Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Submit feedback
Contribute to GitLab
Sign in
Toggle navigation
V
varnish-cache
Project
Project
Details
Activity
Releases
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Commits
Open sidebar
varnishcache
varnish-cache
Commits
bfd0d2d0
Commit
bfd0d2d0
authored
Feb 11, 2015
by
Poul-Henning Kamp
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
Move the param/tweak stuff related to sandboxing to its own source file.
parent
e08ed188
Changes
6
Hide whitespace changes
Inline
Side-by-side
Showing
6 changed files
with
166 additions
and
119 deletions
+166
-119
Makefile.am
bin/varnishd/Makefile.am
+1
-0
mgt_param.c
bin/varnishd/mgt/mgt_param.c
+1
-0
mgt_param.h
bin/varnishd/mgt/mgt_param.h
+4
-11
mgt_param_sandbox.c
bin/varnishd/mgt/mgt_param_sandbox.c
+160
-0
mgt_param_tbl.c
bin/varnishd/mgt/mgt_param_tbl.c
+0
-16
mgt_param_tweak.c
bin/varnishd/mgt/mgt_param_tweak.c
+0
-92
No files found.
bin/varnishd/Makefile.am
View file @
bfd0d2d0
...
...
@@ -68,6 +68,7 @@ varnishd_SOURCES = \
mgt/mgt_param.c
\
mgt/mgt_param_tbl.c
\
mgt/mgt_param_bits.c
\
mgt/mgt_param_sandbox.c
\
mgt/mgt_param_tcp.c
\
mgt/mgt_param_tweak.c
\
mgt/mgt_pool.c
\
...
...
bin/varnishd/mgt/mgt_param.c
View file @
bfd0d2d0
...
...
@@ -470,6 +470,7 @@ MCF_CollectParams(void)
MCF_AddParams
(
mgt_parspec
);
MCF_AddParams
(
WRK_parspec
);
MCF_AddParams
(
VSL_parspec
);
MCF_AddParams
(
mgt_parspec_sandbox
);
}
/*--------------------------------------------------------------------*/
...
...
bin/varnishd/mgt/mgt_param.h
View file @
bfd0d2d0
...
...
@@ -56,14 +56,11 @@ tweak_t tweak_bool;
tweak_t
tweak_bytes
;
tweak_t
tweak_bytes_u
;
tweak_t
tweak_double
;
tweak_t
tweak_group
;
tweak_t
tweak_group_cc
;
tweak_t
tweak_listen_address
;
tweak_t
tweak_poolparam
;
tweak_t
tweak_string
;
tweak_t
tweak_timeout
;
tweak_t
tweak_uint
;
tweak_t
tweak_user
;
tweak_t
tweak_waiter
;
tweak_t
tweak_vsl_buffer
;
tweak_t
tweak_vsl_reclen
;
...
...
@@ -71,11 +68,7 @@ tweak_t tweak_vsl_reclen;
int
tweak_generic_uint
(
struct
vsb
*
vsb
,
volatile
unsigned
*
dest
,
const
char
*
arg
,
const
char
*
min
,
const
char
*
max
);
/* mgt_param_tbl.c */
extern
struct
parspec
mgt_parspec
[];
/* mgt_param_vsl.c */
extern
struct
parspec
VSL_parspec
[];
/* mgt_pool.c */
extern
struct
parspec
WRK_parspec
[];
extern
struct
parspec
mgt_parspec
[];
/* mgt_param_tbl.c */
extern
struct
parspec
VSL_parspec
[];
/* mgt_param_vsl.c */
extern
struct
parspec
WRK_parspec
[];
/* mgt_pool.c */
extern
struct
parspec
mgt_parspec_sandbox
[];
/* mgt_param_sandbox.c */
bin/varnishd/mgt/mgt_param_sandbox.c
0 → 100644
View file @
bfd0d2d0
/*-
* Copyright (c) 2006 Verdens Gang AS
* Copyright (c) 2006-2011 Varnish Software AS
* All rights reserved.
*
* Author: Poul-Henning Kamp <phk@phk.freebsd.dk>
*
* Redistribution and use in source and binary forms, with or without
* modification, are permitted provided that the following conditions
* are met:
* 1. Redistributions of source code must retain the above copyright
* notice, this list of conditions and the following disclaimer.
* 2. Redistributions in binary form must reproduce the above copyright
* notice, this list of conditions and the following disclaimer in the
* documentation and/or other materials provided with the distribution.
*
* THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
* ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
* IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
* ARE DISCLAIMED. IN NO EVENT SHALL AUTHOR OR CONTRIBUTORS BE LIABLE
* FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
* DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
* OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
* HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
* LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
* OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
* SUCH DAMAGE.
