hello,
while working at a setup with httpd serving cgit, I noticed, that privilege
dropping option -u xyz attaches only the primary group of user xyz to the
process but not the supplementary groups.

So httpd works different compared to be started by user xyz.

I wonder whether there is interest for supporting supplementary groups. If
so, I would try to develop a patch for that. The supplementary group
feature could be triggerd by extending the commandline option, e.g with -u
user:+ or -u user:group+. So it would be fully backward compatible.

I'm looking forward to hear from you.

Regards Andreas
_______________________________________________
busybox mailing list
[email protected]
http://lists.busybox.net/mailman/listinfo/busybox

Reply via email to