pkgsubmit.php 22.2 KB
Newer Older
1
<?php
pjmattal's avatar
pjmattal committed
2
3
4

set_include_path(get_include_path() . PATH_SEPARATOR . '../lib' . PATH_SEPARATOR . '../lang');

eric's avatar
eric committed
5
6
include("aur.inc");         # access AUR common functions
include("submit_po.inc");   # use some form of this for i18n support
7
include("pkgfuncs.inc");    # package functions
8
include("config.inc");      # configuration file with dir locations
eric's avatar
eric committed
9
10
set_lang();                 # this sets up the visitor's language
check_sid();                # see if they're still logged in
eric's avatar
eric committed
11
html_header();              # print out the HTML header
eliott's avatar
eliott committed
12
13
14
echo "<div class=\"pgbox\">\n";
echo "  <div class=\"pgboxtitle\"><span class=\"f3\">".__("Submit")."</span></div>\n";
echo "  <div class=\"pgboxbody\">\n";
eric's avatar
eric committed
15

eric's avatar
eric committed
16
# Debugging
jchu's avatar
jchu committed
17
$DBUG = 0;
eric's avatar
eric committed
18

eric's avatar
eric committed
19
20
if ($_COOKIE["AURSID"]) {
	# track upload errors
eric's avatar
eric committed
21
	#
eric's avatar
eric committed
22
	$error = "";
23
24
25
	if ($DBUG) {
		print "</center><pre>\n";
		print_r($_REQUEST);
dsa's avatar
dsa committed
26
27
        print "<br>";
        print_r($_FILES);
28
29
		print "</pre><center>\n";
	}
eric's avatar
eric committed
30
31

	if ($_REQUEST["pkgsubmit"]) {
32
33
34
35
36
		# If this var is set, then the visitor is uploading a file...
		#
		if (!$_REQUEST["pkgname"]) {
			$error = __("You did not specify a package name.");
		} else {
37
			$pkg_name = str_replace("'", "", $_REQUEST["pkgname"]);
38
			$pkg_name = escapeshellarg($pkg_name);
39
			$pkg_name = str_replace("'", "", $pkg_name); # get rid of single quotes
40
41
42
            
            # Solves the problem when you try to submit PKGBUILD
            # that have the name with a period like (gstreamer0.10)
43
44
            # Added support for packages with + characters like (mysql++).
            $presult = preg_match("/^[a-z0-9][a-z0-9\.+_-]*$/", $pkg_name);
45
46
            
            if ($presult == FALSE || $presult <= 0) {
47
				# FALSE => error processing regex, 0 => invalid characters
48
49
50
51
				#
				$error = __("Invalid name: only lowercase letters are allowed.");
			}
		}
eric's avatar
eric committed
52

53
54
55
		if (!$error && (!$_REQUEST["comments"] || $_REQUEST["comments"] == '')) {
			$error = __("You must supply a comment for this upload/change.");
		}
56

57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
		if (!$error) {
			# first, see if this package already exists, and if it can be overwritten
			#	
			$pkg_exists = package_exists($pkg_name);
			if ($pkg_exists) {
				# ok, it exists - should it be overwritten, and does the user have
				# the permissions to do so?
				#
				if (can_overwrite_pkg($pkg_name, $_COOKIE["AURSID"])) {
					if (!$_REQUEST["overwrite"]) {
						$error = __("You did not tag the 'overwrite' checkbox.");
					}
				} else {
					$error = __("You are not allowed to overwrite the %h%s%h package.",
							array("<b>", $pkg_name, "</b>"));
eric's avatar
eric committed
72
73
				}
			}
74
		}
eric's avatar
eric committed
75

76
77
78
79
80
		# TODO check to see if the user has the ability to 'change' package
		# attributes such as location and/or category.	Examples: TUs can
		# only add/change packages in Unsupported and the AUR, normal users
		# can only add/change packages in Unsupported.
		#
81

