Преглед на файлове

* utils/start-stop-daemon.c: Added ability for user.group arg to
--chuid. Also, always call initgroups() when using --chuid.
* utils/start-stop-daemon.8: Document above change, also add note to the
--make-pidfile option concerning its problem with daemons that fork

Ben Collins преди 27 години
родител
ревизия
d444700f1f
променени са 4 файла, в които са добавени 65 реда и са изтрити 16 реда
  1. 7 0
      ChangeLog
  2. 4 0
      debian/changelog
  3. 13 1
      utils/start-stop-daemon.8
  4. 41 15
      utils/start-stop-daemon.c

+ 7 - 0
ChangeLog

@@ -1,3 +1,10 @@
+Thu Nov 18 10:27:35 EST 1999 Ben Collins <bcollins@debian.org>
+
+  * utils/start-stop-daemon.c: Added ability for user.group arg to
+    --chuid. Also, always call initgroups() when using --chuid.
+  * utils/start-stop-daemon.8: Document above change, also add note to the
+    --make-pidfile option concerning its problem with daemons that fork
+
 Fri Nov 12 21:21:21 CET 1999 Wichert Akkerman <wakkerma@debian.org>
 
   * Rename japanses translation to just jp

+ 4 - 0
debian/changelog

@@ -1,6 +1,10 @@
 dpkg (1.4.1.20) unstable; urgency=low
 
   * Fix mixup with Czech and Polish translations, Closes: Bug# 48986
+  * utils/start-stop-daemon.c: Added ability for user.group arg to
+    --chuid. Also, always call initgroups() when using --chuid.
+  * utils/start-stop-daemon.8: Document above change, also add note to the
+    --make-pidfile option concerning its problem with daemons that fork
 
  -- Wichert Akkerman <wakkerma@debian.org>  UNRELEASED
 

+ 13 - 1
utils/start-stop-daemon.8

@@ -122,7 +122,13 @@ Return exit status 0 instead of 1 if no actions are (would be) taken.
 Do not print informational messages; only display error messages.
 .TP
 .I -c|--chuid
-Change to this username/uid before starting the process
+Change to this username/uid before starting the process. You can also
+specify a group by appending a '.', then the group or gid in the same way
+as you would for the `chown' command (user.group). When using this option
+you must realize that the primary and suplimental groups are set as well,
+even if the `group' options is not specified. The group option is only for
+groups that the user isn't normally a member of (like adding per/process
+group membership for generic users like `nobody').
 .TP
 .I -b|--background
 Typically used with programs that don't detach on their own. This option
@@ -145,6 +151,12 @@ create the file referenced with
 .B --pidfile
 and place the pid into it just before executing the process. Note, it will
 not be removed when stopping the program.
+.B NOTE:
+This feature may not work in all cases. Most notably when the program
+being executed forks from it's main process. Because of this it is usually
+only useful when combined with the
+.B --background
+option.
 .TP
 .I -v|--verbose
 Print verbose informational messages.

+ 41 - 15
utils/start-stop-daemon.c

@@ -44,6 +44,7 @@
 #include <unistd.h>
 #include <getopt.h>
 #include <pwd.h>
+#include <grp.h>
 #include <sys/ioctl.h>
 #include <sys/types.h>
 #include <fcntl.h>
@@ -65,9 +66,11 @@ static int mpidfile = 0;
 static int signal_nr = 15;
 static const char *signal_str = NULL;
 static int user_id = -1;
-static int runas_id = -1;
+static int runas_uid = -1;
+static int runas_gid = -1;
 static const char *userspec = NULL;
-static const char *changeuser = NULL;
+static char *changeuser = NULL;
+static char *changegroup = NULL;
 static const char *cmdname = NULL;
 static char *execname = NULL;
 static char *startas = NULL;
@@ -169,7 +172,8 @@ Usage:
 Options (at least one of --exec|--pidfile|--user is required):
   -x|--exec <executable>        program to start/check if it is running\n\
   -p|--pidfile <pid-file>       pid file to check\n\
-  -c|--chuid <username>|<uid>   change to this user before starting process\n\
+  -c|--chuid <name|uid[.group|gid]>
+  		change to this user/group before starting process\n\
   -u|--user <username>|<uid>    stop processes owned by this user\n\
   -n|--name <process-name>      stop processes with this name\n\
   -s|--signal <signal>          signal to send (default TERM)\n\
@@ -307,7 +311,12 @@ parse_options(int argc, char * const *argv)
 			execname = optarg;
 			break;
 		case 'c':  /* --chuid <username>|<uid> */
-			changeuser = optarg;
+			changeuser = strdup(optarg); /* because we need to modify */
+			changegroup = strchr(changeuser, '.');
+			if (changegroup != NULL) {
+				changegroup[0] = '\0';
+				changegroup++;
+			}
 			break;
 		case 'b':  /* --background */
 			background = 1;
@@ -590,15 +599,22 @@ main(int argc, char **argv)
 
 		user_id = pw->pw_uid;
 	}
-
-	if (changeuser && sscanf(changeuser, "%d", &runas_id) != 1) {
-		struct passwd *pw;
-
-		pw = getpwnam(changeuser);
+	
+	if (changegroup && sscanf(changegroup, "%d", &runas_gid) != 1) {
+		struct group *gr = getgrnam(changegroup);
+		if (!gr)
+			fatal("group `%s' not found\n", changegroup);
+		runas_gid = gr->gr_gid;
+	}
+	if (changeuser && sscanf(changeuser, "%d", &runas_uid) != 1) {
+		struct passwd *pw = getpwnam(changeuser);
 		if (!pw)
 			fatal("user `%s' not found\n", changeuser);
-
-		runas_id = pw->pw_uid;
+		runas_uid = pw->pw_uid;
+		if (changegroup == NULL) { /* pass the default group of this user */
+			changegroup = ""; /* just empty */
+			runas_gid = pw->pw_gid;
+		}
 	}
 
 	if (pidfile)
@@ -625,16 +641,26 @@ main(int argc, char **argv)
 		printf("Would start %s ", startas);
 		while (argc-- > 0)
 			printf("%s ", *argv++);
-		if (changeuser != NULL)
-			printf(" (as user %s[%d])", changeuser, runas_id);
+		if (changeuser != NULL) {
+			printf(" (as user %s[%d]", changeuser, runas_uid);
+			if (changegroup != NULL)
+				printf(", and group %s[%d])", changegroup, runas_gid);
+			else
+				printf(")");
+		}
 		printf(".\n");
 		exit(0);
 	}
 	if (quietmode < 0)
 		printf("Starting %s...\n", startas);
 	*--argv = startas;
-	if (changeuser != NULL && seteuid(runas_id))
-		fatal("Unable to set effective uid to %s", changeuser);
+	if (changeuser != NULL) {
+		if (seteuid(runas_uid))
+			fatal("Unable to set effective uid to %s", changeuser);
+		if (initgroups(changeuser, runas_gid))
+			fatal("Unable to set initgroups() with gid %d", runas_gid);
+	}
+	
 	if (background) { /* ok, we need to detach this process */
 		int i, fd;
 		if (quietmode < 0)