From: Robert Klemme Date: 2010-04-06T02:40:09+09:00 Subject: Re: $SAFE=0 for setuid? On 04/04/2010 06:32 PM, Rick Ashton wrote: > Jonathan Nielsen wrote: > >> Not entirely true, it sets $SAFE to 1 if you run it with setuid, but >> just running as root $SAFE will still be 0. >> > > Ok thanks. Yes, running with sudo will have $SAFE set to 0, however, I'm > currently wrapping the script in an app bundle using Platypus. > > This doesn't allow user input into a terminal so I cannot use sudo (see: > http://www.sveinbjorn.org/platypus_tutorial#33) > > However it does allow the entire script to be run as admin using the > Apple Security Framework. I'm unsure about the exact details of the > framework but it appears to start the process with setuid. > > With this entry point then, it doesn't seem to matter what I do (whether > I start Ruby directly or I start ruby through sh), $SAFE is always 1 > when the script starts. > > Starting ruby with -T0 doesn't seem to do anything. > > Not sure what I can do here :/ Write a wrapper script with setuid. You can even do such unsafe things as #!/bin/sh -f "$@" > Why is it that sudo won't raise the safe level but setuid does? Surely > they equally escalate privileges? Setuid can be detected by the Ruby interpreter because it is a property of the script executed. sudo is just a process that changes the environment in which the Ruby interpreter is started. This is significantly more difficult to detect since sudo is gone once the interpreter runs: robert@fussel:~$ sudo pstree -u $$ bash(robert)???pstree(root) robert@fussel:~$ Kind regards robert -- remember.guy do |as, often| as.you_can - without end http://blog.rubybestpractices.com/