82
83
84
85
		#Before processing, make sure we even have a file
		#
		if ($_FILES['pfile']['size'] == 0){
			$error = __("Error - No file uploaded");
dsa's avatar
dsa committed
86
		}
87

eric's avatar
eric committed
88
		if (!$error) {
eric's avatar
eric committed
89
90
91
92
			# no errors checking upload permissions, go ahead and try to process
			# the uploaded package file.
			#

93
            $upload_file = UPLOAD_DIR . $_FILES["pfile"]["name"];
94
95
            
            if (move_uploaded_file($_FILES["pfile"]["tmp_name"], $upload_file)) {
eric's avatar
eric committed
96
97
				# ok, we can proceed
				#
98
				if (file_exists(INCOMING_DIR . $pkg_name)) {
eric's avatar
eric committed
99
100
					# blow away the existing file/dir and contents
					#
101
					rm_rf(INCOMING_DIR . $pkg_name);
eric's avatar
eric committed
102
103
104
105
106
107
108
				}

			} else {
				# errors uploading file...
				#
				$error = __("Error trying to upload file - please try again.");
			}
109
		}
eric's avatar
eric committed
110

111
112
		# at this point, we can safely unpack the uploaded file and parse
		# its contents.
eric's avatar
eric committed
113
		#
114
		if (!$error) {
dsa's avatar
dsa committed
115
			
116
            if (!@mkdir(INCOMING_DIR.$pkg_name)) {
117
				$error = __("Could not create incoming directory: %s.",
118
						array(INCOMING_DIR.$pkg_name));
119
			} else {
120
				if (!@chdir(INCOMING_DIR.$pkg_name)) {
121
					$error = __("Could not change directory to %s.",
122
							array(INCOMING_DIR.$pkg_name));
123
124
125
				} else {
					# try .gz first
					#
dsa's avatar
dsa committed
126
					exec("/bin/sh -c 'tar xzf ".$upload_file."'", $trash, $retval);
127
128
129
					if (!$retval) {
						# now try .bz2 format
						#
dsa's avatar
dsa committed
130
						exec("/bin/sh -c 'tar xjf ".$upload_file."'", $trash, $retval);
131
132
133
134
135
136
137
					}
					if (!$retval) {
						$error = __("Unknown file format for uploaded file.");
					}
				}
			}
		}
eric's avatar
eric committed
138

139
		# At this point, if no error exists, the package has been extracted
140
		# There should be a INCOMING_DIR.$pkg_name."/".$pkg_name directory
141
		# if the user packaged it correctly.	However, if the file was
142
143
		# packaged without the $pkg_name subdirectory, try and create it
		# and move the package contents into the new sub-directory.
144
		#
145
		if (!$error) {
146
147
			if (is_dir(INCOMING_DIR.$pkg_name."/".$pkg_name) &&
					is_file(INCOMING_DIR.$pkg_name."/".$pkg_name."/PKGBUILD")) {
148
149
				# the files were packaged correctly
				#
150
				if (!@chdir(INCOMING_DIR.$pkg_name."/".$pkg_name)) {
151
					$error = __("Could not change to directory %s.",
152
							array(INCOMING_DIR.$pkg_name."/".$pkg_name));
153
				}
154
155
				$pkg_dir = INCOMING_DIR.$pkg_name."/".$pkg_name;
			} elseif (is_file(INCOMING_DIR.$pkg_name."/PKGBUILD")) {
156
				# not packaged correctly, but recovery may be possible.
157
				# try and create INCOMING_DIR.$pkg_name."/".$pkg_name and
158
159
				# move package contents into the new dir
				#
160
				if (!@mkdir(INCOMING_DIR.$pkg_name."/".$pkg_name)) {
161
					$error = __("Could not create directory %s.",
162
							array(INCOMING_DIR.$pkg_name."/".$pkg_name));
163
				} else {
dsa's avatar
dsa committed
164
					exec("/bin/sh -c 'mv * ".$pkg_name."'");
165
					if (!file_exists(INCOMING_DIR.$pkg_name."/".$pkg_name."/PKGBUILD")) {
166
167
168
						$error = __("Error exec'ing the mv command.");
					}
				}
169
				if (!@chdir(INCOMING_DIR.$pkg_name."/".$pkg_name)) {
170
					$error = __("Could not change to directory %s.",
171
							array(INCOMING_DIR.$pkg_name."/".$pkg_name));
172
				}
173
				$pkg_dir = INCOMING_DIR.$pkg_name."/".$pkg_name;
174
175
176
177
178
179
180
			} else {
				# some wierd packaging/extraction error - baal
				#
				$error = __("Error trying to unpack upload - PKGBUILD does not exist.");
			}
		}

