Check the return value from DropRoot()

Unlike the other brillo::Minijail methods, this one can fail if the
username lookup does not succeed.

BUG=chromium:670985
TEST=buildbots

Change-Id: Id1d5059fb155c1a227033af0eba837ab37e96fe9
Reviewed-on: https://chromium-review.googlesource.com/416302
Commit-Ready: Kevin Cernekee <cernekee@chromium.org>
Tested-by: Kevin Cernekee <cernekee@chromium.org>
Reviewed-by: Mattias Nissler <mnissler@chromium.org>
Reviewed-by: Jorge Lucangeli Obes <jorgelo@chromium.org>
diff --git a/iptables.cc b/iptables.cc
index 992df58..93d2f95 100644
--- a/iptables.cc
+++ b/iptables.cc
@@ -475,7 +475,7 @@
 #if !defined(__ANDROID__)
   // TODO(garnold) This needs to be re-enabled once we figure out which
   // unprivileged user we want to use.
-  m->DropRoot(jail, kUnprivilegedUser, kUnprivilegedUser);
+  CHECK(m->DropRoot(jail, kUnprivilegedUser, kUnprivilegedUser));
 #endif  // __ANDROID__
   m->UseCapabilities(jail, capmask);