[Bug 1352617] Re: php5-fpm UNIX sockets in Precise do not listen as www-data:www-data by default, and causes 502s with webservers trying to use socket

Thomas Ward teward at trekweb.org
Fri Aug 8 01:13:48 UTC 2014


I'm attaching the patch I wrote for this.

As this patch is ultimately going to repair a problem introduced by a
security fix, by forcing php5-fpm to force a specific user/group to be
the owner:group settings for the fpm socket, I would like the Security
Team to review the change preliminarily, while I work on getting a
debdiff made.  This is solely because it changes how the php5-fpm
package has its /etc/php5/fpm/pool.d/www.conf file is generated,
changing the default lines slightly.  I'd like to make sure this doesn't
break anything else or introduce any other issues.

** Patch added: "fix-fpm-socket-owner-group.patch"
   https://bugs.launchpad.net/ubuntu/+source/php5/+bug/1352617/+attachment/4172342/+files/fix-fpm-socket-owner-group.patch

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to php5 in Ubuntu.
https://bugs.launchpad.net/bugs/1352617

Title:
  php5-fpm UNIX sockets in Precise do not listen as www-data:www-data by
  default, and causes 502s with webservers trying to use socket

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/php5/+bug/1352617/+subscriptions



More information about the Ubuntu-server-bugs mailing list