var r=0,m=0;m<b.length;m++)r+=b[m].totalCount;for(var s=new Array(r),t=0,m=0;d>m;m++)for(var j=0;j<b.length;j++)m<g[j].length&&(s[t++]=g[j][m]);for(var m=0;e>m;m++)for(var j=0;j<b.length;j++)m<h[j].length&&(s[t++]=h[j][m]);return s};for(var c={MODE_NUMBER:1,MODE_ALPHA_NUM:2,MODE_8BIT_BYTE:4,MODE_KANJI:8},d={L:1,M:0,Q:3,H:2},e={PATTERN000:0,PATTERN001:1,PATTERN010:2,PATTERN011:3,PATTERN100:4,PATTERN101:5,PATTERN110:6,PATTERN111:7},f={PATTERN_POSITION_TABLE:[[],[6,18],[6,22],[6,26],[6,30],[6,34],[6,22,38],[6,24,42],[6,26,46],[6,28,50],[6,30,54],[6,32,58],[6,34,62],[6,26,46,66],[6,26,48,70],[6,26,50,74],[6,30,54,78],[6,30,56,82],[6,30,58,86],[6,34,62,90],[6,28,50,72,94],[6,26,50,74,98],[6,30,54,78,102],[6,28,54,80,106],[6,32,58,84,110],[6,30,58,86,114],[6,34,62,90,118],[6,26,50,74,98,122],[6,30,54,78,102,126],[6,26,52,78,104,130],[6,30,56,82,108,134],[6,34,60,86,112,138],[6,30,58,86,114,142],[6,34,62,90,118,146],[6,30,54,78,102,126,150],[6,24,50,76,102,128,154],[6,28,54,80,106,132,158],[6,32,58,84,110,136,162],[6,26,54,82,110,138,166],[6,30,58,86,114,142,170]],G15:1335,G18:7973,G15_MASK:21522,getBCHTypeInfo:function(a){for(var b=a<<10;f.getBCHDigit(b)-f.getBCHDigit(f.G15)>=0;)b^=f.G15<<f.getBCHDigit(b)-f.getBCHDigit(f.G15);return(a<<10|b)^f.G15_MASK},getBCHTypeNumber:function(a){for(var b=a<<12;f.getBCHDigit(b)-f.getBCHDigit(f.G18)>=0;)b^=f.G18<<f.getBCHDigit(b)-f.getBCHDigit(f.G18);return a<<12|b},getBCHDigit:function(a){for(var b=0;0!=a;)b++,a>>>=1;return b},getPatternPosition:function(a){return f.PATTERN_POSITION_TABLE[a-1]},getMask:function(a,b,c){switch(a){case e.PATTERN000:return 0==(b+c)%2;case e.PATTERN001:return 0==b%2;case e.PATTERN010:return 0==c%3;case e.PATTERN011:return 0==(b+c)%3;case e.PATTERN100:return 0==(Math.floor(b/2)+Math.floor(c/3))%2;case e.PATTERN101:return 0==b*c%2+b*c%3;case e.PATTERN110:return 0==(b*c%2+b*c%3)%2;case e.PATTERN111:return 0==(b*c%3+(b+c)%2)%2;default:throw new Error("bad maskPattern:"+a)}},getErrorCorrectPolynomial:function(a){for(var b=new i([1],0),c=0;a>c;c++)b=b.multiply(new i([1,g.gexp(c)],0));return b},getLengthInBits:function(a,b){if(b>=1&&10>b)switch(a){case c.MODE_NUMBER:return 10;case c.MODE_ALPHA_NUM:return 9;case c.MODE_8BIT_BYTE:return 8;case c.MODE_KANJI:return 8;default:throw new Error("mode:"+a)}else if(27>b)switch(a){case c.MODE_NUMBER:return 12;case c.MODE_ALPHA_NUM:return 11;case c.MODE_8BIT_BYTE:return 16;case c.MODE_KANJI:return 10;default:throw new Error("mode:"+a)}else{if(!(41>b))throw new Error("type:"+b);switch(a){case c.MODE_NUMBER:return 14;case c.MODE_ALPHA_NUM:return 13;case c.MODE_8BIT_BYTE:return 16;case c.MODE_KANJI:return 12;default:throw new Error("mode:"+a)}}},getLostPoint:function(a){for(var b=a.getModuleCount(),c=0,d=0;b>d;d++)for(var e=0;b>e;e++){for(var f=0,g=a.isDark(d,e),h=-1;1>=h;h++)if(!