mirror of
https://github.com/clearlinux/uwsgi.git
synced 2026-08-19 03:57:21 +00:00
added --whitelist and --blacklist context
This commit is contained in:
+17
-3
@@ -1504,7 +1504,7 @@ void add_exported_option(char *key, char *value, int configured) {
|
||||
|
||||
while (blacklist) {
|
||||
if (!strcmp(key, blacklist->value)) {
|
||||
uwsgi_log("uWSGI error: forbidden option \"%s\"\n", key);
|
||||
uwsgi_log("uWSGI error: forbidden option \"%s\" (by blacklist)\n", key);
|
||||
exit(1);
|
||||
}
|
||||
blacklist = blacklist->next;
|
||||
@@ -1520,11 +1520,25 @@ void add_exported_option(char *key, char *value, int configured) {
|
||||
whitelist = whitelist->next;
|
||||
}
|
||||
if (!allowed) {
|
||||
uwsgi_log("uWSGI error: forbidden option \"%s\"\n", key);
|
||||
uwsgi_log("uWSGI error: forbidden option \"%s\" (by whitelist)\n", key);
|
||||
exit(1);
|
||||
}
|
||||
}
|
||||
|
||||
if (uwsgi.blacklist_context) {
|
||||
if (uwsgi_list_has_str(uwsgi.blacklist_context, key)) {
|
||||
uwsgi_log("uWSGI error: forbidden option \"%s\" (by blacklist)\n", key);
|
||||
exit(1);
|
||||
}
|
||||
}
|
||||
|
||||
if (uwsgi.whitelist_context) {
|
||||
if (!uwsgi_list_has_str(uwsgi.whitelist_context, key)) {
|
||||
uwsgi_log("uWSGI error: forbidden option \"%s\" (by whitelist)\n", key);
|
||||
exit(1);
|
||||
}
|
||||
}
|
||||
|
||||
if (uwsgi.logic_opt_running)
|
||||
goto add;
|
||||
|
||||
@@ -1839,7 +1853,7 @@ int uwsgi_list_has_num(char *list, int num) {
|
||||
|
||||
int uwsgi_list_has_str(char *list, char *str) {
|
||||
|
||||
char *list2 = uwsgi_concat2(list + 1, "");
|
||||
char *list2 = uwsgi_str(list);
|
||||
|
||||
char *p = strtok(list2, " ");
|
||||
while (p != NULL) {
|
||||
|
||||
@@ -109,6 +109,12 @@ static struct uwsgi_option uwsgi_base_options[] = {
|
||||
|
||||
{"endif", optional_argument, 0, "(opt logic) end if", uwsgi_opt_noop, NULL, UWSGI_OPT_IMMEDIATE},
|
||||
|
||||
{"blacklist", required_argument, 0, "set options blacklist context", uwsgi_opt_set_str, &uwsgi.blacklist_context, UWSGI_OPT_IMMEDIATE},
|
||||
{"end-blacklist", no_argument, 0, "clear options blacklist context", uwsgi_opt_set_null, &uwsgi.blacklist_context, UWSGI_OPT_IMMEDIATE},
|
||||
|
||||
{"whitelist", required_argument, 0, "set options whitelist context", uwsgi_opt_set_str, &uwsgi.whitelist_context, UWSGI_OPT_IMMEDIATE},
|
||||
{"end-whitelist", no_argument, 0, "clear options whitelist context", uwsgi_opt_set_null, &uwsgi.whitelist_context, UWSGI_OPT_IMMEDIATE},
|
||||
|
||||
{"ignore-sigpipe", no_argument, 0, "do not report (annoying) SIGPIPE", uwsgi_opt_true, &uwsgi.ignore_sigpipe, 0},
|
||||
{"ignore-write-errors", no_argument, 0, "do not report (annoying) write()/writev() errors", uwsgi_opt_true, &uwsgi.ignore_write_errors, 0},
|
||||
{"write-errors-tolerance", required_argument, 0, "set the maximum number of allowed write errors (default: no tolerance)", uwsgi_opt_set_64bit, &uwsgi.write_errors_tolerance, 0},
|
||||
@@ -3225,6 +3231,12 @@ void uwsgi_opt_set_str(char *opt, char *value, void *key) {
|
||||
*ptr = (char *) value;
|
||||
}
|
||||
|
||||
void uwsgi_opt_set_null(char *opt, char *value, void *key) {
|
||||
char **ptr = (char **) key;
|
||||
*ptr = NULL;
|
||||
}
|
||||
|
||||
|
||||
void uwsgi_opt_set_logger(char *opt, char *value, void *prefix) {
|
||||
|
||||
if (!value)
|
||||
|
||||
@@ -1503,53 +1503,55 @@ struct uwsgi_server {
|
||||
|
||||
struct uwsgi_instance_status status;
|
||||
|
||||
struct uwsgi_string_list *get_list;
|
||||
struct uwsgi_string_list *get_list;
|
