unixd.c revision ee88f2698bfe1fcc8c0aa1e023cc5e2cb20971ab
/* Licensed to the Apache Software Foundation (ASF) under one or more
* contributor license agreements. See the NOTICE file distributed with
* this work for additional information regarding copyright ownership.
* The ASF licenses this file to You under the Apache License, Version 2.0
* (the "License"); you may not use this file except in compliance with
* the License. You may obtain a copy of the License at
*
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
#include "ap_config.h"
#include "httpd.h"
#include "http_config.h"
#include "http_main.h"
#include "http_log.h"
#include "unixd.h"
#include "mpm_common.h"
#include "os.h"
#include "ap_mpm.h"
#include "apr_thread_proc.h"
#include "apr_strings.h"
#include "apr_portable.h"
#ifdef HAVE_PWD_H
#include <pwd.h>
#endif
#ifdef HAVE_SYS_RESOURCE_H
#include <sys/resource.h>
#endif
/* XXX */
#ifdef HAVE_UNISTD_H
#include <unistd.h>
#endif
#ifdef HAVE_GRP_H
#include <grp.h>
#endif
#ifdef HAVE_STRINGS_H
#include <strings.h>
#endif
#ifdef HAVE_SYS_SEM_H
#endif
#ifdef HAVE_SYS_PRCTL_H
#endif
const char *arg,
{
#if (defined(RLIMIT_CPU) || defined(RLIMIT_DATA) || defined(RLIMIT_VMEM) || defined(RLIMIT_NPROC) || defined(RLIMIT_AS)) && APR_HAVE_STRUCT_RLIMIT && APR_HAVE_GETRLIMIT
char *str;
/* If your platform doesn't define rlim_t then typedef it in ap_config.h */
return;
}
}
else {
}
}
else {
return;
}
}
/* if we aren't running as root, cannot increase max */
if (geteuid()) {
}
else if (max) {
}
}
else {
if (cur) {
}
if (max) {
}
}
#else
#endif
}
)
(const request_rec *r), (r), NULL)
const char * const *args,
const char * const *env,
apr_pool_t *p)
{
int i = 0;
const char **newargs;
char *newprogname;
const char *argv0;
if (!ap_unixd_config.suexec_enabled) {
}
/* Allow suexec's "/" check to succeed */
argv0++;
}
else {
}
}
else {
}
return APR_ENOMEM;
}
i = 0;
if (args) {
while (args[i]) {
i++;
}
}
/* allocate space for 4 new args, the input args, and a null terminator */
newargs[0] = SUEXEC_BIN;
/*
** using a shell to execute suexec makes no sense thus
** we force everything to be APR_PROGRAM, and never
** APR_SHELLCMD
*/
return APR_EGENERAL;
}
i = 1;
do {
} while (args[i++]);
}
const request_rec *r,
const char * const *args,
const char * const *env,
{
}
}
/* XXX move to APR and externalize (but implement differently :) ) */
{
return APR_LOCK_SYSVSEM;
}
return APR_LOCK_FLOCK;
}
return APR_LOCK_DEFAULT;
}
{
if (!geteuid()) {
switch(mech) {
case APR_LOCK_SYSVSEM:
{
#if !APR_HAVE_UNION_SEMUN
union semun {
long val;
unsigned short *array;
};
#endif
return errno;
}
}
break;
#endif
case APR_LOCK_FLOCK:
{
if (lockfile) {
-1 /* no gid change */) < 0) {
return errno;
}
}
}
break;
#endif
default:
/* do nothing */
break;
}
}
return APR_SUCCESS;
}
{
#else /* APR_PROC_MUTEX_IS_GLOBAL */
/* In this case, apr_proc_mutex_t and apr_global_mutex_t are the same. */
return ap_unixd_set_proc_mutex_perms(gmutex);
#endif /* APR_PROC_MUTEX_IS_GLOBAL */
}
{
#ifdef _OSD_POSIX
int sockdes;
#endif
if (status == APR_SUCCESS) {
#ifdef _OSD_POSIX
if (sockdes >= FD_SETSIZE) {
"new file descriptor %d is too large; you probably need "
"to rebuild Apache with a larger FD_SETSIZE "
"(currently %d)",
return APR_EINTR;
}
#endif
return APR_SUCCESS;
}
if (APR_STATUS_IS_EINTR(status)) {
return status;
}
/* Our old behaviour here was to continue after accept()
* errors. But this leads us into lots of troubles
* because most of the errors are quite fatal. For
* example, EMFILE can be caused by slow descriptor
* leaks (say in a 3rd party module, or libc). It's
* foolish for us to continue after an EMFILE. We also
* seem to tickle kernel bugs on some platforms which
* lead to never-ending loops here. So it seems best
* to just exit in most cases.
