5 ms·
Yup, it's one of those annoying things that makes run scripts more complicated. I rewrote phusion's runit setuser helper in Go because it didn't set all the ri
by midas007 12y ago
Yup, it's one of those annoying things that makes run scripts more complicated. I rewrote phusion's runit setuser helper in Go because it didn't set all the right env vars.
https://raw.githubusercontent.com/steakknife/my_init/master/setuser.go https://raw.githubusercontent.com/steakknife/my_init/master/...
- sigil 12y agoHuh, looks pretty similar to envuidgid(8) from daemontools. [1] Another plug for daemontools-encore (last one I promise). The setuidgid(8) program in classic daemontools doesn't set supplementary groups, and a lot of people I know just end up just using sudo in their run files. If you use daemontools-encore though, you can just use `setuidgid -s` instead. PS. Really, daemontools-encore should imo be called daemontools 1.x, but you know how djb feels about forks of his projects... [1] http://cr.yp.to/daemontools/envuidgid.html http://cr.yp.to/daemontools/envuidgid.html
- midas007 12y agoMaintainers either will or won't accept that forks are the sincerest form of flattery.
- midas007 12y agoThe problem as per the Phusion blog article is that the runit and possibly daemontools equivalent commands don't set all env vars: HOME, USER, GID & UID, it only calls setgid() & setuid() IIRC. (envuidgid only sets UID and GID[0]) This causes breakage for lots of apps that end up inheriting root's env instead. :( Here's the go version I wrote, so there's no need for dep on Python/Ruby/etc on the target system: setuser USERNAME COMMAND [args...] # how to build it go get github.com/steakknife/my_init/setuser go build github.com/steakknife/my_init/setuser # creates setuser exe here [0] FR issue submitted as https://github.com/bruceg/daemontools-encore/issues/18 https://github.com/bruceg/daemontools-encore/issues/18