diff --git a/sesman/sesexec/session.c b/sesman/sesexec/session.c index 93b9579d..c4249b7a 100644 --- a/sesman/sesexec/session.c +++ b/sesman/sesexec/session.c @@ -680,6 +680,19 @@ session_start_wrapped(struct login_info *login_info, int window_manager_pid; enum scp_screate_status status = E_SCP_SCREATE_GENERAL_ERROR; + /* Set the secondary groups before starting the session to prevent + * problems on PAM-based systems (see Linux pam_setcred(3)). + * If we have *BSD setusercontext() this is not done here */ +#ifndef HAVE_SETUSERCONTEXT + if (g_initgroups(login_info->username) != 0) + { + LOG(LOG_LEVEL_ERROR, + "Failed to initialise secondary groups for %s: %s", + login_info->username, g_get_strerror()); + return E_SCP_SCREATE_GENERAL_ERROR; + } +#endif + if (auth_start_session(login_info->auth_info, s->display) != 0) { // Errors are logged by the auth module, as they are @@ -706,19 +719,6 @@ session_start_wrapped(struct login_info *login_info, } #endif - /* Set the secondary groups before starting the session to prevent - * problems on PAM-based systems (see Linux pam_setcred(3)). - * If we have *BSD setusercontext() this is not done here */ -#ifndef HAVE_SETUSERCONTEXT - if (g_initgroups(login_info->username) != 0) - { - LOG(LOG_LEVEL_ERROR, - "Failed to initialise secondary groups for %s: %s", - login_info->username, g_get_strerror()); - return E_SCP_SCREATE_GENERAL_ERROR; - } -#endif - /* start the X server in a new process group. * * We group the X server, window manager and chansrv in a single