pjmattal's avatar
pjmattal committed
181
    $shcmd = "/bin/mv ".$upload_file." ";
182
    $shcmd.= escapeshellarg(INCOMING_DIR.$pkg_name."/".$_FILES["pfile"]["name"]);
183
		@exec($shcmd);
jchu's avatar
jchu committed
184

185
		# if no error, get list of directory contents and process PKGBUILD
eric's avatar
eric committed
186
		#
187
188
189
190
191
192
193
194
		if (!$error) {
			# get list of files
			#
			$d = dir($pkg_dir);
			$pkg_contents = array();
			while ($f = $d->read()) {
				if ($f != "." && $f != "..") {
					$pkg_contents[$f] = filesize($f);
195
196
197
					if (preg_match("/^(.*\.pkg\.tar\.gz|filelist)$/", $f)) {
						$error = __("Binary packages and filelists are not allowed for upload.");
					}
198
199
200
				}
			}
			$d->close();
eric's avatar
eric committed
201

202
			# process PKGBIULD - remove line concatenation
eric's avatar
eric committed
203
			#
204
205
			$pkgbuild = array();
			$fp = fopen($pkg_dir."/PKGBUILD", "r");
206
207
208
209
			$line_no = 0;
			$lines = array();
			$continuation_line = 0;
			$current_line = "";
210
			while (!feof($fp)) {
211
				$line = trim(fgets($fp));
212
				$char_counts = count_chars($line, 0);
213
214
215
216
217
				if (substr($line, strlen($line)-1) == "\\") {
					# continue appending onto existing line_no
					#
					$current_line .= substr($line, 0, strlen($line)-1);
					$continuation_line = 1;
218
219
				} elseif ($char_counts[ord('(')] > $char_counts[ord(')')]) {
					# assumed continuation
220
221
222
223
					# continue appending onto existing line_no
					#
					$current_line .= $line . " ";
					$continuation_line = 1;
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
				} else {
					# maybe the last line in a continuation, or a standalone line?
					#
					if ($continuation_line) {
						# append onto existing line_no
						#
						$current_line .= $line;
						$lines[$line_no] = $current_line;
						$current_line = "";
					} else {
						# it's own line_no
						#
						$lines[$line_no] = $line;
					}
					$continuation_line = 0;
					$line_no++;
				}
			}
			fclose($fp);

244
245
246
247
			# Now process the lines and put any var=val lines into the
			# 'pkgbuild' array.	Also check to make sure it has the build()
			# function.
			#
248
249
			$seen_build_function = 0;
			while (list($k, $line) = each($lines)) {
jchu's avatar
jchu committed
250
				$lparts = explode("=", $line, 2);
251
				if (count($lparts) == 2) {
252
					# this is a variable/value pair, strip out
253
					# array parens and any quoting, except in pkgdesc
254
					# for pkgdesc, only remove start/end pairs of " or '
255
					if ($lparts[0]=="pkgdesc") {
256
257
258
259
260
261
262
263
264
265
266
						if ($lparts[1]{0} == '"' && 
								$lparts[1]{strlen($lparts[1])-1} == '"') {
							$pkgbuild[$lparts[0]] = substr($lparts[1], 1, -1);
						}
					 	elseif 
							($lparts[1]{0} == "'" && 
							 $lparts[1]{strlen($lparts[1])-1} == "'") {
							$pkgbuild[$lparts[0]] = substr($lparts[1], 1, -1);
						} else { 
							$pkgbuild[$lparts[0]] = $lparts[1];
					 	}
267
268
269
270
					} else {
						$pkgbuild[$lparts[0]] = str_replace(array("(",")","\"","'"), "",
								$lparts[1]);
					}
271
				} else {
272
					# either a comment, blank line, continued line, or build function
273
274
					#
					if (substr($lparts[0], 0, 5) == "build") {
275
						$seen_build_function = 1;
276
277
					}
				}
278
279
280
281
				# XXX: closes bug #2280?  Might as well let the loop complete rather
				# than break after the build() function.
				#
				#if ($seen_build_function) {break;}
282
			}
eric's avatar
eric committed
283

