From ab506626580c8b68db5061d800fb5e8f04bfd852 Mon Sep 17 00:00:00 2001 From: Andjelko Horvat Date: Sat, 18 Oct 2014 00:08:08 +0200 Subject: [PATCH] Add emperor-tyrant-initgroups option: add additional groups set via initgroups() in Tyrant mode. --- core/emperor.c | 27 ++++++++++++++++++++++++--- core/uwsgi.c | 1 + uwsgi.h | 1 + 3 files changed, 26 insertions(+), 3 deletions(-) diff --git a/core/emperor.c b/core/emperor.c index 19d0f719..07898aea 100644 --- a/core/emperor.c +++ b/core/emperor.c @@ -1524,9 +1524,30 @@ static void uwsgi_emperor_spawn_vassal(struct uwsgi_instance *n_ui) { uwsgi_error("setgid()"); exit(1); } - if (setgroups(0, NULL)) { - uwsgi_error("setgroups()"); - exit(1); + + if (uwsgi.emperor_tyrant_initgroups) { + char *uidname = NULL; + gid_t gid = NULL; + struct passwd *pw = getpwuid(n_ui->uid); + + if (pw) { + uidname = pw->pw_name; + gid = pw->pw_gid; + } + + if (!uidname) { + uidname = uwsgi_num2str(n_ui->uid); + } + + if (initgroups(uidname, gid)) { + uwsgi_error("initgroups()"); + exit(1); + } + } else { + if (setgroups(0, NULL)) { + uwsgi_error("setgroups()"); + exit(1); + } } if (setuid(n_ui->uid)) { diff --git a/core/uwsgi.c b/core/uwsgi.c index f7ac8b66..4a074b96 100644 --- a/core/uwsgi.c +++ b/core/uwsgi.c @@ -212,6 +212,7 @@ static struct uwsgi_option uwsgi_base_options[] = { {"emperor-pidfile", required_argument, 0, "write the Emperor pid in the specified file", uwsgi_opt_set_str, &uwsgi.emperor_pidfile, 0}, {"emperor-tyrant", no_argument, 0, "put the Emperor in Tyrant mode", uwsgi_opt_true, &uwsgi.emperor_tyrant, 0}, {"emperor-tyrant-nofollow", no_argument, 0, "do not follow symlinks when checking for uid/gid in Tyrant mode", uwsgi_opt_true, &uwsgi.emperor_tyrant_nofollow, 0}, + {"emperor-tyrant-initgroups", no_argument, 0, "add additional groups set via initgroups() in Tyrant mode", uwsgi_opt_true, &uwsgi.emperor_tyrant_initgroups, 0}, {"emperor-stats", required_argument, 0, "run the Emperor stats server", uwsgi_opt_set_str, &uwsgi.emperor_stats, 0}, {"emperor-stats-server", required_argument, 0, "run the Emperor stats server", uwsgi_opt_set_str, &uwsgi.emperor_stats, 0}, {"early-emperor", no_argument, 0, "spawn the emperor as soon as possibile", uwsgi_opt_true, &uwsgi.early_emperor, 0}, diff --git a/uwsgi.h b/uwsgi.h index 3eda5814..0bd428de 100644 --- a/uwsgi.h +++ b/uwsgi.h @@ -1861,6 +1861,7 @@ struct uwsgi_server { int emperor_nofollow; int emperor_tyrant; int emperor_tyrant_nofollow; + int emperor_tyrant_initgroups; int emperor_fd_config; int early_emperor; int emperor_throttle;