diff --git a/doc/config/capabilities.md b/doc/config/capabilities.md index 5aa16c0a..9968b971 100644 --- a/doc/config/capabilities.md +++ b/doc/config/capabilities.md @@ -169,7 +169,8 @@ ps -o user,pid,cmd -p $(pidof nginx) - Linux kernel 4.3+ (for ambient capabilities support) - libcap library installed -- Finit built with `--enable-libcap` +- Finit built with `--enable-libcap`, otherwise a `capabilities` list is + ignored, with a warning ## Limitations @@ -181,6 +182,10 @@ ps -o user,pid,cmd -p $(pidof nginx) - Using `user = "root"` with `^` capabilities will not work effectively, as ambient capabilities are only added to the effective set when euid ≠ 0 - Use inheritable (`%`) or bounding (`!`) capabilities with `user = "root"` if needed + - Finit warns about this when reading the .conf file: + + nginx: ambient capabilities ('^') have no effect as root, use a + non-root user, or '%' and '!' entries - Services without `capabilities` use standard privilege dropping: - Services with a non-root `user` have no special capabilities - Services without `user` run as root with full capabilities diff --git a/src/service.c b/src/service.c index 34647923..4afd9f1e 100644 --- a/src/service.c +++ b/src/service.c @@ -1537,11 +1537,26 @@ static void parse_caps(svc_t *svc, char *caps) return; } + if (!strcmp(svc->username, "root")) { + cap_value_t cap; + + for (cap = 0; cap <= CAP_LAST_CAP; cap++) { + if (!cap_iab_get_vector(cap_iab, CAP_IAB_AMB, cap)) + continue; + + /* the ambient set only reaches effective when euid != 0 */ + logit(LOG_WARNING, "%s: ambient capabilities ('^') have no effect" + " as root, use a non-root user, or '%%' and '!' entries", + svc_ident(svc, NULL, 0)); + break; + } + } + cap_free(cap_iab); strlcpy(svc->capabilities, caps, sizeof(svc->capabilities)); #else - (void)svc; - (void)caps; + logit(LOG_WARNING, "%s: capabilities require Finit built with --enable-libcap," + " ignoring '%s'", svc_ident(svc, NULL, 0), caps); #endif }