suexec-custom checks cannot be disabled

Bug #673289 reported by Bradley M. Froehle
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
apache2 (Ubuntu)
Fix Released
Wishlist
Unassigned

Bug Description

Binary package hint: apache2

apache2-suexec-custom:
  Installed: 2.2.14-5ubuntu8.3

apache2-suexec-custom claims in /etc/apache2/suexec/www-data that
  # The first two lines contain the suexec document root and the suexec userdir
  # suffix. Both features can be disabled separately by prepending a # character.
  # This config file is only used by the apache2-suexec-custom package.

however the actual suexec binary will not allow for the override --- simply prepending by a # character gives errors, e.g.,
/var/log/apache2/error.log:
  [Tue Nov 09 15:50:21 2010] [warn] FastCGI: (dynamic) server "/srv/website1/.fcgi-bin/php5.fcgi" (pid 9279) terminated by calling exit with status '127'
/var/log/apache2/suexec.log:
  [2010-11-09 15:50:21]: docroot disabled in /etc/apache2/suexec/www-data

Since the feature cannot be disabled by prepending a # character --- simply read the source to see that this is the case --- I recommend changing the documentation to remove any mention of disabling the feature.

Tags: suexec

Related branches

Mathias Gug (mathiaz)
Changed in apache2 (Ubuntu):
importance: Undecided → Wishlist
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package apache2 - 2.2.16-4ubuntu1

---------------
apache2 (2.2.16-4ubuntu1) natty; urgency=low

  * Merge from debian unstable. Remaining changes:
    - debian/{control, rules}: Enable PIE hardening.
    - debian/{control, rules, apache2.2-common.ufw.profile}: Add ufw profiles.
    - debian/control: Add bzr tag and point it to our tree

apache2 (2.2.16-4) unstable; urgency=medium

  * Increase the mod_reqtimeout default timeouts to avoid potential problems
    with CRL-requesting browsers. Also extend the comments in reqtimeout.conf.
  * Remove bogus comment in conf.d/security about default in the "release
    after Lenny".
  * Clarify comments in suexec-custom's default config file. LP: #673289
 -- Chuck Short <email address hidden> Sun, 14 Nov 2010 23:31:45 +0000

Changed in apache2 (Ubuntu):
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.