From 0c36d1a7ee50ac5adfc3b5dcf2614ef04822b02e Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Sun, 23 Aug 2026 17:09:05 -1000 Subject: Document cache directory ownership --- cgitrc.5.txt | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) (limited to 'cgitrc.5.txt') diff --git a/cgitrc.5.txt b/cgitrc.5.txt index c795425..ac33d6d 100644 --- a/cgitrc.5.txt +++ b/cgitrc.5.txt @@ -73,7 +73,8 @@ cache-repo-ttl:: cache-root:: Path used to store the cgit cache entries. Default value: - "/var/cache/cgit". See also: "MACRO EXPANSION". + "/var/cache/cgit". See also: "MACRO EXPANSION" and the note on + ownership under "CACHE". cache-root-ttl:: Number which specifies the time-to-live, in minutes, for the cached @@ -840,6 +841,14 @@ will be cached indefinitely, even if the underlying git repository changes. Conversely, when a ttl value is zero, the cache is disabled for that particular page type, and the page type is never cached. +The cache directory holds one file per slot plus transient lock files, all +created by cgit itself. Create the directory ahead of time, owned by the +account the web server runs cgit as, with mode 0700. cgit creates its files +by name without guarding against links planted beside them, so a directory +other accounts can write to would let those accounts redirect the writes. +A directory other accounts can read exposes every cached page along with +the URLs visitors asked for. + SIGNATURES ---------- -- cgit v2.8.0