New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
lpadmin to (limited) root privilege escalation #4223
Comments
CUPS.org User: mike Sigh... I guess we should just blacklist /etc and /usr/local/etc, etc. for the log files. The default LogFilePerm can be changed as well to prevent the log files from having read permissions... |
CUPS.org User: odyx Hi Michael, you might want to read the conversations at [0] and [1]. In particular, Jeff Licquia proposed a temporary fix [2] on which it would be good to have your input. Cheers, OdyX [0] http://bugs.debian.org/692791 |
CUPS.org User: mike Temporary fix 2 is no fix, since it doesn't address the core issue - PUT support for config files and allowing arbitrary values for log files, ServerRoot, and DocumentRoot. I'm now thinking that the easiest fix is to drop support for those directives and provide command-line options instead. That would allow site configuration by root but not configuration by non-root, and avoids us doing blacklists or whitelists for acceptable locations in cupsd.conf. I will be investigating this issue more deeply in the coming days and will have a proposed patch at that time. BTW, the correct vendor contact is security@cups.org and/or security@apple.com, but filing a security bug automatically forwards the report to those addresses. |
CUPS.org User: odyx Hi Michael, what is the status of this issue? What could I do to help gettings this solved? Cheers, Didier |
CUPS.org User: mike Still working on a patch. |
CUPS.org User: twaugh.redhat Anything I can do to help out? By the way, this bug is marked private even though the security issue it talks about is public (since November 8th). Should we open it up? |
CUPS.org User: mike Tim, Since this issue is public, I'll open up our bug as well. I got some internal feedback this morning on my proposed fix, will be posting a preliminary patch in another hour or so with some more changes incorporated... |
CUPS.org User: mike And just so you all know, the changes are somewhat extensive because I opted to move all of the file, directory, user, and group settings out into a separate configuration file that can't be written/read remotely. |
CUPS.org User: mike Proposed patches attached for 1.6 and 1.7. Please review... |
CUPS.org User: mike Here is what is changed:
|
CUPS.org User: mike Additional patch to fix default cups-files.conf pathname and to just warn about directives in cupsd.conf that have moved to cups-files.conf (otherwise that would prevent cupsd from starting...) |
CUPS.org User: twaugh.redhat Thanks, this looks great. I think something was missing was str4223p2.patch? I've attached cups-str4223-set-default.patch which I think adds in the missing part. |
CUPS.org User: mdeslaur Here are a couple of small fixes for things I've noticed so far in the 1.6.x branch. (small-fixes.patch) |
CUPS.org User: mdeslaur Also, DefaultAuthType is now mentioned in the cups-files.conf manpage and help, but it is still being parsed by read_cupsd_conf(). |
CUPS.org User: mdeslaur The attached defaultauthtype.patch patch moves DefaultAuthType to read_cups_files_conf(). |
CUPS.org User: mike Marc, the "small-fixes" patch looks good, will apply and make a new version of the complete patch file. DefaultAuthType shouldn't, IMHO, be in cups-files.conf because the policy and location directives can override it. It was in cupsd.conf, although it looks like a prior find/replace error changed it to "default_auth_type". That was previously fixed in TOT... Tim, not sure why the p2 patch was missing this bit, but I already have something similar in trunk's main.c... Will provide a new patch for all of this later today. Thanks, all! |
CUPS.org User: mike Based on discussions for the Debian bug, I'll also be masking out all but the read/write bits for ConfigFilePerm and LogFilePerm. |
CUPS.org User: odyx Attached the backport of this issue against 1.5.3. Please review. Cheers, OdyX |
CUPS.org User: mike Didier, Your 1.5.3 patch is just missing Tim's main.c patch for making sure that cups-files.conf is initialized, and I have another change (sorry, got pulled away yesterday) to make sure that ConfigFilePerm and LogFilePerm do not have execute or set-id bits set... |
CUPS.org User: mike OK, here are the updated patches. |
CUPS.org User: odyx Here's the patch against 1.5.3, updated. It had a wrong split of configuration stanzas in scheduler/conf.c. Please comment. I started to work on the patch against 1.4.4 as that's the version we have in our stable release, more news soon. |
CUPS.org User: twaugh.redhat The FileDevice warning in ipp.c:add_printer() needs to be changed too. Currently it reads:
|
CUPS.org User: mike Tim, thanks for catching that; changes now in TOT... |
CUPS.org User: twaugh.redhat I've posted cups-logfile-warning.patch for comment too. It changes the misleading syslog error message when cups-files.conf contains bad content. Unable to read configuration file '/etc/cups/cupsd.conf' - exiting! |
CUPS.org User: odyx There, the patch for 1.4.4; please review. |
CUPS.org User: twaugh.redhat I've just attached another patch fixing a documentation issue (0001-Another-documentation-fix-related-to-CVE-2012-5519.patch). The cupsctl man page gives "cupsctl FileDevice=Yes" as an example use, but of course this option can no longer be changed that way. |
CUPS.org User: twaugh.redhat And another documentation patch, cups-str4223-ref-cups-files-conf.patch. This makes sure the new ref-cups-files-conf.html file is actually installed. |
CUPS.org User: twaugh.redhat Another patch needed: 0001-Check-permissions-on-cups-files.conf.patch This time it's to check the permissions on the new cups-files.conf file. Not sure whether it should use ConfigFilePerm or 0600 for that? |
CUPS.org User: mike I think ConfigFilePerm, just like cupsd.conf. Also, I have some changes to cups-logfile-warning.patch and am reviewing the others. Will post a combined patch in a little bit. |
CUPS.org User: mike Here is a roll-up patch for the v2 patch series: Fix cupsctl man page
|
CUPS.org User: mike OK, think I have all of the documentation changes straightened out now... |
"str4223.patch": Index: packaging/cups.spec.in--- packaging/cups.spec.in (revision 10708) Index: packaging/cups.list.in--- packaging/cups.list.in (revision 10708) Property changes on: conf Modified: svn:ignore
Index: conf/cups-files.conf.in--- conf/cups-files.conf.in (revision 10708) "$Id$"-# Sample configuration file for the CUPS scheduler. See "man cupsd.conf" for a -# Log general information in error_log - change "@CUPS_LOG_LEVEL@" to "debug" -# Administrator user group... -# Only listen for connections from the local machine. -# Show shared printers on the local network. -# Default authentication type, when authentication is required... -# Web interface setting... -# Restrict access to the server...
-# Restrict access to the admin pages...
-# Restrict access to configuration files...
-# Set the default printer/job policies...
+# Location of fonts used by older print filters... +# Location of LPD configuration
+# Location of the file logging all pages printed by the scheduler and any
+# Location of the file listing all of the local printers...
+# Format of the Printcap file...
- -# Set the authenticated printer/job policies...
+# SSL/TLS certificate for the scheduler... +# SSL/TLS private key for the scheduler...
+# Location of other configuration files...
+# Location of Samba configuration file...
+# Location of scheduler state files...
- End of "$Id$".Index: conf/cupsd.conf.in--- conf/cupsd.conf.in (revision 10708) for troubleshooting...LogLevel @CUPS_LOG_LEVEL@ -# Administrator user group... -@CUPS_SYSTEM_AUTHKEY@Only listen for connections from the local machine.Listen localhost:@DEFAULT_IPP_PORT@ Index: conf/Makefile--- conf/Makefile (revision 10708) Config files...-KEEP = cupsd.conf snmp.conf Index: CHANGES-1.6.txt--- CHANGES-1.6.txt (revision 10708)
+AC_SUBST(CUPS_SERVERCERT) Index: config-scripts/cups-defaults.m4--- config-scripts/cups-defaults.m4 (revision 10708) AC_DEFINE_UNQUOTED(CUPS_DEFAULT_LPD_CONFIG_FILE, "$CUPS_DEFAULT_LPD_CONFIG_FILE") dnl Default SMB config file... AC_DEFINE_UNQUOTED(CUPS_DEFAULT_SMB_CONFIG_FILE, "$CUPS_DEFAULT_SMB_CONFIG_FILE") dnl Default MaxCopies value... Index: doc/help/ref-cups-files-conf.html.in--- doc/help/ref-cups-files-conf.html.in (revision 10708) - cupsd.conf+ cups-files.conf- The /etc/cups/cupsd.conf file contains + The /etc/cups/cups-files.conf file contains configuration directives that control the files, directories. users. and groups that are used by the CUPS scheduler, - Since the server configuration file consists of plain text, -process using the startup script for your operating system:-
-/etc/init.d/cups restart -
-/sbin/init.d/cups restart -
-sudo launchctl unload /System/Library/LaunchDaemons/org.cups.cupsd.plist --- You can also edit this file from the CUPS web interface, which -automatically handles restarting the scheduler.-
|
mm | netmask | mm | netmask |
---|---|---|---|
0 | 0.0.0.0 | 8 | 255.0.0.0 |
1 | 128.0.0.0 | 16 | 255.255.0.0 |
2 | 192.0.0.0 | 24 | 255.255.255.0 |
... | ... | 32 | 255.255.255.255 |
-
The @LOCAL
name will allow access from all local
-interfaces. The @IF(name)
name will allow access
-from the named interface. In both cases, CUPS only allows access
-from the network that the interface(s) are configured for -
-requests arriving on the interface from a foreign network will
-not be accepted.
-
The Allow
directive must appear inside a <A
-HREF="#Location">Location
or <A
-HREF="#Limit">Limit
section.
-
DeprecatedAuthClass
-
Examples
-
-<Location /path>
- ...
- AuthClass Anonymous
- AuthClass User
- AuthClass System
- AuthClass Group
-</Location>
-
-
Description
-
The AuthClass
directive defines what level of
-authentication is required:
-
Anonymous
- No authentication should be
- performed (default)
User
- A valid username and password is
- required
System
- A valid username and password- is required, and the username must belong to the "sys"
- group; this can be changed using the <A
- HREF="#SystemGroup">
SystemGroup
- directive
Group
- A valid username and password is- required, and the username must belong to the group named
- by the <A
- HREF="#AuthGroupName">
AuthGroupName
- directive
-
-
The AuthClass
directive must appear inside a <A
-HREF="#Location">Location
or <A
-HREF="#Limit">Limit
section.
-
This directive is deprecated and will be removed from a
-future release of CUPS. Consider using the more flexible <A
-HREF="#Require">Require
directive instead.
-
DeprecatedAuthGroupName
-
Examples
-
-<Location /path>
- ...
- AuthGroupName mygroup
- AuthGroupName lp
-</Location>
-
-
Description
-
The AuthGroupName
directive sets the group to use
-for Group
authentication.
-
The AuthGroupName
directive must appear inside a
-Location
or <A
-HREF="#Limit">Limit
section.
-
This directive is deprecated and will be removed from a
-future release of CUPS. Consider using the more flexible <A
-HREF="#Require">Require
directive instead.
-
AuthType
-
Examples
-
-<Location /path>
- ...
- AuthType None
- AuthType Basic
- AuthType Digest
- AuthType BasicDigest
- AuthType Negotiate
-</Location>
-
-
Description
-
The AuthType
directive defines the type of
-authentication to perform:
-
None
- No authentication should be
- performed (default)
Basic
- Basic authentication should be
- performed using the UNIX password and group files
Digest
- Digest authentication should be- performed using the /etc/cups/passwd.md5
- file
BasicDigest
- Basic authentication- should be performed using the
- /etc/cups/passwd.md5 file
Negotiate
- Kerberos authentication
- should be performed
-
-
When using Basic
, Digest
,
-BasicDigest
, or Negotiate
authentication,
-clients connecting through the localhost
interface can
-also authenticate using certificates.
-
The AuthType
directive must appear inside a <A
-HREF="#Location">Location
or <A
-HREF="#Limit">Limit
section.
-
AutoPurgeJobs
-
Examples
-
-AutoPurgeJobs Yes
-AutoPurgeJobs No-
-
Description
-
The AutoPurgeJobs
directive specifies whether or
-not to purge completed jobs once they are no longer required for
-quotas. This option has no effect if quotas are not enabled. The
-default setting is No
.
-
CUPS 1.2/OS X 10.5BrowseLocalProtocols
-
Examples
-
-BrowseLocalProtocols all
-BrowseLocalProtocols none
-BrowseLocalProtocols dnssd-
-
Description
-
The BrowseLocalProtocols
directive specifies the
-protocols to use when advertising local shared printers on the
-network. Multiple protocols can be specified by separating them
-with spaces. The default is "@CUPS_BROWSE_LOCAL_PROTOCOLS@
".
-
BrowseWebIF
-
Examples
-
-BrowseWebIF On
-BrowseWebIF Off-
-
Description
-
The BrowseWebIF
directive controls whether the CUPS web
-interface is advertised via DNS-SD. The default setting is
-Off
.
-
Browsing
-
Examples
-
-Browsing On
-Browsing Off-
-
Description
-
The Browsing
directive controls whether or not
-printer sharing is enabled. The default setting is
-@CUPS_BROWSING@
.
-
CUPS 1.1.7Classification
-
Examples
-
-Classification
-Classification classified
-Classification confidential
-Classification secret
-Classification topsecret
-Classification unclassified-
-
Description
-
The Classification
directive sets the
-classification level on the server. When this option is set, at
-least one of the banner pages is forced to the classification
-level, and the classification is placed on each page of output.
-The default is no classification level.
-
CUPS 1.1.10ClassifyOverride
-
Examples
-
-ClassifyOverride Yes
-ClassifyOverride No-
-
Description
-
The ClassifyOverride
directive specifies whether
-users can override the default classification level on the
-server. When the server classification is set, users can change
-the classification using the job-sheets
option and
-can choose to only print one security banner before or after the
-job. If the job-sheets
option is set to
-none
then the server default classification is
-used.
-
The default is to not allow classification overrides.
CUPS 1.1.15ConfigFilePerm
Examples
@@ -488,171 +92,6 @@ username. The default isBasic
.
-
CUPS 1.2/OS X 10.5DefaultEncryption
-
Examples
-
-DefaultEncryption Never
-DefaultEncryption IfRequested
-DefaultEncryption Required-
-
Description
-
The DefaultEncryption
directive specifies the
-type of encryption to use when performing authentication. The
-default is Required
.
-
DefaultLanguage
-
Examples
-
-DefaultLanguage de
-DefaultLanguage en
-DefaultLanguage es
-DefaultLanguage fr
-DefaultLanguage it-
-
Description
-
The DefaultLanguage
directive specifies the
-default language to use for client connections. Setting the
-default language also sets the default character set if a
-language localization file exists for it. The default language
-is "en" for English.
-
CUPS 1.4/OS X 10.6DefaultPaperSize
-
Examples
-
-DefaultPaperSize Letter
-DefaultPaperSize A4
-DefaultPaperSize Auto
-DefaultPaperSize None-
-
Description
-
The DefaultPaperSize
directive specifies the default paper
-size to use when creating new printers. The default is Auto
-which uses a paper size appropriate for the system default locale. A value
-of None
tells the scheduler to not set the default paper
-size.
-
CUPS 1.2/OS X 10.5DefaultPolicy
-
Examples
-
-DefaultPolicy default
-DefaultPolicy authenticated
-DefaultPolicy foo-
-
Description
-
The DefaultPolicy
directive specifies the default
-policy to use for IPP operation. The default is
-default
. CUPS also includes a policy called
-authenticated
that requires a username and password for printing
-and other job operations.
-
CUPS 1.2/OS X 10.5DefaultShared
-
Examples
-
-DefaultShared yes
-DefaultShared no-
-
Description
-
The DefaultShared
directive specifies whether
-printers are shared (published) by default. The default is
-@CUPS_DEFAULT_SHARED@
.
-
Deny
-
Examples
-
-<Location /path>
- ..
- Deny from All
- Deny from None
- Deny from *.example.com
- Deny from .example.com
- Deny from host.example.com
- Deny from nnn.*
- Deny from nnn.nnn.*
- Deny from nnn.nnn.nnn.*
- Deny from nnn.nnn.nnn.nnn
- Deny from nnn.nnn.nnn.nnn/mm
- Deny from nnn.nnn.nnn.nnn/mmm.mmm.mmm.mmm
- Deny from [xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx]
- Deny from [xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx]/mmm
- Deny from @LOCAL
- Deny from @IF(name)
-</Location>
-
-
Description
-
The Deny
directive specifies a hostname, IP
-address, or network that is denied access to the server.
-Deny
directives are cumulative, so multiple
-Deny
directives can be used to deny access for
-multiple hosts or networks.
-
Host and domain name matching require that you enable the <A
-HREF="#HostNameLookups">HostNameLookups
-directive.
-
The /mm
notation specifies a CIDR netmask, a shown in
-Table 1.
