X-Git-Url: http://git.onelab.eu/?a=blobdiff_plain;f=plc.d%2Fhttpd;h=9a926f33efc3cc4a8b17f302c8112117fec79dc2;hb=1e0e4007e306ca111f0d538c073fd51380abcd99;hp=412f6377587551bc32b255e8c37e61e9c990e1c0;hpb=3c6215a60855c501e1742714257c021472a1c34a;p=myplc.git
diff --git a/plc.d/httpd b/plc.d/httpd
index 412f637..9a926f3 100755
--- a/plc.d/httpd
+++ b/plc.d/httpd
@@ -57,7 +57,7 @@ case "$1" in
sed -i -e "s@[;]*include_path = \"\.:.*\"@include_path = \"$include_path\"@" $php_ini
# Set open_basedir so as to avoid leaks
- open_basedir="$DocumentRoot:/etc/planetlab/php:/usr/share/plc_api/php:/var/log/myslice:/var/tmp/bootmedium:/tmp"
+ open_basedir="$DocumentRoot:/etc/planetlab/php:/usr/share/plc_api/php:/var/log/myslice:/var/tmp/bootmedium:/var/log/bm:/tmp"
sed -i -e "s@[;]*open_basedir =.*@open_basedir = \"$open_basedir\"@" $php_ini
# for php-5.3 under fedora12, otherwise issues tons of warning messages
@@ -74,7 +74,7 @@ case "$1" in
# Disable default Listen directive
sed -i -e '/^Listen/d' $httpd_conf
- plcapi_noslash=$(echo $PLC_API_PATH | sed -e s,/,,g)
+ plc_api_path_noslash=$(echo $PLC_API_PATH | sed -e s,/,,g)
# Set the port numbers
for server in WWW API BOOT ; do
enabled=PLC_${server}_ENABLED
@@ -125,7 +125,7 @@ Listen ${!http_port}
Redirect /planetlab https://$PLC_WWW_HOST:$PLC_WWW_SSL_PORT/planetlab
# as a matter of fact most xmlrpc clients won't follow the redirection
# so this is mostly rethorical, but just in case...
- Redirect /$plcapi_noslash https://$PLC_WWW_HOST:$PLC_WWW_SSL_PORT/$plcapi_noslash
+ Redirect /$plc_api_path_noslash https://$PLC_WWW_HOST:$PLC_WWW_SSL_PORT/$plc_api_path_noslash
EOF
@@ -141,26 +141,63 @@ EOF
-e "s/^Listen .*/Listen ${!https_port}/" \
-e "s///" \
$ssl_conf
- # this is used to locate the right certificates
- server_lower=$(echo $server | tr 'A-Z' 'a-z')
- cat <& /dev/null ; then
+ configure_for_mod_python=true
+ elif rpm -q mod_wsgi >& /dev/null ; then
+ configure_for_mod_wsgi=true
+ else
+ echo "Requires mod_python or mod_wsgi.... exiting"
+ exit 1
+ fi
+
+ # It would be tempting to use here
+ # but early tests showed this could be tricky/fragile
+ # So let's hard-wire it for one module
+ # A lot of trial-and -error was involved in getting this that way...
+
+ if [ -n "$configure_for_mod_python" ] ; then
+#################### for mod_python
+ cat <
+ SetHandler mod_python
+ PythonPath "sys.path + ['/usr/share/plc_api']"
+ PythonHandler apache.ModPython
+
+EOF
+
+ elif [ -n "$configure_for_mod_wsgi" ] ; then
+#################### for mod_wsgi
+ cat <
- WSGIScriptAlias /$plcapi_noslash /usr/share/plc_api/apache/plc.wsgi
-# xxx would be cool to be able to tweak this through config
- WSGIDaemonProcess plcapi-wsgi-ssl user=apache group=apache processes=1 threads=25
- WSGIProcessGroup plcapi-wsgi-ssl
# SSL
SSLEngine On
SSLCertificateFile /etc/planetlab/${server_lower}_ssl.crt
SSLCertificateKeyFile /etc/planetlab/${server_lower}_ssl.key
SSLCertificateChainFile /etc/planetlab/${server_lower}_ca_ssl.crt
-
+ WSGIScriptAlias /$plc_api_path_noslash /usr/share/plc_api/apache/plc.wsgi
+# xxx would be cool to be able to tweak this through config
+ WSGIDaemonProcess plcapi-wsgi-ssl user=apache group=apache processes=1 threads=25
+ WSGIProcessGroup plcapi-wsgi-ssl
+
+
+ Options +ExecCGI
+ $(apache_allow)
+
+
+
EOF
+ fi
fi
done >$plc_conf
@@ -176,7 +213,7 @@ EOF
cat <
- Deny from all
+ $(apache_forbid)
EOF
fi
@@ -249,6 +286,10 @@ EOF
chmod 666 /var/log/php.log
fi
+ ## make room for logs
+ touch /var/log/plcapi.log
+ chmod 666 /var/log/plcapi.log
+
plc_daemon httpd
check