3 ms·
G-WAN does not require any installation and you do not need to run it as root. If you run G-WAN as root, it will automatically apply certain optimizations such
by ers35 14y ago
G-WAN does not require any installation and you do not need to run it as root. If you run G-WAN as root, it will automatically apply certain optimizations such as giving itself access to more than 1024 sockets.
Remove sudo and the examples still work.
- eropple 14y ago> If you run G-WAN as root, it will automatically apply certain optimizations such as giving itself access to more than 1024 sockets. That this is termed "an optimization" terrifies the shit out of me. Even moreso than the whole "hey, run it as root, broseph!" part. I am unsure why you are carrying this dude's water, but nothing I have seen makes anything related to this project seem either sane or production-safe. There is crazy in these hills, my friend. Undiluted.
- ers35 14y ago> That this is termed "an optimization" terrifies the shit out of me. What word do you suggest I use to describe configuring a program to have access to more sockets? > Even moreso than the whole "hey, run it as root, broseph!" part. In daemon mode, G-WAN drops privileges to the user and group of your choosing.
- deleted 14y ago[deleted]
- pjscott 14y agoThis is a little off-topic, but does it strike anybody else as weird that we're still writing this kind of code in our servers instead of using an external utility? Personally, I would probably just write something like: sudo chpst -u gwan:gwan -o 100000 ./gwan This uses the chpst utility from runit to do pretty much exactly what you described: set uid/gid, change the file descriptor limit, drop privileges, and execute ./gwan. For similar reasons, it feels crazy that people still manually write code to handle daemonization and pidfile handling, when there are easy tools that will handle that for you, and generally do a really good job of it. Isn't that the Unix Way?
- eropple 14y agoIt might be off-topic, but I'd never used chpst before. That one's going in the toolbox. Thank you. :-)
- eropple 14y ago> What word do you suggest I use to describe configuring a program to have access to more sockets? Like I said, "terrifying" is a good one. Reserving blocks of sockets in that sort of size is notably odd and from a performance standpoint it's pretty hard to argue that it's necessary. > In daemon mode, G-WAN drops privileges to the user and group of your choosing. I would assume that it would setuid down to something sane, sure, but that's not the WTF part: it's that I'm supposed to run closed-source code by some guy as root on my server machines.