284
			# some error checking on PKGBUILD contents - just make sure each
285
			# variable has a value.	This does not do any validity checking
286
			# on the values, or attempts to fix line continuation/wrapping.
eric's avatar
eric committed
287
			#
dsa's avatar
dsa committed
288
            if (!$seen_build_function) {
289
290
291
292
293
294
295
296
297
298
299
300
301
302
				$error = __("Missing build function in PKGBUILD.");
			}
			if (!array_key_exists("md5sums", $pkgbuild)) {
				$error = __("Missing md5sums variable in PKGBUILD.");
			}
			if (!array_key_exists("source", $pkgbuild)) {
				$error = __("Missing source variable in PKGBUILD.");
			}
			if (!array_key_exists("url", $pkgbuild)) {
				$error = __("Missing url variable in PKGBUILD.");
			}
			if (!array_key_exists("pkgdesc", $pkgbuild)) {
				$error = __("Missing pkgdesc variable in PKGBUILD.");
			}
dsa's avatar
dsa committed
303
304
305
            if (!array_key_exists("license", $pkgbuild)) {
                $error = __("Missing license variable in PKGBUILD.");
            }            
306
307
308
309
310
311
			if (!array_key_exists("pkgrel", $pkgbuild)) {
				$error = __("Missing pkgrel variable in PKGBUILD.");
			}
			if (!array_key_exists("pkgver", $pkgbuild)) {
				$error = __("Missing pkgver variable in PKGBUILD.");
			}
dsa's avatar
dsa committed
312
313
314
            if (!array_key_exists("arch", $pkgbuild)) {
                $error = __("Missing arch variable in PKGBUILD.");
            }
315
316
			if (!array_key_exists("pkgname", $pkgbuild)) {
				$error = __("Missing pkgname variable in PKGBUILD.");
317
318
319
320
			} else {
				if ($pkgbuild["pkgname"] != $pkg_name) {
					$error = __("Package names do not match.");
				}
321
			}
322
323
324
325
326
327
		}

		# TODO This is where other additional error checking can be
		# performed.	Examples: #md5sums == #sources?, md5sums of any
		# included files match?, install scriptlet file exists?
		#
328
329
330
		
		# Check for http:// or other protocol in url
		# 
331
		if (!$error) {
332
333
334
335
			$parsed_url = parse_url($pkgbuild['url']);
			if (!$parsed_url['scheme']) {
				$error = __("Package URL is missing a protocol (ie. http:// ,ftp://)");
			}
336
337
		}
			
338
339
340
		# Now, run through the pkgbuild array and do any $pkgname/$pkgver
		# substituions.
		#
341
		#TODO: run through and do ALL substitutions, to cover custom vars
342
343
344
345
346
347
348
349
350
351
352
353
		if (!$error) {
			$pkgname_var = $pkgbuild["pkgname"];
			$pkgver_var = $pkgbuild["pkgver"];
			$new_pkgbuild = array();
			while (list($k, $v) = each($pkgbuild)) {
				$v = str_replace("\$pkgname", $pkgname_var, $v);
				$v = str_replace("\${pkgname}", $pkgname_var, $v);
				$v = str_replace("\$pkgver", $pkgver_var, $v);
				$v = str_replace("\${pkgver}", $pkgver_var, $v);
				$new_pkgbuild[$k] = $v;
			}
		}
354

