2 ms·
Can't you drop privileges immediately after getting the privileged socket? Why do you need to hold on to them?
by tetrep 9y ago
Can't you drop privileges immediately after getting the privileged socket? Why do you need to hold on to them?
- old-gregg 9y agoWhat do you mean "hold on to them"? Teleport needs root privileges to create sessions like `ssh root@host`, like any SSH server would. But DROPS privileges to start the session, i.e. when they no longer needed. I am assuming you and hackcasual aren't familiar with Golang, since you aren't seeing familiar fork()/setuid()? I'll try to explain: "dropping privileges" term comes from the old tradition of forking a child process from a privileged parent. Teleport, instead of calling fork() directly as you'd probably expect C code to work, uses Golang's syscall.StartProcess(), which does the entire fork-and-drop privileges logic, and the new privileges (user-specific ones) are passed as shown in the line of code above. User SSH sessions are sandboxed in unprivileged processes just like you'd expect.
- devdoomari 9y agoI think the parent comment is about running worker-threads in 'nobody' user account. a lot of proper-distro-packaged apps (e.g. nginx on centos yum/ubuntu apt) spawn 'nobody' processes