On Sat, 25 Apr 2009, Alvaro Lopez Ortega wrote:

> This means that, even if cherokee-worker (the actual web server) was
> running as nobody, it was able to spawn a new PHP fastcgi daemon
> running as the www-data user.
>
> If you guys have the chance, give it a try. I'd love to get feedback
> from you before releasing 0.99.12. The change has been quite big, and
> I wouldn't like to introduce any regression in the upcoming release.

What did you do to prevent executable code to execute the spawn function?
Is it possible to explictly disable respawn as root at configure? (Stack
initialisation of non-zero etc.)


Stefan

_______________________________________________
Cherokee mailing list
[email protected]
http://lists.octality.com/listinfo/cherokee

Reply via email to