-
The @LOCAL
name will deny access from all local
-interfaces. The @IF(name)
name will deny access from
-the named interface. In both cases, CUPS only denies access from
-the network that the interface(s) are configured for - requests
-arriving on the interface from a foreign network will
-not be denied.
-
The Deny
directive must appear inside a <A
-HREF="#Location">Location
or <A
-HREF="#Limit">Limit
section.
-
CUPS 1.4/OS X 10.6DirtyCleanInterval
-
Examples
-
-DirtyCleanInterval 1w
-DirtyCleanInterval 1d
-DirtyCleanInterval 1h
-DirtyCleanInterval 1m
-DirtyCleanInterval 30
-DirtyCleanInterval 0-
-
Description
-
The DirtyCleanInterval
directive specifies the amount of time to wait before updating configuration and state files for printers, classes, subscriptions, and jobs in seconds (no suffix), minutes ("m" suffix), hours ("h" suffix), days ("d" suffix), or weeks ("w" suffix). A value of 0
causes the update to occur as soon as possible, typically within a few milliseconds.
-
The default value is 30
(30 seconds).
DocumentRoot
Examples
@@ -679,28 +118,6 @@
language needed.
-
Encryption
-
Examples
-
-<Location /path>
- ...
- Encryption Never
- Encryption IfRequested
- Encryption Required
-</Location>
-
-
Description
-
The Encryption
directive must appear instead a <A
-HREF="#Location">Location
or <A
-HREF="#Limit">Limit
section and specifies the
-encryption settings for that location. The default setting is
-IfRequested
for all locations.
ErrorLog
Examples
@@ -726,45 +143,6 @@
information to the system log instead of a plain file.
-
CUPS 1.3/OS X 10.5ErrorPolicy
-
Examples
-
-ErrorPolicy abort-job
-ErrorPolicy retry-job
-ErrorPolicy stop-printer-
-
Description
-
The ErrorPolicy
directive defines the default policy that
-is used when a backend is unable to send a print job to the
-printer.
-
The following values are supported:
-
abort-job
- Abort the job and proceed
- with the next job in the queue
retry-job
- Retry the job after waiting- for N seconds; the cupsd.conf <A
- HREF="#JobRetryInterval">
JobRetryInterval
- directive controls the value of N
retry-this-job
- Retry the current job immediately
- and indefinitely.
stop-printer
- Stop the printer and keep- the job for future printing; this is the default
- value
-
CUPS 1.4/OS X 10.6FatalErrors
Examples
@@ -849,50 +227,6 @@-
CUPS 1.1.3FilterLimit
-
Examples
-
-FilterLimit 0
-FilterLimit 200
-FilterLimit 1000-
-
Description
-
The FilterLimit
directive sets the maximum cost
-of all running job filters. It can be used to limit the number of
-filter programs that are run on a server to minimize disk,
-memory, and CPU resource problems. A limit of 0 disables filter
-limiting.
-
An average print to a non-PostScript printer needs a filter
-limit of about 200. A PostScript printer needs about half that
-(100). Setting the limit below these thresholds will effectively
-limit the scheduler to printing a single job at any time.
-
The default limit is 0.
-
CUPS 1.1.16FilterNice
-
Examples
-
-FilterNice 0
-FilterNice 10
-FilterNice 19-
-
Description
-
The FilterNice
directive sets the nice(1)
-value to assign to filter processes. The nice value ranges from
-0, the highest priority, to 19, the lowest priority. The default
-is 0.
CUPS 1.1.3FontPath
Examples
@@ -926,613 +260,6 @@nobody
.
-
CUPS 1.6/OS X 10.8GSSServiceName
-
Examples
-
-GSSServiceName http
-GSSServiceName ipp-
-
Description
-
The GSSServiceName
directive sets the Kerberos service name to use. The default is @CUPS_DEFAULT_GSSSERVICE_NAME@
for compatibility with Microsoft Windows.
-
HostNameLookups
-
Examples
-
-HostNameLookups On
-HostNameLookups Off
-HostNameLookups Double-
-
Description
-
The HostNameLookups
directive controls whether or
-not CUPS looks up the hostname for connecting clients. The
-Double
setting causes CUPS to verify that the
-hostname resolved from the address matches one of the addresses
-returned for that hostname. Double
lookups also
-prevent clients with unregistered addresses from connecting to
-your server.
-
The default is Off
to avoid the potential server
-performance problems with hostname lookups. Set this option to
-On
or Double
only if absolutely
-required.
-
CUPS 1.1.9Include
-
Examples
-
-Include filename
-Include /foo/bar/filename-
-
Description
-
The Include
directive includes the named file in
-the cupsd.conf
file. If no leading path is provided,
-the file is assumed to be relative to the <A
-HREF="#ServerRoot">ServerRoot
directory.
-
CUPS 1.5JobPrivateAccess
-
Examples
-
-JobPrivateAccess all
-JobPrivateAccess default
-JobPrivateAccess {user|@group|@ACL|@OWNER|@SYSTEM}+-
-
Description
-
The JobPrivateAccess
directive specifies the access list for a
-job's private values. The "default" access list is "@owner @System". "@acl" maps
-to the printer's requesting-user-name-allowed or requesting-user-name-denied
-values.
-
The JobPrivateAccess
directive must appear inside a <A
-HREF="#Policy">Policy
section.
-
CUPS 1.5JobPrivateValues
-
Examples
-
-JobPrivateValues all
-JobPrivateValues default
-JobPrivateValues none
-JobPrivateValues attribute-name-1 [ ... attribute-name-N ]-
-
Description
-
The JobPrivateValues
directive specifies the list of job values
-to make private. The "default" values are "job-name",
-"job-originating-host-name", "job-originating-user-name", and "phone".
-
The JobPrivateValues
directive must appear inside a <A
-HREF="#Policy">Policy
section.
-
CUPS 1.2/OS X 10.5JobRetryInterval
-
Examples
-
-JobRetryInterval 1w
-JobRetryInterval 1d
-JobRetryInterval 1h
-JobRetryInterval 1m
-JobRetryInterval 30-
-
Description
-
The JobRetryInterval
directive specifies the amount of time to wait before retrying a job in seconds (no suffix), minutes ("m" suffix), hours ("h" suffix), days ("d" suffix), or weeks ("w" suffix). This is typically used for fax queues but can also be used with normal print queues whose error policy is retry-job
or retry-current-job
.
-
The default is 30
(30 seconds).
-
CUPS 1.4/OS X 10.6JobKillDelay
-
Examples
-
-JobKillDelay 1w
-JobKillDelay 1d
-JobKillDelay 1h
-JobKillDelay 1m
-JobKillDelay 30-
-
Description
-
The JobKillDelay
directive specifies the amount of time to wait before killing the filters and backend associated with a canceled or held job in seconds (no suffix), minutes ("m" suffix), hours ("h" suffix), days ("d" suffix), or weeks ("w" suffix).
-
The default is 30
(30 seconds).
-
CUPS 1.2/OS X 10.5JobRetryLimit
-
Examples
-
-JobRetryLimit 5
-JobRetryLimit 50-
-
Description
-
The JobRetryLimit
directive specifies the maximum
-number of times the scheduler will try to print a job. This is
-typically used for fax queues but can also be used with normal
-print queues whose error policy is retry-job
. The
-default is 5 times.
-
KeepAlive
-
Examples
-
-KeepAlive On
-KeepAlive Off-
-
Description
-
The KeepAlive
directive controls whether or not
-to support persistent HTTP connections. The default is
-On
.
-
HTTP/1.1 clients automatically support persistent connections,
-while HTTP/1.0 clients must specifically request them using the
-Keep-Alive
attribute in the Connection:
-field of each request.
-
KeepAliveTimeout
-
Examples
-
-KeepAliveTimeout 1w
-KeepAliveTimeout 1d
-KeepAliveTimeout 1h
-KeepAliveTimeout 1m
-KeepAliveTimeout 30-
-
Description
-
The KeepAliveTimeout
directive controls how long a persistent HTTP connection will remain open after the last request in seconds (no suffix), minutes ("m" suffix), hours ("h" suffix), days ("d" suffix), or weeks ("w" suffix).
-
The default is 30
(30 seconds).
-
CUPS 1.1.7Limit (Location)
-
Examples
-
-<Location /path>
- <Limit GET POST>
- ...
- </Limit>
- <Limit ALL>
- ...
- </Limit>
-</Location>
-
-
Description
-
The Limit
directive groups access control
-directives for specific types of HTTP requests and must appear
-inside a Location
section.
-Access can be limited for individual request types
-(DELETE
, GET
, HEAD
,
-OPTIONS
, POST
, PUT
, and
-TRACE
) or for all request types (ALL
).
-The request type names are case-sensitive for compatibility with
-Apache.
-
CUPS 1.2/OS X 10.5Limit (Policy)
-
Examples
-
-<Policy name>
- <Limit CUPS-Add-Modify-Printer CUPS-Delete-Printer>
- ...
- </Limit>
- <Limit All>
- ...
- </Limit>
-</Policy>
-
-
Description
-
When included in Policy
-sections, the Limit
directive groups access control
-directives for specific IPP operations. Multiple operations can
-be listed, separated by spaces. Table 2 lists the supported
-operations.
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-Table 2: Supported IPP Operations
Operation Name | Description |
---|---|
All | All operations - used as the default limit for
|
Cancel-Job | Cancel a job |
Cancel-Subscription | Cancel a subscription |
Create-Job | Create a new, empty job |
Create-Job-Subscription | Creates a notification subscription on a job |
Create-Printer-Subscription | Creates a notification subscription on a printer |
CUPS-Accept-Jobs | Sets the printer-is-accepting-jobs value for a printer to true |
CUPS-Add-Modify-Class | Adds or modifies a class |
CUPS-Add-Modify-Printer | Adds or modifies a printer |
CUPS-Authenticate-Job | Authenticates a job for printing |
CUPS-Delete-Class | Deletes a class |
CUPS-Delete-Printer | Deletes a printer |
CUPS-Get-Classes | Gets a list of classes |
CUPS-Get-Default | Gets the (network/server) default printer or class |
CUPS-Get-Devices | Gets a list of available devices |
CUPS-Get-PPDs | Gets a list of available manufacturers or drivers |
CUPS-Get-Printers | Gets a list of printers and/or classes |
CUPS-Move-Job | Moves a job to a new destination |
CUPS-Reject-Jobs | Sets the printer-is-accepting-jobs value for a printer to false |
CUPS-Set-Default | Sets the network/server default printer or class |
Disable-Printer | Sets the printer-state value for a printer to stopped |
Enable-Printer | Sets the printer-state value for a printer to idle/processing |
Get-Job-Attributes | Gets information about a job |
Get-Jobs | Gets a list of jobs |
Get-Notifications | Gets a list of events |
Get-Printer-Attributes | Gets information about a printer or class |
Get-Subscription-Attributes | Gets information about a notification subscription |
Get-Subscriptions | Gets a list of notification subscriptions |
Hold-Job | Holds a job for printing |
Pause-Printer | Sets the printer-state value for a printer to stopped |
Print-Job | Creates a job with a single file for printing |
Purge-Jobs | Removes all jobs from a printer |
Release-Job | Releases a previously held job for printing |
Renew-Subscription | Renews a notification subscription |
Restart-Job | Reprints a job |
Resume-Printer | Sets the printer-state value for a printer to idle/processing |
Send-Document | Adds a file to an job created with Create-Job |
Set-Job-Attributes | Changes job options |
Validate-Job | Validates job options prior to printing |
-
CUPS 1.1.7LimitExcept
-
Examples
-
-<Location /path>
- <LimitExcept GET POST>
- ...
- </LimitExcept>
-</Location>
-
-
Description
-
The LimitExcept
directive groups access control
-directives for specific types of HTTP requests and must appear
-inside a Location
section.
-Unlike the Limit
directive,
-LimitExcept
restricts access for all requests
-except those listed on the LimitExcept
-line.
-
LimitRequestBody
-
Examples
-
-LimitRequestBody 10485760
-LimitRequestBody 10m
-LimitRequestBody 0-
-
Description
-
The LimitRequestBody
directive controls the
-maximum size of print files, IPP requests, and HTML form data in
-HTTP POST requests. The default limit is 0 which disables the
-limit check.
-
Listen
-
Examples
-
-Listen 127.0.0.1:631
-Listen 192.0.2.1:631
-Listen [::1]:631
-Listen *:631-
-
Description
-
The Listen
directive specifies a network address
-and port to listen for connections. Multiple Listen
-directives can be provided to listen on multiple addresses.
-
The Listen
directive is similar to the <A
-HREF="#Port">Port
directive but allows you to
-restrict access to specific interfaces or networks.
-
CUPS 1.1.7ListenBackLog
-
Examples
-
-ListenBackLog 5
-ListenBackLog 10-
-
Description
-
The ListenBackLog
directive sets the maximum
-number of pending connections the scheduler will allow. This
-normally only affects very busy servers that have reached the <A
-HREF="#MaxClients">MaxClients
limit, but can
-also be triggered by large numbers of simultaneous connections.
-When the limit is reached, the operating system will refuse
-additional connections until the scheduler can accept the pending
-ones. The default is the OS-defined default limit, typically
-either 5 for older operating systems or 128 for newer operating
-systems.
-
Location
-
Examples
-
-<Location />
-...-</Location>
-<Location /admin>
-...-</Location>
-<Location /admin/conf>
-...-</Location>
-<Location /admin/log>
-...-</Location>
-<Location /classes>
-...-</Location>
-<Location /classes/name>
-...-</Location>
-<Location /jobs>
-...-</Location>
-<Location /printers>
-...-</Location>
-<Location /printers/name>
-...-</Location>
-
-
Description
-
The Location
directive specifies access control
-and authentication options for the specified HTTP resource or
-path. The Allow
, <A
-HREF="#AuthType">AuthType
, <A
-HREF="#Deny">Deny
, <A
-HREF="#Encryption">Encryption
, <A
-HREF="#Limit">Limit
, <A
-HREF="#LimitExcept">LimitExcept
, <A
-HREF="#Order">Order
, <A
-HREF="#Require">Require
, and <A
-HREF="#Satisfy">Satisfy
directives may all
-appear inside a location.
-
Note that more specific resources override the less specific
-ones. So the directives inside the /printers/name
-location will override ones from /printers
.
-Directives inside /printers
will override ones from
-/
. None of the directives are inherited.
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
Table 3: Common Locations on the ServerLocation | Description |
---|---|
/ | The path for all get operations (get-printers, get-jobs, etc.) |
/admin | The path for all administration operations (add-printer, delete-printer, start-printer, etc.) |
/admin/conf | The path for access to the CUPS configuration files (cupsd.conf, client.conf, etc.) |
/admin/log | The path for access to the CUPS log files (access_log, error_log, page_log) |
/classes | The path for all classes |
/classes/name | The resource for class name |
/jobs | The path for all jobs (hold-job, release-job, etc.) |
/jobs/id | The resource for job id |
/printers | The path for all printers |
/printers/name | The path for printer name |
/printers/name.ppd | The PPD file path for printer name |
-
LogDebugHistory
-
Examples
-
-LogDebugHistory 0
-LogDebugHistory 200-
-
Description
-
When LogLevel
is not set to
-debug
or debug2
, the LogDebugHistory
-directive specifies the number of debugging messages that are logged when an
-error occurs during printing. The default is 200 messages. A value of 0
-disables debugging history entirely and is not recommended.
CUPS 1.1.15LogFilePerm
Examples
@@ -1549,350 +276,6 @@
is @CUPS_LOG_FILE_PERM@.
-
LogLevel
-
Examples
-
-LogLevel none
-LogLevel emerg
-LogLevel alert
-LogLevel crit
-LogLevel error
-LogLevel warn
-LogLevel notice
-LogLevel info
-LogLevel debug
-LogLevel debug2-
-
Description
-
The LogLevel
directive specifies the level of
-logging for the ErrorLog
-file. The following values are recognized (each level logs
-everything under the preceding levels):
-
-
none
- Log nothingemerg
- Log emergency conditions that
- prevent the server from running
alert
- Log alerts that must be handled
- immediately
crit
- Log critical errors that don't
- prevent the server from running
-
error
- Log general errors-
warn
- Log errors and warnings-
notice
- Log temporary error conditionsinfo
- Log all requests and state
- changes
debug
- Log basic debugging
- information
debug2
- Log all debugging
- information
-
-
The default LogLevel
is @CUPS_LOG_LEVEL@
.
-
LogTimeFormat
-
Examples
-
-LogTimeFormat standard
-LogTimeFormat usecs-
-
Description
-
The LogTimeFormat
directive specifies the format used for the
-date and time in the log files. Standard
uses the standard Apache
-Common Log Format date and time while usecs
adds microseconds.
