Page MenuHomeFreeBSD

Further improve www/uwsgi daemon/socket security
ClosedPublic

Authored by feld on Jan 31 2017, 3:40 PM.
Tags
None
Referenced Files
F82889534: D9398.diff
Fri, May 3, 3:26 PM
Unknown Object (File)
Fri, Apr 26, 6:06 PM
Unknown Object (File)
Fri, Apr 26, 5:59 PM
Unknown Object (File)
Fri, Apr 26, 5:58 PM
Unknown Object (File)
Fri, Apr 26, 1:47 PM
Unknown Object (File)
Tue, Apr 23, 11:11 PM
Unknown Object (File)
Tue, Apr 23, 11:08 PM
Unknown Object (File)
Tue, Apr 23, 11:08 PM

Details

Summary

Make uwsgi daemon run under its own user/group by default
Introduce setting to control socket ownership, permitting www:www access by default

This provides a clear separation between the daemon and the webserver while maintaining
compatibilty.

Diff Detail

Repository
rP FreeBSD ports repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

feld retitled this revision from to Further improve www/uwsgi daemon/socket security.
feld updated this object.
feld edited the test plan for this revision. (Show Details)
feld added a reviewer: AMDmi3.
AMDmi3 edited edge metadata.

LGTM. Additional UPDATING entry would be nice too

This revision is now accepted and ready to land.Jan 31 2017, 3:42 PM

adding demon, as this is his port

This revision was automatically updated to reflect the committed changes.