X-Git-Url: https://git.proxmox.com/?a=blobdiff_plain;f=data%2FPVE%2FDaemon.pm;h=9c001e8636e363be0fd559602eb5a6db41e4b75a;hb=c4ad45cf200bc95db0b70c5a4f9b2b82cf27a4f8;hp=b219c73f716caf13aff581e334c3b2e4c4c63118;hpb=517c11257cfee1b17b1e481f17b42d2bac8a9812;p=pve-common.git diff --git a/data/PVE/Daemon.pm b/data/PVE/Daemon.pm index b219c73..9c001e8 100644 --- a/data/PVE/Daemon.pm +++ b/data/PVE/Daemon.pm @@ -12,9 +12,12 @@ package PVE::Daemon; # * handle worker processes (option 'max_workers') # * allow to restart while workers are still runningl # (option 'leave_children_open_on_reload') +# * run as different user using setuid/setgid use strict; use warnings; +use English; + use PVE::SafeSyslog; use PVE::INotify; @@ -181,7 +184,7 @@ my $start_workers = sub { }; my $terminate_server = sub { - my ($self) = @_; + my ($self, $allow_open_children) = @_; $self->{terminate} = 1; # set flag to avoid worker restart @@ -201,7 +204,7 @@ my $terminate_server = sub { } # if configured, leave children running on HUP - return if $self->{got_hup_signal} && + return if $allow_open_children && $self->{leave_children_open_on_reload}; # else, send TERM to old workers @@ -293,7 +296,7 @@ my $server_run = sub { local $SIG{TERM} = sub { local ($@, $!, $?); # do not overwrite error vars syslog('info', "received signal TERM"); - &$terminate_server($self); + &$terminate_server($self, 0); &$server_cleanup($self); &$old_sig_term(@_) if $old_sig_term; }; @@ -302,7 +305,7 @@ my $server_run = sub { local $SIG{QUIT} = sub { local ($@, $!, $?); # do not overwrite error vars syslog('info', "received signal QUIT"); - &$terminate_server($self); + &$terminate_server($self, 0); &$server_cleanup($self); &$old_sig_quit(@_) if $old_sig_quit; }; @@ -312,7 +315,7 @@ my $server_run = sub { local ($@, $!, $?); # do not overwrite error vars syslog('info', "received signal INT"); $SIG{INT} = 'DEFAULT'; # allow to terminate now - &$terminate_server($self); + &$terminate_server($self, 0); &$server_cleanup($self); &$old_sig_int(@_) if $old_sig_int; }; @@ -322,7 +325,7 @@ my $server_run = sub { syslog('info', "received signal HUP"); $self->{got_hup_signal} = 1; if ($self->{max_workers}) { - &$terminate_server($self); + &$terminate_server($self, 1); } elsif ($self->can('hup')) { eval { $self->hup() }; warn $@ if $@; @@ -358,7 +361,7 @@ my $server_run = sub { if ($err) { syslog ('err', "ERROR: $err"); - &$terminate_server($self); + &$terminate_server($self, 1); if (my $wait_time = $self->{restart_on_error}) { $self->restart_daemon($wait_time); @@ -427,11 +430,30 @@ sub new { $self->{$opt} = $value; } elsif ($opt eq 'leave_children_open_on_reload') { $self->{$opt} = $value; + } elsif ($opt eq 'setgid') { + $self->{$opt} = $value; + } elsif ($opt eq 'setuid') { + $self->{$opt} = $value; } else { die "unknown daemon option '$opt'\n"; } } + if (my $gidstr = $self->{setgid}) { + my $gid = getgrnam($gidstr) || die "getgrnam failed - $!\n"; + POSIX::setgid($gid) || die "setgid $gid failed - $!\n"; + $EGID = "$gid $gid"; # this calls setgroups + # just to be sure + die "detected strange gid\n" if !($GID eq "$gid $gid" && $EGID eq "$gid $gid"); + } + + if (my $uidstr = $self->{setuid}) { + my $uid = getpwnam($uidstr) || die "getpwnam failed - $!\n"; + POSIX::setuid($uid) || die "setuid $uid failed - $!\n"; + # just to be sure + die "detected strange uid\n" if !($UID == $uid && $EUID == $uid); + } + if ($restart && $self->{max_workers}) { if (my $wpids = $ENV{PVE_DAEMON_WORKER_PIDS}) { foreach my $pid (split(':', $wpids)) {