Module: Ace::Hitl::Lifecycle::Identity

Defined in:
lib/ace/hitl/lifecycle/identity.rb

Overview

The single identity gateway of the generic lifecycle: euid, user and group lookups, and the privilege drop for effect execution. Every identity decision goes through here so tests can pin a faithful unprivileged fixture without patching call sites (spec 8wm.t.y21 §2).

Class Method Summary collapse

Class Method Details

.drop_to!(uid, gid) ⇒ Object

Drop to the exact requester identity for effect execution. Root drops fully (setgroups/setgid/setuid); a non-root process may only "drop" to itself, so a foreign requester fails closed.



53
54
55
56
57
58
59
60
61
62
# File 'lib/ace/hitl/lifecycle/identity.rb', line 53

def drop_to!(uid, gid)
  if root?
    Process::Sys.setgroups([gid])
    Process::Sys.setgid(gid)
    Process::Sys.setuid(uid)
  elsif uid != euid
    raise Lifecycle::PermissionError,
      "effect callback requires the requester's identity and root authority to drop to it"
  end
end

.euid ⇒ Object



16
17
18
# File 'lib/ace/hitl/lifecycle/identity.rb', line 16

def euid
  Process.euid
end

.gid ⇒ Object



24
25
26
# File 'lib/ace/hitl/lifecycle/identity.rb', line 24

def gid
  Process.gid
end

.group_id(name) ⇒ Object



44
45
46
47
48
# File 'lib/ace/hitl/lifecycle/identity.rb', line 44

def group_id(name)
  Etc.getgrnam(name.to_s).gid
rescue ArgumentError
  raise Lifecycle::Error, "unknown group identity: #{name}"
end

.root? ⇒ Boolean

Returns:

  • (Boolean)


28
29
30
# File 'lib/ace/hitl/lifecycle/identity.rb', line 28

def root?
  euid.zero?
end

.uid ⇒ Object



20
21
22
# File 'lib/ace/hitl/lifecycle/identity.rb', line 20

def uid
  Process.uid
end

.user_ids(name) ⇒ Object

The requester's uid/gid; unknown names fail closed.



37
38
39
40
41
42
# File 'lib/ace/hitl/lifecycle/identity.rb', line 37

def user_ids(name)
  entry = Etc.getpwnam(name.to_s)
  [entry.uid, entry.gid]
rescue ArgumentError
  raise Lifecycle::Error, "unknown requester identity: #{name}"
end

.username ⇒ Object



32
33
34
# File 'lib/ace/hitl/lifecycle/identity.rb', line 32

def username
  Etc.getpwuid(euid)&.name || Process.uid.to_s
end