mod_tls: Mark session as not secure before negotiating TLS
[prosody.git] / plugins / mod_posix.lua
index 7fbdfa9326954c19e4c8a3ff1ff0268522e7afcc..5f7dfc5b1884e9c8b857b851c1aa43764b936c4f 100644 (file)
@@ -1,19 +1,64 @@
+-- Prosody IM
+-- Copyright (C) 2008-2009 Matthew Wild
+-- Copyright (C) 2008-2009 Waqas Hussain
+-- 
+-- This project is MIT/X11 licensed. Please see the
+-- COPYING file in the source package for more information.
+--
 
-local want_pposix_version = "0.3.0";
+
+local want_pposix_version = "0.3.1";
 
 local pposix = assert(require "util.pposix");
 if pposix._VERSION ~= want_pposix_version then module:log("warn", "Unknown version (%s) of binary pposix module, expected %s", tostring(pposix._VERSION), want_pposix_version); end
 
 local signal = select(2, pcall(require, "util.signal"));
 if type(signal) == "string" then
-       log("warn", "Couldn't load signal library, won't respond to SIGTERM");
+       module:log("warn", "Couldn't load signal library, won't respond to SIGTERM");
 end
 
-local config_get = require "core.configmanager".get;
 local logger_set = require "util.logger".setwriter;
 
+local prosody = _G.prosody;
+
 module.host = "*"; -- we're a global module
 
+-- Allow switching away from root, some people like strange ports.
+module:add_event_hook("server-started", function ()
+               local uid = module:get_option("setuid");
+               local gid = module:get_option("setgid");
+               if gid then
+                       local success, msg = pposix.setgid(gid);
+                       if success then
+                               module:log("debug", "Changed group to "..gid.." successfully.");
+                       else
+                               module:log("error", "Failed to change group to "..gid..". Error: "..msg);
+                               prosody.shutdown("Failed to change group to "..gid);
+                       end
+               end
+               if uid then
+                       local success, msg = pposix.setuid(uid);
+                       if success then
+                               module:log("debug", "Changed user to "..uid.." successfully.");
+                       else
+                               module:log("error", "Failed to change user to "..uid..". Error: "..msg);
+                               prosody.shutdown("Failed to change user to "..uid);
+                       end
+               end
+       end);
+
+-- Don't even think about it!
+module:add_event_hook("server-starting", function ()
+               local suid = module:get_option("setuid");
+               if not suid or suid == 0 or suid == "root" then
+                       if pposix.getuid() == 0 and not module:get_option("run_as_root") then
+                               module:log("error", "Danger, Will Robinson! Prosody doesn't need to be run as root, so don't do it!");
+                               module:log("error", "For more information on running Prosody as root, see http://prosody.im/doc/root");
+                               prosody.shutdown("Refusing to run as root");
+                       end
+               end
+       end);
+
 local pidfile_written;
 
 local function remove_pidfile()
@@ -27,11 +72,11 @@ local function write_pidfile()
        if pidfile_written then
                remove_pidfile();
        end
-       local pidfile = config.get("*", "core", "pidfile");
+       local pidfile = module:get_option("pidfile");
        if pidfile then
                local pf, err = io.open(pidfile, "w+");
                if not pf then
-                       log("error", "Couldn't write pidfile; %s", err);
+                       module:log("error", "Couldn't write pidfile; %s", err);
                else
                        pf:write(tostring(pposix.getpid()));
                        pf:close();
@@ -57,15 +102,15 @@ function syslog_sink_maker(config)
 end
 require "core.loggingmanager".register_sink_type("syslog", syslog_sink_maker);
 
-if not config_get("*", "core", "no_daemonize") then
+if not module:get_option("no_daemonize") then
        local function daemonize_server()
                local ok, ret = pposix.daemonize();
                if not ok then
-                       log("error", "Failed to daemonize: %s", ret);
+                       module:log("error", "Failed to daemonize: %s", ret);
                elseif ret and ret > 0 then
                        os.exit(0);
                else
-                       log("info", "Successfully daemonized to PID %d", pposix.getpid());
+                       module:log("info", "Successfully daemonized to PID %d", pposix.getpid());
                        write_pidfile();
                end
        end
@@ -77,16 +122,18 @@ end
 
 module:add_event_hook("server-stopped", remove_pidfile);
 
--- Set signal handler
+-- Set signal handlers
 if signal.signal then
        signal.signal("SIGTERM", function ()
-               log("warn", "Received SIGTERM...");
-               unlock_globals();
-               if prosody_shutdown then
-                       prosody_shutdown("Received SIGTERM");
-               else
-                       log("warn", "...no prosody_shutdown(), ignoring.");
-               end
-               lock_globals();
+               module:log("warn", "Received SIGTERM");
+               prosody.unlock_globals();
+               prosody.shutdown("Received SIGTERM");
+               prosody.lock_globals();
+       end);
+
+       signal.signal("SIGHUP", function ()
+               module:log("info", "Received SIGHUP");
+               prosody.reload_config();
+               prosody.reopen_logfiles();
        end);
 end