-The default is standard
.
-
MaxClients
-
Examples
-
-MaxClients 100
-MaxClients 1024-
-
Description
-
The MaxClients
directive controls the maximum
-number of simultaneous clients that will be allowed by the
-server. The default is 100 clients.
-Note:
-
Since each print job requires a file descriptor for the status
-pipe, the scheduler internally limits the MaxClients
-value to 1/3 of the available file descriptors to avoid possible
-problems when printing large numbers of jobs.
-
-
CUPS 1.1.18MaxClientsPerHost
-
Examples
-
-MaxClientsPerHost 10-
-
Description
-
The MaxClientsPerHost
directive controls the
-maximum number of simultaneous clients that will be allowed from
-a single host by the server. The default is the
-MaxClients
value.
-
This directive provides a small measure of protection against
-Denial of Service attacks from a single host.
-
CUPS 1.1.16MaxCopies
-
Examples
-
-MaxCopies 100
-MaxCopies 65535-
-
Description
-
The MaxCopies
directive controls the maximum
-number of copies that a user can print of a job. The default is
-@CUPS_MAX_COPIES@ copies.
-Note:
-
Most HP PCL laser printers internally limit the number of
-copies to 100.
-
-
CUPS 1.6/OS X 10.8MaxHoldTime
-
Examples
-
-MaxHoldTime 10800
-MaxHoldTime 3h
-MaxHoldTime 180m
-MaxHoldTime 0-
-
Description
-
The MaxHoldTime
directive controls the maximum number of seconds allowed for a job to remain in the "indefinite" hold state. The job is canceled automatically if it remains held indefinitely longer than the specified time interval in seconds (no suffix), minutes ("m" suffix), hours ("h" suffix), days ("d" suffix), or weeks ("w" suffix).
-
The default setting is 0
which disables this functionality.
-
MaxJobs
-
Examples
-
-MaxJobs 100
-MaxJobs 9999
-MaxJobs 0-
-
Description
-
The MaxJobs
directive controls the maximum number
-of jobs that are kept in memory. Once the number of jobs reaches
-the limit, the oldest completed job is automatically purged from
-the system to make room for the new one. If all of the known jobs
-are still pending or active then the new job will be
-rejected.
-
Setting the maximum size to 0 disables this functionality. The
-default setting is 500.
-
CUPS 1.1.7MaxJobsPerPrinter
-
Examples
-
-MaxJobsPerPrinter 100
-MaxJobsPerPrinter 9999
-MaxJobsPerPrinter 0-
-
Description
-
The MaxJobsPerPrinter
directive controls the
-maximum number of active jobs that are allowed for each printer
-or class. Once a printer or class reaches the limit, new jobs
-will be rejected until one of the active jobs is completed,
-stopped, aborted, or canceled.
-
Setting the maximum to 0 disables this functionality. The
-default setting is 0.
-
CUPS 1.1.7MaxJobsPerUser
-
Examples
-
-MaxJobsPerUser 100
-MaxJobsPerUser 9999
-MaxJobsPerUser 0-
-
Description
-
The MaxJobsPerUser
directive controls the maximum
-number of active jobs that are allowed for each user. Once a user
-reaches the limit, new jobs will be rejected until one of the
-active jobs is completed, stopped, aborted, or canceled.
-
Setting the maximum to 0 disables this functionality. The
-default setting is 0.
-
CUPS 1.6/OS X 10.8MaxJobTime
-
Examples
-
-MaxJobTime 10800
-MaxJobTime 3h
-MaxJobTime 180m
-MaxJobTime 0-
-
Description
-
The MaxJobTime
directive controls the maximum number of
-seconds allowed for a job to complete printing before it is considered "stuck".
-The job is canceled automatically if it takes longer than the specified time to complete in seconds (no suffix), minutes ("m" suffix), hours ("h" suffix), days ("d" suffix), or weeks ("w" suffix).
-
Setting the maximum time to 0
disables this functionality. The default setting is 3h
(3 hours).
-
MaxLogSize
-
Examples
-
-MaxLogSize 1048576
-MaxLogSize 1m
-MaxLogSize 0-
-
Description
-
The MaxLogSize
directive controls the maximum
-size of each log file. Once a log file reaches or exceeds the
-maximum size it is closed and renamed to filename.O.
-This allows you to rotate the logs automatically. The default
-size is 1048576 bytes (1MB).
-
Setting the maximum size to 0 disables log rotation.
-
DeprecatedMaxRequestSize
-
Examples
-
-MaxRequestSize 10485760
-MaxRequestSize 10m
-MaxRequestSize 0-
-
Description
-
The MaxRequestSize
directive controls the maximum
-size of print files, IPP requests, and HTML form data in HTTP
-POST requests. The default limit is 0 which disables the limit
-check.
-
This directive is deprecated and will be removed in a
-future CUPS release. Use the <A
-HREF="#LimitRequestBody">LimitRequestBody
-directive instead.
-
CUPS 1.4/OS X 10.6MultipleOperationTimeout
-
Examples
-
-MultipleOperationTimeout 1w
-MultipleOperationTimeout 1d
-MultipleOperationTimeout 1h
-MultipleOperationTimeout 5m
-MultipleOperationTimeout 300-
-
Description
-
The MultipleOperationTimeout
directive sets the maximum amount of time between files in a multi-file print job in seconds (no suffix), minutes ("m" suffix), hours ("h" suffix), days ("d" suffix), or weeks ("w" suffix).
-
The default is 5m
(five minutes).
-
Order
-
Examples
-
-<Location /path>
- ...
- Order Allow,Deny
- Order Deny,Allow
-</Location>
-
-
Description
-
The Order
directive defines the default access
-control. The following values are supported:
-
allow,deny
- Deny requests by default,- then check the
Allow
- lines followed by the <A
- HREF="#Deny">Deny
lines
deny,allow
- Allow requests by default,- then check the
Deny
- lines followed by the <A
- HREF="#Allow">Allow
lines
-
-
The Order
directive must appear inside a <A
-HREF="#Location">Location
or <A
-HREF="#Limit">Limit
section.
PageLog
Examples
@@ -1918,184 +301,6 @@ information to the system log instead of a plain file.-
PageLogFormat
-
Examples
-
-PageLogFormat %p %u %j %T %P %C %{job-billing} %{job-originating-host-name} %{job-name} %{media} %{sides}
-PageLogFormat PAGE %p %u %j %P %C %{job-billing} %{job-originating-host-name}-
-
Description
-
The PageLogFormat
directive sets the format of lines
-that are logged to the page log file. Sequences beginning with percent (%)
-characters are replaced with the corresponding information, while all other
-characters are copied literally. The following percent sequences are
-recognized:
-
-
%%
: Inserts a single percent character.%{name}
: Inserts the value of the specified IPP
- attribute.
-
%C
: Inserts the number of copies for the current page.-
%P
: Inserts the current page number.%T
: Inserts the current date and time in common log
- format.
-
%j
: Inserts the job ID.-
%p
: Inserts the printer name.-
%u
: Inserts the username.-
-
The default is "%p %u %j %T %P %C %{job-billing} %{job-originating-host-name} %{job-name} %{media} %{sides}".
-
CUPS 1.2/OS X 10.5PassEnv
-
Examples
-
-PassEnv MY_ENV_VARIABLE-
-
Description
-
The PassEnv
directive specifies an environment
-variable that should be passed to child processes. Normally, the
-scheduler only passes the DYLD_LIBRARY_PATH
,
-LD_ASSUME_KERNEL
, LD_LIBRARY_PATH
,
-LD_PRELOAD
, NLSPATH
,
-SHLIB_PATH
, TZ
, and VGARGS
-environment variables to child processes.
-
CUPS 1.2/OS X 10.5Policy
-
Examples
-
-<Policy name>
- <Limit operation ... operation>
- ...
- </Limit>
- <Limit operation ... operation>
- ...
- </Limit>
- <Limit All>
- ...
- </Limit>
-</Policy>
-
-
Description
-
The Policy
directive specifies IPP operation
-access control limits. Each policy contains 1 or more <A
-HREF="#LimitIPP">Limit
sections to set the
-access control limits for specific operations - user limits,
-authentication, encryption, and allowed/denied addresses,
-domains, or hosts. The <Limit All>
section
-specifies the default access control limits for operations that
-are not listed.
-
Policies are named and associated with printers via the
-printer's operation policy setting
-(printer-op-policy
). The default policy for the
-scheduler is specified using the <A
-HREF="#DefaultPolicy">DefaultPolicy
-directive.
-
Port
-
Examples
-
-Port 631
-Port 80
-
-Port 631
-Port 80
-
-
Description
-
The Port
directive specifies a port to listen on.
-Multiple -"
|
Name | Value |
---|---|
None | No Server: header is returned |
ProductOnly | "CUPS" |
Major | "CUPS 1" |
Minor | "CUPS 1.2" |
Minimal | "CUPS 1.2.N" where N is the patch release |
OS | "CUPS 1.2.N (UNAME)" where N is the patch release and
|
Full | "CUPS 1.2.N (UNAME) IPP/1.1" where N is the patch
|
-
CUPS 1.2/OS X 10.5SetEnv
-
Examples
-
-SetEnv PATH /usr/lib/cups/filter:/bin:/usr/bin:/usr/local/bin
-SetEnv MY_ENV_VAR foo-
-
Description
-
The SetEnv
directive specifies an environment
-variable that should be passed to child processes.
-
SSLListen
-
Examples
-
-SSLListen 127.0.0.1:443
-SSLListen 192.0.2.1:443-
-
Description
-
The SSLListen
directive specifies a network
-address and port to listen for secure connections. Multiple
-SSLListen
directives can be provided to listen on
-multiple addresses.
-
The SSLListen
directive is similar to the <A
-HREF="#SSLPort">SSLPort
directive but allows you
-to restrict access to specific interfaces or networks.
-
SSLOptions
-
Examples
-
-SSLOptions None
-SSLOptions NoEmptyFragments-
-
Description
-
The SSLOptions
directive specifies additional SSL/TLS
-protocol options to use for encrypted connected. Currently only two
-options are supported - None
(the default) for the most
-secure mode and NoEmptyFragments
to allow CUPS to work with
-Microsoft Windows with the FIPS conformance mode enabled.
-
SSLPort
-
Examples
-
-SSLPort 443-
-
Description
-
The SSLPort
directive specifies a port to listen
-on for secure connections. Multiple SSLPort
lines
-can be specified to listen on multiple ports.
-
CUPS 1.6StrictConformance
-
Examples
-
-StrictConformance No
-StrictConformance Yes-
-
Description
-
The StrictConformance
directive specifies whether the scheduler
-requires strict IPP conformance for client requests, for example to not allow
-document attributes in a Create-Job request. The default is
-No
.
-
CUPS 1.5SubscriptionPrivateAccess
-
Examples
-
-SubscriptionPrivateAccess all
-SubscriptionPrivateAccess default
-SubscriptionPrivateAccess {user|@group|@ACL|@OWNER|@SYSTEM}+-
-
Description
-
The SubscriptionPrivateAccess
directive specifies the access list for a
-subscription's private values. The "default" access list is "@owner @System".
-"@acl" maps to the printer's requesting-user-name-allowed or
-requesting-user-name-denied values.
-
The SubscriptionPrivateAccess
directive must appear inside a <A
-HREF="#Policy">Policy
section.
-
CUPS 1.5SubscriptionPrivateValues
-
Examples
-
-SubscriptionPrivateValues all
-SubscriptionPrivateValues default
-SubscriptionPrivateValues none
-SubscriptionPrivateValues attribute-name-1 [ ... attribute-name-N ]-
-
Description
-
The SubscriptionPrivateValues
directive specifies the list of
-subscription values to make private. The "default" values are "notify-events",
-"notify-pull-method", "notify-recipient-uri", "notify-subscriber-user-name", and
-"notify-user-data".
-
The SubscriptionPrivateValues
directive must appear inside a <A
-HREF="#Policy">Policy
section.
SystemGroup
Examples
@@ -2676,48 +502,6 @@
-
Timeout
-
Examples
-
-Timeout 1w
-Timeout 1d
-Timeout 1h
-Timeout 5m
-Timeout 300-
-
Description
-
The Timeout
directive controls the amount of time
-to wait before an active HTTP or IPP request times out in seconds (no suffix), minutes ("m" suffix), hours ("h" suffix), days ("d" suffix), or weeks ("w" suffix).
-
The default timeout is 5m
(five minutes).
-
CUPS 1.2/OS X 10.5UseNetworkDefault
-
Examples
-
-UseNetworkDefault yes
-UseNetworkDefault no-
-
Description
-
The UseNetworkDefault
directive controls whether
-the client will use a network/remote printer as a default
-printer. If enabled, the default printer of a server is used as
-the default printer on a client. When multiple servers are
-advertising a default printer, the client's default printer is
-set to the first discovered printer, or to the implicit class for
-the same printer available from multiple servers.
-
The default is @CUPS_USE_NETWORK_DEFAULT@
.
User
Examples
@@ -2743,18 +527,5 @@-
CUPS 1.5WebInterface
-
Examples
-
-WebInterface yes
-WebInterface no-
-
Description
-
The WebInterface
directive specifies whether the web interface is enabled. The default value is @CUPS_WEBIF@
.
Index: doc/help/ref-cupsd-conf.html.in
--- doc/help/ref-cupsd-conf.html.in (revision 10708)
+++ doc/help/ref-cupsd-conf.html.in (working copy)
@@ -197,82 +197,6 @@
HREF="#Limit">Limit
section.
-
DeprecatedAuthClass
-
Examples
-
-<Location /path>
- ...
- AuthClass Anonymous
- AuthClass User
- AuthClass System
- AuthClass Group
-</Location>
-
-
Description
-
The AuthClass
directive defines what level of
-authentication is required:
-
Anonymous
- No authentication should be
- performed (default)
User
- A valid username and password is
- required
System
- A valid username and password- is required, and the username must belong to the "sys"
- group; this can be changed using the <A
- HREF="#SystemGroup">
SystemGroup
- directive
Group
- A valid username and password is- required, and the username must belong to the group named
- by the <A
- HREF="#AuthGroupName">
AuthGroupName
- directive
-
-
The AuthClass
directive must appear inside a <A
-HREF="#Location">Location
or <A
-HREF="#Limit">Limit
section.
-
This directive is deprecated and will be removed from a
-future release of CUPS. Consider using the more flexible <A
-HREF="#Require">Require
directive instead.
-
DeprecatedAuthGroupName
-
Examples
-
-<Location /path>
- ...
- AuthGroupName mygroup
- AuthGroupName lp
-</Location>
-
-
Description
-
The AuthGroupName
directive sets the group to use
-for Group
authentication.
-
The AuthGroupName
directive must appear inside a
-Location
or <A
-HREF="#Limit">Limit
section.
-
This directive is deprecated and will be removed from a
-future release of CUPS. Consider using the more flexible <A
-HREF="#Require">Require
directive instead.
AuthType
Examples
@@ -2096,49 +2020,6 @@
-
Printcap
-
Examples
-
-Printcap
-Printcap /etc/printcap
-Printcap /etc/printers.conf
-Printcap /Library/Preferences/org.cups.printers.plist-
-
Description
-
The Printcap
directive controls whether or not a
-printcap file is automatically generated and updated with a list
-of available printers. If specified with no value, then no
-printcap file will be generated. The default is to generate a
-file named @CUPS_DEFAUL_PRINTCAP@.
-
When a filename is specified (e.g. @CUPS_DEFAULT_PRINTCAP@),
-the printcap file is written whenever a printer is added or
-removed. The printcap file can then be used by applications that
-are hardcoded to look at the printcap file for the available
-printers.
-
PrintcapFormat
-
Examples
-
-PrintcapFormat BSD
-PrintcapFormat Solaris
-PrintcapFormat plist-
-
Description
-
The PrintcapFormat
directive controls the output format of the
-printcap file. The default is to generate the plist format on OS X, the
-Solaris format on Solaris, and the BSD format on other operating systems.
CUPS 1.1.21ReloadTimeout
Examples
@@ -2155,42 +2036,6 @@ before doing a restart. The default is 30 seconds.-
CUPS 1.1.3RemoteRoot
-
Examples
-
-RemoteRoot remroot
-RemoteRoot root-
-
Description
-
The RemoteRoot
directive sets the username for
-unauthenticated root requests from remote hosts. The default
-username is remroot. Setting RemoteRoot
-to root effectively disables this security
-mechanism.
