Allow for xrdp not being able to delete PID file
If xrdp is running with dropped privileges it won't be able to delete the PID file it's created. Places where xrdp is stopped need to cater for this. It's prefereable to do this than make the PID file writeable by xrdp with dropped privileges, as this can still lead to DoS attacks if an attacker manages to modify the PID file from a compromised xrdp process.
This commit is contained in:
@@ -98,6 +98,9 @@ endif
|
||||
if FREEBSD
|
||||
# must be tab below
|
||||
install-data-hook:
|
||||
sed -i '' 's|%%PREFIX%%|$(prefix)|g' $(DESTDIR)$(sysconfdir)/rc.d/xrdp \
|
||||
$(DESTDIR)$(sysconfdir)/rc.d/xrdp-sesman
|
||||
sed -e 's|%%PREFIX%%|$(prefix)|g' \
|
||||
-e 's|%%LOCALSTATEDIR%%|$(localstatedir)|g' \
|
||||
-i '' \
|
||||
$(DESTDIR)$(sysconfdir)/rc.d/xrdp \
|
||||
$(DESTDIR)$(sysconfdir)/rc.d/xrdp-sesman
|
||||
endif
|
||||
|
||||
@@ -116,7 +116,7 @@ case "$1" in
|
||||
log_progress_msg $NAME
|
||||
if pidofproc -p $PIDDIR/$NAME.pid $DAEMON > /dev/null; then
|
||||
start-stop-daemon --stop --quiet --oknodo --pidfile $PIDDIR/$NAME.pid \
|
||||
--exec $DAEMON
|
||||
--remove-pidfile --exec $DAEMON
|
||||
value=$?
|
||||
[ $value -gt 0 ] && exitval=$value
|
||||
else
|
||||
|
||||
@@ -48,6 +48,7 @@ command="%%PREFIX%%/sbin/xrdp"
|
||||
allstart_cmd="xrdp_allstart"
|
||||
allstop_cmd="xrdp_allstop"
|
||||
allrestart_cmd="xrdp_allrestart"
|
||||
stop_postcmd="xrdp_poststop"
|
||||
|
||||
xrdp_allstart()
|
||||
{
|
||||
@@ -79,4 +80,10 @@ xrdp_allrestart()
|
||||
run_rc_command "restart"
|
||||
}
|
||||
|
||||
xrdp_poststop()
|
||||
{
|
||||
# If running with dropped privileges, xrdp can't delete its own
|
||||
# PID file
|
||||
rm -f %%LOCALSTATEDIR%%/run/xrdp.pid
|
||||
}
|
||||
run_rc_command "$1"
|
||||
|
||||
Reference in New Issue
Block a user