[cpp-sp] 23/34: Additional documentation and formatting for DAEMON_USER support

Scott Cantor cantor.2 at osu.edu
Thu Dec 20 19:43:29 EST 2018


This is an automated email from the git hooks/post-receive script.

scantor pushed a commit to annotated tag debian/2.3+dfsg-1
in repository cpp-sp.

View the commit online:
http://git.shibboleth.net/view/?p=cpp-sp.git;a=commit;h=ca07de6cdc40b932f6d5079e264a91c4eddd1cd2

commit ca07de6cdc40b932f6d5079e264a91c4eddd1cd2
Author: Russ Allbery <rra at debian.org>
AuthorDate: Tue Nov 10 16:43:57 2009 -0800

    Additional documentation and formatting for DAEMON_USER support
    
    Add a comment to the init script explaining what's going on with the
    DAEMON_USER support and reformat to keep lines below 80 columns.
---
 configs/shibd-debian.in | 14 +++++++++++---
 1 file changed, 11 insertions(+), 3 deletions(-)

diff --git a/configs/shibd-debian.in b/configs/shibd-debian.in
index 6404233..cbe55e6 100644
--- a/configs/shibd-debian.in
+++ b/configs/shibd-debian.in
@@ -56,15 +56,23 @@ prepare_environment () {
     # Ensure @-PKGRUNDIR-@ exists.  /var/run may be on a tmpfs file system.
     [ -d '@-PKGRUNDIR-@' ] || mkdir -p '@-PKGRUNDIR-@'
 
+    # If $DAEMON_USER is set, try to run _shibd as that user.  However,
+    # versions of the Debian package prior to 2.3+dfsg-1 ran shibd as root,
+    # and the local administrator may not have made the server's private key
+    # readable by _shibd.  We therefore test first by running shibd -t and
+    # looking for the error code indicating that the private key could not be
+    # read.  If we get that error, we fall back on running shibd as root.
     if [ -n "$DAEMON_USER" ]; then
-        if DIAG=$(su -s $DAEMON $DAEMON_USER -- -t $DAEMON_OPTS 2>/dev/null); then
+        DIAG=$(su -s $DAEMON $DAEMON_USER -- -t $DAEMON_OPTS 2>/dev/null)
+        if [ $? != 0 ] ; then
             # openssl errstr 200100D (hex for 33558541) says:
             # error:0200100D:system library:fopen:Permission denied
-            if  echo "$DIAG" | fgrep -q 'ERROR OpenSSL : error code: 33558541 '; then
+            ERROR='ERROR OpenSSL : error code: 33558541 '
+            if echo "$DIAG" | fgrep -q "$ERROR" ; then
                 unset DAEMON_USER
                 echo "$NAME warning: file permissions require running as root"
             else
-                chown -R "$DAEMON_USER" '@-PKGRUNDIR-@' '@-PKGLOGDIR-@'
+                chown -Rh "$DAEMON_USER" '@-PKGRUNDIR-@' '@-PKGLOGDIR-@'
             fi
         else
             unset DAEMON_USER

-- 
To stop receiving notification emails like this one, please contact
the administrator of this repository.


More information about the commits mailing list