mod_cgid.c revision 64f9a806e490593c6c4f44ab70b46f3d229e5879
91a031725396faebf51ea7b5475532453b8d6df3Lennart Poettering/* ====================================================================
91a031725396faebf51ea7b5475532453b8d6df3Lennart Poettering * The Apache Software License, Version 1.1
91a031725396faebf51ea7b5475532453b8d6df3Lennart Poettering * Copyright (c) 2000-2002 The Apache Software Foundation. All rights
91a031725396faebf51ea7b5475532453b8d6df3Lennart Poettering * Redistribution and use in source and binary forms, with or without
91a031725396faebf51ea7b5475532453b8d6df3Lennart Poettering * modification, are permitted provided that the following conditions
91a031725396faebf51ea7b5475532453b8d6df3Lennart Poettering * 1. Redistributions of source code must retain the above copyright
91a031725396faebf51ea7b5475532453b8d6df3Lennart Poettering * notice, this list of conditions and the following disclaimer.
91a031725396faebf51ea7b5475532453b8d6df3Lennart Poettering * 2. Redistributions in binary form must reproduce the above copyright
91a031725396faebf51ea7b5475532453b8d6df3Lennart Poettering * notice, this list of conditions and the following disclaimer in
91a031725396faebf51ea7b5475532453b8d6df3Lennart Poettering * the documentation and/or other materials provided with the
91a031725396faebf51ea7b5475532453b8d6df3Lennart Poettering * distribution.
91a031725396faebf51ea7b5475532453b8d6df3Lennart Poettering * 3. The end-user documentation included with the redistribution,
91a031725396faebf51ea7b5475532453b8d6df3Lennart Poettering * if any, must include the following acknowledgment:
91a031725396faebf51ea7b5475532453b8d6df3Lennart Poettering * "This product includes software developed by the
91a031725396faebf51ea7b5475532453b8d6df3Lennart Poettering * Apache Software Foundation (http://www.apache.org/)."
91a031725396faebf51ea7b5475532453b8d6df3Lennart Poettering * Alternately, this acknowledgment may appear in the software itself,
91a031725396faebf51ea7b5475532453b8d6df3Lennart Poettering * if and wherever such third-party acknowledgments normally appear.
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * 4. The names "Apache" and "Apache Software Foundation" must
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * not be used to endorse or promote products derived from this
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * software without prior written permission. For written
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * permission, please contact apache@apache.org.
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * 5. Products derived from this software may not be called "Apache",
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * nor may "Apache" appear in their name, without prior written
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * permission of the Apache Software Foundation.
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESSED OR IMPLIED
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * DISCLAIMED. IN NO EVENT SHALL THE APACHE SOFTWARE FOUNDATION OR
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * ====================================================================
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * This software consists of voluntary contributions made by many
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * individuals on behalf of the Apache Software Foundation. For more
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * information on the Apache Software Foundation, please see
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * Portions of this software are based upon public domain software
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * originally written at the National Center for Supercomputing Applications,
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * University of Illinois, Urbana-Champaign.
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * http_script: keeps all script-related ramblings together.
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * Compliant to cgi/1.1 spec
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * Adapted by rst from original NCSA code by Rob McCool
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * Apache adds some new env vars; REDIRECT_URL and REDIRECT_QUERY_STRING for
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * custom error responses, and DOCUMENT_ROOT because we found it useful.
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * It also adds SERVER_ADMIN - useful for scripts to know who to mail when
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek#include "../filters/mod_include.h"
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek/* ### should be tossed in favor of APR */
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek#include <sys/un.h> /* for sockaddr_un */
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmekmodule AP_MODULE_DECLARE_DATA cgid_module;
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmekstatic int cgid_init(apr_pool_t *p, apr_pool_t *plog, apr_pool_t *ptemp, server_rec *main_server);
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmekstatic int handle_exec(include_ctx_t *ctx, apr_bucket_brigade **bb, request_rec *r,
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek ap_filter_t *f, apr_bucket *head_ptr, apr_bucket **inserted_head);
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmekstatic APR_OPTIONAL_FN_TYPE(ap_register_include_handler) *cgid_pfn_reg_with_ssi;
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmekstatic APR_OPTIONAL_FN_TYPE(ap_ssi_get_tag_and_value) *cgid_pfn_gtv;
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmekstatic APR_OPTIONAL_FN_TYPE(ap_ssi_parse_string) *cgid_pfn_ps;
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmekstatic int daemon_should_exit = 0;
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek/* Read and discard the data in the brigade produced by a CGI script */
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmekstatic void discard_script_output(apr_bucket_brigade *bb);
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek/* KLUDGE --- for back-combatibility, we don't have to check Execcgid
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * in ScriptAliased directories, which means we need to know if this
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * request came through ScriptAlias or not... so the Alias module
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * leaves a note for us.
