Edit: It seems the gid takes effect but the tool (1Password CLI2) I try to execute does not work with the way exec.Command is implemented.
I'm trying to call an executable from go with exec.Command which needs certain permissions granted by its owning group. The setgid bit is set on that executable.
Calling it from exec.Command does not honor the setgid bit and providing credentials which set additional groups does not work without root privileges.
Using syscall.Exec ---does actually set the correct group since it uses execvg, but I think there is not an easy method to catch the output.
Is there a way to use exec.Command and set the correct group without root privileges that I'm missing?
I'm using Go 1.18.3 on Fedora 36.
Minimal example:
package main
import (
"fmt"
"os/exec"
)
func main() {
cmd := exec.Command("op", "account", "get")
out, err := cmd.CombinedOutput()
fmt.Printf("%s\n%s", out, err)
}
Which results in an error due to the required gid not being set:
[ERROR] 2022/07/12 17:33:03 connecting to desktop app: read: connection reset, make sure the CLI is correctly installed and CLI Biometric Unlock is enabled in the 1Password app
Doing the same in Python does work:
from subprocess import check_output
o = check_output(["op", "account", "get"])
print(o)