(0>d+h||d+h>=b))for(var i=-1;1>=i;i++)0>e+i||e+i>=b||(0!=h||0!=i)&&g==a.isDark(d+h,e+i)&&f++;f>5&&(c+=3+f-5)}for(var d=0;b-1>d;d++)for(var e=0;b-1>e;e++){var j=0;a.isDark(d,e)&&j++,a.isDark(d+1,e)&&j++,a.isDark(d,e+1)&&j++,a.isDark(d+1,e+1)&&j++,(0==j||4==j)&&(c+=3)}for(var d=0;b>d;d++)for(var e=0;b-6>e;e++)a.isDark(d,e)&&!a.isDark(d,e+1)&&a.isDark(d,e+2)&&a.isDark(d,e+3)&&a.isDark(d,e+4)&&!a.isDark(d,e+5)&&a.isDark(d,e+6)&&(c+=40);for(var e=0;b>e;e++)for(var d=0;b-6>d;d++)a.isDark(d,e)&&!a.isDark(d+1,e)&&a.isDark(d+2,e)&&a.isDark(d+3,e)&&a.isDark(d+4,e)&&!a.isDark(d+5,e)&&a.isDark(d+6,e)&&(c+=40);for(var k=0,e=0;b>e;e++)for(var d=0;b>d;d++)a.isDark(d,e)&&k++;var l=Math.abs(100*k/b/b-50)/5;return c+=10*l}},g={glog:function(a){if(1>a)throw new Error("glog("+a+")");return g.LOG_TABLE[a]},gexp:function(a){for(;0>a;)a+=255;for(;a>=256;)a-=255;return g.EXP_TABLE[a]},EXP_TABLE:new Array(256),LOG_TABLE:new Array(256)},h=0;8>h;h++)g.EXP_TABLE[h]=1<<h;for(var h=8;256>h;h++)g.EXP_TABLE[h]=g.EXP_TABLE[h-4]^g.EXP_TABLE[h-5]^g.EXP_TABLE[h-6]^g.EXP_TABLE[h-8];for(var h=0;255>h;h++)g.LOG_TABLE[g.EXP_TABLE[h]]=h;i.prototype={get:function(a){return this.num[a]},getLength:function(){return this.num.length},multiply:function(a){for(var b=new Array(this.getLength()+a.getLength()-1),c=0;c<this.getLength();c++)for(var d=0;d<a.getLength();d++)b[c+d]^=g.gexp(g.glog(this.get(c))+g.glog(a.get(d)));return new i(b,0)},mod:function(a){if(this.getLength()-a.getLength()<0)return this;for(var b=g.glog(this.get(0))-g.glog(a.get(0)),c=new Array(this.getLength()),d=0;d<this.getLength();d++)c[d]=this.get(d);for(var d=0;d<a.getLength();d++)c[d]^=g.gexp(g.glog(a.get(d))+b);return new i(c,0).mod(a)}},j.RS_BLOCK_TABLE=[[1,26,19],[1,26,16],[1,26,13],[1,26,9],[1,44,34],[1,44,28],[1,44,22],[1,44,16],[1,70,55],[1,70,44],[2,35,17],[2,35,13],[1,100,80],[2,50,32],[2,50,24],[4,25,9],[1,134,108],[2,67,43],[2,33,15,2,34,16],[2,33,11,2,34,12],[2,86,68],[4,43,27],[4,43,19],[4,43,15],[2,98,78],[4,49,31],[2,32,14,4,33,15],[4,39,13,1,40,14],[2,121,97],[2,60,38,2,61,39],[4,40,18,2,41,19],[4,40,14,2,41,15],[2,146,116],[3,58,36,2,59,37],[4,36,16,4,37,17],[4,36,12,4,37,13],[2,86,68,2,87,69],[4,69,43,1,70,44],[6,43,19,2,44,20],[6,43,15,2,44,16],[4,101,81],[1,80,50,4,81,51],[4,50,22,4,51,23],[3,36,12,8,37,13],[2,116,92,2,117,93],[6,58,36,2,59,37],[4,46,20,6,47,21],[7,42,14,4,43,15],[4,133,107],[8,59,37,1,60,38],[8,44,20,4,45,21],[12,33,11,4,34,12],[3,145,115,1,146,116],[4,64,40,5,65,41],[11,36,16,5,37,17],[11,36,12,5,37,13],[5,109,87,1,110,88],[5,65,41,5,66,42],[5,54,24,7,55,25],[11,36,12],[5,122,98,1,123,99],[7,73,45,3,74,46],[15,43,19,2,44,20],[3,45,15,13,46,16],[1,135,107,5,136,108],[10,74,46,1,75,47],[1,50,22,15,51,23],[2,42,14,17,43,15],[5,150,120,1,151,121],[9,69,43,4,70,44],[17,50,22,1,51,23],[2,42,14,19,43,15],[3,141,113,4,142,114],[3,70,44,11,71,45],[17,47