-
RequestRoot
-
Examples
-
-RequestRoot /var/spool/cups
-RequestRoot /foo/bar/spool/cups-
-
Description
-
The RequestRoot
directive sets the directory for
-incoming IPP requests and HTML forms. If an absolute path is not
-provided then it is assumed to be relative to the <A
-HREF="#ServerRoot">ServerRoot
directory. The
-default request directory is @CUPS_REQUESTS@.
CUPS 1.1.7Require
Examples
@@ -2343,64 +2188,6 @@-
ServerBin
-
Examples
-
-ServerBin /usr/lib/cups
-ServerBin /foo/bar/lib/cups-
-
Description
-
The ServerBin
directive sets the directory for
-server-run executables. If an absolute path is not provided then
-it is assumed to be relative to the <A
-HREF="#ServerRoot">ServerRoot
directory. The
-default executable directory is /usr/lib/cups,
-/usr/lib32/cups, or /usr/libexec/cups
-depending on the operating system.
-
ServerCertificate
-
Examples
-
-ServerCertificate /etc/cups/ssl/server.crt-
-
Description
-
The ServerCertificate
directive specifies the
-location of the SSL certificate file used by the server when
-negotiating encrypted connections. The certificate must not be
-encrypted (password protected) since the scheduler normally runs
-in the background and will be unable to ask for a password.
-
The default certificate file is
-/etc/cups/ssl/server.crt.
-
ServerKey
-
Examples
-
-ServerKey /etc/cups/ssl/server.key-
-
Description
-
The ServerKey
directive specifies the location of
-the SSL private key file used by the server when negotiating
-encrypted connections.
-
The default key file is
-/etc/cups/ssl/server.crt.
ServerName
Examples
@@ -2417,23 +2204,6 @@ hostname.-
ServerRoot
-
Examples
-
-ServerRoot /etc/cups
-ServerRoot /foo/bar/cups-
-
Description
-
The ServerRoot
directive specifies the absolute
-path to the server configuration and state files. It is also used
-to resolve relative paths in the cupsd.conf file. The
-default server directory is /etc/cups.
CUPS 1.1.21ServerTokens
Examples
@@ -2629,53 +2399,6 @@ HREF="#Policy">Policy
section.
-
SystemGroup
-
Examples
-
-SystemGroup lpadmin
-SystemGroup sys
-SystemGroup system
-SystemGroup root
-SystemGroup root lpadmin-
-
Description
-
The SystemGroup
directive specifies the system
-administration group for System
authentication.
-Multiple groups can be listed, separated with spaces. The default
-group list is @CUPS_SYSTEM_GROUPS@
.
-
TempDir
-
Examples
-
-TempDir /var/tmp
-TempDir /foo/bar/tmp-
-
Description
-
The TempDir
directive specifies an absolute path
-for the directory to use for temporary files. The default
-directory is @CUPS_REQUESTS@/tmp.
-
Temporary directories must be world-writable and should have
-the "sticky" permission bit enabled so that other users cannot
-delete filter temporary files. The following commands will create
-an appropriate temporary directory called
-/foo/bar/tmp:
-
-mkdir /foo/bar/tmp
-chmod a+rwxt /foo/bar/tmp-
Timeout
Examples
@@ -2696,53 +2419,6 @@The default timeout is 5m
(five minutes).
-
CUPS 1.2/OS X 10.5UseNetworkDefault
-
Examples
-
-UseNetworkDefault yes
-UseNetworkDefault no-
-
Description
-
The UseNetworkDefault
directive controls whether
-the client will use a network/remote printer as a default
-printer. If enabled, the default printer of a server is used as
-the default printer on a client. When multiple servers are
-advertising a default printer, the client's default printer is
-set to the first discovered printer, or to the implicit class for
-the same printer available from multiple servers.
-
The default is @CUPS_USE_NETWORK_DEFAULT@
.
-
User
-
Examples
-
-User lp
-User guest-
-
Description
-
The User
directive specifies the UNIX user that
-filter and CGI programs run as. The default user is
-@CUPS_USER@
.
-Note:
-
You may not use user root
, as that would expose
-the system to unacceptable security risks. The scheduler will
-automatically choose user nobody
if you specify a
-user whose ID is 0.
-
CUPS 1.5WebInterface
Examples
Index: doc/Makefile
--- doc/Makefile (revision 10708)
+++ doc/Makefile (working copy)
@@ -3,7 +3,7 @@
Documentation makefile for CUPS.
-# Copyright 2007-2011 by Apple Inc.
+# Copyright 2007-2012 by Apple Inc.
Copyright 1997-2007 by Easy Software Products.
These coded instructions, statements, and computer programs are the
Property changes on: man
Modified: svn:ignore
- *.0
*.1
*.1m
*.3
*.5
*.7
*.8
*.gz
*.z
client.conf.man
cups-deviced.man
cups-driverd.man
cups-lpd.man
cups-snmp.man
cupsaddsmb.man
cupsd.conf.man
cupsd.man
lpoptions.man
mantohtml - *.0
*.1
*.1m
*.3
*.5
*.7
*.8
*.gz
*.z
client.conf.man
cups-deviced.man
cups-driverd.man
cups-files.conf.man
cups-lpd.man
cups-snmp.man
cupsaddsmb.man
cupsd.conf.man
cupsd.man
lpoptions.man
mantohtml
Index: man/cupsd.conf.man.in
--- man/cupsd.conf.man.in (revision 10708)
+++ man/cupsd.conf.man.in (working copy)
@@ -12,12 +12,15 @@
." which should have been included with this file. If this file is
." file is missing or damaged, see the license at "http://www.cups.org/".
."
-.TH cupsd.conf 5 "CUPS" "18 May 2012" "Apple Inc."
+.TH cupsd.conf 5 "CUPS" "19 November 2012" "Apple Inc."
.SH NAME
cupsd.conf - server configuration file for cups
.SH DESCRIPTION
The \fIcupsd.conf\fR file configures the CUPS scheduler, \fIcupsd(8)\fR. It
-is normally located in the \fI@CUPS_SERVERROOT@\fR directory.
+is normally located in the \fI@CUPS_SERVERROOT@\fR directory. \fBNote:\fR
+File, directory, and user configuration directives that used to be allowed in
+the \fIcupsd.conf\fR file are now stored in the \fIcups-files.conf(5)\fR instead
+in order to prevent certain types of privilege escalation attacks.
.LP
Each line in the file can be a configuration directive, a blank line,
or a comment. Comment lines start with the # character. The
@@ -27,12 +30,6 @@
The following directives are understood by \fIcupsd(8)\fR. Consult the
on-line help for detailed descriptions:
.TP 5
-AccessLog filename
-.TP 5
-AccessLog syslog
-.br
-Defines the access log filename.
-.TP 5
AccessLogLevel config
.TP 5
AccessLogLevel actions
@@ -61,20 +58,6 @@
.br
Allows access from the named hosts or addresses.
.TP 5
-AuthClass User
-.TP 5
-AuthClass Group
-.TP 5
-AuthClass System
-.br
-Specifies the authentication class (User, Group, System) -
-\fBthis directive is deprecated\fR.
-.TP 5
-AuthGroupName group-name
-.br
-Specifies the authentication group - \fBthis directive is
-deprecated\fR.
-.TP 5
AuthType None
.TP 5
AuthType Basic
@@ -108,7 +91,7 @@
.TP 5
Browsing No
.br
-Specifies whether or not remote printer browsing should be enabled.
+Specifies whether or not shared printers should be advertised.
.TP 5
Classification banner
.br
@@ -121,15 +104,6 @@
Specifies whether to allow users to override the classification
of individual print jobs.
.TP 5
-ConfigFilePerm mode
-.br
-Specifies the permissions for all configuration files that the scheduler
-writes.
-.TP 5
-DataDir path
-.br
-Specified the directory where data files can be found.
-.TP 5
DefaultAuthType Basic
.TP 5
DefaultAuthType BasicDigest
@@ -197,10 +171,6 @@
causes the update to happen as soon as possible, typically within a few
milliseconds.
.TP 5
-DocumentRoot directory
-.br
-Specifies the root directory for the internal web server documents.
-.TP 5
Encryption IfRequested
.TP 5
Encryption Never
@@ -210,28 +180,6 @@
Specifies the level of encryption that is required for a particular
location.
.TP 5
-ErrorLog filename
-.TP 5
-ErrorLog syslog
-.br
-Specifies the error log filename.
-.TP 5
-FatalErrors none
-.TP 5
-FatalErrors all -kind [... -kind]
-.TP 5
-FatalErrors kind [... kind]
-.br
-Specifies which errors are fatal, causing the scheduler to exit. "Kind" is
-"browse", "config", "listen", "log", or "permissions".
-.TP 5
-FileDevice Yes
-.TP 5
-FileDevice No
-.br
-Specifies whether the file pseudo-device can be used for new
-printer queues.
-.TP 5
FilterLimit limit
.br
Specifies the maximum cost of filters that are run concurrently.
@@ -241,15 +189,6 @@
Specifies the scheduling priority ("nice" value) of filters that
are run to print a job.
.TP 5
-FontPath directory[:directory:...]
-.br
-Specifies the search path for fonts.
-.TP 5
-Group group-name-or-number
-.br
-Specifies the group name or ID that will be used when executing
-external programs.
-.TP 5
GSSServiceName name
.br
Specifies the service name when using Kerberos authentication. The default
@@ -341,10 +280,6 @@
Specifies the number of debugging messages that are logged when an error
occurs in a print job.
.TP 5
-LogFilePerm mode
-.br
-Specifies the permissions for all log files that the scheduler writes.
-.TP 5
LogLevel alert
.TP 5
LogLevel crit
@@ -429,12 +364,6 @@
.br
Specifies the order of HTTP access control (allow,deny or deny,allow)
.TP 5
-PageLog filename
-.TP 5
-PageLog syslog
-.br
-Specifies the page log filename.
-.TP 5
PageLogFormat format string
.br
Specifies the format of page log lines.
@@ -464,15 +393,6 @@
Specifies whether or not to preserve the job history after they are
printed.
.TP 5
-Printcap
-.TP 5
-Printcap filename
-.br
-Specifies the filename for a printcap file that is updated
-automatically with a list of available printers (needed for
-legacy applications); specifying Printcap with no filename
-disables printcap generation.
-.TP 5
PrintcapFormat bsd
.TP 5
PrintcapFormat plist
@@ -481,29 +401,11 @@
.br
Specifies the format of the printcap file.
.TP 5
-PrintcapGUI
-.TP 5
-PrintcapGUI gui-program-filename
-.br
-Specifies whether to generate option panel definition files on
-some operating systems. When provided with no program filename,
-disables option panel definition files.
-.TP 5
ReloadTimeout seconds
.br
Specifies the amount of time to wait for job completion before
restarting the scheduler.
.TP 5
-RemoteRoot user-name
-.br
-Specifies the username that is associated with unauthenticated root
-accesses.
-.TP 5
-RequestRoot directory
-.br
-Specifies the directory to store print jobs and other HTTP request
-data.
-.TP 5
Require group group-name-list
.TP 5
Require user user-name-list
@@ -535,27 +437,10 @@
Specifies an alternate name that the server is known by. The special name "*"
allows any name to be used.
.TP 5
-ServerBin directory
-.br
-Specifies the directory where backends, CGIs, daemons, and filters may
-be found.
-.TP 5
-ServerCertificate filename
-.br
-Specifies the encryption certificate to use.
-.TP 5
-ServerKey filename
-.br
-Specifies the encryption key to use.
-.TP 5
ServerName hostname-or-ip-address
.br
Specifies the fully-qualified hostname of the server.
.TP 5
-ServerRoot directory
-.br
-Specifies the directory where the server configuration files can be found.
-.TP 5
ServerTokens Full
.TP 5
ServerTokens Major
@@ -619,29 +504,17 @@
"notify-events", "notify-pull-method", "notify-recipient-uri",
"notify-subscriber-user-name", and "notify-user-data".
.TP 5
-SystemGroup group-name [group-name ...]
-.br
-Specifies the group(s) to use for System class authentication.
-.TP 5
-TempDir directory
-.br
-Specifies the directory where temporary files are stored.
-.TP 5
Timeout seconds
.br
Specifies the HTTP request timeout in seconds.
.TP 5
-User user-name
-.br
-Specifies the user name or ID that is used when running external programs.
-.TP 5
WebInterface yes
.TP 5
WebInterface no
Specifies whether the web interface is enabled.
.SH SEE ALSO
-\fIclasses.conf(5)\fR, \fIcupsd(8)\fR, \fImime.convs(5)\fR,
-\fImime.types(5)\fR, \fIprinters.conf(5)\fR,
+\fIclasses.conf(5)\fR, \fIcups-files.conf(5)\fR, \fIcupsd(8)\fR,
+\fImime.convs(5)\fR, \fImime.types(5)\fR, \fIprinters.conf(5)\fR,
\fIsubscriptions.conf(5)\fR,
.br
http://localhost:631/help
Index: man/cups-files.conf.man.in
--- man/cups-files.conf.man.in (revision 10708)
+++ man/cups-files.conf.man.in (working copy)
@@ -12,17 +12,16 @@
." which should have been included with this file. If this file is
." file is missing or damaged, see the license at "http://www.cups.org/".
."
-.TH cupsd.conf 5 "CUPS" "18 May 2012" "Apple Inc."
+.TH cups-files.conf 5 "CUPS" "19 November 2012" "Apple Inc."
.SH NAME
-cupsd.conf - server configuration file for cups
+cups-files.conf - file and directory configuration file for cups
.SH DESCRIPTION
-The \fIcupsd.conf\fR file configures the CUPS scheduler, \fIcupsd(8)\fR. It
-is normally located in the \fI@CUPS_SERVERROOT@\fR directory.
+The \fIcups-file.conf\fR file configures the files and directories used by the
+CUPS scheduler, \fIcupsd(8)\fR. It is normally located in the
+\fI@CUPS_SERVERROOT@\fR directory.
.LP
Each line in the file can be a configuration directive, a blank line,
-or a comment. Comment lines start with the # character. The
-configuration directives are intentionally similar to those used by the
-popular Apache web server software and are described below.
+or a comment. Comment lines start with the # character.
.SH DIRECTIVES
The following directives are understood by \fIcupsd(8)\fR. Consult the
on-line help for detailed descriptions:
@@ -33,94 +32,6 @@
.br
Defines the access log filename.
.TP 5
-AccessLogLevel config
-.TP 5
-AccessLogLevel actions
-.TP 5
-AccessLogLevel all
-.br
-Specifies the logging level for the AccessLog file.
-.TP 5
-Allow all
-.TP 5
-Allow none
-.TP 5
-Allow host.domain.com
-.TP 5
-Allow .domain.com
-.TP 5
-Allow ip-address
-.TP 5
-Allow ip-address/netmask
-.TP 5
-Allow ip-address/mm
-.TP 5
-Allow @if(name)
-.TP 5
-Allow @Local
-.br
-Allows access from the named hosts or addresses.
-.TP 5
-AuthClass User
-.TP 5
-AuthClass Group
-.TP 5
-AuthClass System
-.br
-Specifies the authentication class (User, Group, System) -
-\fBthis directive is deprecated\fR.
-.TP 5
-AuthGroupName group-name
-.br
-Specifies the authentication group - \fBthis directive is
-deprecated\fR.
-.TP 5
-AuthType None
-.TP 5
-AuthType Basic
-.TP 5
-AuthType BasicDigest
-.TP 5
-AuthType Digest
-.TP 5
-AuthType Negotiate
-.br
-Specifies the authentication type (None, Basic, BasicDigest, Digest, Negotiate)
-.TP 5
-AutoPurgeJobs Yes
-.TP 5
-AutoPurgeJobs No
-.br
-Specifies whether to purge job history data automatically when
-it is no longer required for quotas.
-.TP 5
-BrowseLocalProtocols [All] [DNSSD]
-.br
-Specifies the protocols to use for local printer sharing.
-.TP 5
-BrowseWebIF Yes
-.TP 5
-BrowseWebIF No
-.br
-Specifies whether the CUPS web interface is advertised via DNS-SD.
-.TP 5
-Browsing Yes
-.TP 5
-Browsing No
-.br
-Specifies whether or not remote printer browsing should be enabled.
-.TP 5
-Classification banner
-.br
-Specifies the security classification of the server.
-.TP 5
-ClassifyOverride Yes
-.TP 5
-ClassifyOverride No
-.br
-Specifies whether to allow users to override the classification
-of individual print jobs.
-.TP 5
ConfigFilePerm mode
.br
Specifies the permissions for all configuration files that the scheduler
@@ -130,86 +41,10 @@
.br
Specified the directory where data files can be found.
.TP 5
-DefaultAuthType Basic
-.TP 5
-DefaultAuthType BasicDigest
-.TP 5
-DefaultAuthType Digest
-.TP 5
-DefaultAuthType Negotiate
-.br
-Specifies the default type of authentication to use.
