git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] Added support for dropping privileges to git-daemon.

From
MJMitchell Blank Jr <mitch@sfgoth.com>
Date
Aug 19, 2006, 17:25 UTC
Message-ID
<20060819172533.GB64962@gaz.sfgoth.com>
In-Reply-To
<1155990772.6591@hammerfest>
Tilman Sauerbeck wrote:
> +	if (user && group)
> +		drop_privileges();
It seems "if (user)" would be sufficient here.
> +	if (!user ^ !group)
> +		die("either set both user and group or none of them");

For simplicities sake I'd actually suggest allowing group==NULL. So change this test to be

	if (group && !user)
		die("--group supplied without --user");
Then in drop_privileges() do something like:
	struct passwd *p;
	gid_t gid;
	p = getpwnam(user);
	if (!p)
		die("user not found - %s", user);
	if (group == NULL)
		gid = p->pw_gid;
	else {
		struct group *g = getgrnam(group);
		if (!g)
			die("group not found - %s", group);
		gid = g->gr_gid;
	}

Since usually you want to use the same gid that is normally associated with that pid, this just makes things a little easier on the user

-Mitch
Previous: Johannes SchindelinNext: Tilman Sauerbeck
Message 8 of 13 in “Added support for dropping privileges to git-daemon.”
  1. Added support for dropping privileges to git-daemon.Tilman Sauerbeck, Aug 19, 2006
  2. Marco CostalbaAug 19, 2006
  3. Tilman SauerbeckAug 19, 2006
  4. Marco CostalbaAug 19, 2006
  5. Marco CostalbaAug 19, 2006
  6. Mitchell Blank JrAug 19, 2006
  7. Johannes SchindelinAug 19, 2006
  8. Mitchell Blank JrAug 19, 2006
  9. Added support for dropping privileges to git-daemon.Tilman Sauerbeck, Aug 19, 2006
  10. Junio C HamanoAug 22, 2006
  11. Added support for dropping privileges to git-daemon.Tilman Sauerbeck, Aug 22, 2006
  12. Junio C HamanoAug 22, 2006
  13. Tilman SauerbeckAug 23, 2006

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.