355
356
357
		# Re-tar the package for consistency's sake
		#
		if (!$error) {
358
			if (!@chdir(INCOMING_DIR.$pkg_name)) {
359
				$error = __("Could not change directory to %s.",
360
				array(INCOMING_DIR.$pkg_name));
361
362
363
364
365
366
367
368
			}
		}
		if (!$error) {
			@exec("/bin/sh -c 'tar czf ".$pkg_name.".tar.gz ".$pkg_name."'", $trash, $retval);
			if ($retval) {
				$error = __("Could not re-tar");
			}
		}
369
370
		# update the backend database
		#
371
372
373
374
375
376
377
378
		if (!$error) {
			$dbh = db_connect();
			# this is an overwrite of an existing package, the database ID
			# needs to be preserved so that any votes are retained.	However,
			# PackageDepends, PackageSources, and PackageContents can be
			# purged.
			#
			$q = "SELECT * FROM Packages ";
379
			$q.= "WHERE Name = '".mysql_real_escape_string($new_pkgbuild['pkgname'])."'";
380
381
382
383
384
385
386
387
388
389
390
391
392
			$result = db_query($q, $dbh);
			$pdata = mysql_fetch_assoc($result);

			if ($pdata) {

				# flush out old data that will be replaced with new data
				#
				$q = "DELETE FROM PackageContents WHERE PackageID = ".$pdata["ID"];
				db_query($q, $dbh);
				$q = "DELETE FROM PackageDepends WHERE PackageID = ".$pdata["ID"];
				db_query($q, $dbh);
				$q = "DELETE FROM PackageSources WHERE PackageID = ".$pdata["ID"];
				db_query($q, $dbh);
393

jchu's avatar
jchu committed
394
395
				# update package data
				#
396
				$q = "UPDATE Packages SET ";
397
398
399
400
401
402
				# if the package was a dummy, undummy it and change submitter
				# also give it a maintainer so we dont go making an orphan
				if ($pdata['DummyPkg'] == 1) {
					$q.= "DummyPkg = 0, ";
					$q.= "SubmitterUID = ".uid_from_sid($_COOKIE["AURSID"]).", ";
					$q.= "MaintainerUID = ".uid_from_sid($_COOKIE["AURSID"]).", ";
simo's avatar
simo committed
403
404
405
					$q.= "SubmittedTS = UNIX_TIMESTAMP(), ";
				} else {
					$q.="ModifiedTS = UNIX_TIMESTAMP(), ";
406
				}
407
408
409
410
411
412
413
				$q.="Name='".mysql_real_escape_string($new_pkgbuild['pkgname'])."', ";
				$q.="Version='".mysql_real_escape_string($new_pkgbuild['pkgver'])."-".
				  mysql_real_escape_string($new_pkgbuild['pkgrel'])."',";
				$q.="CategoryID=".mysql_real_escape_string($_REQUEST['category']).", ";
                $q.="License='".mysql_real_escape_string($new_pkgbuild['license'])."', ";
                $q.="Description='".mysql_real_escape_string($new_pkgbuild['pkgdesc'])."', ";
				$q.="URL='".mysql_real_escape_string($new_pkgbuild['url'])."', ";
414
				$q.="LocationID=2, ";
415
				$fspath=INCOMING_DIR.$pkg_name."/".$_FILES["pfile"]["name"];
416
				$q.="FSPath='".mysql_real_escape_string($fspath)."', ";
417
				$urlpath=URL_DIR.$pkg_name."/".$_FILES["pfile"]["name"];
418
				$q.="URLPath='".mysql_real_escape_string($urlpath)."' ";
419
420
421
422
423
424
425
426
427
				$q.="WHERE ID = " . $pdata["ID"];
				$result = db_query($q, $dbh);

				# update package contents
				#
				while (list($k, $v) = each($pkg_contents)) {
					$q = "INSERT INTO PackageContents ";
					$q.= "(PackageID, FSPath, URLPath, FileSize) VALUES (";
					$q.= $pdata['ID'].", ";
428
429
					$q.= "'".INCOMING_DIR.$pkg_name."/".$pkg_name."/".$k."', ";
					$q.= "'".URL_DIR.$pkg_name."/".$pkg_name."/".$k."', ";
430
431
432
					$q.= $v.")";
					db_query($q);
				}
jchu's avatar
jchu committed
433
434
435