39c155ea0d8b24895017fd5cf48508924ce2016dLennart Poetteringstatic int is_scriptaliased(request_rec *r)
39c155ea0d8b24895017fd5cf48508924ce2016dLennart Poettering const char *t = apr_table_get(r->notes, "alias-forced-type");
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek return t && (!strcasecmp(t, "cgi-script"));
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek/* Configuration stuff */
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek#define DEFAULT_LOGBYTES 10385760
39c155ea0d8b24895017fd5cf48508924ce2016dLennart Poettering#define DEFAULT_SOCKET DEFAULT_REL_RUNTIMEDIR "/cgisock"
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek/* DEFAULT_CGID_LISTENBACKLOG controls the max depth on the unix socket's
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * pending connection queue. If a bunch of cgi requests arrive at about
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * the same time, connections from httpd threads/processes will back up
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * in the queue while the cgid process slowly forks off a child to process
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * each connection on the unix socket. If the queue is too short, the
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * httpd process will get ECONNREFUSED when trying to connect.
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek#ifndef DEFAULT_CGID_LISTENBACKLOG
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek#define DEFAULT_CGID_LISTENBACKLOG 100
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek/* DEFAULT_CONNECT_ATTEMPTS controls how many times we'll try to connect
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * to the cgi daemon from the thread/process handling the cgi request.
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * Generally we want to retry when we get ECONNREFUSED since it is
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * probably because the listen queue is full. We need to try harder so
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * the client doesn't see it as a 503 error.
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * Set this to 0 to continually retry until the connect works or Apache
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek#define DEFAULT_CONNECT_ATTEMPTS 15
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek/* If a request includes query info in the URL (stuff after "?"), and
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * the query info does not contain "=" (indicative of a FORM submission),
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * then this routine is called to create the argument list to be passed
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * to the CGI script. When suexec is enabled, the suexec path, user, and
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * group are the first three arguments to be passed; if not, all three
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * must be NULL. The query info is split into separate arguments, where
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * "+" is the separator between keyword arguments.
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmekstatic char **create_argv(apr_pool_t *p, char *path, char *user, char *group,
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek /* count the number of keywords */
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek for (x = 0, numwords = 1; args[x]; x++) {
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek if (numwords > APACHE_ARG_MAX - 5) {
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek numwords = APACHE_ARG_MAX - 5; /* Truncate args to prevent overrun */
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek av = (char **) apr_pcalloc(p, (numwords + 5) * sizeof(char *));
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek av[idx++] = apr_pstrdup(p, av0);
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek for (x = 1; x <= numwords; x++) {
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek w = ap_getword_nulls(p, &args, '+');
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek av[idx++] = ap_escape_shell_cmd(p, w);
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmekstatic void cgid_maint(int reason, void *data, apr_wait_t status)
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek /* don't do anything; server is stopping or restarting */
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek apr_proc_other_child_unregister(data);
85210bffd8363e491b4c31f2d09404f9869ad0c7Lennart Poettering /* it would be better to restart just the cgid child
85210bffd8363e491b4c31f2d09404f9869ad0c7Lennart Poettering * process but for now we'll gracefully restart the entire
