Showing posts with label suexec. Show all posts
Showing posts with label suexec. Show all posts

Wednesday, July 8, 2020

How to Rebuild Apache httpd to Change suexec AP_DOC_ROOT from /var/www to /home (CentOS & RHEL)

Standard RPM packages of Apache httpd in CentOS and RHEL compile suexec with a hardcoded document root of /var/www (--with-suexec-docroot=/var/www). However, web control panels like Virtualmin host customer accounts under /home. When suexec executes a user script under /home, it aborts with "command not in docroot". Here is how to rebuild the official upstream httpd SRPM with AP_DOC_ROOT set to /home.

Compilation Flag: --with-suexec-docroot=/home

Rebuilding the RPM

# 1. Install build tools and dependencies
yum install rpm-build redhat-rpm-config gcc make -y
yum-builddep httpd -y

# 2. Download and unpack httpd SRPM
mkdir -p ~/rpmbuild/{BUILD,RPMS,SOURCES,SPECS,SRPMS}
cd ~/rpmbuild/SRPMS
yumdownloader --source httpd
rpm -ivh httpd-*.src.rpm

# 3. Edit SPECS/httpd.spec and modify suexec docroot
cd ~/rpmbuild/SPECS
sed -i 's|--with-suexec-docroot=/var/www|--with-suexec-docroot=/home|g' httpd.spec

# 4. Rebuild binary RPM
rpmbuild -bb httpd.spec

# 5. Install the custom suexec binary
rpm -Uvh --force ~/rpmbuild/RPMS/x86_64/httpd-*.rpm

Confirm the new docroot:

suexec -V | grep AP_DOC_ROOT

Monday, June 22, 2020

[Solved] Fixing Apache suexec and mod_fcgid: Error Reading Data from FastCGI Server

When running PHP applications under Apache using mod_fcgid combined with suexec privilege separation, web requests may suddenly abort with HTTP 500 Internal Server Errors and the following message in Apache error logs:

Error Message: End of script output before headers: php.fcgi • mod_fcgid: error reading data from FastCGI server

Root Cause

suexec enforces strict security checks on the FastCGI wrapper script and user directory:

  1. The wrapper script and parent directories must be owned exclusively by the virtual server user and group—not root or apache.
  2. File permissions cannot be group-writeable (chmod 755 is required, 775 or 777 causes instant suexec rejection).
  3. The target script must reside strictly inside the compiled suexec document root (e.g. /home/user/public_html).

Resolution Steps

Inspect /var/log/httpd/suexec.log to reveal the exact permission violation, and enforce correct ownership:

# Fix permissions and ownership
chown -R user:user /home/user/fcgi-bin /home/user/public_html
chmod 755 /home/user/fcgi-bin/php.fcgi
chmod 755 /home/user/public_html

How Google Antigravity Solved the Mysterious NVIDIA Sleep Reboot on My Dell Inspiron 7567 (Ubuntu Linux)

If you run modern Ubuntu or Linux on a Dell Inspiron 15 Gaming (7567) or a similar 7th-gen Intel laptop paired with an NVIDIA GeForce GTX ...