From: Fabian Keil Date: Fri, 6 Feb 2009 18:02:58 +0000 (+0000) Subject: When dropping privileges, also give up membership in supplementary X-Git-Tag: v_3_0_11~95 X-Git-Url: http://www.privoxy.org/gitweb/?p=privoxy.git;a=commitdiff_plain;h=892b30a145ea051b5f9f5a46967175cede143a31 When dropping privileges, also give up membership in supplementary groups. Thanks to Matthias Drochner for reporting the problem, providing the initial patch and testing the final version. --- diff --git a/jcc.c b/jcc.c index ea4ae644..76a491be 100644 --- a/jcc.c +++ b/jcc.c @@ -1,4 +1,4 @@ -const char jcc_rcs[] = "$Id: jcc.c,v 1.219 2009/01/31 16:08:21 fabiankeil Exp $"; +const char jcc_rcs[] = "$Id: jcc.c,v 1.220 2009/02/04 18:29:07 fabiankeil Exp $"; /********************************************************************* * * File : $Source: /cvsroot/ijbswa/current/jcc.c,v $ @@ -33,6 +33,10 @@ const char jcc_rcs[] = "$Id: jcc.c,v 1.219 2009/01/31 16:08:21 fabiankeil Exp $" * * Revisions : * $Log: jcc.c,v $ + * Revision 1.220 2009/02/04 18:29:07 fabiankeil + * Initialize the log module before parsing arguments. + * Thanks to Matthias Drochner for the report. + * * Revision 1.219 2009/01/31 16:08:21 fabiankeil * Remove redundant error check in receive_client_request(). * @@ -3859,6 +3863,17 @@ int main(int argc, const char *argv[]) { log_error(LOG_LEVEL_FATAL, "Cannot setgid(): Insufficient permissions."); } + if (NULL != grp) + { + if (setgroups(1, &grp->gr_gid)) + { + log_error(LOG_LEVEL_FATAL, "setgroups() failed: %E"); + } + } + else if (initgroups(pw->pw_name, pw->pw_gid)) + { + log_error(LOG_LEVEL_FATAL, "initgroups() failed: %E"); + } if (do_chroot) { if (!pw->pw_dir)