Balabit - Web server fix after the upgrade from 4 to 5
Balabit SCB Solution · Config document · referenced from Operations, upgrades and troubleshooting
lighttpd.conf among the changed files, see below.After the upgrade of the appliance from SCB 4 to SCB 5 the web interface did not come up. The error log of lighttpd showed that it still tried to start PHP 5 as its FastCGI back end, which the new core firmware no longer had. A symbolic link from the old path to the PHP 7.0 interpreter let the web server start.
| Item | Value |
|---|---|
| Where | SSH console of the SCB as root, boot shell, then a chroot into the core firmware tree /mnt/firmware |
| Which appliance | Not named in the notes; the log lines are dated 2017-07-12, the link 13 July |
| Firmware | Core firmware just upgraded from 4 LTS to 5 LTS; the notes are headed "BALABIT notes - 4.0.7.a" |
| Symptom | No web interface; lighttpd stopped with "Configuration of plugins failed. Going down." |
| Change | ln -s /usr/lib/cgi-bin/php7.0 /usr/lib/cgi-bin/php5 inside the core firmware |
| Source | Troubleshooting notes, section "CORE FIRMWARE - web server not works after upgrade from version 4 to version 5" |
The commands
Check which firmware the shell is in. In the boot shell the file answers boot.
$ cat /etc/firmware-type
output 1 line
boot
Change root into the file tree of the core firmware, which the boot firmware has mounted under /mnt/firmware.
$ /usr/sbin/chroot /mnt/firmwareCheck again; inside the chroot the same file says core.
$ cat /etc/firmware-type
output 1 line
core
Read the end of the web server's error log. lighttpd tried to spawn /usr/lib/cgi-bin/php5 as FastCGI back end, the child exited with status 2, and the server shut down.
$ tail -n 20 /var/log/lighttpd/error.log
output 7 lines
2017-07-12 09:25:15: (log.c.164) server started 2017-07-12 09:25:15: (mod_fastcgi.c.1112) the fastcgi-backend /usr/lib/cgi-bin/php5 failed to start: 2017-07-12 09:25:15: (mod_fastcgi.c.1116) child exited with status 2 /usr/lib/cgi-bin/php5 2017-07-12 09:25:15: (mod_fastcgi.c.1119) If you're trying to run your app as a FastCGI backend, make sure you're using the FastCGI-enabled version. If this is PHP on Gentoo, add 'fastcgi' to the USE flags. 2017-07-12 09:25:15: (mod_fastcgi.c.1406) [ERROR]: spawning fcgi failed. 2017-07-12 09:25:15: (server.c.1022) Configuration of plugins failed. Going down.
Create the symbolic link from the path the configuration expects to the PHP 7.0 interpreter that the new firmware ships.
$ ln -s /usr/lib/cgi-bin/php7.0 /usr/lib/cgi-bin/php5
Check that the link exists. php is the firmware's own link through the alternatives system; php5 is the new one.
$ ls -lh /usr/lib/cgi-bin/
output 3 lines
lrwxrwxrwx 1 root root 29 Apr 18 11:21 php -> /etc/alternatives/php-cgi-bin lrwxrwxrwx 1 root root 23 Jul 13 09:00 php5 -> /usr/lib/cgi-bin/php7.0 -rwxr-xr-x 1 root root 4.2M Mar 13 12:55 php7.0
Start the web server with its init script.
$ /etc/init.d/lighttpd startoutput 1 line
* Starting web server lighttpd [ OK ]
Check its status.
$ /etc/init.d/lighttpd statusoutput 1 line
* lighttpd is running
| Step or line | What it means |
|---|---|
/etc/firmware-type | A one-word file that tells the two firmwares apart: boot or core (the operation how-to writes them with a capital letter, Boot and Core) |
/usr/sbin/chroot /mnt/firmware | Enters the core firmware's files from the boot shell. The vendor's support used the same chroot for the core auth key procedure; the other way into the core firmware is the core-shell command |
fastcgi-backend /usr/lib/cgi-bin/php5 | The FastCGI back end named in the web server's configuration; I take it that version 4 ran the web interface on PHP 5 and version 5 on PHP 7.0, which is what the directory listing shows |
php -> /etc/alternatives/php-cgi-bin | The generic path, managed by the alternatives system (as I understand it, the core firmware is built like a Debian or Ubuntu system, which the init scripts and this path suggest). A configuration written against it would have survived the PHP upgrade; one written against php5 did not |
Jul 13 09:00 | The link was made the morning after the error of 12 July; when the web interface was back the notes do not say |
Why the configuration still named PHP 5 the notes do not say. A later check for tainted firmware, in Finding and removing tainted files, listed /mnt/drbd/private/root/etc/lighttpd/lighttpd.conf among the files that differed from the firmware. My reading, which the material does not confirm, is that a lighttpd.conf from version 4 was kept in the appliance's persistent area through the upgrade and shadowed the one that came with version 5; removing it, as was done in the tainted cleanup, would have been the real fix, and the php5 link would then no longer be needed. The notes do not say whether the link was removed afterwards.