LINUXOR.SK ... open source notes ...

Balabit - Web server fix after the upgrade from 4 to 5

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from Operations, upgrades and troubleshooting

noteThis is a workaround, not a repair: it makes a path of the old PHP 5 point to the PHP 7.0 interpreter so that a leftover configuration finds something to start. The notes do not record whether the vendor's support approved it; a later check for tainted firmware listed lighttpd.conf among the changed files, see below.

After the upgrade of the appliance from SCB 4 to SCB 5 the web interface did not come up. The error log of lighttpd showed that it still tried to start PHP 5 as its FastCGI back end, which the new core firmware no longer had. A symbolic link from the old path to the PHP 7.0 interpreter let the web server start.

ItemValue
WhereSSH console of the SCB as root, boot shell, then a chroot into the core firmware tree /mnt/firmware
Which applianceNot named in the notes; the log lines are dated 2017-07-12, the link 13 July
FirmwareCore firmware just upgraded from 4 LTS to 5 LTS; the notes are headed "BALABIT notes - 4.0.7.a"
SymptomNo web interface; lighttpd stopped with "Configuration of plugins failed. Going down."
Changeln -s /usr/lib/cgi-bin/php7.0 /usr/lib/cgi-bin/php5 inside the core firmware
SourceTroubleshooting notes, section "CORE FIRMWARE - web server not works after upgrade from version 4 to version 5"

The commands

Check which firmware the shell is in. In the boot shell the file answers boot.

bash
$ cat /etc/firmware-type
output 1 line
boot

Change root into the file tree of the core firmware, which the boot firmware has mounted under /mnt/firmware.

bash
$ /usr/sbin/chroot /mnt/firmware

Check again; inside the chroot the same file says core.

bash
$ cat /etc/firmware-type
output 1 line
core

Read the end of the web server's error log. lighttpd tried to spawn /usr/lib/cgi-bin/php5 as FastCGI back end, the child exited with status 2, and the server shut down.

bash
$ tail -n 20 /var/log/lighttpd/error.log
output 7 lines
2017-07-12 09:25:15: (log.c.164) server started
2017-07-12 09:25:15: (mod_fastcgi.c.1112) the fastcgi-backend /usr/lib/cgi-bin/php5 failed to start:
2017-07-12 09:25:15: (mod_fastcgi.c.1116) child exited with status 2 /usr/lib/cgi-bin/php5
2017-07-12 09:25:15: (mod_fastcgi.c.1119) If you're trying to run your app as a FastCGI backend, make sure you're using the FastCGI-enabled version.
If this is PHP on Gentoo, add 'fastcgi' to the USE flags.
2017-07-12 09:25:15: (mod_fastcgi.c.1406) [ERROR]: spawning fcgi failed.
2017-07-12 09:25:15: (server.c.1022) Configuration of plugins failed. Going down.

Create the symbolic link from the path the configuration expects to the PHP 7.0 interpreter that the new firmware ships.

bash
$ ln -s /usr/lib/cgi-bin/php7.0 /usr/lib/cgi-bin/php5

Check that the link exists. php is the firmware's own link through the alternatives system; php5 is the new one.

bash
$ ls -lh /usr/lib/cgi-bin/
output 3 lines
lrwxrwxrwx 1 root root   29 Apr 18 11:21 php -> /etc/alternatives/php-cgi-bin
lrwxrwxrwx 1 root root   23 Jul 13 09:00 php5 -> /usr/lib/cgi-bin/php7.0
-rwxr-xr-x 1 root root 4.2M Mar 13 12:55 php7.0

Start the web server with its init script.

bash
$ /etc/init.d/lighttpd start
output 1 line
 * Starting web server lighttpd                                                  [ OK ]

Check its status.

bash
$ /etc/init.d/lighttpd status
output 1 line
 * lighttpd is running
Step or lineWhat it means
/etc/firmware-typeA one-word file that tells the two firmwares apart: boot or core (the operation how-to writes them with a capital letter, Boot and Core)
/usr/sbin/chroot /mnt/firmwareEnters the core firmware's files from the boot shell. The vendor's support used the same chroot for the core auth key procedure; the other way into the core firmware is the core-shell command
fastcgi-backend /usr/lib/cgi-bin/php5The FastCGI back end named in the web server's configuration; I take it that version 4 ran the web interface on PHP 5 and version 5 on PHP 7.0, which is what the directory listing shows
php -> /etc/alternatives/php-cgi-binThe generic path, managed by the alternatives system (as I understand it, the core firmware is built like a Debian or Ubuntu system, which the init scripts and this path suggest). A configuration written against it would have survived the PHP upgrade; one written against php5 did not
Jul 13 09:00The link was made the morning after the error of 12 July; when the web interface was back the notes do not say

Why the configuration still named PHP 5 the notes do not say. A later check for tainted firmware, in Finding and removing tainted files, listed /mnt/drbd/private/root/etc/lighttpd/lighttpd.conf among the files that differed from the firmware. My reading, which the material does not confirm, is that a lighttpd.conf from version 4 was kept in the appliance's persistent area through the upgrade and shadowed the one that came with version 5; removing it, as was done in the tainted cleanup, would have been the real fix, and the php5 link would then no longer be needed. The notes do not say whether the link was removed afterwards.

← solutionz