Bug #80669 [Csd]: Can't initgroups() when specifying numeric user
| From: | bukka@php.net | Date: | Wed, 23 Nov 2022 12:35:53 +0000 |
| Subject: | Bug #80669 [Csd]: Can't initgroups() when specifying numeric user | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-242889@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80669&edit=1
ID: 80669
Updated by: bukka@php.net
Reported by: andreas dot ley at kit dot edu
Summary: Can't initgroups() when specifying numeric user
Status: Closed
Type: Bug
Package: FPM related
Operating System: Debian GNU/Linux
PHP Version: Irrelevant
-Assigned To:
+Assigned To: bukka
Block user comment: N
Private report: N
New Comment:
Just for the reference this was fixed by this PR: https://github.com/php/php-src/pull/9983
Except setting user from getpwuid, I also set a group which is a small BC break but the previous
behavior (using root group) was not intended and seems wrong and not very secure... Anyway in case
anyone relies on it, I merged it to 8.2 only.
I think we don't really need to worry about non unique uid as there are probably not many users
that use them and as you say it doesn't work for non-root already.
Previous Comments:
------------------------------------------------------------------------
[2022-11-23 10:41:36] git@php.net
Automatic comment on behalf of bukka
Revision: https://github.com/php/php-src/commit/94702c56e0cc98166b12ebc202e6aebf08b12b5e
Log: Fix bug #80669: FPM numeric user fails to set groups
------------------------------------------------------------------------
[2021-01-25 16:49:48] andreas dot ley at kit dot edu
Description:
------------
When using PHP-FPM, you can configure the "user" directive for a pool with either an
(alphanumeric) username or a (numeric) uid. However, if you do the latter, initgroups() won't
set supplementary groups.
This is due to fpm_unix_init_child() in sapi/fpm/fpm/fpm_unix.c calling
"initgroups(wp->config->user, wp->set_gid)".
One possible solution would be changing this to "initgroups(wp->user, wp->set_gid)"
which would require to set wp->user from getpwuid(wp->set_uid) in fpm_unix_conf_wp() in the
very same file, which currently is only done when is_root is false.
One objection could be that a uid might not be unique, but the same applies to the non-root case.
Another possibility then might be an explicit configuration directive for supplementary groups.
If you decide to go for the first solution, I'd volunteer to write a patch for that upon
request.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80669&edit=1