				# update package depends
				#
436
				$depends = explode(" ", $new_pkgbuild['depends']);
437
438
439
                
                while (list($k, $v) = each($depends)) {
					$q = "INSERT INTO PackageDepends (PackageID, DepPkgID, DepCondition) VALUES (";
440
					$deppkgname = preg_replace("/[<>]?=.*/", "", $v);
441
                    $depcondition = str_replace($deppkgname, "", $v);
pjmattal's avatar
pjmattal committed
442
443
444
445
446
447
                    
                    # Solve the problem with comments and deps
                    # added by: dsa <dsandrade@gmail.com>
                    if ($deppkgname == "#")
                        break;
                    
jchu's avatar
jchu committed
448
					$deppkgid = create_dummy($deppkgname, $_COOKIE['AURSID']);
449
450
451
452
453
454
					
                    if(!empty($depcondition))
                        $q .= $pdata["ID"].", ".$deppkgid.", '".$depcondition."')";
                    else
                        $q .= $pdata["ID"].", ".$deppkgid.", '')";
                        
jchu's avatar
jchu committed
455
					db_query($q, $dbh);
456
				}
jchu's avatar
jchu committed
457

458
459
460
				$sources = explode(" ", $new_pkgbuild['source']);
				while (list($k, $v) = each($sources)) {
					$q = "INSERT INTO PackageSources (PackageID, Source) VALUES (";
461
					$q .= $pdata["ID"].", '".mysql_real_escape_string($v)."')";
jchu's avatar
jchu committed
462
					db_query($q, $dbh);
463
				}
jchu's avatar
jchu committed
464
465
466

				# add upload history
				#
eric's avatar
eric committed
467
468
				$q = "INSERT INTO PackageComments ";
				$q.= "(PackageID, UsersID, Comments, CommentTS) VALUES (";
469
				$q.= $pdata["ID"] . ", " . uid_from_sid($_COOKIE['AURSID']);
470
				$q.= ", '" . mysql_real_escape_string($_REQUEST["comments"]);
471
472
473
474
475
476
477
				$q.= "', UNIX_TIMESTAMP())";
				db_query($q);

			} else {
				# this is a brand new package
				#
				$q = "INSERT INTO Packages ";
478
				$q.= " (Name, License, Version, CategoryID, Description, URL, LocationID, ";
479
480
				$q.= " SubmittedTS, SubmitterUID, MaintainerUID, FSPath, URLPath) ";
				$q.= "VALUES ('";
481
482
483
484
485
486
487
				$q.= mysql_real_escape_string($new_pkgbuild['pkgname'])."', '";
                $q.= mysql_real_escape_string($new_pkgbuild['license'])."', '";
				$q.= mysql_real_escape_string($new_pkgbuild['pkgver'])."-".
				  mysql_real_escape_string($new_pkgbuild['pkgrel'])."', ";
				$q.= mysql_real_escape_string($_REQUEST['category']).", '";
				$q.= mysql_real_escape_string($new_pkgbuild['pkgdesc'])."', '";
				$q.= mysql_real_escape_string($new_pkgbuild['url']);
488
489
				$q.= "', 2, ";
				$q.= "UNIX_TIMESTAMP(), ";
490
491
				$q.= uid_from_sid($_COOKIE["AURSID"]).", ";
				$q.= uid_from_sid($_COOKIE["AURSID"]).", '";
492
				$fspath=INCOMING_DIR.$pkg_name."/".$_FILES["pfile"]["name"];
493
				$q.= mysql_real_escape_string($fspath)."', '";
494
				$urlpath=URL_DIR.$pkg_name."/".$_FILES["pfile"]["name"];
495
				$q.= mysql_real_escape_string($urlpath)."')";
496
497
				$result = db_query($q, $dbh);
#				print $result . "<br>";
jchu's avatar
jchu committed
498

jchu's avatar
jchu committed
499
500
				$packageID = mysql_insert_id($dbh);