85210bffd8363e491b4c31f2d09404f9869ad0c7Lennart Poettering * server by sending AP_SIG_GRACEFUL to ourself, the httpd
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * parent process
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek kill(getpid(), AP_SIG_GRACEFUL);
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek /* we get here when pcgi is cleaned up; pcgi gets cleaned
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek * up when pconf gets cleaned up
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek kill(*sd, SIGHUP); /* send signal to daemon telling it to die */
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmekstatic int get_req(int fd, request_rec *r, char **argv0, char ***env, int *req_type)
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek module *suexec_mod = ap_find_linked_module("mod_suexec.c");
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek r->server = apr_pcalloc(r->pool, sizeof(server_rec));
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek rc = read(fd, req_type, sizeof(int));
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek if (rc != sizeof(int)) {
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek if (rc != sizeof(int)) {
85210bffd8363e491b4c31f2d09404f9869ad0c7Lennart Poettering if (rc != sizeof(int)) {
85210bffd8363e491b4c31f2d09404f9869ad0c7Lennart Poettering data = apr_pcalloc(r->pool, len + 1); /* get a cleared byte for final '\0' */
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek r->filename = ap_getword(r->pool, (const char **)&data, '\n');
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek *argv0 = ap_getword(r->pool, (const char **)&data, '\n');
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek r->uri = ap_getword(r->pool, (const char **)&data, '\n');
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek environ = apr_pcalloc(r->pool, (j + 2) *sizeof(char *));
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek for (i = 0; i < j; i++) {
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek environ[i] = ap_getword(r->pool, (const char **)&data, '\n');
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek r->args = ap_getword(r->pool, (const char **)&data, '\n');
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek if (rc != sizeof(int)) {
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek /* add 1, so that if i == 0, we still malloc something. */
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek dconf = (void **) apr_pcalloc(r->pool, sizeof(void *) * (total_modules + DYNAMIC_MODULE_LIMIT));
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek temp_core = (core_dir_config *)apr_palloc(r->pool, sizeof(core_module));
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek suexec_config_t *suexec_cfg = apr_pcalloc(r->pool, sizeof(*suexec_cfg));
798d3a524ea57aaf40cb53858aaa45ec702f012dZbigniew Jędrzejewski-Szmek if (rc != sizeof(int)) {
91a031725396faebf51ea7b5475532453b8d6df3Lennart Poettering rc = read(fd, suexec_cfg, sizeof(*suexec_cfg));
#ifdef RLIMIT_CPU
#ifdef RLIMIT_NPROC
char *data;
NULL);
for (i =0; env[i]; i++) {
for (i = 0; env[i]; i++) {
if (suexec_mod) {
#ifdef RLIMIT_CPU
len = 0;
len = 0;
#ifdef RLIMIT_NPROC
len = 0;
len = 0;
&cgid_module);
return errno;
if (rc < 0) {
return errno;
return errno;
if (!geteuid()) {
return errno;
while (!daemon_should_exit) {
char *argv0;
char **env;
const char * const *argv;
request_rec *r;
if (sd2 < 0) {
if (rc) {
(const char * const *)env,
void *data;
int first_time = 0;
module **m;
if (!data) {
if (!first_time) {
total_modules = 0;
return DECLINED;
else if (daemon_pid == 0) {
return OK;
cgid_server_conf *c =
&cgid_module);
return NULL;
&cgid_module);
return NULL;
&cgid_module);
return NULL;
&cgid_module);
return NULL;
{NULL}
return ret;
apr_file_close(f);
return ret;
apr_bucket *e;
const char *buf;
int first;
if (script_err) {
return ret;
&& *dbuf) {
if (APR_BUCKET_IS_EOS(e)) {
if (first) {
first = 0;
if (script_err) {
if (script_err) {
apr_file_close(f);
return ret;
int sd;
int connect_tries;
connect_tries = 0;
return OK;
apr_bucket *e;
const char *buf;
if (APR_BUCKET_IS_EOS(e)) {
apr_bucket *b;
int is_included;
int sd;
char **env;
return DECLINED;
return DECLINED;
argv0++;
argv0++;
ap_add_cgi_vars(r);
return retval;
argv0++;
seen_eos = 0;
dbpos = 0;
return rv;
const char *data;
if (child_stopped_reading) {
int cursize;
while (!seen_eos);
if (!nph) {
const char *location;
int ret;
return OK;
return HTTP_MOVED_TEMPORARILY;
if (nph) {
int rr_status;
c->bucket_alloc);
c->bucket_alloc);
c->bucket_alloc);
c->bucket_alloc);
c->bucket_alloc);
if (r->args) {
char **env;
const char *location;
int sd;
int retval;
apr_bucket *b;
&cgid_module);
return retval;
return rc;
return retval;
return OK;
return HTTP_MOVED_TEMPORARILY;
if (!r->header_only) {
return retval;