From: Luke Kanies Date: 2006-12-17T10:07:42+09:00 Subject: Re: UID/EUID subshell solutions On Dec 11, 2006, at 9:15 PM, Paul Lutus wrote: > Luke Kanies wrote: >> >> I'm currently setting EUID and executing external commands, but some >> shells ignore that (which is apparently the "standard"). > > This is a very desirable shell behavior, to avoid an obvious hacker > vulnerability. I don't see how it's an obvious vulnerability; I thought the kernel was just as protective of UID as it as of EUID. >> I need some solution that will allow me (when running as root) to run >> shell commands as another user and capture stdout and (hopefully) >> stderr. This basically means fork and run Process.uid = blah, but >> there's some IPC to do too. >> >> Is there a semi-standard pattern for doing this, or does someone have >> some simple example code I can use? > > `su (username) -c (command)` This isn't very cross-platform, unfortunately; I'm looking more for a Ruby implementation, rather than shell, and I specifically require support on as many platforms as possible. This is for Puppet[1], which attempts to provide an abstraction layer across different *nix machines, so it's very important that it be as easy to make it work on many platforms. 1 - http://reductivelabs.com/projects/puppet -- Like frozen sentries of the serengeti, the century-old termite mounds had withstood all tests of time and foe - all tests, that is, except the one involving drunken aardvarks and a stolen wrecking ball." -- Gary Larson --------------------------------------------------------------------- Luke Kanies | http://reductivelabs.com | http://madstop.com