||||
|
||||
// enable threads
|
||||
int has_threads;
|
||||
int no_threads_wait;
|
||||
// enable threads
|
||||
int has_threads;
|
||||
int no_threads_wait;
|
||||
|
||||
// default app id
|
||||
int default_app;
|
||||
// default app id
|
||||
int default_app;
|
||||
|
||||
char *logto2;
|
||||
char *logformat;
|
||||
int logformat_strftime;
|
||||
int logformat_vectors;
|
||||
struct uwsgi_logchunk *logchunks;
|
||||
void (*logit) (struct wsgi_request *);
|
||||
struct iovec **logvectors;
|
||||
char *logto2;
|
||||
char *logformat;
|
||||
int logformat_strftime;
|
||||
int logformat_vectors;
|
||||
struct uwsgi_logchunk *logchunks;
|
||||
void (*logit) (struct wsgi_request *);
|
||||
struct iovec **logvectors;
|
||||
|
||||
// autoload plugins
|
||||
int autoload;
|
||||
struct uwsgi_string_list *plugins_dir;
|
||||
struct uwsgi_string_list *blacklist;
|
||||
struct uwsgi_string_list *whitelist;
|
||||
// autoload plugins
|
||||
int autoload;
|
||||
struct uwsgi_string_list *plugins_dir;
|
||||
struct uwsgi_string_list *blacklist;
|
||||
struct uwsgi_string_list *whitelist;
|
||||
char *blacklist_context;
|
||||
char *whitelist_context;
|
||||
|
||||
int snapshot;
|
||||
int respawn_snapshots;
|
||||
int snapshot;
|
||||
int respawn_snapshots;
|
||||
|
||||
// enable auto-snapshotting
|
||||
int auto_snapshot;
|
||||
pid_t restore_snapshot;
|
||||
// enable auto-snapshotting
|
||||
int auto_snapshot;
|
||||
pid_t restore_snapshot;
|
||||
|
||||
|
||||
unsigned int reloads;
|
||||
unsigned int reloads;
|
||||
|
||||
// leave master running as root
|
||||
int master_as_root;
|
||||
// kill the stack on SIGTERM (instead of brutal reloading)
|
||||
int die_on_term;
|
||||
// leave master running as root
|
||||
int master_as_root;
|
||||
// kill the stack on SIGTERM (instead of brutal reloading)
|
||||
int die_on_term;
|
||||
|
||||
// disable fd passing on unix socket
|
||||
int no_fd_passing;
|
||||
// disable fd passing on unix socket
|
||||
int no_fd_passing;
|
||||
|
||||
// store the current time
|
||||
time_t current_time;
|
||||
// store the current time
|
||||
time_t current_time;
|
||||
|
||||
uint64_t master_cycles;
|
||||
uint64_t master_cycles;
|
||||
|
||||
int reuse_port;
|
||||
int reuse_port;
|
||||
int tcp_fast_open;
|
||||
int tcp_fast_open_client;
|
||||
|
||||
@@ -3178,98 +3180,97 @@ void uwsgi_set_processname(char *);
|
||||
|
||||
int uwsgi_manage_opt(char *, char *);
|
||||
|
||||
void uwsgi_opt_print(char *, char *, void *);
|
||||
void uwsgi_opt_true(char *, char *, void *);
|
||||
void uwsgi_opt_set_str(char *, char *, void *);
|
||||
void uwsgi_opt_set_logger(char *, char *, void *);
|
||||
void uwsgi_opt_set_req_logger(char *, char *, void *);
|
||||
void uwsgi_opt_set_str_spaced(char *, char *, void *);
|
||||
void uwsgi_opt_add_string_list(char *, char *, void *);
|
||||
void uwsgi_opt_add_addr_list(char *, char *, void *);
|
||||
void uwsgi_opt_add_string_list_custom(char *, char *, void *);
|
||||
void uwsgi_opt_add_dyn_dict(char *, char *, void *);
|
||||
void uwsgi_opt_print(char *, char *, void *);
|
||||
void uwsgi_opt_true(char *, char *, void *);
|
||||
void uwsgi_opt_set_str(char *, char *, void *);
|
||||
void uwsgi_opt_set_null(char *, char *, void *);
|
||||
void uwsgi_opt_set_logger(char *, char *, void *);
|
||||
void uwsgi_opt_set_req_logger(char *, char *, void *);
|
||||
void uwsgi_opt_set_str_spaced(char *, char *, void *);
|
||||
void uwsgi_opt_add_string_list(char *, char *, void *);
|
||||
void uwsgi_opt_add_addr_list(char *, char *, void *);
