@cryptotaxi247 / netdata-1 / commits / 3f8fc797c

by default use current uid and gid for web files; fixes #2575

Costa Tsaousis (ktsaou) committed Aug 10, 2017 at 02:40 UTC 3f8fc797c3591b8cf5c34a475b03201bd4cf6a2b
2 files changed +17 -9
src/main.c
+5 -5
@@ -940,11 +940,6 @@ int main(int argc, char **argv) {
940 user = config_get(CONFIG_SECTION_GLOBAL, "run as user", (passwd && passwd->pw_name)?passwd->pw_name:"");
941 }
942
943 - // IMPORTANT: these have to run once, while single threaded
944 - web_files_uid(); // IMPORTANT: web_files_uid() before web_files_gid()
945 - web_files_gid();
946 -
947 -
943 // --------------------------------------------------------------------
944 // create the listening sockets
945
@@ -975,6 +970,11 @@ int main(int argc, char **argv) {
970
971 info("netdata started on pid %d.", getpid());
972
973 + // IMPORTANT: these have to run once, while single threaded
974 + // but after we have switched user
975 + web_files_uid();
976 + web_files_gid();
977 +
978
979 // ------------------------------------------------------------------------
980 // set default pthread stack size - after we have forked
src/web_client.c
+12 -4
@@ -210,14 +210,18 @@ uid_t web_files_uid(void) {
210 static uid_t owner_uid = 0;
211
212 if(unlikely(!web_owner)) {
213 - web_owner = config_get(CONFIG_SECTION_WEB, "web files owner", config_get(CONFIG_SECTION_GLOBAL, "run as user", ""));
213 + // getpwuid() is not thread safe,
214 + // but we have called this function once
215 + // while single threaded
216 + struct passwd *pw = getpwuid(geteuid());
217 + web_owner = config_get(CONFIG_SECTION_WEB, "web files owner", (pw)?(pw->pw_name?pw->pw_name:""):"");
218 if(!web_owner || !*web_owner)
219 owner_uid = geteuid();
220 else {
221 // getpwnam() is not thread safe,
222 // but we have called this function once
223 // while single threaded
220 - struct passwd *pw = getpwnam(web_owner);
224 + pw = getpwnam(web_owner);
225 if(!pw) {
226 error("User '%s' is not present. Ignoring option.", web_owner);
227 owner_uid = geteuid();
@@ -237,14 +241,18 @@ gid_t web_files_gid(void) {
241 static gid_t owner_gid = 0;
242
243 if(unlikely(!web_group)) {
240 - web_group = config_get(CONFIG_SECTION_WEB, "web files group", config_get(CONFIG_SECTION_WEB, "web files owner", ""));
244 + // getgrgid() is not thread safe,
245 + // but we have called this function once
246 + // while single threaded
247 + struct group *gr = getgrgid(getegid());
248 + web_group = config_get(CONFIG_SECTION_WEB, "web files group", (gr)?(gr->gr_name?gr->gr_name:""):"");
249 if(!web_group || !*web_group)
250 owner_gid = getegid();
251 else {
252 // getgrnam() is not thread safe,
253 // but we have called this function once
254 // while single threaded
247 - struct group *gr = getgrnam(web_group);
255 + gr = getgrnam(web_group);
256 if(!gr) {
257 error("Group '%s' is not present. Ignoring option.", web_group);
258 owner_gid = getegid();