-.TP 5
-DefaultEncryption Never
-.TP 5
-DefaultEncryption IfRequested
-.TP 5
-DefaultEncryption Required
-.br
-Specifies the type of encryption to use for authenticated requests.
-.TP 5
-DefaultLanguage locale
-.br
-Specifies the default language to use for text and web content.
-.TP 5
-DefaultPaperSize Auto
-.TP 5
-DefaultPaperSize None
-.TP 5
-DefaultPaperSize sizename
-.br
-Specifies the default paper size for new print queues. "Auto" uses a locale-
-specific default, while "None" specifies there is no default paper size.
-.TP 5
-DefaultPolicy policy-name
-.br
-Specifies the default access policy to use.
-.TP 5
-DefaultShared Yes
-.TP 5
-DefaultShared No
-.br
-Specifies whether local printers are shared by default.
-.TP 5
-Deny all
-.TP 5
-Deny none
-.TP 5
-Deny host.domain.com
-.TP 5
-Deny *.domain.com
-.TP 5
-Deny ip-address
-.TP 5
-Deny ip-address/netmask
-.TP 5
-Deny ip-address/mm
-.TP 5
-Deny @if(name)
-.TP 5
-Deny @Local
-.br
-Denies access to the named host or address.
-.TP 5
-DirtyCleanInterval seconds
-.br
-Specifies the delay for updating of configuration and state files. A value of 0
-causes the update to happen as soon as possible, typically within a few
-milliseconds.
-.TP 5
DocumentRoot directory
.br
Specifies the root directory for the internal web server documents.
.TP 5
-Encryption IfRequested
-.TP 5
-Encryption Never
-.TP 5
-Encryption Required
-.br
-Specifies the level of encryption that is required for a particular
-location.
-.TP 5
ErrorLog filename
.TP 5
ErrorLog syslog
@@ -232,15 +67,6 @@
Specifies whether the file pseudo-device can be used for new
printer queues.
.TP 5
-FilterLimit limit
-.br
-Specifies the maximum cost of filters that are run concurrently.
-.TP 5
-FilterNice nice-value
-.br
-Specifies the scheduling priority ("nice" value) of filters that
-are run to print a job.
-.TP 5
FontPath directory[:directory:...]
.br
Specifies the search path for fonts.
@@ -250,220 +76,16 @@
Specifies the group name or ID that will be used when executing
external programs.
.TP 5
-GSSServiceName name
-.br
-Specifies the service name when using Kerberos authentication. The default
-service name is "@CUPS_DEFAULT_GSSSERVICENAME@".
-.TP 5
-HostNameLookups On
-.TP 5
-HostNameLookups Off
-.TP 5
-HostNameLookups Double
-.br
-Specifies whether or not to do reverse lookups on client addresses.
-.TP 5
-Include filename
-.br
-Includes the named file.
-.TP 5
-JobKillDelay seconds
-.br
-Specifies the number of seconds to wait before killing the filters and backend
-associated with a canceled or held job.
-.TP 5
-JobPrivateAccess all
-.TP 5
-JobPrivateAccess default
-.TP 5
-JobPrivateAccess {user|@group|@acl|@owner|@System}+
-.br
-Specifies an access list for a job's private values. The "default" access list
-is "@owner @System". "@acl" maps to the printer's requesting-user-name-allowed
-or requesting-user-name-denied values.
-.TP 5
-JobPrivateValues all
-.TP 5
-JobPrivateValues default
-.TP 5
-JobPrivateValues none
-.TP 5
-JobPrivateValues attribute-name-1 [ ... attribute-name-N ]
-Specifies the list of job values to make private. The "default" values are
-"job-name", "job-originating-host-name", and "job-originating-user-name".
-.TP 5
-JobRetryInterval seconds
-.br
-Specifies the interval between retries of jobs in seconds.
-.TP 5
-JobRetryLimit count
-.br
-Specifies the number of retries that are done for jobs.
-.TP 5
-KeepAlive Yes
-.TP 5
-KeepAlive No
-.br
-Specifies whether to support HTTP keep-alive connections.
-.TP 5
-KeepAliveTimeout seconds
-.br
-Specifies the amount of time that connections are kept alive.
-.TP 5
- ...
-.br
-Specifies the IPP operations that are being limited inside a policy.
-.TP 5
- ...
-.TP 5
- ...
-.br
-Specifies the HTTP methods that are being limited inside a location.
-.TP 5
-LimitRequestBody
-.br
-Specifies the maximum size of any print job request.
-.TP 5
-Listen ip-address:port
-.TP 5
-Listen *:port
-.TP 5
-Listen /path/to/domain/socket
-.br
-Listens to the specified address and port or domain socket path.
-.TP 5
-<Location /path> ...
-.br
-Specifies access control for the named location.
-.TP 5
-LogDebugHistory #-messages
-.br
-Specifies the number of debugging messages that are logged when an error
-occurs in a print job.
-.TP 5
LogFilePerm mode
.br
Specifies the permissions for all log files that the scheduler writes.
.TP 5
-LogLevel alert
-.TP 5
-LogLevel crit
-.TP 5
-LogLevel debug2
-.TP 5
-LogLevel debug
-.TP 5
-LogLevel emerg
-.TP 5
-LogLevel error
-.TP 5
-LogLevel info
-.TP 5
-LogLevel none
-.TP 5
-LogLevel notice
-.TP 5
-LogLevel warn
-.br
-Specifies the logging level for the ErrorLog file.
-.TP 5
-LogTimeFormat standard
-.TP 5
-LogTimeFormat usecs
-.br
-Specifies the format of the date and time in the log files.
-.TP 5
-MaxClients number
-.br
-Specifies the maximum number of simultaneous clients to support.
-.TP 5
-MaxClientsPerHost number
-.br
-Specifies the maximum number of simultaneous clients to support from a
-single address.
-.TP 5
-MaxCopies number
-.br
-Specifies the maximum number of copies that a user can print of each job.
-.TP 5
-MaxHoldTime seconds
-.br
-Specifies the maximum time a job may remain in the "indefinite" hold state
-before it is canceled. Set to 0 to disable cancellation of held jobs.
-.TP 5
-MaxJobs number
-.br
-Specifies the maximum number of simultaneous jobs to support.
-.TP 5
-MaxJobsPerPrinter number
-.br
-Specifies the maximum number of simultaneous jobs per printer to support.
-.TP 5
-MaxJobsPerUser number
-.br
-Specifies the maximum number of simultaneous jobs per user to support.
-.TP 5
-MaxJobTime seconds
-.br
-Specifies the maximum time a job may take to print before it is canceled. The
-default is 10800 seconds (3 hours). Set to 0 to disable cancellation of "stuck"
-jobs.
-.TP 5
-MaxLogSize number-bytes
-.br
-Specifies the maximum size of the log files before they are
-rotated (0 to disable rotation)
-.TP 5
-MaxRequestSize number-bytes
-.br
-Specifies the maximum request/file size in bytes (0 for no limit)
-.TP 5
-MultipleOperationTimeout seconds
-.br
-Specifies the maximum amount of time to allow between files in a multiple file
-print job.
-.TP 5
-Order allow,deny
-.TP 5
-Order deny,allow
-.br
-Specifies the order of HTTP access control (allow,deny or deny,allow)
-.TP 5
PageLog filename
.TP 5
PageLog syslog
.br
Specifies the page log filename.
.TP 5
-PageLogFormat format string
-.br
-Specifies the format of page log lines.
-.TP 5
-PassEnv variable [... variable]
-.br
-Passes the specified environment variable(s) to child processes.
-.TP 5
- ...
-.br
-Specifies access control for the named policy.
-.TP 5
-Port number
-.br
-Specifies a port number to listen to for HTTP requests.
-.TP 5
-PreserveJobFiles Yes
-.TP 5
-PreserveJobFiles No
-.br
-Specifies whether or not to preserve job files after they are printed.
-.TP 5
-PreserveJobHistory Yes
-.TP 5
-PreserveJobHistory No
-.br
-Specifies whether or not to preserve the job history after they are
-printed.
-.TP 5
Printcap
.TP 5
Printcap filename
@@ -473,27 +95,6 @@
legacy applications); specifying Printcap with no filename
disables printcap generation.
.TP 5
-PrintcapFormat bsd
-.TP 5
-PrintcapFormat plist
-.TP 5
-PrintcapFormat solaris
-.br
-Specifies the format of the printcap file.
-.TP 5
-PrintcapGUI
-.TP 5
-PrintcapGUI gui-program-filename
-.br
-Specifies whether to generate option panel definition files on
-some operating systems. When provided with no program filename,
-disables option panel definition files.
-.TP 5
-ReloadTimeout seconds
-.br
-Specifies the amount of time to wait for job completion before
-restarting the scheduler.
-.TP 5
RemoteRoot user-name
.br
Specifies the username that is associated with unauthenticated root
@@ -504,37 +105,6 @@
Specifies the directory to store print jobs and other HTTP request
data.
.TP 5
-Require group group-name-list
-.TP 5
-Require user user-name-list
-.TP 5
-Require valid-user
-.br
-Specifies that user or group authentication is required.
-.TP 5
-RIPCache bytes
-.br
-Specifies the maximum amount of memory to use when converting images
-and PostScript files to bitmaps for a printer.
-.TP 5
-Satisfy all
-.TP 5
-Satisfy any
-.br
-Specifies whether all or any limits set for a Location must be
-satisfied to allow access.
-.TP 5
-ServerAdmin user@domain.com
-.br
-Specifies the email address of the server administrator.
-.TP 5
-ServerAlias hostname [... hostname]
-.TP 5
-ServerAlias *
-.br
-Specifies an alternate name that the server is known by. The special name ""
-allows any name to be used.
-.TP 5
ServerBin directory
.br
Specifies the directory where backends, CGIs, daemons, and filters may
@@ -548,77 +118,10 @@
.br
Specifies the encryption key to use.
.TP 5
-ServerName hostname-or-ip-address
-.br
-Specifies the fully-qualified hostname of the server.
-.TP 5
ServerRoot directory
.br
Specifies the directory where the server configuration files can be found.
.TP 5
-ServerTokens Full
-.TP 5
-ServerTokens Major
-.TP 5
-ServerTokens Minimal
-.TP 5
-ServerTokens Minor
-.TP 5
-ServerTokens None
-.TP 5
-ServerTokens OS
-.TP 5
-ServerTokens ProductOnly
-.br
-Specifies what information is included in the Server header of HTTP
-responses.
-.TP 5
-SetEnv variable value
-.br
-Set the specified environment variable to be passed to child processes.
-.TP 5
-SSLListen
-.br
-Listens on the specified address and port for encrypted connections.
-.TP 5
-SSLOptions None
-.TP 5
-SSLOptions NoEmptyFragments
-.br
-Sets SSL/TLS protocol options for encrypted connections.
-.TP 5
-SSLPort
-.br
-Listens on the specified port for encrypted connections.
-.TP 5
-StrictConformance Yes
-.TP 5
-StrictConformance No
-.br
-Specifies whether the scheduler requires clients to strictly adhere to the IPP
-specifications. The default is No.
-.TP 5
-SubscriptionPrivateAccess all
-.TP 5
-SubscriptionPrivateAccess default
-.TP 5
-SubscriptionPrivateAccess {user|@group|@acl|@owner|@System}+
-.br
-Specifies an access list for a subscription's private values. The "default"
-access list is "@owner @System". "@acl" maps to the printer's
-requesting-user-name-allowed or requesting-user-name-denied values.
-.TP 5
-SubscriptionPrivateValues all
-.TP 5
-SubscriptionPrivateValues default
-.TP 5
-SubscriptionPrivateValues none
-.TP 5
-SubscriptionPrivateValues attribute-name-1 [ ... attribute-name-N ]
-Specifies the list of job values to make private. The "default" values are
-"notify-events", "notify-pull-method", "notify-recipient-uri",
-"notify-subscriber-user-name", and "notify-user-data".
-.TP 5
SystemGroup group-name [group-name ...]
.br
Specifies the group(s) to use for System class authentication.
@@ -627,20 +130,11 @@
.br
Specifies the directory where temporary files are stored.
.TP 5
-Timeout seconds
-.br
-Specifies the HTTP request timeout in seconds.
-.TP 5
User user-name
.br
Specifies the user name or ID that is used when running external programs.
-.TP 5
-WebInterface yes
-.TP 5
-WebInterface no
-Specifies whether the web interface is enabled.
.SH SEE ALSO
-\fIclasses.conf(5)\fR, \fIcupsd(8)\fR, \fImime.convs(5)\fR,
+\fIclasses.conf(5)\fR, \fIcupsd(8)\fR, \fIcupsd.conf(5)\fR, \fImime.convs(5)\fR,
\fImime.types(5)\fR, \fIprinters.conf(5)\fR,
\fIsubscriptions.conf(5)\fR,
.br
Index: man/Makefile
--- man/Makefile (revision 10708)
+++ man/Makefile (working copy)
@@ -39,6 +39,7 @@
ppdpo.$(MAN1EXT)
MAN5 = classes.conf.$(MAN5EXT)
client.conf.$(MAN5EXT) \
-
cups-files.conf.$(MAN5EXT) \ cups-snmp.conf.$(MAN5EXT) \ cupsd.conf.$(MAN5EXT) \ ipptoolfile.$(MAN5EXT) \
Index: test/run-stp-tests.sh
--- test/run-stp-tests.sh (revision 10708)
+++ test/run-stp-tests.sh (working copy)
@@ -390,26 +390,11 @@
cat >/tmp/cups-$user/cupsd.conf <<EOF
StrictConformance Yes
Browsing Off
-FileDevice yes
-Printcap
Listen localhost:$port
-User $user
-ServerRoot /tmp/cups-$user
-StateDir /tmp/cups-$user
-ServerBin /tmp/cups-$user/bin
-CacheDir /tmp/cups-$user/share
-DataDir /tmp/cups-$user/share
-FontPath /tmp/cups-$user/share/fonts
PassEnv LOCALEDIR
PassEnv DYLD_INSERT_LIBRARIES
-DocumentRoot $root/doc
-RequestRoot /tmp/cups-$user/spool
-TempDir /tmp/cups-$user/spool/temp
MaxSubscriptions 3
MaxLogSize 0
-AccessLog /tmp/cups-$user/log/access_log
-ErrorLog /tmp/cups-$user/log/error_log
-PageLog /tmp/cups-$user/log/page_log
AccessLogLevel actions
LogLevel debug2
LogTimeFormat usecs
@@ -422,6 +407,24 @@
EOF
+cat >/tmp/cups-$user/cups-files.conf <<EOF
+FileDevice yes
+Printcap
+User $user
+ServerRoot /tmp/cups-$user
+StateDir /tmp/cups-$user
+ServerBin /tmp/cups-$user/bin
+CacheDir /tmp/cups-$user/share
+DataDir /tmp/cups-$user/share
+FontPath /tmp/cups-$user/share/fonts
+DocumentRoot $root/doc
+RequestRoot /tmp/cups-$user/spool
+TempDir /tmp/cups-$user/spool/temp
+AccessLog /tmp/cups-$user/log/access_log
+ErrorLog /tmp/cups-$user/log/error_log
+PageLog /tmp/cups-$user/log/page_log
+EOF
+
Setup lots of test queues - half with PPD files, half without...
Index: configure.in
--- configure.in (revision 10708)
+++ configure.in (working copy)
@@ -60,6 +60,7 @@
AC_SUBST(UNINSTALL_LANGUAGES)
AC_OUTPUT(Makedefs
-
conf/cupsd.conf
conf/cups-files.conf
conf/mime.convs
conf/pam.std
@@ -73,6 +74,7 @@
man/client.conf.man
man/cups-deviced.man
man/cups-driverd.man -
man/cups-files.conf.man
man/cups-lpd.man
--- scheduler/conf.c (revision 10708)
man/cups-snmp.man
man/cupsaddsmb.man
Index: scheduler/conf.c
+++ scheduler/conf.c (working copy)
@@ -14,23 +14,25 @@
*- Contents:
*
- Contents:
- * cupsdAddAlias() - Add a host alias.
- * cupsdAddAlias() - Add a host alias.
- cupsdCheckPermissions() - Fix the mode and ownership of a file or
- * directory.
- * directory.
- cupsdDefaultAuthType() - Get the default AuthType.
- cupsdFreeAliases() - Free all of the alias entries.
- cupsdReadConfiguration() - Read the cupsd.conf file.
- * get_address() - Get an address + port number from a line.
- * get_address() - Get an address + port number from a line.
- get_addr_and_mask() - Get an IP address and netmask.
- * mime_error_cb() - Log a MIME error.
