git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC/PATCH 2/3] gitweb: Support caching projects list

From
Frank Lichtenheld <frank@lichtenheld.de>
Date
Mar 17, 2008, 16:54 UTC
Message-ID
<20080317165405.GD18624@mail-vs.djpig.de>
In-Reply-To
<1205766570-13550-3-git-send-email-jnareb@gmail.com>
On Mon, Mar 17, 2008 at 04:09:29PM +0100, Jakub Narebski wrote:
Show 7 quoted lines
> From: Petr Baudis <pasky@suse.cz>
> $projlist_cache_lifetime gitweb configuration variable is introduced,
> by default set to zero. If set to non-zero, it describes the number of
> minutes for which the cache remains valid. Only single project root
> per system can use the cache. Any script running with the same uid as
> gitweb can change the cache trivially - this is for secure
> installations only.

The more subtle threat is the fact that anyone with writing rights to /tmp can give gitweb any data he wants if the file doesn't exist yet.

At the very least you should:
 - Allow to override /tmp (via ENV{TMPDIR} or via a configuration
   variable)
 - Advise people to change that to something that is not world-writable
 - Check if the file is owned by the uid gitweb is running under and
   not word-writable.
[...]
Show 7 quoted lines
> +	my @projects;
> +	my $stale = 0;
> +	my $now = time();
> +	if ($cache_lifetime && -f $cache_file &&
> +	    stat($cache_file)->mtime + $cache_lifetime * 60 > $now &&
> +	    open(my $fd, '<', $cache_file)) {
> +		$stale = $now - stat($cache_file)->mtime;
One stat() call instead of three would be better for performance.
Gruesse,
-- 
Frank Lichtenheld <frank@lichtenheld.de>
www: http://www.djpig.de/
Previous: Jakub NarebskiNext: Jakub Narebski
Message 4 of 12 in “gitweb: Support caching projects list”
  1. 0/3 gitweb: Support caching projects listJakub Narebski, Mar 17, 2008
  2. 1/3 gitweb: Separate @projects population into git_get_projects_details()Jakub Narebski, Mar 17, 2008
  3. 2/3 gitweb: Support caching projects listJakub Narebski, Mar 17, 2008
  4. Frank LichtenheldMar 17, 2008
  5. Jakub NarebskiMar 17, 2008
  6. Frank LichtenheldMar 17, 2008
  7. Jakub NarebskiMar 17, 2008
  8. 2/3 gitweb: Support caching projects listJakub Narebski, Mar 17, 2008
  9. 3/3 gitweb: Fill project details lazily when cachingJakub Narebski, Mar 17, 2008
  10. Petr BaudisMar 18, 2008
  11. Jakub NarebskiMar 18, 2008
  12. Frank LichtenheldMar 18, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.