Re: daemontools control over sophie not working any more since release 3.04
[email protected] Thu, 29 Sep 2005 16:11:05 +0900
| Newsgroups | gmane.comp.security.virus.vtools |
|---|---|
| Message-ID | <OF8B89348E.3E5A292C-ON4925708B.001C9391-4925708B.002777E3@sophos.com> |
--0__=C6BBFA18DF8F15018f9e8a93df938690918cC6BBFA18DF8F1501 Content-type: text/plain; charset=ISO-2022-JP Uwe, I incorrectly assumed that other processes would use the pid in /var/run/sophie.pid to send signals to Sophie. You are correct that daemontools just uses the pid of the initial process. I've attached a patch that makes the main Sophie process catch and forward any signals it receives to the Sophie working process (the process who's pid is in the sophie.pid file). I've tried using it with daemontools and it seems to work now. Let me know if it works for you. Regards, Scott. (See attached file: sophie-3_04-daemontools_patch.txt) > thank You for the fast reply, let me try to explain the problem we have. > So far we prefered using bernstein´s daemontools instead of the > usual init.d start/stop scripts to control the sophie daemon process. > The use of daemontools garanteed reliable restarts of the sophie > process if it unexpectedly died. We have made good experiences with > daemontools so far. > > Now with sophie version 3.04, if I send signals to sophie (SIGTERM / > SIGHUP) by using the daemontools "svc" command, theses signals go to > the sophie main process and not to the subprocess. I don´t have > deeper knowledge about the way daemontools work, but for me it seems > that svc does not know anything about a sophie subprocess. It does > not fetch the subprocess ID from a pid file like the init.d > start/stop scripts usually do. It only gets the PID at the time, > when it spawns the daemon. In case of sophie, it is the PID of the > main process. > > You can reproduce the problem by sending a TERM signal directly to > the sophie main process. Doing so only terminates the main but not > the child process. This child process even stays alive after > starting a new sophie instance with a new main and subprocess. > > I don´t know much about process signaling, spawning, forking etc. > but wouldn´t it be a cleaner way, if the sophie main process is made > responsable for it´s children? It could catch all incoming signals > and send them to it´s child process(es). So a SIGTERM signal sent to > the main process would also reach the children, the children will > then terminate and at the end the main process terminates itself. > > I hope You now know what a mean. Thank You for Your help > > Uwe > > > [email protected] wrote: > Uwe, > > Sophie 3.04 and Sophie 3.04rc1/2 both switch to an unprivledged user (the > one specified in the user:, group: options in the sophie config file) to > perform scans. The difference is where they actually switch to this user. > > Lets assume sophie is started as root. In 3.04rc2, the main process will > be running as root, which forks child processes to perform the actual > scans. The first thing these child processes to is a setgid, setuid to the > non-root user, group (or whatever is specified in sophie.cfg). In 3.04, > the main process performs the setgid, setuid before the main loop so the > main process and child processes are all running as the non-root user. > This change was necessary because of some semaphores that were added to > libsavi. These have since been removed temporarily I believe, so 3.04rc2 > should work again. > > However, since both versions switch to an unprivileged user, and they use > the same code to do so, I'm not sure why you are having problems now. If > you could provide some more detail as to what exactly the problem is, the > Sophie log, etc, then maybe we can help you out. > > Scott. > > [email protected] wrote on 09/20/2005 06:18:50 PM: > > > Hello List, > > we are using sophie 3.04rc1/2 under the daemontools control for years > without any problems. > Since the last update to release 3.04 there seems to be a significant > change in the way how sophie handles subprocesses. > I read that sophie is now responsable for starting subprocesses which > are run under an unprivileged user account. Does that mean that sophie > now needs to be run as root to be able to change the user for the > subprocess? > We never ran sophie as root so far. Under daemontools we always changed > to an unprivileged user with the setuidgid command before starting > > sophie. > > Is version 3.04 not compatible with daemontools any more? If so, was the > change in source code absolutely necessary to work properly? What to do > to make it work under daemontools? > > Thanke You, Uwe > _______________________________________________ > vtools mailing list > [email protected] > http://www.vanja.com/list/listinfo.cgi/vtools > > > _______________________________________________ > vtools mailing list > [email protected] > http://www.vanja.com/list/listinfo.cgi/vtools > > > _______________________________________________ > vtools mailing list > [email protected] > http://www.vanja.com/list/listinfo.cgi/vtools --0__=C6BBFA18DF8F15018f9e8a93df938690918cC6BBFA18DF8F1501 Content-type: application/octet-stream; name="=?ISO-2022-JP?B?c29waGllLTNfMDQtZGFlbW9udG9vbHNfcGF0Y2gudHh0?=" Content-Disposition: attachment; filename="=?ISO-2022-JP?B?c29waGllLTNfMDQtZGFlbW9udG9vbHNfcGF0Y2gudHh0?=" Content-Transfer-Encoding: base64 LS0tIHNvcGhpZS5jLm9yaWdpbmFsCTIwMDUtMDktMjkgMTQ6Mzg6MzUuMDAwMDAwMDAwICswOTAw CisrKyBzb3BoaWUuYwkyMDA1LTA5LTI5IDE0OjM4OjU5LjAwMDAwMDAwMCArMDkwMApAQCAtNDIs NiArNDIsOSBAQAogLyogQ29uZmlndXJhdGlvbiBmaWxlICovCiBjaGFyIGNvbmZpZ19maWxlW01B WFBBVEhMRU5dOwogCisvKiB3b3JraW5nIHByb2Nlc3MgcGlkICovCitwaWRfdCB3cGlkID0gMDsK KwogLyogUHJpbnQgdGhlIHVzYWdlICovCiBzdGF0aWMgdm9pZCB1c2FnZSh2b2lkKQogewpAQCAt MTE3LDYgKzEyMCwxMiBAQAogCWV4aXQoMCk7CiB9CiAKK3ZvaWQgc2lnX21haW5fZ2VuZXJhbChp bnQgc2lnKQoreworCXNvcGhpZV9wcmludCgwLCAiJXMgU0lHTkFMICclZCcgY2F1Z2h0IC0gZm9y d2FyZGluZyB0byB3b3JraW5nIHByb2Nlc3MiLCBOT1RFU1RSLCBzaWcpOworCWtpbGwod3BpZCwg c2lnKTsKK30KKwogdm9pZCBzaWdfcGlwZShpbnQgc2lnKQogewogLy8Jc29waGllX3ByaW50KDAs ICJTSUdQSVBFIHNpZ25hbCByZWNlaXZlZCAtIGNsaWVudCBwcm9iYWJseSBkaXNjb25uZWN0ZWQi KTsKQEAgLTU0Nyw2ICs1NTYsMTQgQEAKICAgICAgICAgICAgIGZwcmludGYoZiwgIiV1XG4iLCAo dV9pbnQpIGNwaWQpOwogICAgICAgICAgICAgZmNsb3NlKGYpOwogICAgICAgICB9CisJCXdwaWQg PSBjcGlkOworCisJCXNpZ25hbChTSUdBTFJNLCBTSUdfSUdOKTsKKwkJc2lnbmFsKFNJR0hVUCwg c2lnX21haW5fZ2VuZXJhbCk7CisJCXNpZ25hbChTSUdJTlQsIHNpZ19tYWluX2dlbmVyYWwpOwor CQlzaWduYWwoU0lHVEVSTSwgc2lnX21haW5fZ2VuZXJhbCk7CisJCXNpZ25hbChTSUdRVUlULCBz aWdfbWFpbl9nZW5lcmFsKTsKKwkJc2lnbmFsKFNJR1NFR1YsIHNpZ19tYWluX2dlbmVyYWwpOwog CiAgICAgICAgIHdhaXRwaWQoY3BpZCwgJm1zdGF0dXMsIDApOyAgICAgICAgCiAgICAgICAgIGNs ZWFudXAoKTsK --0__=C6BBFA18DF8F15018f9e8a93df938690918cC6BBFA18DF8F1501 Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Disposition: inline Content-Transfer-Encoding: 7bit _______________________________________________ vtools mailing list [email protected] http://www.vanja.com/list/listinfo.cgi/vtools --0__=C6BBFA18DF8F15018f9e8a93df938690918cC6BBFA18DF8F1501--