@cryptotaxi247 / netdata-1 / commits / 3fce25320

prevent logging error about supplementary groups when netdata is not started as root; #2266

Costa Tsaousis (ktsaou) committed Jun 5, 2017 at 22:20 UTC 3fce25320cd44cf4b4247a2de5f3ad89b7402462
1 file changed +15 -11
src/daemon.c
+15 -11
@@ -73,8 +73,9 @@ void create_needed_dir(const char *dir, uid_t uid, gid_t gid)
73 error("Cannot create directory '%s'", dir);
74 }
75
76 -int become_user(const char *username, int pid_fd)
77 -{
76 +int become_user(const char *username, int pid_fd) {
77 + int am_i_root = (getuid() == 0)?1:0;
78 +
79 struct passwd *pw = getpwnam(username);
80 if(!pw) {
81 error("User %s is not present.", username);
@@ -94,12 +95,12 @@ int become_user(const char *username, int pid_fd)
95
96 int ngroups = (int)sysconf(_SC_NGROUPS_MAX);
97 gid_t *supplementary_groups = NULL;
97 - if(ngroups) {
98 + if(ngroups > 0) {
99 supplementary_groups = mallocz(sizeof(gid_t) * ngroups);
100 if(getgrouplist(username, gid, supplementary_groups, &ngroups) == -1) {
100 - error("Cannot get supplementary groups of user '%s'.", username);
101 - freez(supplementary_groups);
102 - supplementary_groups = NULL;
101 + if(am_i_root)
102 + error("Cannot get supplementary groups of user '%s'.", username);
103 +
104 ngroups = 0;
105 }
106 }
@@ -109,14 +110,17 @@ int become_user(const char *username, int pid_fd)
110 chown_open_file(stdaccess_fd, uid, gid);
111 chown_open_file(pid_fd, uid, gid);
112
112 - if(supplementary_groups && ngroups) {
113 - if(setgroups(ngroups, supplementary_groups) == -1)
114 - error("Cannot set supplementary groups for user '%s'", username);
115 -
116 - freez(supplementary_groups);
113 + if(supplementary_groups && ngroups > 0) {
114 + if(setgroups((size_t)ngroups, supplementary_groups) == -1) {
115 + if(am_i_root)
116 + error("Cannot set supplementary groups for user '%s'", username);
117 + }
118 ngroups = 0;
119 }
120
121 + if(supplementary_groups)
122 + freez(supplementary_groups);
123 +
124 #ifdef __APPLE__
125 if(setregid(gid, gid) != 0) {
126 #else