src/server/daemon/webserver.c

Sun, 25 Sep 2022 10:36:28 +0200

author
Olaf Wintermann <olaf.wintermann@gmail.com>
date
Sun, 25 Sep 2022 10:36:28 +0200
changeset 388
30d29ef5b79a
parent 386
b91f8efadb63
child 391
80ee93a7d257
permissions
-rw-r--r--

change uid before most of the config is loaded

1
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
1 /*
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
2 * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS HEADER.
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
3 *
44
3da1f7b6847f added some error messages
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 41
diff changeset
4 * Copyright 2013 Olaf Wintermann. All rights reserved.
1
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
5 *
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
6 * Redistribution and use in source and binary forms, with or without
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
7 * modification, are permitted provided that the following conditions are met:
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
8 *
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
9 * 1. Redistributions of source code must retain the above copyright
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
10 * notice, this list of conditions and the following disclaimer.
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
11 *
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
12 * 2. Redistributions in binary form must reproduce the above copyright
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
13 * notice, this list of conditions and the following disclaimer in the
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
14 * documentation and/or other materials provided with the distribution.
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
15 *
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
16 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
17 * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
18 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
19 * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
20 * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
21 * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
22 * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
23 * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
24 * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
25 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
26 * POSSIBILITY OF SUCH DAMAGE.
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
27 */
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
28
41
bb7a1f5a8b48 added Linux support
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 39
diff changeset
29
bb7a1f5a8b48 added Linux support
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 39
diff changeset
30 #ifdef __gnu_linux__
bb7a1f5a8b48 added Linux support
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 39
diff changeset
31 #define _GNU_SOURCE
bb7a1f5a8b48 added Linux support
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 39
diff changeset
32 #endif
bb7a1f5a8b48 added Linux support
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 39
diff changeset
33
1
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
34 #include <stdio.h>
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
35 #include <stdlib.h>
9
30e51941a673 Added mod_jk dependencies
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 6
diff changeset
36 #include <dlfcn.h>
47
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
37 #include <grp.h>
58
66c22e54aa90 webdav uses the vfs api
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 47
diff changeset
38 #include <sys/types.h>
66c22e54aa90 webdav uses the vfs api
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 47
diff changeset
39 #include <sys/stat.h>
1
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
40
106
b122f34ddc80 added minimal ssl support
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 85
diff changeset
41 #include <openssl/bio.h>
b122f34ddc80 added minimal ssl support
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 85
diff changeset
42 #include <openssl/ssl.h>
b122f34ddc80 added minimal ssl support
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 85
diff changeset
43 #include <openssl/err.h>
b122f34ddc80 added minimal ssl support
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 85
diff changeset
44
14
b8bf95b39952 New source folder layout
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 9
diff changeset
45 #include "../public/nsapi.h"
59
ab25c0a231d0 some fixes and new public APIs
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 58
diff changeset
46 #include "../public/auth.h"
14
b8bf95b39952 New source folder layout
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 9
diff changeset
47 #include "../util/systhr.h"
363
7f0f5c03666a port pblock.cpp to pblock.c
Mike Becker <universe@uap-core.de>
parents: 179
diff changeset
48 #include "../util/pblock.h"
47
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
49 #include "../util/util.h"
1
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
50
254
4784c14aa639 ucx update
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 179
diff changeset
51 #include <ucx/utils.h>
156
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
52
154
6394ce09889a adds set-variable saf
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 146
diff changeset
53 #include "../safs/common.h"
6394ce09889a adds set-variable saf
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 146
diff changeset
54
1
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
55 #include "func.h"
18
73aacbf6e492 Added server.conf parser
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 14
diff changeset
56 #include "config.h"
19
d680536f8c2f Added configuration manager
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 18
diff changeset
57 #include "configmanager.h"
1
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
58 #include "httplistener.h"
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
