int setgid(gid_t gid)
Under Linux, setgid is implemented like SYSV with SAVED_IDS. This allows a setgid (other than root) program to drop all of it's group privileges, do some un-privileged work, and then re-engage the original effective group ID in a secure manner.
If the user is root or the program is setgid root, special care must be taken. The setgid function checks the effective gid of the caller and if it is the superuser, all process related group ID's are set to gid. After this has occurred, it is impossible for the program to regain root privileges.