|
||||
void uwsgi_opt_add_string_list_custom(char *, char *, void *);
|
||||
void uwsgi_opt_add_dyn_dict(char *, char *, void *);
|
||||
#ifdef UWSGI_PCRE
|
||||
void uwsgi_opt_pcre_jit(char *, char *, void *);
|
||||
void uwsgi_opt_add_regexp_dyn_dict(char *, char *, void *);
|
||||
void uwsgi_opt_add_regexp_list(char *, char *, void *);
|
||||
void uwsgi_opt_add_regexp_custom_list(char *, char *, void *);
|
||||
void uwsgi_opt_pcre_jit(char *, char *, void *);
|
||||
void uwsgi_opt_add_regexp_dyn_dict(char *, char *, void *);
|
||||
void uwsgi_opt_add_regexp_list(char *, char *, void *);
|
||||
void uwsgi_opt_add_regexp_custom_list(char *, char *, void *);
|
||||
#endif
|
||||
void uwsgi_opt_set_int(char *, char *, void *);
|
||||
void uwsgi_opt_set_rawint(char *, char *, void *);
|
||||
void uwsgi_opt_set_16bit(char *, char *, void *);
|
||||
void uwsgi_opt_set_64bit(char *, char *, void *);
|
||||
void uwsgi_opt_set_megabytes(char *, char *, void *);
|
||||
void uwsgi_opt_set_dyn(char *, char *, void *);
|
||||
void uwsgi_opt_dyn_true(char *, char *, void *);
|
||||
void uwsgi_opt_dyn_false(char *, char *, void *);
|
||||
void uwsgi_opt_set_placeholder(char *, char *, void *);
|
||||
void uwsgi_opt_add_shared_socket(char *, char *, void *);
|
||||
void uwsgi_opt_add_socket(char *, char *, void *);
|
||||
void uwsgi_opt_add_lazy_socket(char *, char *, void *);
|
||||
void uwsgi_opt_add_cron(char *, char *, void *);
|
||||
void uwsgi_opt_load_plugin(char *, char *, void *);
|
||||
void uwsgi_opt_load_dl(char *, char *, void *);
|
||||
void uwsgi_opt_load(char *, char *, void *);
|
||||
|
||||
void uwsgi_opt_set_int(char *, char *, void *);
|
||||
void uwsgi_opt_set_rawint(char *, char *, void *);
|
||||
void uwsgi_opt_set_16bit(char *, char *, void *);
|
||||
void uwsgi_opt_set_64bit(char *, char *, void *);
|
||||
void uwsgi_opt_set_megabytes(char *, char *, void *);
|
||||
void uwsgi_opt_set_dyn(char *, char *, void *);
|
||||
void uwsgi_opt_dyn_true(char *, char *, void *);
|
||||
void uwsgi_opt_dyn_false(char *, char *, void *);
|
||||
void uwsgi_opt_set_placeholder(char *, char *, void *);
|
||||
void uwsgi_opt_add_shared_socket(char *, char *, void *);
|
||||
void uwsgi_opt_add_socket(char *, char *, void *);
|
||||
void uwsgi_opt_add_lazy_socket(char *, char *, void *);
|
||||
void uwsgi_opt_add_cron(char *, char *, void *);
|
||||
void uwsgi_opt_load_plugin(char *, char *, void *);
|
||||
void uwsgi_opt_load_dl(char *, char *, void *);
|
||||
void uwsgi_opt_load(char *, char *, void *);
|
||||
#ifdef UWSGI_SSL
|
||||
void uwsgi_opt_sni(char *, char *, void *);
|
||||
struct uwsgi_string_list *uwsgi_ssl_add_sni_item(char *, char *, char *, char *, char *);
|
||||
void uwsgi_opt_sni(char *, char *, void *);
|
||||
struct uwsgi_string_list *uwsgi_ssl_add_sni_item(char *, char *, char *, char *, char *);
|
||||
#endif
|
||||
|
||||
void uwsgi_opt_flock(char *, char *, void *);
|
||||
void uwsgi_opt_flock_wait(char *, char *, void *);
|
||||
void uwsgi_opt_flock(char *, char *, void *);
|
||||
void uwsgi_opt_flock_wait(char *, char *, void *);
|
||||
#ifdef UWSGI_INI
|
||||
void uwsgi_opt_load_ini(char *, char *, void *);
|
||||
void uwsgi_opt_load_ini(char *, char *, void *);
|
||||
#endif
|
||||
#ifdef UWSGI_XML
|
||||
void uwsgi_opt_load_xml(char *, char *, void *);
|
||||
void uwsgi_opt_load_xml(char *, char *, void *);
|
||||
#endif
|
||||
#ifdef UWSGI_YAML
|
||||
void uwsgi_opt_load_yml(char *, char *, void *);
|
||||
