Replies: 1 comment 5 replies
|
Thanks for the clear example. I was actually able to easily reproduce this outside of xyOps with a small Node.js script: console.log( require('child_process').execSync('id', { encoding: 'utf8', uid: 1000 } ) );When I run this as root, I get: All my supplemental groups are missing, which is exactly what you are reporting in xyOps. So, after some research, I found that this is actually a well-known libuv (Node.js) behavior, not a xyOps-specific bug. When a privileged Node.js process launches a child with a This also explains why I'm working on how to address this for Plugin jobs, but it may be a while. Supplementary groups need to be initialized before the child gives up its privileges, so it may require a rather nasty shell workaround or launcher helper. Ugh... I'll update this discussion when I have a practical solution, but it sure doesn't look like there is an easy, low-hanging fruit fix here... |

Uh oh!
There was an error while loading. Please reload this page.
Is there a way to run scripts with supplemental groups (for the Shell Script plugin)? I noticed that I can set a group ID to run as, but I need the user the scripts run as to retain all of their supplemental groups in order for files to make their way where they are supposed to go.
When I have a script run "id" it indicates that the user is only getting one group, but when I run "id user1" it shows all of the groups that that user should be getting.
`id:
uid=31001(user1) gid=31000(primarygroup) groups=31000(primarygroup)
id user1:
uid=31001(user1) gid=31000(primarygroup) groups=31000(primarygroup),31002(group01),31003(group02),31004(group03),31005(group04),31006(group05),31001(user1),31007(group06),31008(group07),31009(group08),31010(group09),31011(group10)`
If I run commands with "sudo -u user1 COMMAND" it does get all of the groups, but I'd prefer not to have to run scripts in this manner if possible.
Thank you very much for your help!
All reactions