,21,4,48,22],[9,39,13,16,40,14],[3,135,107,5,136,108],[3,67,41,13,68,42],[15,54,24,5,55,25],[15,43,15,10,44,16],[4,144,116,4,145,117],[17,68,42],[17,50,22,6,51,23],[19,46,16,6,47,17],[2,139,111,7,140,112],[17,74,46],[7,54,24,16,55,25],[34,37,13],[4,151,121,5,152,122],[4,75,47,14,76,48],[11,54,24,14,55,25],[16,45,15,14,46,16],[6,147,117,4,148,118],[6,73,45,14,74,46],[11,54,24,16,55,25],[30,46,16,2,47,17],[8,132,106,4,133,107],[8,75,47,13,76,48],[7,54,24,22,55,25],[22,45,15,13,46,16],[10,142,114,2,143,115],[19,74,46,4,75,47],[28,50,22,6,51,23],[33,46,16,4,47,17],[8,152,122,4,153,123],[22,73,45,3,74,46],[8,53,23,26,54,24],[12,45,15,28,46,16],[3,147,117,10,148,118],[3,73,45,23,74,46],[4,54,24,31,55,25],[11,45,15,31,46,16],[7,146,116,7,147,117],[21,73,45,7,74,46],[1,53,23,37,54,24],[19,45,15,26,46,16],[5,145,115,10,146,116],[19,75,47,10,76,48],[15,54,24,25,55,25],[23,45,15,25,46,16],[13,145,115,3,146,116],[2,74,46,29,75,47],[42,54,24,1,55,25],[23,45,15,28,46,16],[17,145,115],[10,74,46,23,75,47],[10,54,24,35,55,25],[19,45,15,35,46,16],[17,145,115,1,146,116],[14,74,46,21,75,47],[29,54,24,19,55,25],[11,45,15,46,46,16],[13,145,115,6,146,116],[14,74,46,23,75,47],[44,54,24,7,55,25],[59,46,16,1,47,17],[12,151,121,7,152,122],[12,75,47,26,76,48],[39,54,24,14,55,25],[22,45,15,41,46,16],[6,151,121,14,152,122],[6,75,47,34,76,48],[46,54,24,10,55,25],[2,45,15,64,46,16],[17,152,122,4,153,123],[29,74,46,14,75,47],[49,54,24,10,55,25],[24,45,15,46,46,16],[4,152,122,18,153,123],[13,74,46,32,75,47],[48,54,24,14,55,25],[42,45,15,32,46,16],[20,147,117,4,148,118],[40,75,47,7,76,48],[43,54,24,22,55,25],[10,45,15,67,46,16],[19,148,118,6,149,119],[18,75,47,31,76,48],[34,54,24,34,55,25],[20,45,15,61,46,16]],j.getRSBlocks=function(a,b){var c=j.getRsBlockTable(a,b);if(void 0==c)throw new Error("bad rs block @ typeNumber:"+a+"/errorCorrectLevel:"+b);for(var d=c.length/3,e=[],f=0;d>f;f++)for(var g=c[3*f+0],h=c[3*f+1],i=c[3*f+2],k=0;g>k;k++)e.push(new j(h,i));return e},j.getRsBlockTable=function(a,b){switch(b){case d.L:return j.RS_BLOCK_TABLE[4*(a-1)+0];case d.M:return j.RS_BLOCK_TABLE[4*(a-1)+1];case d.Q:return j.RS_BLOCK_TABLE[4*(a-1)+2];case d.H:return j.RS_BLOCK_TABLE[4*(a-1)+3];default:return void 0}},k.prototype={get:function(a){var b=Math.floor(a/8);return 1==(1&this.buffer[b]>>>7-a%8)},put:function(a,b){for(var c=0;b>c;c++)this.putBit(1==(1&a>>>b-c-1))},getLengthInBits:function(){return this.length},putBit:function(a){var b=Math.floor(this.length/8);this.buffer.length<=b&&this.buffer.push(0),a&&(this.buffer[b]|=128>>>this.length%8),this.length++}};var