Module: Ace::Hitl::Lifecycle::Identity
- Defined in:
- lib/ace/hitl/lifecycle/identity.rb
Overview
The single identity gateway of the generic lifecycle: euid, user and group lookups, and the privilege drop for effect execution. Every identity decision goes through here so tests can pin a faithful unprivileged fixture without patching call sites (spec 8wm.t.y21 §2).
Class Method Summary collapse
-
.drop_to!(uid, gid) ⇒ Object
Drop to the exact requester identity for effect execution.
- .euid ⇒ Object
- .gid ⇒ Object
- .group_id(name) ⇒ Object
- .root? ⇒ Boolean
- .uid ⇒ Object
-
.user_ids(name) ⇒ Object
The requester's uid/gid; unknown names fail closed.
- .username ⇒ Object
Class Method Details
.drop_to!(uid, gid) ⇒ Object
Drop to the exact requester identity for effect execution. Root drops fully (setgroups/setgid/setuid); a non-root process may only "drop" to itself, so a foreign requester fails closed.
53 54 55 56 57 58 59 60 61 62 |
# File 'lib/ace/hitl/lifecycle/identity.rb', line 53 def drop_to!(uid, gid) if root? Process::Sys.setgroups([gid]) Process::Sys.setgid(gid) Process::Sys.setuid(uid) elsif uid != euid raise Lifecycle::PermissionError, "effect callback requires the requester's identity and root authority to drop to it" end end |
.euid ⇒ Object
16 17 18 |
# File 'lib/ace/hitl/lifecycle/identity.rb', line 16 def euid Process.euid end |
.gid ⇒ Object
24 25 26 |
# File 'lib/ace/hitl/lifecycle/identity.rb', line 24 def gid Process.gid end |
.group_id(name) ⇒ Object
44 45 46 47 48 |
# File 'lib/ace/hitl/lifecycle/identity.rb', line 44 def group_id(name) Etc.getgrnam(name.to_s).gid rescue ArgumentError raise Lifecycle::Error, "unknown group identity: #{name}" end |
.root? ⇒ Boolean
28 29 30 |
# File 'lib/ace/hitl/lifecycle/identity.rb', line 28 def root? euid.zero? end |
.uid ⇒ Object
20 21 22 |
# File 'lib/ace/hitl/lifecycle/identity.rb', line 20 def uid Process.uid end |
.user_ids(name) ⇒ Object
The requester's uid/gid; unknown names fail closed.
37 38 39 40 41 42 |
# File 'lib/ace/hitl/lifecycle/identity.rb', line 37 def user_ids(name) entry = Etc.getpwnam(name.to_s) [entry.uid, entry.gid] rescue ArgumentError raise Lifecycle::Error, "unknown requester identity: #{name}" end |
.username ⇒ Object
32 33 34 |
# File 'lib/ace/hitl/lifecycle/identity.rb', line 32 def username Etc.getpwuid(euid)&.name || Process.uid.to_s end |