diff options
context:
space:
mode:
-rw-r--r--cgitrc.5.txt11
-rw-r--r--custom/cgitrc4
2 files changed, 13 insertions, 2 deletions
diff --git a/cgitrc.5.txt b/cgitrc.5.txt
index c795425..ac33d6d 100644
--- a/cgitrc.5.txt
+++ b/cgitrc.5.txt
@@ -73,7 +73,8 @@ cache-repo-ttl::
cache-root::
Path used to store the cgit cache entries. Default value:
- "/var/cache/cgit". See also: "MACRO EXPANSION".
+ "/var/cache/cgit". See also: "MACRO EXPANSION" and the note on
+ ownership under "CACHE".
cache-root-ttl::
Number which specifies the time-to-live, in minutes, for the cached
@@ -840,6 +841,14 @@ will be cached indefinitely, even if the underlying git repository changes.
Conversely, when a ttl value is zero, the cache is disabled for that
particular page type, and the page type is never cached.
+The cache directory holds one file per slot plus transient lock files, all
+created by cgit itself. Create the directory ahead of time, owned by the
+account the web server runs cgit as, with mode 0700. cgit creates its files
+by name without guarding against links planted beside them, so a directory
+other accounts can write to would let those accounts redirect the writes.
+A directory other accounts can read exposes every cached page along with
+the URLs visitors asked for.
+
SIGNATURES
----------
diff --git a/custom/cgitrc b/custom/cgitrc
index 4b0b4ac..c284aca 100644
--- a/custom/cgitrc
+++ b/custom/cgitrc
@@ -27,7 +27,9 @@
cache-size=0
# Directory used to store cgit cache entries. Value is a filesystem path that
-# may use macros. Default is /var/cache/cgit.
+# may use macros. Default is /var/cache/cgit. The directory must be owned by
+# the account the web server runs cgit as, with mode 0700, since the cache
+# holds every rendered page and the URLs visitors asked for.
#cache-root=/var/cache/cgit
# Minutes to cache the repository index page. Value is an integer number of