Once it has opened the required files and sockets it should drop its privileges to something like "nobody".
Looks good.