NetBSD-Bugs archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: bin/58713: httpd: CGIs have wrong cwd



The following reply was made to PR bin/58713; it has been noted by GNATS.

From: nia <nia%NetBSD.org@localhost>
To: gnats-bugs%NetBSD.org@localhost
Cc: 
Subject: Re: bin/58713: httpd: CGIs have wrong cwd
Date: Tue, 6 Oct 2026 23:36:59 +0000

 --gFozmR4EQ2aGyEcT
 Content-Type: text/plain; charset=us-ascii
 Content-Disposition: inline
 
 This patch is not enough for my use case, you also need to set the PWD
 environment variable, e.g.
 
 
 --gFozmR4EQ2aGyEcT
 Content-Type: text/x-diff; charset=us-ascii
 Content-Disposition: attachment; filename=cgi-bozo.patch
 
 Index: cgi-bozo.c
 ===================================================================
 RCS file: /cvsroot/src/libexec/httpd/cgi-bozo.c,v
 retrieving revision 1.57
 diff -u -r1.57 cgi-bozo.c
 --- cgi-bozo.c	11 Jun 2026 05:44:11 -0000	1.57
 +++ cgi-bozo.c	6 Oct 2026 23:35:52 -0000
 @@ -493,6 +493,7 @@
  	    (request->hr_remotehost && *request->hr_remotehost ? 1 : 0) +
  	    (request->hr_remoteaddr && *request->hr_remoteaddr ? 1 : 0) +
  	    (cgihandler ? 1 : 0) +
 +	    (httpd->cgibin ? 1 : 0) +
  	    bozo_auth_cgi_count(request) +
  	    (request->hr_serverport && *request->hr_serverport ? 1 : 0);
  
 @@ -568,6 +569,12 @@
  		bozo_setenv(httpd, "REMOTE_ADDR", request->hr_remoteaddr,
  				curenvp++);
  	/*
 +	 * RFC3875 The current working directory for the script SHOULD
 +	 * be set to the directory containing the script.
 +	 */
 +	if (httpd->cgibin)
 +		bozo_setenv(httpd, "PWD", httpd->cgibin, curenvp++);
 +	/*
  	 * Apache does this when invoking content handlers, and PHP
  	 * 5.3 requires it as a "security" measure.
  	 */
 @@ -608,6 +615,9 @@
  		closelog();
  		bozo_daemon_closefds(httpd);
  
 +		if (httpd->cgibin && chdir(httpd->cgibin) == -1)
 +			bozoerr(httpd, 1, "failed to chdir(2)");
 +
  		if (-1 == execve(path, argv, envp)) {
  			int saveerrno = errno;
  			bozo_http_error(httpd, 404, request,
 Index: bozohttpd.8
 ===================================================================
 RCS file: /cvsroot/src/libexec/httpd/bozohttpd.8,v
 retrieving revision 1.102
 diff -u -r1.102 bozohttpd.8
 --- bozohttpd.8	8 May 2026 16:46:40 -0000	1.102
 +++ bozohttpd.8	6 Oct 2026 23:35:52 -0000
 @@ -26,7 +26,7 @@
  .\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
  .\" SUCH DAMAGE.
  .\"
 -.Dd May 8, 2026
 +.Dd October 7, 2026
  .Dt BOZOHTTPD 8
  .Os
  .Sh NAME
 @@ -110,16 +110,21 @@
  should be any normal file suffix, and the
  .Ar cgihandler
  should be a full path to an interpreter.
 -This option is the only way to enable CGI programs that exist
 -outside of the cgibin directory to be executed.
 +This option is the only way to enable CGI programs to be executed
 +outside of the
 +.Ql /cgi-bin
 +prefix.
  Multiple
  .Fl C
  options may be passed.
 +.Pp
 +Note that ordinary script interpreters that are not CGI-aware can not
 +be used directly, see the examples below.
  .It Fl c Ar cgibin
  Enables the CGI/1.1 interface.
 -The
  .Ar cgibin
 -directory is expected to contain the CGI programs to be used.
 +is an absolute path to a file system directory expected to contain
 +the CGI programs to be used.
  .Nm
  looks for URLs in the form of
  .Ql /cgi-bin/ Ns Ar scriptname
 
 --gFozmR4EQ2aGyEcT--
 



Home | Main Index | Thread Index | Old Index