- * parse_aaa() - Parse authentication, authorization, and access
- * control lines.
- * mime_error_cb() - Log a MIME error.
- * parse_aaa() - Parse authentication, authorization, and access
- * control lines.
- parse_fatal_errors() - Parse FatalErrors values in a string.
- * parse_groups() - Parse system group names in a string.
- * parse_protocols() - Parse browse protocols in a string.
- * read_configuration() - Read a configuration file.
- * read_location() - Read a definition.
- * read_policy() - Read a definition.
- * parse_groups() - Parse system group names in a string.
- * parse_protocols() - Parse browse protocols in a string.
- * parse_variable() - Parse a variable line.
- * read_cupsd_conf() - Read the cupsd.conf configuration file.
- * read_cups_files_conf() - Read the cups-files.conf configuration file.
- * read_location() - Read a definition.
- * read_policy() - Read a definition.
- set_policy_defaults() - Set default policy values as needed.
*/
- set_policy_defaults() - Set default policy values as needed.
@@ -83,35 +85,25 @@
- Local globals...
*/
-static int default_auth_type = CUPSD_AUTH_AUTO;
-
-static const cupsd_var_t variables[] =
/\* Default AuthType, if not specified */
+static const cupsd_var_t cupsd_vars[] =
{ - { "AccessLog", &AccessLog, CUPSD_VARTYPE_STRING },
{ "AutoPurgeJobs", &JobAutoPurge, CUPSD_VARTYPE_BOOLEAN },
#if defined(HAVE_DNSSD) || defined(HAVE_AVAHI)
{ "BrowseDNSSDSubTypes", &DNSSDSubTypes, CUPSD_VARTYPE_STRING },
#endif /* HAVE_DNSSD || HAVE_AVAHI */
{ "BrowseWebIF", &BrowseWebIF, CUPSD_VARTYPE_BOOLEAN },
{ "Browsing", &Browsing, CUPSD_VARTYPE_BOOLEAN }, - { "CacheDir", &CacheDir, CUPSD_VARTYPE_STRING },
{ "Classification", &Classification, CUPSD_VARTYPE_STRING },
{ "ClassifyOverride", &ClassifyOverride, CUPSD_VARTYPE_BOOLEAN }, - { "ConfigFilePerm", &ConfigFilePerm, CUPSD_VARTYPE_INTEGER },
- { "DataDir", &DataDir, CUPSD_VARTYPE_STRING },
{ "DefaultLanguage", &DefaultLanguage, CUPSD_VARTYPE_STRING },
{ "DefaultLeaseDuration", &DefaultLeaseDuration, CUPSD_VARTYPE_TIME },
{ "DefaultPaperSize", &DefaultPaperSize, CUPSD_VARTYPE_STRING },
{ "DefaultPolicy", &DefaultPolicy, CUPSD_VARTYPE_STRING },
{ "DefaultShared", &DefaultShared, CUPSD_VARTYPE_BOOLEAN },
{ "DirtyCleanInterval", &DirtyCleanInterval, CUPSD_VARTYPE_TIME }, - { "DocumentRoot", &DocumentRoot, CUPSD_VARTYPE_STRING },
- { "ErrorLog", &ErrorLog, CUPSD_VARTYPE_STRING },
{ "ErrorPolicy", &ErrorPolicy, CUPSD_VARTYPE_STRING }, - { "FileDevice", &FileDevice, CUPSD_VARTYPE_BOOLEAN },
{ "FilterLimit", &FilterLimit, CUPSD_VARTYPE_INTEGER },
{ "FilterNice", &FilterNice, CUPSD_VARTYPE_INTEGER }, - { "FontPath", &FontPath, CUPSD_VARTYPE_STRING },
#ifdef HAVE_GSSAPI
{ "GSSServiceName", &GSSServiceName, CUPSD_VARTYPE_STRING },
#endif /* HAVE_GSSAPI */
@@ -126,8 +118,6 @@
{ "LimitRequestBody", &MaxRequestSize, CUPSD_VARTYPE_INTEGER },
{ "ListenBackLog", &ListenBackLog, CUPSD_VARTYPE_INTEGER },
{ "LogDebugHistory", &LogDebugHistory, CUPSD_VARTYPE_INTEGER }, - { "LogFilePerm", &LogFilePerm, CUPSD_VARTYPE_INTEGER },
- { "LPDConfigFile", &LPDConfigFile, CUPSD_VARTYPE_STRING },
{ "MaxActiveJobs", &MaxActiveJobs, CUPSD_VARTYPE_INTEGER },
{ "MaxClients", &MaxClients, CUPSD_VARTYPE_INTEGER },
{ "MaxClientsPerHost", &MaxClientsPerHost, CUPSD_VARTYPE_INTEGER },
@@ -146,17 +136,34 @@
{ "MaxSubscriptionsPerPrinter",&MaxSubscriptionsPerPrinter, CUPSD_VARTYPE_INTEGER },
{ "MaxSubscriptionsPerUser", &MaxSubscriptionsPerUser, CUPSD_VARTYPE_INTEGER },
{ "MultipleOperationTimeout", &MultipleOperationTimeout, CUPSD_VARTYPE_TIME }, - { "PageLog", &PageLog, CUPSD_VARTYPE_STRING },
{ "PageLogFormat", &PageLogFormat, CUPSD_VARTYPE_STRING },
{ "PreserveJobFiles", &JobFiles, CUPSD_VARTYPE_TIME },
{ "PreserveJobHistory", &JobHistory, CUPSD_VARTYPE_TIME }, - { "Printcap", &Printcap, CUPSD_VARTYPE_STRING },
{ "ReloadTimeout", &ReloadTimeout, CUPSD_VARTYPE_TIME },
{ "RemoteRoot", &RemoteRoot, CUPSD_VARTYPE_STRING }, - { "RequestRoot", &RequestRoot, CUPSD_VARTYPE_STRING },
{ "RIPCache", &RIPCache, CUPSD_VARTYPE_STRING },
{ "RootCertDuration", &RootCertDuration, CUPSD_VARTYPE_TIME },
{ "ServerAdmin", &ServerAdmin, CUPSD_VARTYPE_STRING }, - { "ServerName", &ServerName, CUPSD_VARTYPE_STRING },
- { "StrictConformance", &StrictConformance, CUPSD_VARTYPE_BOOLEAN },
- { "Timeout", &Timeout, CUPSD_VARTYPE_TIME },
- { "WebInterface", &WebInterface, CUPSD_VARTYPE_BOOLEAN }
+};
+static const cupsd_var_t cupsfiles_vars[] =
+{ - { "AccessLog", &AccessLog, CUPSD_VARTYPE_STRING },
- { "CacheDir", &CacheDir, CUPSD_VARTYPE_STRING },
- { "ConfigFilePerm", &ConfigFilePerm, CUPSD_VARTYPE_INTEGER },
- { "DataDir", &DataDir, CUPSD_VARTYPE_STRING },
- { "DocumentRoot", &DocumentRoot, CUPSD_VARTYPE_STRING },
- { "ErrorLog", &ErrorLog, CUPSD_VARTYPE_STRING },
- { "FileDevice", &FileDevice, CUPSD_VARTYPE_BOOLEAN },
- { "FontPath", &FontPath, CUPSD_VARTYPE_STRING },
- { "LogFilePerm", &LogFilePerm, CUPSD_VARTYPE_INTEGER },
- { "LPDConfigFile", &LPDConfigFile, CUPSD_VARTYPE_STRING },
- { "PageLog", &PageLog, CUPSD_VARTYPE_STRING },
- { "Printcap", &Printcap, CUPSD_VARTYPE_STRING },
- { "RequestRoot", &RequestRoot, CUPSD_VARTYPE_STRING },
{ "ServerBin", &ServerBin, CUPSD_VARTYPE_PATHNAME },
#ifdef HAVE_SSL
{ "ServerCertificate", &ServerCertificate, CUPSD_VARTYPE_PATHNAME },
@@ -164,20 +171,17 @@
{ "ServerKey", &ServerKey, CUPSD_VARTYPE_PATHNAME },
endif /* HAVE_LIBSSL || HAVE_GNUTLS _/
#endif /_ HAVE_SSL */
- { "ServerName", &ServerName, CUPSD_VARTYPE_STRING },
{ "ServerRoot", &ServerRoot, CUPSD_VARTYPE_PATHNAME },
{ "SMBConfigFile", &SMBConfigFile, CUPSD_VARTYPE_STRING },
{ "StateDir", &StateDir, CUPSD_VARTYPE_STRING }, - { "StrictConformance", &StrictConformance, CUPSD_VARTYPE_BOOLEAN },
#ifdef HAVE_AUTHORIZATION_H
{ "SystemGroupAuthKey", &SystemGroupAuthKey, CUPSD_VARTYPE_STRING },
#endif /* HAVE_AUTHORIZATION_H */ - { "TempDir", &TempDir, CUPSD_VARTYPE_PATHNAME },
- { "Timeout", &Timeout, CUPSD_VARTYPE_TIME },
- { "WebInterface", &WebInterface, CUPSD_VARTYPE_BOOLEAN }
- { "TempDir", &TempDir, CUPSD_VARTYPE_PATHNAME }
};
-#define NUM_VARS (sizeof(variables) / sizeof(variables[0]))
+static int default_auth_type = CUPSD_AUTH_AUTO;
-
/* Default AuthType, if not specified */
static const unsigned ones[4] =
{
@@ -202,7 +206,12 @@
static int parse_fatal_errors(const char *s);
static int parse_groups(const char *s);
static int parse_protocols(const char *s);
-static int read_configuration(cups_file_t *fp);
+static int parse_variable(const char *filename, int linenum, -
const char *line, const char *value,
-
size_t num_vars,
-
const cupsd_var_t *vars);
+static int read_cupsd_conf(cups_file_t *fp);
+static int read_cups_files_conf(cups_file_t *fp);
static int read_location(cups_file_t *fp, char *name, int linenum);
static int read_policy(cups_file_t *fp, char *name, int linenum);
static void set_policy_defaults(cupsd_policy_t *pol);
@@ -778,22 +787,48 @@
cupsdInitEnv();/*
-
* Read the configuration file...
-
- Read the cups-files.conf file...
*/
- Read the cups-files.conf file...
-
if ((fp = cupsFileOpen(CupsFilesFile, "r")) != NULL)
-
{
-
status = read_cups_files_conf(fp);
- cupsFileClose(fp);
- if (!status)
-
return (0);
- }
- else if (errno == ENOENT)
- cupsdLogMessage(CUPSD_LOG_INFO, "No %s, using defaults.", CupsFilesFile);
- else
- {
- cupsdLogMessage(CUPSD_LOG_CRIT, "Unable to open %s: %s", CupsFilesFile,
-
strerror(errno));
- return (0);
- }
- if (!ErrorLog)
- cupsdSetString(&ErrorLog, CUPS_LOGDIR "/error_log");
- /*
- * Read the cupsd.conf file...
- */
if ((fp = cupsFileOpen(ConfigurationFile, "r")) == NULL)
- {
- cupsdLogMessage(CUPSD_LOG_CRIT, "Unable to open %s: %s", ConfigurationFile,
-
return (0);
strerror(errno));
- }
- status = read_configuration(fp);
- status = read_cupsd_conf(fp);
cupsFileClose(fp);
if (!status)
return (0);
- if (!ErrorLog)
- cupsdSetString(&ErrorLog, CUPS_LOGDIR "/error_log");
RunUser = getuid();
cupsdLogMessage(CUPSD_LOG_INFO, "Remote access is %s.",
@@ -2548,13 +2583,244 @@
/*
-
* 'read_configuration()' - Read a configuration file.
-
- 'parse_variable()' - Parse a variable line.
*/
static int /* O - 1 on success, 0 on failure /
-read_configuration(cups_file_t *fp) / I - File to read from */
+parse_variable( - 'parse_variable()' - Parse a variable line.
-
const char filename, / I - Name of configuration file */
-
int linenum, /* I - Line in configuration file */
-
const char line, / I - Line from configuration file */
-
const char value, / I - Value from configuration file */
-
size_t num_vars, /* I - Number of variables */
-
const cupsd_var_t vars) / I - Variables */
{ -
int i; /* Looping var */
-
size_t i; /* Looping var */
-
const cupsd_var_t var; / Variables */
-
char temp[1024]; /* Temporary string */
- for (i = num_vars, var = vars; i > 0; i --, var ++)
- if (!_cups_strcasecmp(line, var->name))
-
break;
- if (i == 0)
- {
- /*
- * Unknown directive! Output an error message and continue...