*/
switch (status) {
/* On HPUX 11.x, the 'ENOBUFS, No buffer space available'
* error occurs because the accept() cannot complete.
* You will not see ENOBUFS with 10.20 because the kernel
* hides any occurrence from being returned to user space.
* occur intermittently. As a work-around, we are going to
* ignore ENOBUFS.
*/
case ENOBUFS:
#endif
#ifdef EPROTO
/* EPROTO on certain older kernels really means
* ECONNABORTED, so we need to ignore it for them.
* See discussion in new-httpd archives nh.9701
* search for EPROTO.
*
* Also see nh.9603, search for EPROTO:
* There is potentially a bug in Solaris 2.x x<6,
* and other boxes that implement tcp sockets in
* userland (i.e. on top of STREAMS). On these
* systems, EPROTO can actually result in a fatal
* loop. See PR#981 for example. It's hard to
* handle both uses of EPROTO.
*/
case EPROTO:
#endif
#ifdef ECONNABORTED
case ECONNABORTED:
#endif
/* Linux generates the rest of these, other tcp
* stacks (i.e. bsd) tend to hide them behind
* getsockopt() interfaces. They occur when
* the net goes sour or the client disconnects
* after the three-way handshake has been done
* in the kernel but before userland has picked
* up the socket.
*/
#ifdef ECONNRESET
case ECONNRESET:
#endif
#ifdef ETIMEDOUT
case ETIMEDOUT:
#endif
#ifdef EHOSTUNREACH
case EHOSTUNREACH:
#endif
#ifdef ENETUNREACH
case ENETUNREACH:
#endif
/* EAGAIN/EWOULDBLOCK can be returned on BSD-derived
* TCP stacks when the connection is aborted before
* we call connect, but only because our listener
* sockets are non-blocking (AP_NONBLOCK_WHEN_MULTI_LISTEN)
*/
#ifdef EAGAIN
case EAGAIN:
#endif
#ifdef EWOULDBLOCK
case EWOULDBLOCK:
#endif
#endif
break;
#ifdef ENETDOWN
case ENETDOWN:
/*
* When the network layer has been shut down, there
* is not much use in simply exiting: the parent
* would simply re-create us (and we'd fail again).
* Use the CHILDFATAL code to tear the server down.
* @@@ Martin's idea for possible improvement:
* A different approach would be to define
* a new APEXIT_NETDOWN exit code, the reception
* of which would make the parent shutdown all
* children, then idle-loop until it detected that
* the network is up again, and restart the children.
* Ben Hyde noted that temporary ENETDOWN situations
* occur in mobile IP.
*/
"apr_socket_accept: giving up.");
return APR_EGENERAL;
#endif /*ENETDOWN*/
default:
/* If the socket has been closed in ap_close_listeners()
* Do not print an error in this case.
*/
"apr_socket_accept failed for inactive listener");
return status;
}
"apr_socket_accept: (client socket)");
return APR_EGENERAL;
}
return status;
}
#ifdef _OSD_POSIX
#include "apr_lib.h"
#define USER_LEN 8
typedef enum
{
bs2_unknown, /* not initialized yet. */
bs2_noFORK, /* no fork() because -X flag was specified */
bs2_FORK, /* only fork() because uid != 0 */
bs2_UFORK /* Normally, ufork() is used to switch identities. */
} bs2_ForkType;
static void ap_str_toupper(char *str)
{
while (*str) {
++str;
}
}
/* Determine the method for forking off a child in such a way as to
* set both the POSIX and BS2000 user id's to the unprivileged user.
*/
{
/* have we checked the OS version before? If yes return the previous
* result - the OS release isn't going to change suddenly!
*/
if (forktype == bs2_unknown) {
/* not initialized yet */
/* No fork if the one_process option was set */
if (one_process) {
}
/* If the user is unprivileged, use the normal fork() only. */
else if (getuid() != 0) {
}
else
}
return forktype;
}
/* This routine complements the setuid() call: it causes the BS2000 job
* environment to be switched to the target user's user id.
* That is important if CGI scripts try to execute native BS2000 commands.
*/
{
/* We can be sure that no change to uid==0 is possible because of
* the checks in http_core.c:set_user()
*/
if (one_process) {
"The debug mode of Apache should only "
"be started by an unprivileged user!");
return 0;
}
return 0;
}
/* BS2000 requires a "special" version of fork() before a setuid() call */
{
switch (os_forktype(0)) {
case bs2_FORK:
break;
case bs2_UFORK:
/* Make user name all upper case - for some versions of ufork() */
NULL, "ufork: Possible mis-configuration "
"for user %s - Aborting.", user);
exit(1);
}
break;
default:
pid = 0;
break;
}
return pid;
}
#endif /* _OSD_POSIX */