l=[[17,14,11,7],[32,26,20,14],[53,42,32,24],[78,62,46,34],[106,84,60,44],[134,106,74,58],[154,122,86,64],[192,152,108,84],[230,180,130,98],[271,213,151,119],[321,251,177,137],[367,287,203,155],[425,331,241,177],[458,362,258,194],[520,412,292,220],[586,450,322,250],[644,504,364,280],[718,560,394,310],[792,624,442,338],[858,666,482,382],[929,711,509,403],[1003,779,565,439],[1091,857,611,461],[1171,911,661,511],[1273,997,715,535],[1367,1059,751,593],[1465,1125,805,625],[1528,1190,868,658],[1628,1264,908,698],[1732,1370,982,742],[1840,1452,1030,790],[1952,1538,1112,842],[2068,1628,1168,898],[2188,1722,1228,958],[2303,1809,1283,983],[2431,1911,1351,1051],[2563,1989,1423,1093],[2699,2099,1499,1139],[2809,2213,1579,1219],[2953,2331,1663,1273]],o=function(){var a=function(a,b){this._el=a,this._htOption=b};return a.prototype.draw=function(a){function g(a,b){var c=document.createElementNS("http://www.w3.org/2000/svg",a);for(var d in b)b.hasOwnProperty(d)&&c.setAttribute(d,b[d]);return c}var b=this._htOption,c=this._el,d=a.getModuleCount();Math.floor(b.width/d),Math.floor(b.height/d),this.clear();var h=g("svg",{viewBox:"0 0 "+String(d)+" "+String(d),width:"100%",height:"100%",fill:b.colorLight});h.setAttributeNS("http://www.w3.org/2000/xmlns/","xmlns:xlink","http://www.w3.org/1999/xlink"),c.appendChild(h),h.appendChild(g("rect",{fill:b.colorDark,width:"1",height:"1",id:"template"}));for(var i=0;d>i;i++)for(var j=0;d>j;j++)if(a.isDark(i,j)){var k=g("use",{x:String(i),y:String(j)});k.setAttributeNS("http://www.w3.org/1999/xlink","href","#template"),h.appendChild(k)}},a.prototype.clear=function(){for(;this._el.hasChildNodes();)this._el.removeChild(this._el.lastChild)},a}(),p="svg"===document.documentElement.tagName.toLowerCase(),q=p?o:m()?function(){function a(){this._elImage.src=this._elCanvas.toDataURL("image/png"),this._elImage.style.display="block",this._elCanvas.style.display="none"}function d(a,b){var c=this;if(c._fFail=b,c._fSuccess=a,null===c._bSupportDataURI){var d=document.createElement("img"),e=function(){c._bSupportDataURI=!1,c._fFail&&_fFail.call(c)},f=function(){c._bSupportDataURI=!0,c._fSuccess&&c._fSuccess.call(c)};return d.onabort=e,d.onerror=e,d.onload=f,d.src="data:image/gif;base64,iVBORw0KGgoAAAANSUhEUgAAAAUAAAAFCAYAAACNbyblAAAAHElEQVQI12P4//8/w38GIAXDIBKE0DHxgljNBAAO9TXL0Y4OHwAAAABJRU5ErkJggg==",void 0}c._bSupportDataURI===!0&&c._fSuccess?c._fSuccess.call(c):c._bSupportDataURI===!1&&c._fFail&&c._fFail.call(c)}if(this._android&&this._android<=2.1){var b=1/window.devicePixelRatio,c=CanvasRenderingContext2D.prototype.drawImage;CanvasRenderingContext2D.prototype.drawImage=function(a,d,e,f,g,h,i,j){if("nodeName"in a&&/img/i.test(a.nodeName))for(var l=arguments.length-1;l>=1;l--)arguments[l]=arguments[l]*b;else"undefined"==typeof j&&(arguments[1]*=b,arguments[2]*=b,arguments[3]*=b,arguments[4]*=b);c.apply(this,arguments)}}var e=function(a,b){this._bIsPainted=!1,this._android=n(),this._htOption=b,this._elCanvas=document.createElement("canvas"),this._elCanvas.width=b.width,this._elCanvas.height=b.height,a.appendChild(this._elCanvas),this._el=a,this._oContext=this._elCanvas.getContext("2d"),this._bIsPainted=!1,this._elImage=document.createElement("img"),this._elImage.style.display="none",this._el.appendChild(this._elImage),this._bSupportDataURI=null};return