mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-10 23:49:09 +02:00
Add an optional --allow-group flag restricting the daemon sockets to a group
This commit is contained in:
@@ -29,6 +29,11 @@ func LookupGroupID(gid string) (*user.Group, error) {
|
||||
return user.LookupGroupId(gid)
|
||||
}
|
||||
|
||||
// LookupGroupName looks up a group by name.
|
||||
func LookupGroupName(name string) (*user.Group, error) {
|
||||
return user.LookupGroup(name)
|
||||
}
|
||||
|
||||
// GroupIDs returns the IDs of the groups the user is a member of; libc's
|
||||
// getgrouplist handles NSS groups natively.
|
||||
func GroupIDs(u *user.User) ([]string, error) {
|
||||
|
||||
@@ -88,6 +88,25 @@ func LookupGroupID(gid string) (*user.Group, error) {
|
||||
return g, nil
|
||||
}
|
||||
|
||||
// LookupGroupName looks up a group by name, falling back to getent if os/user
|
||||
// fails.
|
||||
func LookupGroupName(name string) (*user.Group, error) {
|
||||
g, err := user.LookupGroup(name)
|
||||
if err == nil {
|
||||
return g, nil
|
||||
}
|
||||
|
||||
stdErr := err
|
||||
log.Debugf("os/user.LookupGroup(%q) failed, trying getent: %v", name, err)
|
||||
|
||||
g, _, getentErr := groupLookup(name)
|
||||
if getentErr != nil {
|
||||
log.Debugf("getent fallback for group %q also failed: %v", name, getentErr)
|
||||
return nil, stdErr
|
||||
}
|
||||
return g, nil
|
||||
}
|
||||
|
||||
// GroupIDs returns the IDs of the groups the user is a member of.
|
||||
// NOTE: unlike the lookups above, which try the standard library first, this
|
||||
// intentionally tries `id -G` first because without cgo, user.GroupIds only
|
||||
|
||||
Reference in New Issue
Block a user