summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorTsukasa Hiiragi <bakalolka@gmail.com>2016-11-08 16:50:32 +0200
committerTsukasa Hiiragi <bakalolka@gmail.com>2016-11-08 16:50:32 +0200
commit8e76363ccf2cdc05b691337d07291cd27107e468 (patch)
treee9ade81c380226740b4034c3ff8db0afcf00fab4
parent360c84e0351728b0c0479ceddba924997acb46e4 (diff)
downloadinfinitytier-8e76363ccf2cdc05b691337d07291cd27107e468.tar.gz
infinitytier-8e76363ccf2cdc05b691337d07291cd27107e468.zip
Fix chown on /var/lib/zerotier-one
-rw-r--r--osdep/LinuxDropPrivileges.cpp4
1 files changed, 2 insertions, 2 deletions
diff --git a/osdep/LinuxDropPrivileges.cpp b/osdep/LinuxDropPrivileges.cpp
index dab85bd8..e2688e65 100644
--- a/osdep/LinuxDropPrivileges.cpp
+++ b/osdep/LinuxDropPrivileges.cpp
@@ -102,6 +102,8 @@ void dropPrivileges(std::string homeDir) {
return;
}
+ createOwnedHomedir(homeDir, targetUser);
+
if (prctl(PR_CAP_AMBIENT, PR_CAP_AMBIENT_IS_SET, CAP_NET_RAW, 0, 0) < 0) {
// Kernel has no support for ambient capabilities.
notDropping(homeDir);
@@ -113,8 +115,6 @@ void dropPrivileges(std::string homeDir) {
return;
}
- createOwnedHomedir(homeDir, targetUser);
-
if (setCapabilities((1 << CAP_NET_ADMIN) | (1 << CAP_NET_RAW) | (1 << CAP_SETUID) | (1 << CAP_SETGID)) < 0) {
fprintf(stderr, "ERROR: failed to set capabilities (not running as real root?)\n");
exit(1);