From 5cb583ac1cc6c9225e341f0cf8d02d42eff7d684 Mon Sep 17 00:00:00 2001 From: Lennart Poettering Date: Wed, 20 May 2015 14:41:39 +0200 Subject: [PATCH] util: introduce reset_uid_gid() for resetting all uids and gids to 0 --- src/shared/util.c | 25 +++++++++++++++---------- src/shared/util.h | 2 ++ 2 files changed, 17 insertions(+), 10 deletions(-) diff --git a/src/shared/util.c b/src/shared/util.c index 5efb9591a..62c1739c9 100644 --- a/src/shared/util.c +++ b/src/shared/util.c @@ -4666,16 +4666,7 @@ int namespace_enter(int pidns_fd, int mntns_fd, int netns_fd, int root_fd) { return -errno; } - if (setresgid(0, 0, 0) < 0) - return -errno; - - if (setgroups(0, NULL) < 0) - return -errno; - - if (setresuid(0, 0, 0) < 0) - return -errno; - - return 0; + return reset_uid_gid(); } int getpeercred(int fd, struct ucred *ucred) { @@ -6162,3 +6153,17 @@ int mount_move_root(const char *path) { return 0; } + +int reset_uid_gid(void) { + + if (setgroups(0, NULL) < 0) + return -errno; + + if (setresgid(0, 0, 0) < 0) + return -errno; + + if (setresuid(0, 0, 0) < 0) + return -errno; + + return 0; +} diff --git a/src/shared/util.h b/src/shared/util.h index 4cea62758..014e61c2e 100644 --- a/src/shared/util.h +++ b/src/shared/util.h @@ -906,3 +906,5 @@ char *shell_maybe_quote(const char *s); int parse_mode(const char *s, mode_t *ret); int mount_move_root(const char *path); + +int reset_uid_gid(void); -- 2.30.2