From: Sam Duncan Date: 2012-10-29T06:06:04+09:00 Subject: Re: File.readable? and /proc On 10/29/2012 09:18 AM, Jeff Moore wrote: > Igor Pirnovar wrote in post #1081714: >> Jeff Moore wrote in post #1081712: >> >>> It's the inconsistency with: >>> >>> root@nail:/projects/proc_fs# ls -al /proc/sys/fs/binfmt_misc/register >>> --w------- 1 root root 0 2012-10-28 08:24 >>> /proc/sys/fs/binfmt_misc/register >>> >>> that I find mostly surprising. >> Well, that's how Unix works. I have two objections: >> >> (1) You should not be using superuser account for regular work! >> (2) You have no business running irb in /proc filesystem! >> >> If you do either of these things, you better not be surprised, ever! > And if you 'regular work' involves interrogating the /proc file system, > then what? > You could use something like this? You'd need to flesh out some error/ input handling, and these constants (sadly not exposed by ruby that I can find) will be platform specific. I think the 'problem' is that root can do pretty much anything it wants (make a file owned root:root, chmod 000, and enjoy echo'ing stuff into it). The stdlib seems to use 'eaccess( path, R_OK )' which I guess gives a 0 for euid 0. require 'etc' S_IFMT = 0170000 S_IFLNK 0120000 S_IRUSR = 00400 S_IRGRP = 00040 S_IROTH = 00004 def readable?( path, follow=false ) st = File.lstat( path ) if follow && ( S_IFLNK == ( st.mode & S_IFMT ) ) st = File.stat( path ) end uid = Process.euid if ( st.mode & S_IROTH ) > 0 print 'Other read' true elsif( ( ( st.mode & S_IRUSR ) > 0 ) && ( st.uid == uid ) ) print 'Owner read' true elsif ( st.mode & S_IRGRP ) > 0 username = Etc.getpwuid( uid ).name if Etc.getgrgid( st.gid ).mem.include?( username ) print 'Group read' true else false end else false end end Sam