head	1.2;
access;
symbols
	pkgsrc-2026Q3:1.2.0.12
	pkgsrc-2026Q3-base:1.2
	pkgsrc-2026Q2:1.2.0.10
	pkgsrc-2026Q2-base:1.2
	pkgsrc-2026Q1:1.2.0.8
	pkgsrc-2026Q1-base:1.2
	pkgsrc-2025Q4:1.2.0.6
	pkgsrc-2025Q4-base:1.2
	pkgsrc-2025Q3:1.2.0.4
	pkgsrc-2025Q3-base:1.2
	pkgsrc-2025Q2:1.2.0.2
	pkgsrc-2025Q2-base:1.2
	pkgsrc-2025Q1:1.1.0.2
	pkgsrc-2025Q1-base:1.1;
locks; strict;
comment	@# @;


1.2
date	2025.04.04.13.30.18;	author schmonz;	state Exp;
branches;
next	1.1;
commitid	ppZQ7L9QRh1hLJPF;

1.1
date	2025.01.10.21.29.37;	author schmonz;	state Exp;
branches;
next	;
commitid	KpdayT8VPfb77ZEF;


desc
@@


1.2
log
@lighttpd: update to 1.4.79, and take MAINTAINER. Changes:

* [autotools] spelling Couldn't => Could not
* [mod_openssl] revert SSL_CTX default cert assign
* [mod_openssl] spelling in comment
* [TLS] issue trace if unable to check/refresh cert
* [core] set server.max-fds = 4096 if not specified
* [core] clear Linux ambient capabilities, if any
* [core] rename remove_pid_file() -> server_pid_file_remove()
* [core] retry pidfile open on Linux
* [doc] systemd lighttpd.service hardening
* [doc] move TLS config to separate file tls.conf
* [doc] systemd lighttpd.service hardening addition
* [doc] systemd lighttpd*.socket activation examples
* [core] default listen() backlog to SOMAXCONN
@
text
@$NetBSD: patch-doc_config_lighttpd.annotated.conf,v 1.1 2025/01/10 21:29:37 schmonz Exp $

Follow hier(7).

--- doc/config/lighttpd.annotated.conf.orig	2025-01-10 04:12:08.000000000 +0000
+++ doc/config/lighttpd.annotated.conf
@@@@ -13,11 +13,11 @@@@
 ## if you add a variable here. Add the corresponding variable in the
 ## chroot example as well.
 ##
-var.log_root    = "/var/log/lighttpd"
+var.log_root    = "@@LIGHTTPD_LOGDIR@@"
 var.server_root = "/srv/www"
-var.state_dir   = "/run"
-var.home_dir    = "/var/lib/lighttpd"
-var.conf_dir    = "/etc/lighttpd"
+var.state_dir   = "@@LIGHTTPD_STATEDIR@@"
+var.home_dir    = "@@LIGHTTPD_HOMEDIR@@"
+var.conf_dir    = "@@PKG_SYSCONFDIR@@"
 
 ##
 ## run the server chrooted.
@@@@ -58,7 +58,7 @@@@ var.vhosts_dir  = server_root + "/vhosts
 ## used in:
 ## conf.d/deflate.conf
 ##
-var.cache_dir   = "/var/cache/lighttpd"
+var.cache_dir   = "@@LIGHTTPD_CACHEDIR@@"
 
 ##
 ## Base directory for sockets.
@@@@ -97,8 +97,8 @@@@ include conf_dir + "/modules.conf"
 ## Run as a different username/groupname.
 ## This requires root permissions during startup.
 ##
-server.username  = "lighttpd"
-server.groupname = "lighttpd"
+server.username  = "@@LIGHTTPD_USER@@"
+server.groupname = "@@LIGHTTPD_GROUP@@"
 
 ##
 ## Enable lighttpd to serve requests on sockets received from systemd
@@@@ -389,7 +389,7 @@@@ include conf_dir + "/conf.d/dirlisting.c
 ##
 ## defaults to /var/tmp as we assume it is a local harddisk
 ## default: "/var/tmp"
-#server.upload-dirs = ( "/var/tmp" )
+#server.upload-dirs = ( "@@VARBASE@@/tmp" )
 
 ##
 #######################################################################
@


1.1
log
@lighttpd: update to 1.4.77. Changes:

* [build] packdist.sh tweaks of convenience commands
* [build] remove ancient distribute.sh.in script
* [core] add .torrent to mimetype.assign builtin defaults
* Revert "[core] special value for Linux POLLRDHUP on SPARC" (fixes #3251)
* [core] special value for Linux POLLRDHUP on SPARC (fixes #3251)
* [mod_ssi] rename ssi_val_tobool to ssi_val_to_bool
* [multiple] rename config_plugin_value_tobool
* [core] fix graceful shutdown timeout handling
* [core] preprocessor option to force crypto lib
* [cmake] fix some typos in pcre2 detection
* [tests] disambiguate regex test value from string
* [tests] fix deflate tests w/ Fedora zlib-ng-compat
* [core] port for QNX7.1/8.0
* [doc] remove ancient doc/scripts/spawn-php.sh
* [mod_deflate] limit zstd max window size to 8 MB
* [mod_accesslog] ignore format specifier w/o label
* [autotools] add pkgconf test for libdbi
* [mod_webdav] use SQLITE_PREPARE_PERSISTENT
* [mod_webdav] call sqlite3_initialize() at init
* [mod_webdav] disable double-quoted string literal
* [core] clarify error msg for plugin ver mismatch
* [mod_dirlisting] Add dark mode support
* [autotools] Prefer libpcre.pc to pcre-config
* [core] server.ip-transparent option on listen sock
* [core] reject HTTP/1.x request-line URI trail sp
* [core] remove http_request_parse_proto_loose()
* [core] strictly require CRLF on chunked header
* [core] strictly require CRLF on all chunked header
* [multiple] quiet coverity false positives
* [core] http_request_check_uri_strict optimization
* [h2] fix spurious connection resets with zero log_monotonic_secs
* [mod_dirlisting] fix ?json output; emit JSON list (fixes #3256)
* [mod_dirlisting] minor optimization for ?json
* [mod_auth] fix Digest nonce validation w/ nonce_secret
* [core] omit pcre2 JIT error trace if JIT not avail
* [doc] rename sample config lighttpd.annotated.conf
* [doc] simplify doc/config/lighttpd.conf entry
* [doc] use shorter https://wiki.lighttpd.net/ url
* [meson] use pkg-config to find mbedtls 3.6
* [meson] update FORCE_* vars to select crypto lib
* [core] remove long-unused #ifdef USE_ALARM
* [core] avoid pedantic compiler warning (fixes #3262)
* [mod_auth] HTTP Digest and HTTP/2 extended CONNECT
* [mod_dirlisting] sort by exact value of size (fixes #3264)
* [mod_dirlisting] sort mtime using data-value (#3264)
* [core] remove mimetype.assign from tests/lighttpd.conf
* [doc] update create-mime.conf.pl compression types
* [doc] update doc/config/conf.d/mime.conf
* [core] remove cast from ioctl() RNDGETENTCNT
* [core] update ls-hpack
* [core] light_isprint(), light_iscntrl()
* [core] perf: tighter loops for str encode,escape
* [mod_wstunnel] Sec-WebSocket-Protocol: binary
* [core] light_iscntrl_or_utf8_invalid_byte()
* [core] option: allow unescaped UTF-8 in errorlog (fixes #3268)
* [systemd] test config in ExecReload before signal
* [core] config parsing: detect invalid keys
* [TLS] allow list of Groups/Curves
* [mbedtls] reset crt_profile when reconfigured
* [mod_mbedtls] guard mbedtls use of RSA_PSK
* [mod_nss] add ssl.openssl.ssl-conf-cmd Ciphersuite
* [mod_wolfssl] typo
* [mod_nss] ver check for experimental groups/curves
* [mod_wolfssl] missing return
* [tests] do not test for exact compress zlib size
* [tests] consolidate test value comparison logic
* [multiple] avoid sending body to GW_AUTHORIZER (fixes #3272)
* [mod_magnet] use local sys-dirent.h (portability)
* [mod_magnet] add code header to mod_magnet.c
* [TLS] skip SSL_CTX init if not in SOCKET condition
* [mod_openssl] ssl.ech-opts, load ECH keys
* [mod_openssl] ssl.non-ech-host opt to require ECH
* [mod_openssl] free mem from SSL_ech_get1_status()
* [mod_openssl] ECH: use new OSSL_ECHSTORE APIs
* [mod_openssl] ECH: refresh 4 year old patches
* [mod_openssl] ECH: kludge compat w/ OpenSSL ECH API
* [mod_openssl] omit OSSL_ECH_FOR_RETRY for ECH-only
* [mod_openssl] ECH: OSSL_ECH_FOR_RETRY for cur key
* [mod_openssl] ECH: boringssl support
* [TLS] modify TLS defaults to MinProtocol TLSv1.3
* [TLS] use TLSv1.3 groups X25519:P-256:P-384:X448
* [mod_openssl] skip *.ech files beginning with '.'
* [mod_openssl] ECH: rename directives to ECH terms
* [core] server.error-handler-404 handles only 404
* [mod_magnet] quiet coverity false positive
* [mod_openssl] ECH: use same (debug) CGI var names
* [mod_openssl] ECH: reload keys only if modified
* [mod_openssl] ECH: remove kludge compat w/ OpenSSL ECH API
* [core] reset cond cache item URL if pathinfo
* [mod_openssl] use BUF_PTR_LEN when buffer not NULL
* [mod_openssl] ECH: code comments for ECH-only host
* [core] import xxHash v0.8.3
* [autoconf] update ax_prog_cc_for_build.m4
@
text
@d1 1
a1 1
$NetBSD$
d3 1
a3 1
Sane defaults.
@