- */
- if (!value)
-
cupsdLogMessage(CUPSD_LOG_ERROR, "Missing value for %s on line %d of %s.",
-
line, linenum, filename);
- else
-
cupsdLogMessage(CUPSD_LOG_ERROR, "Unknown directive %s on line %d of %s.",
-
line, linenum, filename);
- return (0);
- }
- switch (var->type)
- {
- case CUPSD_VARTYPE_INTEGER :
- if (!value)
- {
-
cupsdLogMessage(CUPSD_LOG_ERROR,
-
"Missing integer value for %s on line %d of %s.",
-
line, linenum, filename);
-
return (0);
- }
- else if (!isdigit(*value & 255))
- {
-
cupsdLogMessage(CUPSD_LOG_ERROR,
-
"Bad integer value for %s on line %d of %s.",
-
line, linenum, filename);
-
return (0);
- }
- else
- {
-
int n; /\* Number */
-
char _units; /_ Units */
+/*
/*
- */
- int uid = atoi(value);
- struct passwd p; / Password information */
- p = getpwnam(value);
- */
- group = getgrnam(value);
- */
- */
- mode = ConfigFilePerm;
/*
- NeedReload = RELOAD_ALL;
/* Index: scheduler/main.c--- scheduler/main.c (revision 10708)
@@ -234,6 +233,35 @@
|
"str4223-1.6.patch": Index: packaging/cups.spec.in--- packaging/cups.spec.in (revision 10708) Index: packaging/cups.list.in--- packaging/cups.list.in (revision 10708) Index: conf/cups-files.conf.in--- conf/cups-files.conf.in (revision 0) Property changes on: conf/cups-files.conf.in Added: svn:keywords
Index: conf/cupsd.conf.in--- conf/cupsd.conf.in (revision 10708) for troubleshooting...LogLevel @CUPS_LOG_LEVEL@ -# Administrator user group... -@CUPS_SYSTEM_AUTHKEY@Only listen for connections from the local machine.Listen localhost:@DEFAULT_IPP_PORT@ Index: conf/Makefile--- conf/Makefile (revision 10708) Config files...-KEEP = cupsd.conf snmp.conf Index: config-scripts/cups-ssl.m4--- config-scripts/cups-ssl.m4 (revision 10708) if test x$enable_ssl != xno; then
+AC_SUBST(CUPS_SERVERCERT) Index: config-scripts/cups-defaults.m4--- config-scripts/cups-defaults.m4 (revision 10708) AC_DEFINE_UNQUOTED(CUPS_DEFAULT_LPD_CONFIG_FILE, "$CUPS_DEFAULT_LPD_CONFIG_FILE") dnl Default SMB config file... AC_DEFINE_UNQUOTED(CUPS_DEFAULT_SMB_CONFIG_FILE, "$CUPS_DEFAULT_SMB_CONFIG_FILE") dnl Default MaxCopies value... Index: doc/help/ref-cups-files-conf.html.in--- doc/help/ref-cups-files-conf.html.in (revision 0)
+ cups-files.conf+ + The /etc/cups/cups-files.conf file contains configuration directives that control the files, directories. users. and groups that are used by the CUPS scheduler, + + AccessLog+ + Examples+ +
+ + Description+ + The + + The server name can be included in the filename by using + + The special name "syslog" can be used to send the access + + The default access log file is + + + CUPS 1.1.15ConfigFilePerm+ + Examples+ +
+ + Description+ + The + + Note: + + + DataDir+ + Examples+ +
+ + Description+ + The + + + CUPS 1.2/OS X 10.5DefaultAuthType+ + Examples+ +
+ + Description+ + The + + + DocumentRoot+ + Examples+ +
+ + Description+ + The + + Documents are first looked up in a sub-directory for the + + + ErrorLog+ + Examples+ +
+ + Description+ + The + + The server name can be included in the filename by using + + The special name "syslog" can be used to send the error + + + CUPS 1.4/OS X 10.6FatalErrors+ + Examples+ +
+ + Description+ + The + +
+ + + + Multiple errors can be listed, and the form "-kind" can be used with + + + CUPS 1.1.18FileDevice+ + Examples+ +
+ + Description+ + The + + The default setting is + + Note: + + + CUPS 1.1.3FontPath+ + Examples+ +
+ + Description+ + The + + + Group+ + Examples+ +
+ + Description+ + The + + + CUPS 1.1.15LogFilePerm+ + Examples+ +
+ + Description+ + The + + + PageLog+ + Examples+ +
+ + Description+ + The + + The server name can be included in the filename by using + + The special name "syslog" can be used to send the page + + + Printcap+ + Examples+ +
+ + Description+ + The + + When a filename is specified (e.g. @CUPS_DEFAULT_PRINTCAP@), + + + PrintcapFormat+ + Examples+ +
+ + Description+ + The + + + CUPS 1.1.3RemoteRoot+ + Examples+ +
+ + Description+ + The + + + RequestRoot+ + Examples+ +
+ + Description+ + The + + + ServerBin+ + Examples+ +
+ + Description+ + The + + + ServerCertificate+ + Examples+ +
+ + Description+ + The + + The default certificate file is + + + ServerKey+ + Examples+ +
+ + Description+ + The + + The default key file is + + + ServerRoot+ + Examples+ +
+ + Description+ + The + + + SystemGroup+ + Examples+ +
+ + Description+ + The + + + TempDir+ + Examples+ +
+ + Description+ + The + + Temporary directories must be world-writable and should have + +
+ + + User+ + Examples+ +
+ + Description+ + The + + Note: + + + + Property changes on: doc/help/ref-cups-files-conf.html.in Added: svn:keywords
Index: doc/help/ref-cupsd-conf.html.in--- doc/help/ref-cupsd-conf.html.in (revision 10708) -DeprecatedAuthClass-Examples-
-Description-The -
- performed (default)
- required
- directive
- directive-- The -HREF="#Limit">
|
+/*
/*
- */
- int uid = atoi(value);
- struct passwd p; / Password information */
- p = getpwnam(value);
- */
- group = getgrnam(value);
- */
- */
- mode = ConfigFilePerm;
/*
- NeedReload = RELOAD_ALL;
/* Index: scheduler/main.c--- scheduler/main.c (revision 10708)
@@ -238,6 +237,35 @@
|
"str4223p2.patch": Index: scheduler/conf.c--- scheduler/conf.c (revision 10710)
|
"cups-str4223-set-default.patch": --- cups-1.5.4/scheduler/main.c 2012-11-27 13:36:54.518147854 +0000
/*
|
"small-fixes.patch": diff -Naur cups-1.6.x.ori/conf/cups-files.conf.in cups-1.6.x/conf/cups-files.conf.in Location of the static web content served by the scheduler...-#DocRoot @CUPS_DOCROOT@ Location of the file logging all messages produced by the scheduler and anyhelper programs; may be the name "syslog". If not an absolute path, the valuediff -Naur cups-1.6.x.ori/scheduler/conf.c cups-1.6.x/scheduler/conf.c
|
"defaultauthtype.patch": diff -Naur cups-1.6.x.ori/scheduler/conf.c cups-1.6.x/scheduler/conf.c
- */
|
"split-configuration-files-STR4223.patch": Description: Move file, directory, user, and group configuration to a Author: Michael Sweet msweet@apple.com Author: Marc Deslauriers marc.deslauriers@canonical.com Bug-Upstream: https://www.cups.org/strfiles/4223/small-fixes.patch --- a/conf/Makefile Config files...-KEEP = cupsd.conf snmp.conf --- /dev/null for troubleshooting...LogLevel @CUPS_LOG_LEVEL@ -# Administrator user group... -@CUPS_SYSTEM_AUTHKEY@Only listen for connections from the local machine.Listen localhost:@DEFAULT_IPP_PORT@ AC_DEFINE_UNQUOTED(CUPS_DEFAULT_LPD_CONFIG_FILE, "$CUPS_DEFAULT_LPD_CONFIG_FILE") dnl Default SMB config file... AC_DEFINE_UNQUOTED(CUPS_DEFAULT_SMB_CONFIG_FILE, "$CUPS_DEFAULT_SMB_CONFIG_FILE") dnl Default MaxCopies value... if test x$enable_ssl != xno; then
+AC_SUBST(CUPS_SERVERCERT) AC_OUTPUT(Makedefs
+ cups-files.conf+ + The /etc/cups/cups-files.conf file contains configuration directives that control the files, directories. users. and groups that are used by the CUPS scheduler, + + AccessLog+ + Examples+ +
+ + Description+ + The + + The server name can be included in the filename by using + + The special name "syslog" can be used to send the access + + The default access log file is + + + CUPS 1.1.15ConfigFilePerm+ + Examples+ +
+ + Description+ + The + + Note: + + + DataDir+ + Examples+ +
+ + Description+ + The + + + CUPS 1.2/OS X 10.5DefaultAuthType+ + Examples+ +
+ + Description+ + The + + + DocumentRoot+ + Examples+ +
+ + Description+ + The + + Documents are first looked up in a sub-directory for the + + + ErrorLog+ + Examples+ +
+ + Description+ + The + + The server name can be included in the filename by using + + The special name "syslog" can be used to send the error + + + CUPS 1.4/OS X 10.6FatalErrors+ + Examples+ +
+ + Description+ + The + +
+ + + + Multiple errors can be listed, and the form "-kind" can be used with + + + CUPS 1.1.18FileDevice+ + Examples+ +
+ + Description+ + The + + The default setting is + + Note: + + + CUPS 1.1.3FontPath+ + Examples+ +
+ + Description+ + The + + + Group+ + Examples+ +
+ + Description+ + The + + + CUPS 1.1.15LogFilePerm+ + Examples+ +
+ + Description+ + The + + + PageLog+ + Examples+ +
+ + Description+ + The + + The server name can be included in the filename by using + + The special name "syslog" can be used to send the page + + + Printcap+ + Examples+ +
+ + Description+ + The + + When a filename is specified (e.g. @CUPS_DEFAULT_PRINTCAP@), + + + PrintcapFormat+ + Examples+ +
+ + Description+ + The + + + CUPS 1.1.3RemoteRoot+ + Examples+ +
+ + Description+ + The + + + RequestRoot+ + Examples+ +
+ + Description+ + The + + + ServerBin+ + Examples+ +
+ + Description+ + The + + + ServerCertificate+ + Examples+ +
+ + Description+ + The + + The default certificate file is + + + ServerKey+ + Examples+ +
+ + Description+ + The + + The default key file is + + + ServerRoot+ + Examples+ +
+ + Description+ + The + + + SystemGroup+ + Examples+ +
+ + Description+ + The + + + TempDir+ + Examples+ +
+ + Description+ + The + + Temporary directories must be world-writable and should have + +
+ + + User+ + Examples+ +
+ + Description+ + The + + Note: + + + + --- a/doc/help/ref-cupsd-conf.html.in +++ b/doc/help/ref-cupsd-conf.html.in @@ -191,82 +191,6 @@ HREF="#Limit"> Limit section.
-DeprecatedAuthClass-Examples-
-Description-The -
- performed (default)
- required
- directive
- directive-- The -HREF="#Limit">
|
+/*
- break;
- char units; / Units */- n = strtol(value, &units, 0);
- }
/*
cat >/tmp/cups-$user/cupsd.conf <<EOF +cat >/tmp/cups-$user/cups-files.conf <<EOF Setup lots of test queues - half with PPD files, half without... |
"str4223v2.patch": Index: conf/cups-files.conf.in--- conf/cups-files.conf.in (revision 0) Property changes on: conf/cups-files.conf.in Added: svn:keywords
Index: conf/cupsd.conf.in--- conf/cupsd.conf.in (revision 10708) for troubleshooting...LogLevel @CUPS_LOG_LEVEL@ -# Administrator user group... -@CUPS_SYSTEM_AUTHKEY@Only listen for connections from the local machine.Listen localhost:@DEFAULT_IPP_PORT@ Index: conf/Makefile--- conf/Makefile (revision 10708) Config files...-KEEP = cupsd.conf snmp.conf Property changes on: conf Modified: svn:ignore
Index: scheduler/conf.c--- scheduler/conf.c (revision 10708)
@@ -83,35 +85,25 @@
-static int default_auth_type = CUPSD_AUTH_AUTO;
endif /* HAVE_LIBSSL || HAVE_GNUTLS _/#endif /_ HAVE_SSL */
+static int default_auth_type = CUPSD_AUTH_AUTO;
if ((fp = cupsFileOpen(ConfigurationFile, "r")) == NULL)
cupsFileClose(fp); if (!status)
- cupsdSetString(&ErrorLog, CUPS_LOGDIR "/error_log");RunUser = getuid(); cupsdLogMessage(CUPSD_LOG_INFO, "Remote access is %s.", /*
@@ -2548,13 +2590,244 @@ /*
+/*
/*
- */
- int uid = atoi(value);
- struct passwd p; / Password information */
- p = getpwnam(value);
- */
- group = getgrnam(value);
- */
- */
@@ -272,6 +271,29 @@
/*
VAR char *ConfigurationFile VALUE(NULL),
- mode = ConfigFilePerm;
/*
- NeedReload = RELOAD_ALL;
/* Index: packaging/cups.spec.in--- packaging/cups.spec.in (revision 10708) Index: packaging/cups.list.in--- packaging/cups.list.in (revision 10708) Index: CHANGES-1.6.txt--- CHANGES-1.6.txt (revision 10708)
+AC_SUBST(CUPS_SERVERCERT) Index: config-scripts/cups-defaults.m4--- config-scripts/cups-defaults.m4 (revision 10708) AC_DEFINE_UNQUOTED(CUPS_DEFAULT_LPD_CONFIG_FILE, "$CUPS_DEFAULT_LPD_CONFIG_FILE") dnl Default SMB config file... AC_DEFINE_UNQUOTED(CUPS_DEFAULT_SMB_CONFIG_FILE, "$CUPS_DEFAULT_SMB_CONFIG_FILE") dnl Default MaxCopies value... Index: doc/help/ref-cups-files-conf.html.in--- doc/help/ref-cups-files-conf.html.in (revision 0)
+ cups-files.conf+ + The /etc/cups/cups-files.conf file contains configuration directives that control the files, directories. users. and groups that are used by the CUPS scheduler, + + AccessLog+ + Examples+ +
+ + Description+ + The + + The server name can be included in the filename by using + + The special name "syslog" can be used to send the access + + The default access log file is + + + CUPS 1.1.15ConfigFilePerm+ + Examples+ +
+ + Description+ + The + + Note: + + + DataDir+ + Examples+ +
+ + Description+ + The + + + CUPS 1.2/OS X 10.5DefaultAuthType+ + Examples+ +
+ + Description+ + The + + + DocumentRoot+ + Examples+ +
+ + Description+ + The + + Documents are first looked up in a sub-directory for the + + + ErrorLog+ + Examples+ +
+ + Description+ + The + + The server name can be included in the filename by using + + The special name "syslog" can be used to send the error + + + CUPS 1.4/OS X 10.6FatalErrors+ + Examples+ +
+ + Description+ + The + +
+ + + + Multiple errors can be listed, and the form "-kind" can be used with + + + CUPS 1.1.18FileDevice+ + Examples+ +
+ + Description+ + The + + The default setting is + + Note: + + + CUPS 1.1.3FontPath+ + Examples+ +
+ + Description+ + The + + + Group+ + Examples+ +
+ + Description+ + The + + + CUPS 1.1.15LogFilePerm+ + Examples+ +
+ + Description+ + The + + + PageLog+ + Examples+ +
+ + Description+ + The + + The server name can be included in the filename by using + + The special name "syslog" can be used to send the page + + + Printcap+ + Examples+ +
+ + Description+ + The + + When a filename is specified (e.g. @CUPS_DEFAULT_PRINTCAP@), + + + PrintcapFormat+ + Examples+ +
+ + Description+ + The + + + CUPS 1.1.3RemoteRoot+ + Examples+ +
+ + Description+ + The + + + RequestRoot+ + Examples+ +
+ + Description+ + The + + + ServerBin+ + Examples+ +
+ + Description+ + The + + + ServerCertificate+ + Examples+ +
+ + Description+ + The + + The default certificate file is + + + ServerKey+ + Examples+ +
+ + Description+ + The + + The default key file is + + + ServerRoot+ + Examples+ +
+ + Description+ + The + + + SystemGroup+ + Examples+ +
+ + Description+ + The + + + TempDir+ + Examples+ +
+ + Description+ + The + + Temporary directories must be world-writable and should have + +
+ + + User+ + Examples+ +
+ + Description+ + The + + Note: + + + + Property changes on: doc/help/ref-cups-files-conf.html.in Added: svn:mime-type
Index: doc/help/ref-cupsd-conf.html.in--- doc/help/ref-cupsd-conf.html.in (revision 10708) -DeprecatedAuthClass-Examples-
-Description-The -
- performed (default)
- required
- directive
- directive-- The -HREF="#Limit">
|
-Printcap /Library/Preferences/org.cups.printers.plist --Description- The -file named @CUPS_DEFAUL_PRINTCAP@.- When a filename is specified (e.g. @CUPS_DEFAULT_PRINTCAP@), -printers.-PrintcapFormat-Examples-
-Description- The -Solaris format on Solaris, and the BSD format on other operating systems.CUPS 1.1.21ReloadTimeoutExamples@@ -2155,42 +2036,6 @@ before doing a restart. The default is 30 seconds.-CUPS 1.1.3RemoteRoot-Examples-
-Description- The -mechanism.-RequestRoot-Examples-
-Description- The -default request directory is @CUPS_REQUESTS@.CUPS 1.1.7RequireExamples@@ -2343,64 +2188,6 @@-ServerBin-Examples-
-Description- The -depending on the operating system.-ServerCertificate-Examples-
-Description- The -in the background and will be unable to ask for a password.- The default certificate file is -/etc/cups/ssl/server.crt.-ServerKey-Examples-
-Description- The -encrypted connections.- The default key file is -/etc/cups/ssl/server.crt.ServerNameExamples@@ -2417,23 +2204,6 @@ hostname.-ServerRoot-Examples-
-Description- The -default server directory is /etc/cups.CUPS 1.1.21ServerTokensExamples@@ -2629,53 +2399,6 @@ HREF="#Policy">Policy section.