501
502
503
504
505
506
				# update package contents
				#
				while (list($k, $v) = each($pkg_contents)) {
					$q = "INSERT INTO PackageContents ";
					$q.= "(PackageID, FSPath, URLPath, FileSize) VALUES (";
					$q.= $packageID.", ";
507
508
					$q.= "'".INCOMING_DIR.$pkg_name."/".$pkg_name."/".$k."', ";
					$q.= "'".URL_DIR.$pkg_name."/".$pkg_name."/".$k."', ";
509
510
511
					$q.= $v.")";
					db_query($q);
				}
jchu's avatar
jchu committed
512
513
514

				# update package depends
				#
515
516
517
518
				$depends = explode(" ", $new_pkgbuild['depends']);
				while (list($k, $v) = each($depends)) {
					$q = "INSERT INTO PackageDepends (PackageID, DepPkgID) VALUES (";
					$deppkgname = preg_replace("/[<>]?=.*/", "", $v);
pjmattal's avatar
pjmattal committed
519
520
521
522
523
524
                    
                    # Solve the problem with comments and deps
                    # added by: dsa <dsandrade@gmail.com>
                    if ($deppkgname == "#")
                        break;
                    
jchu's avatar
jchu committed
525
					$deppkgid = create_dummy($deppkgname, $_COOKIE['AURSID']);
526
					$q .= $packageID.", ".$deppkgid.")";
jchu's avatar
jchu committed
527
					db_query($q, $dbh);
528
				}
jchu's avatar
jchu committed
529

530
531
532
				$sources = explode(" ", $new_pkgbuild['source']);
				while (list($k, $v) = each($sources)) {
					$q = "INSERT INTO PackageSources (PackageID, Source) VALUES (";
533
					$q .= $packageID.", '".mysql_real_escape_string($v)."')";
jchu's avatar
jchu committed
534
					db_query($q, $dbh);
535
				}
jchu's avatar
jchu committed
536
537
538

				# add upload history
				#
eric's avatar
eric committed
539
540
				$q = "INSERT INTO PackageComments ";
				$q.= "(PackageID, UsersID, Comments, CommentTS) VALUES (";
541
				$q.= $packageID . ", " . uid_from_sid($_COOKIE["AURSID"]) . ", '";
542
				$q.= mysql_real_escape_string($_REQUEST["comments"]);
543
544
545
546
				$q.= "', UNIX_TIMESTAMP())";
				db_query($q, $dbh);
			}
		}
eric's avatar
eric committed
547
548
549
	}


eric's avatar
eric committed
550
	if (!$_REQUEST["pkgsubmit"] || $error) {
551
		# User is not uploading, or there were errors uploading - then
eric's avatar
eric committed
552
553
554
		# give the visitor the default upload form
		#
		if (ini_get("file_uploads")) {
555
			if ($error) {
eric's avatar
eric committed
556
557
558
				print "<span class='error'>".$error."</span><br />\n";
				print "<br />&nbsp;<br />\n";
			}
dsa's avatar
dsa committed
559
560
561
562
563
564
            
            if ($warning) {
                print "<br><span class='error'>".$warning."</span><br />\n";
                print "<br />&nbsp;<br />\n";
            }
            
565
566
			$pkg_categories = pkgCategories();
			$pkg_locations = pkgLocations();
567