*
* Functions for tweaking parameters
*
*/
#include "config.h"
#include <grp.h>
#include <limits.h>
#include <math.h>
#include <pwd.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <unistd.h>
#include "mgt/mgt.h"
#include "common/params.h"
#include "mgt/mgt_param.h"
/*--------------------------------------------------------------------
* XXX: slightly magic. We want to initialize to "nobody" (XXX: shouldn't
* XXX: that be something autocrap found for us ?) but we don't want to
* XXX: fail initialization if that user doesn't exists, even though we
* XXX: do want to fail it, in subsequent sets.
* XXX: The magic init string is a hack for this.
*/
static
int
tweak_user
(
struct
vsb
*
vsb
,
const
struct
parspec
*
par
,
const
char
*
arg
)
{
struct
passwd
*
pw
;
(
void
)
par
;
if
(
arg
!=
NULL
)
{
pw
=
getpwnam
(
arg
);
if
(
pw
==
NULL
)
{
VSB_printf
(
vsb
,
"Unknown user '%s'"
,
arg
);
return
(
-
1
);
}
REPLACE
(
mgt_param
.
user
,
pw
->
pw_name
);
mgt_param
.
uid
=
pw
->
pw_uid
;
endpwent
();
}
else
if
(
mgt_param
.
user
)
{
VSB_printf
(
vsb
,
"%s (%d)"
,
mgt_param
.
user
,
(
int
)
mgt_param
.
uid
);
}
else
{
VSB_printf
(
vsb
,
"UID %d"
,
(
int
)
mgt_param
.
uid
);
}
return
(
0
);
}
/*--------------------------------------------------------------------
* XXX: see comment for tweak_user, same thing here.
*/
static
int
tweak_group
(
struct
vsb
*
vsb
,
const
struct
parspec
*
par
,
const
char
*
arg
)
{
struct
group
*
gr
;
(
void
)
par
;
if
(
arg
!=
NULL
)
{
gr
=
getgrnam
(
arg
);
if
(
gr
==
NULL
)
{
VSB_printf
(
vsb
,
"Unknown group '%s'"
,
arg
);
return
(
-
1
);
}
REPLACE
(
mgt_param
.
group
,
gr
->
gr_name
);
mgt_param
.
gid
=
gr
->
gr_gid
;
endgrent
();
}
else
if
(
mgt_param
.
group
)
{
VSB_printf
(
vsb
,
"%s (%d)"
,
mgt_param
.
group
,
(
int
)
mgt_param
.
gid
);
}
else
{
VSB_printf
(
vsb
,
"GID %d"
,
(
int
)
mgt_param
.
gid
);
}
return
(
0
);
}
/*--------------------------------------------------------------------
* XXX: see comment for tweak_user, same thing here.
*/
static
int
tweak_group_cc
(
struct
vsb
*
vsb
,
const
struct
parspec
*
par
,
const
char
*
arg
)
{
struct
group
*
gr
;
(
void
)
par
;
if
(
arg
!=
NULL
)
{
if
(
*
arg
!=
'\0'
)
{
gr
=
getgrnam
(
arg
);
if
(
gr
==
NULL
)
{
VSB_printf
(
vsb
,
"Unknown group"
);
return
(
-
1
);
}
REPLACE
(
mgt_param
.
group_cc
,
gr
->
gr_name
);
mgt_param
.
gid_cc
=
gr
->
gr_gid
;
}
else
{
REPLACE
(
mgt_param
.
group_cc
,
""
);
mgt_param
.
gid_cc
=
0
;
}
}
else
if
(
strlen
(
mgt_param
.
group_cc
)
>
0
)
{
VSB_printf
(
vsb
,
"%s (%d)"
,
mgt_param
.
group_cc
,
(
int
)
mgt_param
.
gid_cc
);
}
else
{
VSB_printf
(
vsb
,
"<not set>"
);
}
return
(
0
);
}
/*--------------------------------------------------------------------
*/
struct
parspec
mgt_parspec_sandbox
[]
=
{
{
"user"
,
tweak_user
,
NULL
,
NULL
,
NULL
,
"The unprivileged user to run as."
,
MUST_RESTART
|
ONLY_ROOT
,
""
},
{
"group"
,
tweak_group
,
NULL
,
NULL
,
NULL
,
"The unprivileged group to run as."
,
MUST_RESTART
|
ONLY_ROOT
,
""
},
{
"group_cc"
,
tweak_group_cc
,
NULL
,
NULL
,
NULL
,
"On some systems the C-compiler is restricted so not"
" everybody can run it. This parameter makes it possible"
" to add an extra group to the sandbox process which runs the"
" cc_command, in order to gain access to such a restricted"
" C-compiler."
,
ONLY_ROOT
,
""
},
{
NULL
,
NULL
,
NULL
}
};
bin/varnishd/mgt/mgt_param_tbl.c
View file @
bfd0d2d0
...
...
@@ -45,22 +45,6 @@
"\tmax_age\tmax age of free element."
struct
parspec
mgt_parspec
[]
=
{
{
"user"
,
tweak_user
,
NULL
,
NULL
,
NULL
,
"The unprivileged user to run as."