59 #include "webserver.h"
66
74babc0082b7 added authentication cache
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 63
diff changeset
60 #include "auth.h"
158
77f4f0079428 adds reconfig and shutdown handler to srvctrl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 156
diff changeset
61 #include "srvctrl.h"
269
3dfbd0b91950 add ResourcePool initialization
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 256
diff changeset
62 #include "resourcepool.h"
1
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
63
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
64 extern struct FuncStruct webserver_funcs[];
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
65
68
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
66 static RestartCallback *atrestart;
1
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
67
129
fd324464f56f adds support for ssl cert chain files and improves ssl error handling
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 115
diff changeset
68 int webserver_init() {
1
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
69 // init NSPR
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
70 systhread_init("webserver");
28
f387669912e8 added logging
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 22
diff changeset
71
106
b122f34ddc80 added minimal ssl support
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 85
diff changeset
72 // init ssl
b122f34ddc80 added minimal ssl support
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 85
diff changeset
73 if(ws_init_ssl()) {
b122f34ddc80 added minimal ssl support
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 85
diff changeset
74 return -1;
b122f34ddc80 added minimal ssl support
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 85
diff changeset
75 }
b122f34ddc80 added minimal ssl support
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 85
diff changeset
76
1
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
77 // init NSAPI functions
363
7f0f5c03666a port pblock.cpp to pblock.c
Mike Becker <universe@uap-core.de>
parents: 179
diff changeset
78 pblock_init_default_keys();
7f0f5c03666a port pblock.cpp to pblock.c
Mike Becker <universe@uap-core.de>
parents: 179
diff changeset
79 atexit(pblock_free_default_keys);
1
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
80 func_init();
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
81 add_functions(webserver_funcs);
38
d07810b02147 added ldap authentication
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 32
diff changeset
82
269
3dfbd0b91950 add ResourcePool initialization
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 256
diff changeset
83 // init resource pools
3dfbd0b91950 add ResourcePool initialization
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 256
diff changeset
84 if(init_resource_pools()) {
3dfbd0b91950 add ResourcePool initialization
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 256
diff changeset
85 return -1;
3dfbd0b91950 add ResourcePool initialization
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 256
diff changeset
86 }
3dfbd0b91950 add ResourcePool initialization
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 256
diff changeset
87
1
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
88 // load init.conf
60
feb2f1e115c6 improved logging
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 59
diff changeset
89 if(load_init_conf("config/init.conf")) {
feb2f1e115c6 improved logging
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 59
diff changeset
90 return -1;
feb2f1e115c6 improved logging
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 59
diff changeset
91 }
1
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
92
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
93 // load server.conf
388
30d29ef5b79a change uid before most of the config is loaded
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 386
diff changeset
94 // Only the runtime infos are stored in the ServerConfiguration at
30d29ef5b79a change uid before most of the config is loaded
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 386
diff changeset
95 // this stage. The remaining configuration is loaded after the uid
30d29ef5b79a change uid before most of the config is loaded
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 386
diff changeset
96 // is changed (if needed).
19
d680536f8c2f Added configuration manager
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 18
diff changeset
97 init_configuration_manager();
388
30d29ef5b79a change uid before most of the config is loaded
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 386
diff changeset
98 CfgManager mgr;
30d29ef5b79a change uid before most of the config is loaded
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 386
diff changeset
99 if(cfgmgr_load_config(&mgr) != 0) {
19
d680536f8c2f Added configuration manager
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 18
diff changeset
100 return -1;
d680536f8c2f Added configuration manager
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 18
diff changeset
101 }
388
30d29ef5b79a change uid before most of the config is loaded
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 386
diff changeset
102 ServerConfiguration *cfg = mgr.cfg;
47
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
103
66
74babc0082b7 added authentication cache
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 63
diff changeset
104 // init caches
74babc0082b7 added authentication cache
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 63
diff changeset
105 auth_cache_init();
74babc0082b7 added authentication cache
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 63
diff changeset
106
154
6394ce09889a adds set-variable saf
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 146
diff changeset
107 // init SAFs
6394ce09889a adds set-variable saf
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 146
diff changeset
108 common_saf_init();
6394ce09889a adds set-variable saf
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 146
diff changeset
109
47
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
110 // set global vars
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
111 conf_global_vars_s *vars = conf_getglobals();
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
112
146
a9591a91c004 fixes server user init
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 133
diff changeset
113 WSBool changeuid = FALSE;
73
79fa26ecd135 added file system ACLs for linux
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 68
diff changeset
114 uid_t ws_uid = geteuid();
63
66442f81f823 supports file system ACLs on Solaris
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 60
diff changeset
115 setpwent();
73
79fa26ecd135 added file system ACLs for linux
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 68
diff changeset
116 char *pwbuf = malloc(DEF_PWBUF);
79fa26ecd135 added file system ACLs for linux
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 68
diff changeset
117 vars->Vuserpw = malloc(sizeof(struct passwd));
79fa26ecd135 added file system ACLs for linux
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 68
diff changeset
118 if(cfg->user.ptr) {
79fa26ecd135 added file system ACLs for linux
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 68
diff changeset
119 if(!util_getpwnam(cfg->user.ptr, vars->Vuserpw, pwbuf, DEF_PWBUF)) {
79fa26ecd135 added file system ACLs for linux
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 68
diff changeset
120 log_ereport(
79fa26ecd135 added file system ACLs for linux
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 68
diff changeset
121 LOG_MISCONFIG,
79fa26ecd135 added file system ACLs for linux
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 68
diff changeset
122 "user %s does not exist!",
79fa26ecd135 added file system ACLs for linux
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 68
diff changeset
123 cfg->user.ptr);
79fa26ecd135 added file system ACLs for linux
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 68
diff changeset
124 free(vars->Vuserpw);
79fa26ecd135 added file system ACLs for linux
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 68
diff changeset
125 vars->Vuserpw = NULL;
146
a9591a91c004 fixes server user init
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 133
diff changeset
126 } else {
a9591a91c004 fixes server user init
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 133
diff changeset
127 changeuid = TRUE;
73
79fa26ecd135 added file system ACLs for linux
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 68
diff changeset
128 }
79fa26ecd135 added file system ACLs for linux
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 68
diff changeset
129 } else {
79fa26ecd135 added file system ACLs for linux
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 68
diff changeset
130 if(!util_getpwuid(ws_uid, vars->Vuserpw, pwbuf, DEF_PWBUF)) {
79fa26ecd135 added file system ACLs for linux
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 68
diff changeset
131 log_ereport(LOG_FAILURE, "webserver_init: cannot get passwd data");
79fa26ecd135 added file system ACLs for linux
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 68
diff changeset
132 free(vars->Vuserpw);
79fa26ecd135 added file system ACLs for linux
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 68
diff changeset
133 vars->Vuserpw = NULL;
79fa26ecd135 added file system ACLs for linux
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 68
diff changeset
134 }
79fa26ecd135 added file system ACLs for linux
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 68
diff changeset
135 }
79fa26ecd135 added file system ACLs for linux
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 68
diff changeset
136 if(!vars->Vuserpw) {
79fa26ecd135 added file system ACLs for linux
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 68
diff changeset
137 log_ereport(LOG_WARN, "globalvars->Vuserpw is null");
79fa26ecd135 added file system ACLs for linux
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 68
diff changeset
138 }
22
adb0bda54e6b Server can run as daemon
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 19
diff changeset
139
47
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
140 // change uid
146
a9591a91c004 fixes server user init
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 133
diff changeset
141 if(changeuid && ws_uid == 0) {
47
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
142 // a webserver user is set and we are root
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
143
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
144 if(setgid(vars->Vuserpw->pw_gid) != 0) {
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
145 log_ereport(
60
feb2f1e115c6 improved logging
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 59
diff changeset
146 LOG_FAILURE,
47
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
147 "setgid(%d) failed",
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
148 vars->Vuserpw->pw_gid);
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
149 } else {
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
150 // setgid was successful
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
151 // we need to call initgroups to have all group permissions
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
152 if(initgroups(vars->Vuserpw->pw_name, vars->Vuserpw->pw_gid)!=0) {
60
feb2f1e115c6 improved logging
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 59
diff changeset
153 log_ereport(LOG_FAILURE, "initgroups failed");
47
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
154 }
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
155 }
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
156
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
157 // change the uid
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
158 if(setuid(vars->Vuserpw->pw_uid)) {
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
159 log_ereport(
60
feb2f1e115c6 improved logging
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 59
diff changeset
160 LOG_FAILURE,
47
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
161 "setuid(%d) failed",
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
162 vars->Vuserpw->pw_uid);
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
163 }
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
164 } else if(vars->Vuserpw) {
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
165 log_ereport(
60
feb2f1e115c6 improved logging
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 59
diff changeset
166 LOG_WARN,
47
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
167 "server must be started as root to change uid");
ce9790523346 server can change uid
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 44
diff changeset
168 }
66
74babc0082b7 added authentication cache
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 63
diff changeset
169
388
30d29ef5b79a change uid before most of the config is loaded
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 386
diff changeset
170
30d29ef5b79a change uid before most of the config is loaded
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 386
diff changeset
171 // now that the process is running as the correct user, we can load
30d29ef5b79a change uid before most of the config is loaded
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 386
diff changeset
172 // the remaining config
30d29ef5b79a change uid before most of the config is loaded
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 386
diff changeset
173 if(cfgmgr_apply_config(&mgr)) {
30d29ef5b79a change uid before most of the config is loaded
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 386
diff changeset
174 return -1;
30d29ef5b79a change uid before most of the config is loaded
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 386
diff changeset
175 }
30d29ef5b79a change uid before most of the config is loaded
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 386
diff changeset
176
30d29ef5b79a change uid before most of the config is loaded
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 386
diff changeset
177
156
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
178 // create tmp dir and pid file
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
179 char *mkdir_cmd = NULL;
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
180 asprintf(&mkdir_cmd, "mkdir -p %s", cfg->tmp.ptr);
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
181 system(mkdir_cmd);
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
182 free(mkdir_cmd);
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
183
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
184 char *pid_file_path = NULL;
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
185 asprintf(&pid_file_path, "%s/pid", cfg->tmp.ptr);
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
186 FILE *pidfile = fopen(pid_file_path, "w"); // TODO: check error
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
187 pid_t pid = getpid();
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
188 fprintf(pidfile, "%d", pid);
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
189 fclose(pidfile);
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
190 free(pid_file_path);
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
191
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
192 // create unix domain socket for server control
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
193 sstr_t tmp_priv = ucx_sprintf("%s/private", cfg->tmp.ptr);
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
194 // TODO: remove existing private dir
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
195 if(mkdir(tmp_priv.ptr, S_IRWXU)) {
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
196 if(errno == EEXIST) {
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
197 if(chmod(tmp_priv.ptr, S_IRWXU)) {
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
198 log_ereport(
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
199 LOG_CATASTROPHE,
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
200 "cannot change permissions of tmp dir %s:",
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
201 tmp_priv.ptr,
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
202 strerror(errno));
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
203 return 0;
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
204 }
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
205 } else {
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
206 log_ereport(
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
207 LOG_CATASTROPHE,
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
208 "cannot create tmp dir %s:",
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
209 tmp_priv.ptr,
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
210 strerror(errno));
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
211 return -1;
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
212 }
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
213 }
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
214
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
215
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
216 // create srvctrl unix domain socket
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
217 // this socket is used for stop, reconfigure and other operations
158
77f4f0079428 adds reconfig and shutdown handler to srvctrl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 156
diff changeset
218 if(srvctrl_init(cfg)) {
156
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
219 return -1;
158
77f4f0079428 adds reconfig and shutdown handler to srvctrl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 156
diff changeset
220 }
156
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
221
146
a9591a91c004 fixes server user init
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 133
diff changeset
222 //endpwent(); // TODO: close or not?
a9591a91c004 fixes server user init
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 133
diff changeset
223 //free(pwbuf); // TODO: ?
a9591a91c004 fixes server user init
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 133
diff changeset
224
1
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
225 return 0;
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
226 }
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
227
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
228 int webserver_run() {
115
51d9a15eac98 improves logging
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 106
diff changeset
229 log_ereport(LOG_VERBOSE, "webserver_run");
1
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
230
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
231 // start all http listener
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
232 if(start_all_listener() != 0) {
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
233 fprintf(stderr, "Error: Cannot start http listener\n");
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
234 }
115
51d9a15eac98 improves logging
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 106
diff changeset
235
51d9a15eac98 improves logging
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 106
diff changeset
236 log_ereport(LOG_INFORM, "webserver started");
1
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
237
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
238 return 0;
3c066d52342d added source
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
239 }
9
30e51941a673 Added mod_jk dependencies
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 6
diff changeset
240
68
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
241 void webserver_shutdown() {
115
51d9a15eac98 improves logging
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 106
diff changeset
242 log_ereport(LOG_INFORM, "webserver shutdown");
68
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
243
158
77f4f0079428 adds reconfig and shutdown handler to srvctrl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 156
diff changeset
244 srvctrl_shutdown();
77f4f0079428 adds reconfig and shutdown handler to srvctrl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 156
diff changeset
245
68
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
246 // execute restart callbacks
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
247 RestartCallback *re = atrestart;
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
248 while(re) {
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
249 re->func(re->data);
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
250 re = re->next;
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
251 }
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
252 }
9
30e51941a673 Added mod_jk dependencies
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 6
diff changeset
253
158
77f4f0079428 adds reconfig and shutdown handler to srvctrl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 156
diff changeset
254 int webserver_reconfig() {
77f4f0079428 adds reconfig and shutdown handler to srvctrl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 156
diff changeset
255 if(cfgmgr_load_config(NULL) != 0) {
77f4f0079428 adds reconfig and shutdown handler to srvctrl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 156
diff changeset
256 return -1;
77f4f0079428 adds reconfig and shutdown handler to srvctrl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 156
diff changeset
257 }
77f4f0079428 adds reconfig and shutdown handler to srvctrl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 156
diff changeset
258 // start newly created listeners
77f4f0079428 adds reconfig and shutdown handler to srvctrl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 156
diff changeset
259 start_all_listener();
77f4f0079428 adds reconfig and shutdown handler to srvctrl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 156
diff changeset
260
77f4f0079428 adds reconfig and shutdown handler to srvctrl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 156
diff changeset
261 return 0;
156
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
262 }
724e107983e9 adds unix domain socket for server control ops
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 154
diff changeset
263
9
30e51941a673 Added mod_jk dependencies
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 6
diff changeset
264 void webserver_atrestart(void (*fn)(void *), void *data) {
68
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
265 RestartCallback *cb = malloc(sizeof(RestartCallback));
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
266 cb->func = fn;
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
267 cb->data = data;
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
268 cb->next = NULL;
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
269
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
270 if(atrestart) {
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
271 RestartCallback *elm = atrestart;
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
272 while(elm) {
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
273 if(!elm->next) {
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
274 elm->next = cb;
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
275 break;
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
276 }
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
277 elm = elm->next;
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
278 }
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
279 } else {
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
280 atrestart = cb;
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
281 }
9
30e51941a673 Added mod_jk dependencies
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 6
diff changeset
282 }
30e51941a673 Added mod_jk dependencies
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 6
diff changeset
283
68
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
284 int nsapi_runtime_version() {
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
285 return 303;
f5102a892ed4 some fixes for mod_jk
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 66
diff changeset
286 }
106
b122f34ddc80 added minimal ssl support
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 85
diff changeset
287
b122f34ddc80 added minimal ssl support
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 85
diff changeset
288
b122f34ddc80 added minimal ssl support
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 85
diff changeset
289 int ws_init_ssl() {
b122f34ddc80 added minimal ssl support
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 85
diff changeset
290 // TODO: handle errors
b122f34ddc80 added minimal ssl support
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 85
diff changeset
291 SSL_load_error_strings();
b122f34ddc80 added minimal ssl support
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 85
diff changeset
292 SSL_library_init();
b122f34ddc80 added minimal ssl support
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 85
diff changeset
293 OpenSSL_add_all_algorithms();
b122f34ddc80 added minimal ssl support
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 85
diff changeset
294 return 0;
b122f34ddc80 added minimal ssl support
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 85
diff changeset
295 }

mercurial