eric's avatar
eric committed
568
569
570
571
572
573
574
			print "<form action='/pkgsubmit.php' method='post'";
			print "	enctype='multipart/form-data'>\n";
			print "<input type='hidden' name='pkgsubmit' value='1' />\n";
			print "<input type='hidden' name='MAX_FILE_SIZE' value='";
			print initeger(ini_get("upload_max_filesize"))."' />\n";
			print "<table border='0' cellspacing='5'>\n";
			print "<tr>\n";
575
			print "	<td span='f4' align='right'>";
576
			print __("Package name").":</td>\n";
577
			print "	<td span='f4' align='left'>";
578
			print "<input type='text' name='pkgname' size='30' maxlength='32' />\n";
579
			print "	</td>\n";
580
581
			print "</tr>\n";
			print "<tr>\n";
582
583
584
585
			print "	<td span='f4' align='right'>";
			print __("Package Category").":</td>\n";
			print "	<td span='f4' align='left'>";
			print "<select name='category'>";
586
			print "<option value='1'> " . __("Select Category") . "</option>";
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
			while (list($k, $v) = each($pkg_categories)) {
				print "<option value='".$k."'> " . $v . "</option>";
			}
			print "</select></td>\n";
			print "</tr>\n";
#			print "<tr>\n";
#			print "	<td span='f4' align='right'>";
#			print __("Package Location").":</td>\n";
#			print "	<td span='f4' align='left'>";
#			print "<select name='location'>";
#			print "<option value='0'> " . __("Select Location") . "</option>";
#			while (list($k, $v) = each($pkg_locations)) {
#				print "<option value='".$k."'> " . $v . "</option>";
#			}
#			print "</select></td>\n";
#			print "</tr>\n";
			print "<tr>\n";
			print "	<td span='f4' align='right'>";
605
			print __("Upload package file").":</td>\n";
606
			print "	<td span='f4' align='left'>";
eric's avatar
eric committed
607
			print "<input type='file' name='pfile' size='30' />\n";
608
			print "	</td>\n";
eric's avatar
eric committed
609
610
			print "</tr>\n";
			print "<tr>\n";
611
			print "	<td span='f4' align='right'>";
eric's avatar
eric committed
612
			print __("Overwrite existing package?");
613
614
			print "	</td>\n";
			print "	<td span='f4' align='left'>";
615
			print "<input type='radio' name='overwrite' value='1'> ".__("Yes");
eric's avatar
eric committed
616
			print "&nbsp;&nbsp;&nbsp;";
617
			print "<input type='radio' name='overwrite' value='0' checked> ";
eric's avatar
eric committed
618
			print __("No");
619
			print "	</td>\n";
eric's avatar
eric committed
620
			print "</tr>\n";
621
			print "<tr>\n";
622
			print "	<td valign='top' span='f4' align='right'>";
623
			print __("Comment").":</td>\n";
624
625
626
			print "	<td span='f4' align='left'>";
			print "<textarea rows='10' cols='50' name='comments'></textarea>";
			print "	</td>\n";
627
			print "</tr>\n";
eric's avatar
eric committed
628
629

			print "<tr>\n";
630
631
			print "	<td>&nbsp;</td>\n";
			print "	<td align='left'>";
eric's avatar
eric committed
632
			print "<input class='button' type='submit' value='".__("Upload")."' />\n";
633
			print "&nbsp;&nbsp;&nbsp;";
634
			print "<input class='button' type='reset' value='".__("Reset")."' />\n";
eric's avatar
eric committed
635
636
637
638
639
640
641
642
643
			print "</td>\n";
			print "</tr>\n";
			print "</table>\n";

			print "</form>\n";
		} else {
			print __("Sorry, uploads are not permitted by this server.");
			print "<br />\n";
		}
644
	} else {
645
		print __("Package upload successful.");
dsa's avatar
dsa committed
646
647
648
649
650
        
        if ($warning) {
            print "<span class='warning'>".$warning."</span><br />\n";
            print "<br />&nbsp;<br />\n";
        }
651
	}
eric's avatar
eric committed
652

eric's avatar
eric committed
653
} else {
eric's avatar
eric committed
654
	# visitor is not logged in
eric's avatar
eric committed
655
	#
eric's avatar
eric committed
656
657
	print __("You must create an account before you can upload packages.");
	print "<br />\n";
eric's avatar
eric committed
658
}
eliott's avatar
eliott committed
659
660
echo "  </div>\n";
echo "</div>\n";
tardo's avatar
tardo committed
661
html_footer(AUR_VERSION);
662
# vim: ts=2 sw=2 noet ft=php
eric's avatar
eric committed
663
?>