by default use current uid and gid for web files; fixes #2575
Costa Tsaousis (ktsaou) committed
Aug 10, 2017 at 02:40 UTC
3f8fc797c3591b8cf5c34a475b03201bd4cf6a2b
2 files changed
+17
-9
src/main.c
+5
-5
@@ -940,11 +940,6 @@ int main(int argc, char **argv) {
940
user = config_get(CONFIG_SECTION_GLOBAL, "run as user", (passwd && passwd->pw_name)?passwd->pw_name:"");
941
}
942
943
- // IMPORTANT: these have to run once, while single threaded
944
- web_files_uid(); // IMPORTANT: web_files_uid() before web_files_gid()
945
- web_files_gid();
946
-
947
-
943
// --------------------------------------------------------------------
944
// create the listening sockets
945
@@ -975,6 +970,11 @@ int main(int argc, char **argv) {
970
971
info("netdata started on pid %d.", getpid());
972
973
+ // IMPORTANT: these have to run once, while single threaded
974
+ // but after we have switched user
975
+ web_files_uid();
976
+ web_files_gid();
977
+
978
979
// ------------------------------------------------------------------------
980
// set default pthread stack size - after we have forked
src/web_client.c
+12
-4
@@ -210,14 +210,18 @@ uid_t web_files_uid(void) {
210
static uid_t owner_uid = 0;
211
212
if(unlikely(!web_owner)) {
213
- web_owner = config_get(CONFIG_SECTION_WEB, "web files owner", config_get(CONFIG_SECTION_GLOBAL, "run as user", ""));
213
+ // getpwuid() is not thread safe,
214
+ // but we have called this function once
215
+ // while single threaded
216
+ struct passwd *pw = getpwuid(geteuid());
217
+ web_owner = config_get(CONFIG_SECTION_WEB, "web files owner", (pw)?(pw->pw_name?pw->pw_name:""):"");
218
if(!web_owner || !*web_owner)
219
owner_uid = geteuid();
220
else {
221
// getpwnam() is not thread safe,
222
// but we have called this function once
223
// while single threaded
220
- struct passwd *pw = getpwnam(web_owner);
224
+ pw = getpwnam(web_owner);
225
if(!pw) {
226
error("User '%s' is not present. Ignoring option.", web_owner);
227
owner_uid = geteuid();
@@ -237,14 +241,18 @@ gid_t web_files_gid(void) {
241
static gid_t owner_gid = 0;
242
243
if(unlikely(!web_group)) {
240
- web_group = config_get(CONFIG_SECTION_WEB, "web files group", config_get(CONFIG_SECTION_WEB, "web files owner", ""));
244
+ // getgrgid() is not thread safe,
245
+ // but we have called this function once
246
+ // while single threaded
247
+ struct group *gr = getgrgid(getegid());
248
+ web_group = config_get(CONFIG_SECTION_WEB, "web files group", (gr)?(gr->gr_name?gr->gr_name:""):"");
249
if(!web_group || !*web_group)
250
owner_gid = getegid();
251
else {
252
// getgrnam() is not thread safe,
253
// but we have called this function once
254
// while single threaded
247
- struct group *gr = getgrnam(web_group);
255
+ gr = getgrnam(web_group);
256
if(!gr) {
257
error("Group '%s' is not present. Ignoring option.", web_group);
258
owner_gid = getegid();