,
MUST_RESTART
|
ONLY_ROOT
,
""
},
{
"group"
,
tweak_group
,
NULL
,
NULL
,
NULL
,
"The unprivileged group to run as."
,
MUST_RESTART
|
ONLY_ROOT
,
""
},
{
"group_cc"
,
tweak_group_cc
,
NULL
,
NULL
,
NULL
,
"On some systems the C-compiler is restricted so not"
" everybody can run it. This parameter makes it possible"
" to add an extra group to the sandbox process which runs the"
" cc_command, in order to gain access to such a restricted"
" C-compiler."
,
ONLY_ROOT
,
""
},
{
"default_ttl"
,
tweak_timeout
,
&
mgt_param
.
default_ttl
,
"0"
,
NULL
,
"The TTL assigned to objects if neither the backend nor "
...
...
bin/varnishd/mgt/mgt_param_tweak.c
View file @
bfd0d2d0
...
...
@@ -32,10 +32,8 @@
#include "config.h"
#include <grp.h>
#include <limits.h>
#include <math.h>
#include <pwd.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
...
...
@@ -369,96 +367,6 @@ tweak_vsl_reclen(struct vsb *vsb, const struct parspec *par, const char *arg)
return
(
0
);
}
/*--------------------------------------------------------------------
* XXX: slightly magic. We want to initialize to "nobody" (XXX: shouldn't
* XXX: that be something autocrap found for us ?) but we don't want to
* XXX: fail initialization if that user doesn't exists, even though we
* XXX: do want to fail it, in subsequent sets.
* XXX: The magic init string is a hack for this.
*/
int
tweak_user
(
struct
vsb
*
vsb
,
const
struct
parspec
*
par
,
const
char
*
arg
)
{
struct
passwd
*
pw
;
(
void
)
par
;
if
(
arg
!=
NULL
)
{
pw
=
getpwnam
(
arg
);
if
(
pw
==
NULL
)
{
VSB_printf
(
vsb
,
"Unknown user '%s'"
,
arg
);
return
(
-
1
);
}
REPLACE
(
mgt_param
.
user
,
pw
->
pw_name
);
mgt_param
.
uid
=
pw
->
pw_uid
;
endpwent
();
}
else
if
(
mgt_param
.
user
)
{
VSB_printf
(
vsb
,
"%s (%d)"
,
mgt_param
.
user
,
(
int
)
mgt_param
.
uid
);
}
else
{
VSB_printf
(
vsb
,
"UID %d"
,
(
int
)
mgt_param
.
uid
);
}
return
(
0
);
}
/*--------------------------------------------------------------------
* XXX: see comment for tweak_user, same thing here.
*/
int
tweak_group
(
struct
vsb
*
vsb
,
const
struct
parspec
*
par
,
const
char
*
arg
)
{
struct
group
*
gr
;
(
void
)
par
;
if
(
arg
!=
NULL
)
{
gr
=
getgrnam
(
arg
);
if
(
gr
==
NULL
)
{
VSB_printf
(
vsb
,
"Unknown group '%s'"
,
arg
);
return
(
-
1
);
}
REPLACE
(
mgt_param
.
group
,
gr
->
gr_name
);
mgt_param
.
gid
=
gr
->
gr_gid
;
endgrent
();
}
else
if
(
mgt_param
.
group
)
{
VSB_printf
(
vsb
,
"%s (%d)"
,
mgt_param
.
group
,
(
int
)
mgt_param
.
gid
);
}
else
{
VSB_printf
(
vsb
,
"GID %d"
,
(
int
)
mgt_param
.
gid
);
}
return
(
0
);
}
/*--------------------------------------------------------------------
* XXX: see comment for tweak_user, same thing here.
*/
int
tweak_group_cc
(
struct
vsb
*
vsb
,
const
struct
parspec
*
par
,
const
char
*
arg
)
{
struct
group
*
gr
;
(
void
)
par
;
if
(
arg
!=
NULL
)
{
if
(
*
arg
!=
'\0'
)
{
gr
=
getgrnam
(
arg
);
if
(
gr
==
NULL
)
{
VSB_printf
(
vsb
,
"Unknown group"
);
return
(
-
1
);
}
REPLACE
(
mgt_param
.
group_cc
,
gr
->
gr_name
);
mgt_param
.
gid_cc
=
gr
->
gr_gid
;
}
else
{
REPLACE
(
mgt_param
.
group_cc
,
""
);
mgt_param
.
gid_cc
=
0
;
}
}
else
if
(
strlen
(
mgt_param
.
group_cc
)
>
0
)
{
VSB_printf
(
vsb
,
"%s (%d)"
,
mgt_param
.
group_cc
,
(
int
)
mgt_param
.
gid_cc
);
}
else
{
VSB_printf
(
vsb
,
"<not set>"
);
}
return
(
0
);
}
/*--------------------------------------------------------------------*/
static
void
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment