httpd-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Rob Hartill <r...@imdb.com>
Subject Re: WWW Form Bug Report: "FollowSymLinksIfOwnerMatch and automounting don't mix well" on Solaris 2.x
Date Sat, 23 Nov 1996 20:21:53 GMT

Thanks for the info and patch.

cheers,
rob

drl@vuse.vanderbilt.edu wrote:

>Submitter: drl@vuse.vanderbilt.edu
>Operating system: Solaris 2.x, version: 
>Version of Apache Used: 1.1.1
>Extra Modules used: 
>URL exhibiting problem: 
>
>Symptoms:
>--
>I use amd automounted filesystems on my info
>server and also set httpd to follow symlinks
>only if the owner of the link and of the target
>match.  This broke some things so I patched
>http_request.c to allow matches on same owner
>or when the symlink is owned by root.  This is
>a one-line change as I did it but to do it right
>you'd need to add a new Option and then check
>that option before making the one-line test.
>
>Whether this is a bug report or an enhancement
>request is up to y'all.  I include a diff for my
>change:
>
>*** http_request.c-dist	Mon Jul  1 13:10:29 1996
>--- http_request.c	Sat Nov 23 12:46:14 1996
>***************
>*** 125,130 ****
>--- 125,133 ----
>  		    
>      if (!(res >= 0) || !S_ISLNK(lfi.st_mode)) return OK;
>  
>+     /* 960830 - DRL - VUSE addition - follow any symlinks owned by root */
>+     if (lfi.st_uid == 0) return OK;
>+ 
>      /* OK, it's a symlink.  May still be OK with OPT_SYM_OWNER */
>      
>      if (!(opts & OPT_SYM_OWNER)) return FORBIDDEN;
>
>--
>
>Backtrace:
>--
>
>--
>


-- 
Rob Hartill.       Internet Movie Database Ltd.    http://www.imdb.com/  

Mime
View raw message