prevent logging error about supplementary groups when netdata is not started as root; #2266
Costa Tsaousis (ktsaou) committed
Jun 5, 2017 at 22:20 UTC
3fce25320cd44cf4b4247a2de5f3ad89b7402462
1 file changed
+15
-11
src/daemon.c
+15
-11
@@ -73,8 +73,9 @@ void create_needed_dir(const char *dir, uid_t uid, gid_t gid)
73
error("Cannot create directory '%s'", dir);
74
}
75
76
-int become_user(const char *username, int pid_fd)
77
-{
76
+int become_user(const char *username, int pid_fd) {
77
+ int am_i_root = (getuid() == 0)?1:0;
78
+
79
struct passwd *pw = getpwnam(username);
80
if(!pw) {
81
error("User %s is not present.", username);
@@ -94,12 +95,12 @@ int become_user(const char *username, int pid_fd)
95
96
int ngroups = (int)sysconf(_SC_NGROUPS_MAX);
97
gid_t *supplementary_groups = NULL;
97
- if(ngroups) {
98
+ if(ngroups > 0) {
99
supplementary_groups = mallocz(sizeof(gid_t) * ngroups);
100
if(getgrouplist(username, gid, supplementary_groups, &ngroups) == -1) {
100
- error("Cannot get supplementary groups of user '%s'.", username);
101
- freez(supplementary_groups);
102
- supplementary_groups = NULL;
101
+ if(am_i_root)
102
+ error("Cannot get supplementary groups of user '%s'.", username);
103
+
104
ngroups = 0;
105
}
106
}
@@ -109,14 +110,17 @@ int become_user(const char *username, int pid_fd)
110
chown_open_file(stdaccess_fd, uid, gid);
111
chown_open_file(pid_fd, uid, gid);
112
112
- if(supplementary_groups && ngroups) {
113
- if(setgroups(ngroups, supplementary_groups) == -1)
114
- error("Cannot set supplementary groups for user '%s'", username);
115
-
116
- freez(supplementary_groups);
113
+ if(supplementary_groups && ngroups > 0) {
114
+ if(setgroups((size_t)ngroups, supplementary_groups) == -1) {
115
+ if(am_i_root)
116
+ error("Cannot set supplementary groups for user '%s'", username);
117
+ }
118
ngroups = 0;
119
}
120
121
+ if(supplementary_groups)
122
+ freez(supplementary_groups);
123
+
124
#ifdef __APPLE__
125
if(setregid(gid, gid) != 0) {
126
#else