l i n u x - u s e r s - g r o u p - o f - d a v i s
L U G O D
 
Next Meeting:
October 7: Social gathering
Next Installfest:
TBD
Latest News:
Aug. 18: Discounts to "Velocity" in NY; come to tonight's "Photography" talk
Page last updated:
2006 Oct 09 12:03

The following is an archive of a post made to our 'vox-tech mailing list' by one of its subscribers.

Report this post as spam:

(Enter your email address)
Re: [vox-tech] Apache and group permissions
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [vox-tech] Apache and group permissions



On Fri, 2006-10-06 at 14:47 -0700, Micah Cowan wrote:
> On Fri, 2006-10-06 at 14:38 -0700, Rod Roark wrote:
> > Replying to myself:
> > 
> > On Friday 06 October 2006 13:35, Rod Roark wrote:
> > > I have a very puzzling (to me) problem.  I'm working with a Mandriva
> > > box running Apache 2.0.54.  It runs as user nobody with its group ID
> > > set to -1 -- i.e. httpd.conf includes:
> > > 
> > >     User nobody
> > >     Group #-1
> > 
> > It turns out if I change it to "Group nogroup", everything works.
> > 
> > So is setgid(-1) supposed to disable group permissions?  I have never
> > seen that documented....
> 
> No, it would probably set the group id to 65535 on most systems (which
> is frequently called "nobody").
> 
> The problem is that the groups listed in /etc/group are "supplementary"
> groups, and a simple setgid or setuid don't by themselves load the
> supplementary group information for the new user into the kernel's
> process table for that process. Something else is required, but I'm not
> entirely sure what that something is for non-interactive scripts.

The command "newgrp" is used to "log in" as a new group. This can be
used to spawn a new shell with the specified group. For instance,
running a shell-script CGI program, you could probably get it to do what
you want by changing the shebang line from:

#!/bin/sh

to:

#!/usr/bin/newgrp faxgroup

newgrp uses the system call setgroups() to accomplish what it needs to.
I'm still not sure what the appropriate way to get this working in PHP
would be, though.

-- 
Micah J. Cowan
Programmer, musician, typesetting enthusiast, gamer...
http://micah.cowan.name/


_______________________________________________
vox-tech mailing list
vox-tech@lists.lugod.org
http://lists.lugod.org/mailman/listinfo/vox-tech



LinkedIn
LUGOD Group on LinkedIn
Sign up for LUGOD event announcements
Your email address:
facebook
LUGOD Group on Facebook
'Like' LUGOD on Facebook:

Hosting provided by:
Sunset Systems
Sunset Systems offers preconfigured Linux systems, remote system administration and custom software development.

LUGOD: Linux Users' Group of Davis
PO Box 2082, Davis, CA 95617
Contact Us

LUGOD is a 501(c)7 non-profit organization
based in Davis, California
and serving the Sacramento area.
"Linux" is a trademark of Linus Torvalds.

Sponsored in part by:
Sunset Systems
Who graciously hosts our website & mailing lists!