/* Licensed to the Apache Software Foundation (ASF) under one or more *contributorlicenseagreements.SeetheNOTICEfiledistributedwith *thisworkforadditionalinformationregardingcopyrightownership. *TheASFlicensesthisfiletoYouundertheApacheLicense,Version2.0 *(the"License");youmaynotusethisfileexceptincompliancewith *theLicense.YoumayobtainacopyoftheLicenseat * *http://www.apache.org/licenses/LICENSE-2.0 * *Unlessrequiredbyapplicablelaworagreedtoinwriting,software *distributedundertheLicenseisdistributedonan"ASIS"BASIS, *WITHOUTWARRANTIESORCONDITIONSOFANYKIND,eitherexpressorimplied. *SeetheLicenseforthespecificlanguagegoverningpermissionsand *limitationsundertheLicense.
*/
typedefenum
{
bs2_unknown, /* not initialized yet. */
bs2_noFORK, /* no fork() because -X flag was specified */
bs2_FORK, /* only fork() because uid != 0 */
bs2_UFORK /* Normally, ufork() is used to switch identities. */
} bs2_ForkType;
static bs2_ForkType forktype = bs2_unknown;
/* Determine the method for forking off a child in such a way as to *setboththePOSIXandBS2000userid'stotheunprivilegeduser.
*/ static bs2_ForkType os_forktype(int one_process)
{ /* have we checked the OS version before? If yes return the previous *result-theOSreleaseisn'tgoingtochangesuddenly!
*/ if (forktype == bs2_unknown) { /* not initialized yet */
/* No fork if the one_process option was set */ if (one_process) {
forktype = bs2_noFORK;
} /* If the user is unprivileged, use the normal fork() only. */ elseif (getuid() != 0) {
forktype = bs2_FORK;
} else
forktype = bs2_UFORK;
} return forktype;
}
/* This routine complements the setuid() call: it causes the BS2000 job *environmenttobeswitchedtothetargetuser'suserid. *ThatisimportantifCGIscriptstrytoexecutenativeBS2000commands.
*/ int os_init_job_environment(server_rec *server, constchar *user_name, int one_process)
{
bs2_ForkType type = os_forktype(one_process);
/* We can be sure that no change to uid==0 is possible because of *thechecksinhttp_core.c:set_user()
*/
if (one_process) {
type = forktype = bs2_noFORK;
ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, APLOGNO(02170) "The debug mode of Apache should only " "be started by an unprivileged user!"); return0;
}
return0;
}
/* BS2000 requires a "special" version of fork() before a setuid() call */
pid_t os_fork(constchar *user)
{
pid_t pid; char username[USER_LEN+1];
switch (os_forktype(0)) {
case bs2_FORK:
pid = fork(); break;
case bs2_UFORK:
apr_cpystrn(username, user, sizeof username);
/* Make user name all upper case - for some versions of ufork() */
ap_str_toupper(username);
pid = ufork(username); if (pid == -1 && errno == EPERM) {
ap_log_error(APLOG_MARK, APLOG_EMERG, errno, ap_server_conf,
APLOGNO(02171) "ufork: Possible mis-configuration " "for user %s - Aborting.", user); exit(1);
} break;
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.