-SystemGroup-Examples-
-Description- The -group list is
|
"str4223v2-1.6.patch": Index: packaging/cups.spec.in--- packaging/cups.spec.in (revision 10708) Index: packaging/cups.list.in--- packaging/cups.list.in (revision 10708) Index: conf/cups-files.conf.in--- conf/cups-files.conf.in (revision 0) Property changes on: conf/cups-files.conf.in Added: svn:keywords
Index: conf/cupsd.conf.in--- conf/cupsd.conf.in (revision 10708) for troubleshooting...LogLevel @CUPS_LOG_LEVEL@ -# Administrator user group... -@CUPS_SYSTEM_AUTHKEY@Only listen for connections from the local machine.Listen localhost:@DEFAULT_IPP_PORT@ Index: conf/Makefile--- conf/Makefile (revision 10708) Config files...-KEEP = cupsd.conf snmp.conf Index: config-scripts/cups-ssl.m4--- config-scripts/cups-ssl.m4 (revision 10708) if test x$enable_ssl != xno; then
+AC_SUBST(CUPS_SERVERCERT) Index: config-scripts/cups-defaults.m4--- config-scripts/cups-defaults.m4 (revision 10708) AC_DEFINE_UNQUOTED(CUPS_DEFAULT_LPD_CONFIG_FILE, "$CUPS_DEFAULT_LPD_CONFIG_FILE") dnl Default SMB config file... AC_DEFINE_UNQUOTED(CUPS_DEFAULT_SMB_CONFIG_FILE, "$CUPS_DEFAULT_SMB_CONFIG_FILE") dnl Default MaxCopies value... Index: doc/help/ref-cups-files-conf.html.in--- doc/help/ref-cups-files-conf.html.in (revision 0)
+ cups-files.conf+ + The /etc/cups/cups-files.conf file contains configuration directives that control the files, directories. users. and groups that are used by the CUPS scheduler, + + AccessLog+ + Examples+ +
+ + Description+ + The + + The server name can be included in the filename by using + + The special name "syslog" can be used to send the access + + The default access log file is + + + CUPS 1.1.15ConfigFilePerm+ + Examples+ +
+ + Description+ + The + + Note: + + + DataDir+ + Examples+ +
+ + Description+ + The + + + CUPS 1.2/OS X 10.5DefaultAuthType+ + Examples+ +
+ + Description+ + The + + + DocumentRoot+ + Examples+ +
+ + Description+ + The + + Documents are first looked up in a sub-directory for the + + + ErrorLog+ + Examples+ +
+ + Description+ + The + + The server name can be included in the filename by using + + The special name "syslog" can be used to send the error + + + CUPS 1.4/OS X 10.6FatalErrors+ + Examples+ +
+ + Description+ + The + +
+ + + + Multiple errors can be listed, and the form "-kind" can be used with + + + CUPS 1.1.18FileDevice+ + Examples+ +
+ + Description+ + The + + The default setting is + + Note: + + + CUPS 1.1.3FontPath+ + Examples+ +
+ + Description+ + The + + + Group+ + Examples+ +
+ + Description+ + The + + + CUPS 1.1.15LogFilePerm+ + Examples+ +
+ + Description+ + The + + + PageLog+ + Examples+ +
+ + Description+ + The + + The server name can be included in the filename by using + + The special name "syslog" can be used to send the page + + + Printcap+ + Examples+ +
+ + Description+ + The + + When a filename is specified (e.g. @CUPS_DEFAULT_PRINTCAP@), + + + PrintcapFormat+ + Examples+ +
+ + Description+ + The + + + CUPS 1.1.3RemoteRoot+ + Examples+ +
+ + Description+ + The + + + RequestRoot+ + Examples+ +
+ + Description+ + The + + + ServerBin+ + Examples+ +
+ + Description+ + The + + + ServerCertificate+ + Examples+ +
+ + Description+ + The + + The default certificate file is + + + ServerKey+ + Examples+ +
+ + Description+ + The + + The default key file is + + + ServerRoot+ + Examples+ +
+ + Description+ + The + + + SystemGroup+ + Examples+ +
+ + Description+ + The + + + TempDir+ + Examples+ +
+ + Description+ + The + + Temporary directories must be world-writable and should have + +
+ + + User+ + Examples+ +
+ + Description+ + The + + Note: + + + + Property changes on: doc/help/ref-cups-files-conf.html.in Added: svn:keywords
Index: doc/help/ref-cupsd-conf.html.in--- doc/help/ref-cupsd-conf.html.in (revision 10708) -DeprecatedAuthClass-Examples-
-Description-The -
- performed (default)
- required
- directive
- directive-- The -HREF="#Limit">
|
+/*
/*
- */
- int uid = atoi(value);
- struct passwd p; / Password information */
- p = getpwnam(value);
- */
- group = getgrnam(value);
- */
- */
- mode = ConfigFilePerm;
/*
- NeedReload = RELOAD_ALL;
/* Index: scheduler/main.c--- scheduler/main.c (revision 10708)
@@ -276,6 +275,29 @@
/*
|
"str4223v2-1.5.3.patch": Description: Move file, directory, user, and group configuration to a Author: Michael Sweet msweet@apple.com Author: Marc Deslauriers marc.deslauriers@canonical.com Bug-Upstream: https://www.cups.org/strfiles/4223/small-fixes.patch --- a/conf/Makefile Config files...-KEEP = cupsd.conf snmp.conf --- /dev/null for troubleshooting...LogLevel @CUPS_LOG_LEVEL@ -# Administrator user group... -@CUPS_SYSTEM_AUTHKEY@Only listen for connections from the local machine.Listen localhost:@DEFAULT_IPP_PORT@ AC_DEFINE_UNQUOTED(CUPS_DEFAULT_LPD_CONFIG_FILE, "$CUPS_DEFAULT_LPD_CONFIG_FILE") dnl Default SMB config file... AC_DEFINE_UNQUOTED(CUPS_DEFAULT_SMB_CONFIG_FILE, "$CUPS_DEFAULT_SMB_CONFIG_FILE") dnl Default MaxCopies value... if test x$enable_ssl != xno; then
+AC_SUBST(CUPS_SERVERCERT) AC_OUTPUT(Makedefs
+ cups-files.conf+ + The /etc/cups/cups-files.conf file contains configuration directives that control the files, directories. users. and groups that are used by the CUPS scheduler, + + AccessLog+ + Examples+ +
+ + Description+ + The + + The server name can be included in the filename by using + + The special name "syslog" can be used to send the access + + The default access log file is + + + CUPS 1.1.15ConfigFilePerm+ + Examples+ +
+ + Description+ + The + + Note: + + + DataDir+ + Examples+ +
+ + Description+ + The + + + CUPS 1.2/OS X 10.5DefaultAuthType+ + Examples+ +
+ + Description+ + The + + + DocumentRoot+ + Examples+ +
+ + Description+ + The + + Documents are first looked up in a sub-directory for the + + + ErrorLog+ + Examples+ +
+ + Description+ + The + + The server name can be included in the filename by using + + The special name "syslog" can be used to send the error + + + CUPS 1.4/OS X 10.6FatalErrors+ + Examples+ +
+ + Description+ + The + +
+ + + + Multiple errors can be listed, and the form "-kind" can be used with + + + CUPS 1.1.18FileDevice+ + Examples+ +
+ + Description+ + The + + The default setting is + + Note: + + + CUPS 1.1.3FontPath+ + Examples+ +
+ + Description+ + The + + + Group+ + Examples+ +
+ + Description+ + The + + + CUPS 1.1.15LogFilePerm+ + Examples+ +
+ + Description+ + The + + + PageLog+ + Examples+ +
+ + Description+ + The + + The server name can be included in the filename by using + + The special name "syslog" can be used to send the page + + + Printcap+ + Examples+ +
+ + Description+ + The + + When a filename is specified (e.g. @CUPS_DEFAULT_PRINTCAP@), + + + PrintcapFormat+ + Examples+ +
+ + Description+ + The + + + CUPS 1.1.3RemoteRoot+ + Examples+ +
+ + Description+ + The + + + RequestRoot+ + Examples+ +
+ + Description+ + The + + + ServerBin+ + Examples+ +
+ + Description+ + The + + + ServerCertificate+ + Examples+ +
+ + Description+ + The + + The default certificate file is + + + ServerKey+ + Examples+ +
+ + Description+ + The + + The default key file is + + + ServerRoot+ + Examples+ +
+ + Description+ + The + + + SystemGroup+ + Examples+ +
+ + Description+ + The + + + TempDir+ + Examples+ +
+ + Description+ + The + + Temporary directories must be world-writable and should have + +
+ + + User+ + Examples+ +
+ + Description+ + The + + Note: + + + + --- a/doc/help/ref-cupsd-conf.html.in +++ b/doc/help/ref-cupsd-conf.html.in @@ -191,82 +191,6 @@ HREF="#Limit"> Limit section.
-DeprecatedAuthClass-Examples-
-Description-The -
- performed (default)
- required
- directive
- directive-- The -HREF="#Limit">
|
- */
+/*
- break;
- char units; / Units */- n = strtol(value, &units, 0);
- }
- cupsdSetString(&ConfigurationFile, CUPS_SERVERROOT "/cupsd.conf");
+cat >/tmp/cups-$user/cups-files.conf <<EOF Setup lots of test queues - half with PPD files, half without... |
"str4223v2p2.patch": Index: locale/cups_ja.po--- locale/cups_ja.po (revision 10728) #, c-format Index: locale/cups_ca.po--- locale/cups_ca.po (revision 10728) #, c-format Index: locale/cups_es.po--- locale/cups_es.po (revision 10728) #, c-format Index: scheduler/ipp.c--- scheduler/ipp.c (revision 10728)
|
"str4223v2p2-1.6.patch": Index: locale/cups_ja.po--- locale/cups_ja.po (revision 10728) #: filter/rastertoepson.c:1117 filter/rastertohp.c:845 Index: locale/cups_ca.po--- locale/cups_ca.po (revision 10728) #: filter/rastertoepson.c:1117 filter/rastertohp.c:845 Index: locale/cups_es.po--- locale/cups_es.po (revision 10728) #: scheduler/ipp.c:2370 #: filter/rastertoepson.c:1117 Index: scheduler/ipp.c--- scheduler/ipp.c (revision 10728)
|
"cups-logfile-warning.patch": diff -up cups-1.6.1/scheduler/conf.c.extra cups-1.6.1/scheduler/conf.c
if (!status)
RunUser = getuid(); diff -up cups-1.6.1/scheduler/main.c.extra cups-1.6.1/scheduler/main.c if (!cupsdReadConfiguration())
|
"str4223v2-1.4.4-debian.patch": #! /bin/sh /usr/share/dpatch/dpatch-run DP: Description: Move file, directory, user, and group configuration to aDP: separate file. Also warn about directives that have moved and setDP: default cups-files.conf.DP:DP: Author: Michael Sweet msweet@apple.comDP: Origin: http://svn.cups.org/public/cups/branches/branch-1.6@10710DP: Origin: http://svn.cups.org/public/cups/branches/branch-1.6@10713DP:DP: Author: Marc Deslauriers marc.deslauriers@canonical.comDP: Author: Tim Waugh twaugh@redhat.comDP:DP: Bug-Upstream: https://www.cups.org/str.php?L4223DP: Bug-Debian: http://bugs.debian.org/692791DP: Bug-CVE: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5519@dpatch@ Config files...-KEEP = cupsd.conf snmp.conf diff -urNad '--exclude=CVS' '--exclude=.svn' '--exclude=.git' '--exclude=.arch' '--exclude=.hg' '--exclude=_darcs' '--exclude=.bzr' cups~/conf/cups-files.conf.in cups/conf/cups-files.conf.in LogLevel debug2 gets usable nowMaxLogSize 0 -# Administrator user group... -@CUPS_SYSTEM_AUTHKEY@Only listen for connections from the local machine.Listen localhost:@DEFAULT_IPP_PORT@ AC_DEFINE_UNQUOTED(CUPS_DEFAULT_LPD_CONFIG_FILE, "$CUPS_DEFAULT_LPD_CONFIG_FILE") dnl Default SMB config file... AC_DEFINE_UNQUOTED(CUPS_DEFAULT_SMB_CONFIG_FILE, "$CUPS_DEFAULT_SMB_CONFIG_FILE") dnl Default MaxCopies value... if test x$enable_ssl != xno; then
+AC_SUBST(CUPS_SERVERCERT) diff -urNad '--exclude=CVS' '--exclude=.svn' '--exclude=.git' '--exclude=.arch' '--exclude=.hg' '--exclude=_darcs' '--exclude=.bzr' cups~/configure.in cups/configure.in AC_OUTPUT(Makedefs packaging/cups.list init/cups.sh init/cups-lpd cups-config
diff -urNad '--exclude=CVS' '--exclude=.svn' '--exclude=.git' '--exclude=.arch' '--exclude=.hg' '--exclude=_darcs' '--exclude=.bzr' cups~/doc/help/ref-cups-files-conf.html.in cups/doc/help/ref-cups-files-conf.html.in
+ cups-files.conf+ + The /etc/cups/cups-files.conf file contains configuration directives that control the files, directories. users. and groups that are used by the CUPS scheduler, + + AccessLog+ + Examples+ +
+ + Description+ + The + + The server name can be included in the filename by using + + The special name "syslog" can be used to send the access + + The default access log file is + + + CUPS 1.1.15ConfigFilePerm+ + Examples+ +
+ + Description+ + The + + Note: + + + DataDir+ + Examples+ +
+ + Description+ + The + + + CUPS 1.2/OS X 10.5DefaultAuthType+ + Examples+ +
+ + Description+ + The + + + DocumentRoot+ + Examples+ +
+ + Description+ + The + + Documents are first looked up in a sub-directory for the + + + ErrorLog+ + Examples+ +
+ + Description+ + The + + The server name can be included in the filename by using + + The special name "syslog" can be used to send the error + + + CUPS 1.4/OS X 10.6FatalErrors+ + Examples+ +
+ + Description+ + The + +
+ + + + Multiple errors can be listed, and the form "-kind" can be used with + + + CUPS 1.1.18FileDevice+ + Examples+ +
+ + Description+ + The + + The default setting is + + Note: + + + CUPS 1.1.3FontPath+ + Examples+ +
+ + Description+ + The + + + Group+ + Examples+ +
+ + Description+ + The + + + CUPS 1.1.15LogFilePerm+ + Examples+ +
+ + Description+ + The + + + PageLog+ + Examples+ +
+ + Description+ + The + + The server name can be included in the filename by using + + The special name "syslog" can be used to send the page + + + Printcap+ + Examples+ +
+ + Description+ + The + + When a filename is specified (e.g. @CUPS_DEFAULT_PRINTCAP@), + + + PrintcapFormat+ + Examples+ +
+ + Description+ + The + + + CUPS 1.1.3RemoteRoot+ + Examples+ +
+ + Description+ + The + + + RequestRoot+ + Examples+ +
+ + Description+ + The + + + ServerBin+ + Examples+ +
+ + Description+ + The + + + ServerCertificate+ + Examples+ +
+ + Description+ + The + + The default certificate file is + + + ServerKey+ + Examples+ +
+ + Description+ + The + + The default key file is + + + ServerRoot+ + Examples+ +
+ + Description+ + The + + + SystemGroup+ + Examples+ +
+ + Description+ + The + + + TempDir+ + Examples+ +
+ + Description+ + The + + Temporary directories must be world-writable and should have + +
+ + + User+ + Examples+ +
+ + Description+ + The + + Note: + + + + diff -urNad '--exclude=CVS' '--exclude=.svn' '--exclude=.git' '--exclude=.arch' '--exclude=.hg' '--exclude=_darcs' '--exclude=.bzr' cups~/doc/help/ref-cupsd-conf.html.in cups/doc/help/ref-cupsd-conf.html.in --- cups~/doc/help/ref-cupsd-conf.html.in 2012-12-07 13:00:48.000000000 +0100 +++ cups/doc/help/ref-cupsd-conf.html.in 2012-12-08 00:29:10.000000000 +0100 @@ -191,82 +191,6 @@ HREF="#Limit"> Limit section.
-DeprecatedAuthClass-Examples-
-Description-The -
- performed (default)
- required
- directive
- directive-- The -HREF="#Limit">
|
cupsdLogMessage(CUPSD_LOG_INFO, "Installing config file "%s"...", conffile); @@ -3829,14 +3826,10 @@ /*
- NeedReload = RELOAD_ALL;
/*
-static const cupsd_var_t variables[] =
endif /* HAVE_LIBSSL || HAVE_GNUTLS _/#endif /_ HAVE_SSL */
-#define NUM_VARS (sizeof(variables) / sizeof(variables[0]))static const unsigned ones[4] =
@@ -697,18 +705,59 @@ /*
cupsFileClose(fp); if (!status)
RunUser = getuid(); @@ -828,6 +877,13 @@ /*
@@ -2389,13 +2445,174 @@ /*
+/*
/*
- */
- int uid = atoi(value);
- struct passwd p; / Password information */
- p = getpwnam(value);
- */
- group = getgrnam(value);
- */
- */
+/*
- break;
- char units; / Units */- n = strtol(value, &units, 0);
- }
/*
/*
cat >/tmp/cups-$user/cupsd.conf <<EOF +cat >/tmp/cups-$user/cups-files.conf <<EOF Setup lots of test queues - half with PPD files, half without... |
"0001-Another-documentation-fix-related-to-CVE-2012-5519.patch": From 0bb53055d0a42f389806d0087b34e9a540e51564 Mon Sep 17 00:00:00 2001 The FileDevice option can no longer be adjusted using cupsctl.man/cupsctl.man | 5 ----- diff --git a/man/cupsctl.man b/man/cupsctl.man
|
"cups-str4223-ref-cups-files-conf.patch": diff -up cups-1.5.4/configure.in.str4223-extra cups-1.5.4/configure.in
|
"0001-Check-permissions-on-cups-files.conf.patch": From 3c03696466ff3dcb6caded170c5866f2523ccf5e Mon Sep 17 00:00:00 2001 scheduler/conf.c | 2 ++ diff --git a/scheduler/conf.c b/scheduler/conf.c
|
"str4223v2p3.patch": Index: doc/Makefile--- doc/Makefile (revision 10749)
@@ -817,8 +825,8 @@ if ((fp = cupsFileOpen(ConfigurationFile, "r")) == NULL)
@@ -827,7 +835,15 @@ if (!status)
RunUser = getuid(); @@ -1108,8 +1124,10 @@
/* Index: scheduler/log.c--- scheduler/log.c (revision 10749) +#ifdef HAVE_VSYSLOG
/*
|
Version: 1.5.3
CUPS.org User: odyx
Hi,
as was reported to http://bugs.debian.org/692791 , any user belonging to the "lpadmin" group (as defined by the --with-system-groups configure stanza), can get access to any file on the host.
This happens through the following steps:
a) the configuration file is modified through the webinterface with PageLog /etc/shadow (e.g.)
b) the webinterface triggers a server restart
c) as cupsd runs as root, it then grants access to lpadmin users access to /etc/shadow trough the PageLog.
This is clearly a privilege escalation for users in the lpadmin group to access root-owned files.
Cheers,
OdyX
The text was updated successfully, but these errors were encountered: