NetBSD-Bugs archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
Re: bin/58713: httpd: CGIs have wrong cwd
The following reply was made to PR bin/58713; it has been noted by GNATS.
From: nia <nia%NetBSD.org@localhost>
To: gnats-bugs%NetBSD.org@localhost
Cc:
Subject: Re: bin/58713: httpd: CGIs have wrong cwd
Date: Tue, 6 Oct 2026 23:36:59 +0000
--gFozmR4EQ2aGyEcT
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
This patch is not enough for my use case, you also need to set the PWD
environment variable, e.g.
--gFozmR4EQ2aGyEcT
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment; filename=cgi-bozo.patch
Index: cgi-bozo.c
===================================================================
RCS file: /cvsroot/src/libexec/httpd/cgi-bozo.c,v
retrieving revision 1.57
diff -u -r1.57 cgi-bozo.c
--- cgi-bozo.c 11 Jun 2026 05:44:11 -0000 1.57
+++ cgi-bozo.c 6 Oct 2026 23:35:52 -0000
@@ -493,6 +493,7 @@
(request->hr_remotehost && *request->hr_remotehost ? 1 : 0) +
(request->hr_remoteaddr && *request->hr_remoteaddr ? 1 : 0) +
(cgihandler ? 1 : 0) +
+ (httpd->cgibin ? 1 : 0) +
bozo_auth_cgi_count(request) +
(request->hr_serverport && *request->hr_serverport ? 1 : 0);
@@ -568,6 +569,12 @@
bozo_setenv(httpd, "REMOTE_ADDR", request->hr_remoteaddr,
curenvp++);
/*
+ * RFC3875 The current working directory for the script SHOULD
+ * be set to the directory containing the script.
+ */
+ if (httpd->cgibin)
+ bozo_setenv(httpd, "PWD", httpd->cgibin, curenvp++);
+ /*
* Apache does this when invoking content handlers, and PHP
* 5.3 requires it as a "security" measure.
*/
@@ -608,6 +615,9 @@
closelog();
bozo_daemon_closefds(httpd);
+ if (httpd->cgibin && chdir(httpd->cgibin) == -1)
+ bozoerr(httpd, 1, "failed to chdir(2)");
+
if (-1 == execve(path, argv, envp)) {
int saveerrno = errno;
bozo_http_error(httpd, 404, request,
Index: bozohttpd.8
===================================================================
RCS file: /cvsroot/src/libexec/httpd/bozohttpd.8,v
retrieving revision 1.102
diff -u -r1.102 bozohttpd.8
--- bozohttpd.8 8 May 2026 16:46:40 -0000 1.102
+++ bozohttpd.8 6 Oct 2026 23:35:52 -0000
@@ -26,7 +26,7 @@
.\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
.\" SUCH DAMAGE.
.\"
-.Dd May 8, 2026
+.Dd October 7, 2026
.Dt BOZOHTTPD 8
.Os
.Sh NAME
@@ -110,16 +110,21 @@
should be any normal file suffix, and the
.Ar cgihandler
should be a full path to an interpreter.
-This option is the only way to enable CGI programs that exist
-outside of the cgibin directory to be executed.
+This option is the only way to enable CGI programs to be executed
+outside of the
+.Ql /cgi-bin
+prefix.
Multiple
.Fl C
options may be passed.
+.Pp
+Note that ordinary script interpreters that are not CGI-aware can not
+be used directly, see the examples below.
.It Fl c Ar cgibin
Enables the CGI/1.1 interface.
-The
.Ar cgibin
-directory is expected to contain the CGI programs to be used.
+is an absolute path to a file system directory expected to contain
+the CGI programs to be used.
.Nm
looks for URLs in the form of
.Ql /cgi-bin/ Ns Ar scriptname
--gFozmR4EQ2aGyEcT--
Home |
Main Index |
Thread Index |
Old Index