void uwsgi_opt_load_yml(char *, char *, void *);
|
||||
#endif
|
||||
#ifdef UWSGI_SQLITE3
|
||||
void uwsgi_opt_load_sqlite3(char *, char *, void *);
|
||||
void uwsgi_opt_load_sqlite3(char *, char *, void *);
|
||||
#endif
|
||||
#ifdef UWSGI_JSON
|
||||
void uwsgi_opt_load_json(char *, char *, void *);
|
||||
void uwsgi_opt_load_json(char *, char *, void *);
|
||||
#endif
|
||||
#ifdef UWSGI_LDAP
|
||||
void uwsgi_opt_load_ldap(char *, char *, void *);
|
||||
void uwsgi_opt_load_ldap(char *, char *, void *);
|
||||
#endif
|
||||
|
||||
void uwsgi_opt_set_umask(char *, char *, void *);
|
||||
void uwsgi_opt_add_spooler(char *, char *, void *);
|
||||
void uwsgi_opt_add_daemon(char *, char *, void *);
|
||||
void uwsgi_opt_set_uid(char *, char *, void *);
|
||||
void uwsgi_opt_set_gid(char *, char *, void *);
|
||||
void uwsgi_opt_set_env(char *, char *, void *);
|
||||
void uwsgi_opt_unset_env(char *, char *, void *);
|
||||
void uwsgi_opt_pidfile_signal(char *, char *, void *);
|
||||
void uwsgi_opt_set_umask(char *, char *, void *);
|
||||
void uwsgi_opt_add_spooler(char *, char *, void *);
|
||||
void uwsgi_opt_add_daemon(char *, char *, void *);
|
||||
void uwsgi_opt_set_uid(char *, char *, void *);
|
||||
void uwsgi_opt_set_gid(char *, char *, void *);
|
||||
void uwsgi_opt_set_env(char *, char *, void *);
|
||||
void uwsgi_opt_unset_env(char *, char *, void *);
|
||||
void uwsgi_opt_pidfile_signal(char *, char *, void *);
|
||||
|
||||
void uwsgi_opt_check_static(char *, char *, void *);
|
||||
void uwsgi_opt_fileserve_mode(char *, char *, void *);
|
||||
void uwsgi_opt_static_map(char *, char *, void *);
|
||||
void uwsgi_opt_check_static(char *, char *, void *);
|
||||
void uwsgi_opt_fileserve_mode(char *, char *, void *);
|
||||
void uwsgi_opt_static_map(char *, char *, void *);
|
||||
|
||||
void uwsgi_opt_add_mule(char *, char *, void *);
|
||||
void uwsgi_opt_add_mules(char *, char *, void *);
|
||||
void uwsgi_opt_add_farm(char *, char *, void *);
|
||||
void uwsgi_opt_add_mule(char *, char *, void *);
|
||||
void uwsgi_opt_add_mules(char *, char *, void *);
|
||||
void uwsgi_opt_add_farm(char *, char *, void *);
|
||||
|
||||
void uwsgi_opt_signal(char *, char *, void *);
|
||||
void uwsgi_opt_signal(char *, char *, void *);
|
||||
|
||||
void uwsgi_opt_snmp(char *, char *, void *);
|
||||
void uwsgi_opt_snmp_community(char *, char *, void *);
|
||||
void uwsgi_opt_snmp(char *, char *, void *);
|
||||
void uwsgi_opt_snmp_community(char *, char *, void *);
|
||||
|
||||
void uwsgi_opt_logfile_chmod(char *, char *, void *);
|
||||
void uwsgi_opt_logfile_chmod(char *, char *, void *);
|
||||
|
||||
void uwsgi_opt_log_date(char *, char *, void *);
|
||||
void uwsgi_opt_chmod_socket(char *, char *, void *);
|
||||
void uwsgi_opt_log_date(char *, char *, void *);
|
||||
void uwsgi_opt_chmod_socket(char *, char *, void *);
|
||||
|
||||
void uwsgi_opt_max_vars(char *, char *, void *);
|
||||
void uwsgi_opt_deprecated(char *, char *, void *);
|
||||
void uwsgi_opt_max_vars(char *, char *, void *);
|
||||
void uwsgi_opt_deprecated(char *, char *, void *);
|
||||
|
||||
void uwsgi_opt_noop(char *, char *, void *);
|
||||
void uwsgi_opt_noop(char *, char *, void *);
|
||||
|
||||
void uwsgi_opt_logic(char *, char *, void *);
|
||||
void uwsgi_opt_logic(char *, char *, void *);
|
||||
int uwsgi_logic_opt_for(char *, char *);
|
||||
int uwsgi_logic_opt_for_glob(char *, char *);
|
||||
int uwsgi_logic_opt_if_env(char *, char *);
|
||||
|
||||
Reference in New Issue
Block a user