From: Brian Candler Date: 2010-04-06T19:06:21+09:00 Subject: Re: $SAFE=0 for setuid? > Regardless, there isn't then a good workaround for what I need? :/ There almost certainly is one for Mac, but I'm not a Mac user. sudo doesn't require any user input if you configure it correctly (i.e. with suitable use of NOPASSWD flag in the sudoers file). Many Ubuntu GUI apps prompt for a password when they need to escalate to root privileges (e.g. update-manager). I don't know what that framework they use as I've never had to use it myself. Anyway, the way that ruby checks setuid is to test for real uid != effective uid (grep for "forbid_setid" in the ruby source). So a simple C program which is setuid root and which sets real id to effective id is all you need. $ cat myrunner.c // gcc -Wall -o myrunner myrunner.c #include #include #include int main(int argc, char *argv[]) { if (setgid(getegid()) < 0) { perror("setgid"); return 1; } if (setuid(geteuid()) < 0) { perror("setuid"); return 1; } execl("/usr/bin/ruby","ruby","/home/candlerb/myscript.rb",NULL); return 1; } $ gcc -Wall -o myrunner myrunner.c $ sudo chown 0:0 myrunner $ sudo chmod 4755 myrunner $ cat myscript.rb p $SAFE $ ./myrunner 0 Note that I have intentionally hard-coded the name of the script to run, and the path to the ruby interpreter, into the wrapper. You don't want people being able to run arbitrary code as root. A better wrapper would also reset the environment (man execle) HTH, Brian. -- Posted via http://www.ruby-forum.com/.