/* Licensed to the Apache Software Foundation (ASF) under one or more *contributorlicenseagreements.SeetheNOTICEfiledistributedwith *thisworkforadditionalinformationregardingcopyrightownership. *TheASFlicensesthisfiletoYouundertheApacheLicense,Version2.0 *(the"License");youmaynotusethisfileexceptincompliancewith *theLicense.YoumayobtainacopyoftheLicenseat * *http://www.apache.org/licenses/LICENSE-2.0 * *Unlessrequiredbyapplicablelaworagreedtoinwriting,software *distributedundertheLicenseisdistributedonan"ASIS"BASIS, *WITHOUTWARRANTIESORCONDITIONSOFANYKIND,eitherexpressorimplied. *SeetheLicenseforthespecificlanguagegoverningpermissionsand *limitationsundertheLicense.
*/
/* Set group privileges. * *Notethatweusetheusernameassetintheconfigfiles,ratherthan *thelookupoftouid---thesameuidmayhavemultiplepasswdentries, *withdifferentsetsofgroupsforeach.
*/
staticint set_group_privs(void)
{ if (!geteuid()) { constchar *name;
if ((ent = getpwuid(uid)) == NULL) {
ap_log_error(APLOG_MARK, APLOG_ALERT, errno, NULL, APLOGNO(02155) "getpwuid: couldn't determine user name from uid %ld, " "you probably need to modify the User directive",
(long)uid); return -1;
}
name = ent->pw_name;
} else
name = ap_unixd_config.user_name;
#if !defined(OS2) /* OS/2 doesn't support groups. */ /* *SettheGIDbeforeinitgroups(),sinceonsomeplatforms *setgid()isknowntozapthegrouplist.
*/ if (setgid(ap_unixd_config.group_id) == -1) {
ap_log_error(APLOG_MARK, APLOG_ALERT, errno, NULL, APLOGNO(02156) "setgid: unable to set group id to Group %ld",
(long)ap_unixd_config.group_id); return -1;
}
/* Reset `groups' attributes. */
if (initgroups(name, ap_unixd_config.group_id) == -1) {
ap_log_error(APLOG_MARK, APLOG_ALERT, errno, NULL, APLOGNO(02157) "initgroups: unable to set groups for User %s " "and Group %ld", name, (long)ap_unixd_config.group_id); return -1;
} #endif/* !defined(OS2) */
} return0;
}
staticint
unixd_drop_privileges(apr_pool_t *pool, server_rec *s)
{ int rv = set_group_privs();
if (rv) { return rv;
}
if (NULL != ap_unixd_config.chroot_dir) { if (geteuid()) {
rv = errno;
ap_log_error(APLOG_MARK, APLOG_ALERT, errno, NULL, APLOGNO(02158) "Cannot chroot when not started as root"); return rv;
}
ap_unixd_config.user_name = arg;
ap_unixd_config.user_id = ap_uname2id(arg); #if !defined (BIG_SECURITY_HOLE) && !defined (OS2) if (ap_unixd_config.user_id == 0) { return"Error:\tApache has not been designed to serve pages while\n" "\trunning as root. There are known race conditions that\n" "\twill allow any local user to read any file on the system.\n" "\tIf you still desire to serve pages as root then\n" "\tadd -DBIG_SECURITY_HOLE to the CFLAGS env variable\n" "\tand then rebuild the server.\n" "\tIt is strongly suggested that you instead modify the User\n" "\tdirective in your httpd.conf file to list a non-root\n" "\tuser.\n";
} #endif
#ifdef AP_SUEXEC_CAPABILITIES /* If suexec is using capabilities, don't test for the setuid bit. */ #define SETUID_TEST(finfo) (1) #else #define SETUID_TEST(finfo) (finfo.protection & APR_USETID) #endif
staticconst command_rec unixd_cmds[] = {
AP_INIT_TAKE1("User", unixd_set_user, NULL, RSRC_CONF, "Effective user id for this server"),
AP_INIT_TAKE1("Group", unixd_set_group, NULL, RSRC_CONF, "Effective group id for this server"),
AP_INIT_TAKE1("ChrootDir", unixd_set_chroot_dir, NULL, RSRC_CONF, "The directory to chroot(2) into"),
AP_INIT_FLAG("Suexec", unixd_set_suexec, NULL, RSRC_CONF, "Enable or disable suEXEC support"),
{NULL}
};
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.