Most systems don't honor setuid/setgid on scripts. My Linux system at home doesn't, and I don't believe HP-UX or AIX do either.
However, Solaris does honor setuid scripts. A setuid script will open an unclosable security hole on most systems. Solaris has the fd file system and uses it to close that particular hole.
I too think that sudo is right way to go here; so I have been reluctant to mention another option. But now that I'm here... Let's say that we have three users whose processes need to be killed:
moe (uid=1025)
larry (uid=1026)
curly (uid=1027)
And we want shemp (uid=1028) to be able to kill processes owned only by moe, larry, and curly. We create a group called "killers" with a gid of, say, 1500; and we make shemp a member of that group. Now, we
Now /usr/local/killcmds has a private kill command for each killable user. It is setuid to the target and it can be executed only by members of the killers group. These kill commands are enough, but I would also develop a script as a front end that invokes the correct kill command. I have not tested this, but I believe that it will work.
Hi All,
How can i give permission for a specific user ( eg. admin ) ?
I tried with chmod admin+r prog.sh
which doesnt work.
Is there any way i can specify a user's name and give the permission?
Thanks in advance.
Saneesh Joseph. (1 Reply)
I have some of programs in unix system which are to started with one_user say "xxxx".
I have sudo permission if i start these programs with sudo it shows root permission. But i want these programs permession should be "xxxx".
I tried "su user_name -c Program_name"
but it is not... (3 Replies)
Hi all,
I created testuser. by following command.
/usr/sbin/adduser -n test -d /disk05/collections/GET/testdata/
and then set its password by following command.
passwd testuser
When I login to system by testuser, it enters everything is ok.
The problem is how to set permission to this... (3 Replies)
Is there any possible way to give permission to a user to a file whose not a member of that group. Also the permission of the file shouls be given only to that USER but not all OTHERS.
Thanks in Advance for ur replies/suggestions... (5 Replies)
I have problem giving user access to his public_html directory.
While when I am logged as root I can access my files by going to
www.myserver.com/file.htmlwhere file.html is actually on this path...
var/www/file.htmlBut when user tries to access his file.html on this path....
~user/file.html it... (10 Replies)
I have a script that do read data for Munin Graph.
My problem is that it have some reading problems, and I do not know how to fix it.
script traf.sh (its not the complete script)#!/bin/sh
PORT="80"
NETDEVICE="eth0"
IPTRAFlogdir="/var/log/iptraf"
... (8 Replies)
Hi,
I'm newbie to unix.
There is a directory, say Testing/ under /home/user1.
I have created a user by the name check.
I was looking for a way to give the above user read & execute access only to this directory Testing/ while for other remaining files,directories,etc this user... (2 Replies)
Hi folks,
I am trying to grant the access like below items using the setfacl command, but i couldn't achieve as what I required. any other possibility.
username : testing
Readonly access in /form_dl/system/prd/logs
Write only access in /form_dl/system/prd/deploy
No access to other... (0 Replies)
Hi All,
We have a scenario in production where we want only one user from a group to modify the file. The file is not set to write permission for application manager.
-r--r--r-- 1 amgr u00 15661716 Aug 30 00:06 DCI.dat
So here amgr will have permission to edit the file. We want a... (10 Replies)
Discussion started by: arunkumar_mca
10 Replies
LEARN ABOUT DEBIAN
flock
FLOCK(1) User Commands FLOCK(1)NAME
flock - manage locks from shell scripts
SYNOPSIS
flock [-sxon] [-w timeout] lockfile [-c] command...
flock [-sxon] [-w timeout] lockdir [-c] command...
flock [-sxun] [-w timeout] fd
DESCRIPTION
This utility manages flock(2) locks from within shell scripts or the command line.
The first and second forms wraps the lock around the executing a command, in a manner similar to su(1) or newgrp(1). It locks a specified
file or directory, which is created (assuming appropriate permissions), if it does not already exist.
The third form is convenient inside shell scripts, and is usually used the following manner:
(
flock -n 9 || exit 1
# ... commands executed under lock ...
) 9>/var/lock/mylockfile
The mode used to open the file doesn't matter to flock; using > or >> allows the lockfile to be created if it does not already exist, how-
ever, write permission is required; using < requires that the file already exists but only read permission is required.
By default, if the lock cannot be immediately acquired, flock waits until the lock is available.
OPTIONS -s, --shared
Obtain a shared lock, sometimes called a read lock.
-x, -e, --exclusive
Obtain an exclusive lock, sometimes called a write lock. This is the default.
-u, --unlock
Drop a lock. This is usually not required, since a lock is automatically dropped when the file is closed. However, it may be
required in special cases, for example if the enclosed command group may have forked a background process which should not be hold-
ing the lock.
-n, --nb, --nonblock
Fail (with an exit code of 1) rather than wait if the lock cannot be immediately acquired.
-w, --wait, --timeout seconds
Fail (with an exit code of 1) if the lock cannot be acquired within seconds seconds. Decimal fractional values are allowed.
-o, --close
Close the file descriptor on which the lock is held before executing command. This is useful if command spawns a child process
which should not be holding the lock.
-c, --command command
Pass a single command to the shell with -c.
-h, --help
Print a help message.
AUTHOR
Written by H. Peter Anvin <hpa@zytor.com>.
COPYRIGHT
Copyright (C) 2003-2006 H. Peter Anvin.
This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICU-
LAR PURPOSE.
SEE ALSO flock(2)AVAILABILITY
The flock command is part of the util-linux package and is available from ftp://ftp.kernel.org/pub/linux/utils/util-linux/.
util-linux February 2006 FLOCK(1)