e.prototype.draw=function(a){var b=this._elImage,c=this._oContext,d=this._htOption,e=a.getModuleCount(),f=d.width/e,g=d.height/e,h=Math.round(f),i=Math.round(g);b.style.display="none",this.clear();for(var j=0;e>j;j++)for(var k=0;e>k;k++){var l=a.isDark(j,k),m=k*f,n=j*g;c.strokeStyle=l?d.colorDark:d.colorLight,c.lineWidth=1,c.fillStyle=l?d.colorDark:d.colorLight,c.fillRect(m,n,f,g),c.strokeRect(Math.floor(m)+.5,Math.floor(n)+.5,h,i),c.strokeRect(Math.ceil(m)-.5,Math.ceil(n)-.5,h,i)}this._bIsPainted=!0},e.prototype.makeImage=function(){this._bIsPainted&&d.call(this,a)},e.prototype.isPainted=function(){return this._bIsPainted},e.prototype.clear=function(){this._oContext.clearRect(0,0,this._elCanvas.width,this._elCanvas.height),this._bIsPainted=!1},e.prototype.round=function(a){return a?Math.floor(1e3*a)/1e3:a},e}():function(){var a=function(a,b){this._el=a,this._htOption=b};return a.prototype.draw=function(a){for(var b=this._htOption,c=this._el,d=a.getModuleCount(),e=Math.floor(b.width/d),f=Math.floor(b.height/d),g=['<table style="border:0;border-collapse:collapse;">'],h=0;d>h;h++){g.push("<tr>");for(var i=0;d>i;i++)g.push('<td style="border:0;border-collapse:collapse;padding:0;margin:0;width:'+e+"px;height:"+f+"px;background-color:"+(a.isDark(h,i)?b.colorDark:b.colorLight)+';"></td>');g.push("</tr>")}g.push("</table>"),c.innerHTML=g.join("");var j=c.childNodes[0],k=(b.width-j.offsetWidth)/2,l=(b.height-j.offsetHeight)/2;k>0&&l>0&&(j.style.margin=l+"px "+k+"px")},a.prototype.clear=function(){this._el.innerHTML=""},a}();QRCode=function(a,b){if(this._htOption={width:256,height:256,typeNumber:4,colorDark:"#000000",colorLight:"#ffffff",correctLevel:d.H},"string"==typeof b&&(b={text:b}),b)for(var c in b)this._htOption[c]=b[c];"string"==typeof a&&(a=document.getElementById(a)),this._android=n(),this._el=a,this._oQRCode=null,this._oDrawing=new q(this._el,this._htOption),this._htOption.text&&this.makeCode(this._htOption.text)},QRCode.prototype.makeCode=function(a){this._oQRCode=new b(r(a,this._htOption.correctLevel),this._htOption.correctLevel),this._oQRCode.addData(a),this._oQRCode.make(),this._el.title=a,this._oDrawing.draw(this._oQRCode),this.makeImage()},QRCode.prototype.makeImage=function(){"function"==typeof this._oDrawing.makeImage&&(!this._android||this._android>=3)&&this._oDrawing.makeImage()},QRCode.prototype.clear=function(){this._oDrawing.clear()},QRCode.CorrectLevel=d}();
</script>
</head>
diff --git a/src/frontend/typecheck.sh b/src/frontend/typecheck.sh
@@ -1,11 +1,34 @@
-#!/usr/bin/env bash
+#!/bin/sh
+# Type-check paywall.js with the TypeScript compiler in checkJs mode.
