Search Again:

Re: Linux FM Server 5.5 considerations

From: Paul Farber
Date: Tuesday, October 1, 2002
Time: 12:46:54 pm

If you don't have the required directories/files under the chrooted root
dir, then no, nothing would work as the chrooted dir cannot see ANY other
part of the filesystem (technically).

So if your app needs a tmp, var and shell to operate.. you need to
replicate that under the chrooted dir.


At 02:59 PM 9/25/2002 -0700, you wrote:
>Ok I managed to get it running. It doesn't need much at all, mind you
>this is
>a hack to get it work under Redhat 7.3 (does not work without a lot of
>special
>love.) It just needs a C library and a /tmp directory in its
>chroot-jail. You
>get an "unknown error" if there is no /tmp directory (at least when you
>try to
>run "fms_registration". Make sure there is an /etc and /var (basically just
>mirror what would be installed from the RPM) with a shell and glibc. Works
>fine and should be very secure in the case of a future Filemaker buffer-
>overrun / remote-shell exploit. :P I really don't know what the hell they
>goofed up in glibc 2.2.5 for Redhat 7.3, but that is a topic for a different
>list!
>
>
>-----Original Message-----
>From: isp-list@optigold.com [mailto:isp-list@optigold.com] On Behalf Of Shawn
>Hogan
>Sent: Wednesday, September 25, 2002 2:32 PM
>To: Optigold ISP List
>Subject: Re: [Optigold ISP] Linux FM Server 5.5 considerations
>
>phillip@succeed.net wrote:
>
> > Do you know off hand if the Linux FM server 5.5 would rely on any external
> > programs other than possibly a shell? The reason I ask is that I am
> going to
> > run it from a chrooted environment and would like to have minimal clutter.
> > Also NOTE that it does not run under *RedHat 7.3*. I had to compile a fresh
> > glibc and chroot the server to get it working. I'll rate RedHat 7.3
> > as "garbage" at this point I think. :P It is clearly not a Filemaker or
> > glibc
> > issue, though a statically compiled "fmserverd" would have probably
> eliminated
> > all of this.
>
>I don't think it it relies on anything external (other than things it tells
>you when it installs... like glib). Although I couldn't tell you for 100%
>certain because I never tried to delete everything from a machine and run no
>processes but FileMaker Server... but my guess is that it doesn't rely on
>anything else...
>
> - Shawn
>
>-------------------------------
>Shawn D. Hogan
>President, Digital Point Solutions
>http://www.digitalpoint.com
>(858) 452-3696
>
>
>-----Original Message-----
>From: isp-list@optigold.com [mailto:isp-list@optigold.com] On Behalf Of Shawn
>Hogan
>Sent: Wednesday, September 25, 2002 2:32 PM
>To: Optigold ISP List
>Subject: Re: [Optigold ISP] Linux FM Server 5.5 considerations
>
>phillip@succeed.net wrote:
>
> > Do you know off hand if the Linux FM server 5.5 would rely on any external
> > programs other than possibly a shell? The reason I ask is that I am
> going to
> > run it from a chrooted environment and would like to have minimal clutter.
> > Also NOTE that it does not run under *RedHat 7.3*. I had to compile a fresh
> > glibc and chroot the server to get it working. I'll rate RedHat 7.3
> > as "garbage" at this point I think. :P It is clearly not a Filemaker or
> > glibc
> > issue, though a statically compiled "fmserverd" would have probably
> eliminated
> > all of this.
>
>I don't think it it relies on anything external (other than things it tells
>you when it installs... like glib). Although I couldn't tell you for 100%
>certain because I never tried to delete everything from a machine and run no
>processes but FileMaker Server... but my guess is that it doesn't rely on
>anything else...
>
> - Shawn
>
>-------------------------------
>Shawn D. Hogan
>President, Digital Point Solutions
>http://www.digitalpoint.com
>(858) 452-3696
>
>---------------------------------------------------
>To subscribe, unsubscribe or to search list archive
>please visit http://www.optigold.com/lists/isp.html
>---------------------------------------------------

Customer Care
Farber Technology

Get FREE Internet! Sign up a friend and receive 1 free month of Internet
access! For more information, go to http://www.f-tech.net/freeinternet.html


---------------------------------------------------
To subscribe, unsubscribe or to search list archive
please visit http://www.optigold.com/lists/isp.html
---------------------------------------------------



Messages In This Thread:



Return to Digital Point Solutions' Home Page