+#
+# Exits 77 ("skipped" for meson and for the GNU test convention) when no
+# TypeScript compiler is available locally. We never fall back to a
+# plain `npx --package typescript', which would download a compiler:
+# running the test suite must not reach out to the network. To run it
+# by hand without installing anything:
+#
+# npx --package typescript tsc --allowJs --checkJs --noEmit \
+# --target esnext --lib esnext,esnext.bigint,dom \
+# src/frontend/paywall.js src/frontend/global.d.ts
-if tsc --version &>/dev/null; then
- TSC=tsc
-elif npx --version &>/dev/null; then
- TSC="npx --package typescript tsc"
+set -eu
+
+srcdir=${SRCDIR:-$(dirname "$0")}
+
+if command -v tsc >/dev/null 2>&1; then
+ set -- tsc
+elif npx --no-install tsc --version >/dev/null 2>&1; then
+ set -- npx --no-install tsc
else
- echo "TypeScript compiler not found" >&2
+ echo "no local TypeScript compiler found, skipping type check" >&2
+ exit 77
fi
-$TSC --allowJs --checkJs --noEmit --target esnext --lib esnext,esnext.bigint,dom paywall.js global.d.ts
+exec "$@" \
+ --allowJs \
+ --checkJs \
+ --noEmit \
+ --target esnext \
+ --lib esnext,esnext.bigint,dom \
+ "$srcdir/paywall.js" \
+ "$srcdir/global.d.ts"
diff --git a/src/include/Makefile.am b/src/include/Makefile.am
@@ -1,7 +0,0 @@
-# This Makefile.am is in the public domain
-SUBDIRS = .
-
-paivanaincludedir = $(includedir)/paivana
-
-paivanainclude_HEADERS = \
- platform.h
diff --git a/src/include/platform.h b/src/include/platform.h
@@ -28,6 +28,11 @@
*
* This file should never be included by installed
* header files (those starting with "gnunet_").
+ *
+ * Every `#if HAVE_..._H' guard below needs a matching entry in the
+ * `check_headers' list in the top-level meson.build. An unprobed guard
+ * is not a conservative default: the macro stays undefined, the guard
+ * evaluates to 0, and the header is silently never included.
*/
#ifndef PLATFORM_H
#define PLATFORM_H
@@ -56,16 +61,14 @@
*/
#define ALLOW_EXTRA_CHECKS GNUNET_YES
-/**
- * For strptime (glibc2 needs this).
- */
-#ifndef _XOPEN_SOURCE
-#define _XOPEN_SOURCE 499
-#endif
-
-#ifndef _REENTRANT
-#define _REENTRANT
-#endif
+/* A feature test macro only has an effect when it is defined before the
+ first libc header is pulled in, and by this point <inttypes.h> (and
+ hence <features.h>) has already been included. _XOPEN_SOURCE and
+ _REENTRANT used to be set here and were therefore inert; they are
+ gone rather than moved, because paivana uses no XSI-only function
+ and defining _XOPEN_SOURCE for real would *narrow* the visible
+ namespace rather than widen it. Add a feature test macro at the top
+ of this file, above every #include, if one is ever needed. */
/* configuration options */
@@ -194,7 +197,7 @@ atoll (const char *nptr);
#endif
#if ENABLE_NLS
-#include "langinfo.h"
+#include <langinfo.h>
#endif
#ifndef SIZE_MAX