Sudo access of rm to non-root user


Login to Reply

Thread Tools Search this Thread
# 8  
Old 08-24-2017
Originally Posted by solaris_1977
It is Solaris-10. There is a file as /opt/vpp/dom1.2/pdd/today_23. It is always generated by root, so owned by root only.
This file has to be deleted as part of application restart always and that is done by app_user and SA is always involved to do rm on that file.
Is it possible to give rm access to app_user, only to that file, via sudoers ? So that, he can delete only that file, not any other path or file or folder.

I'm willing to bet that when you come back with why the file is written by root it is because the directory /opt/vpp/dom1.2/pdd is owned by root.

Consider this:
dewi(6)$ file xyzzy
xyzzy: cannot open `xyzzy' (No such file or directory)
dewi(7)$ sudo touch xyzzy
[sudo] password for apm: 
dewi(8)$ ls -l xyzzy
-rw-r--r-- 1 root root 0 24 Aug 11:29 xyzzy
dewi(9)$ rm xyzzy
rm: remove write-protected regular empty file 'xyzzy'? y
dewi(10)$ ls -l xyzzy
ls: cannot access 'xyzzy': No such file or directory
dewi(11)$ sudo mkdir XYZZY
dewi(12)$ ls -ld XYZZY/                                                        
drwxr-xr-x 2 root root 4096 24 Aug 11:31 XYZZY/
dewi(13)$ cd XYZZY/                                                            
dewi(14)$ sudo touch xyzzy
dewi(15)$ ls -la
total 8
drwxr-xr-x  2 root root 4096 24 Aug 11:32 .
drwxr-xr-x 19 apm  sog  4096 24 Aug 11:31 ..
-rw-r--r--  1 root root    0 24 Aug 11:32 xyzzy
dewi(16)$ rm -f xyzzy 
rm: cannot remove 'xyzzy': Permission denied

So because I own the parent directory I was able to deleted the first xyzzy file, but because root owned the directory XYZZY I was unable to delete the second xyzzy file.

So why does the file today_23 need to be created in the directory /opt/vpp/dom1.2/pdd? Can it be created elsewhere? Failing that, could the directory pdd be modified to give the user the required write permission to create and delete the file without root access?

# 9  
Old 08-24-2017
Originally Posted by solaris_1977
But, is it possible at all, to give sudo access to app_user to remove that root owned file ? I just want to have my statement correct, before jumping into discussion with them.
In fact it is possible to set such a sudo-rule. Put the follwoing in /etc/sudoers:

username ALL=(ALL:ALL) NOPASSWD: /path/to/rm /path/to/file

PLEASE NOTICE, though, this does not invalidate what my colleagues have already said about problems, symptoms and patching over them. I just want to tell you that - if every other way of correcting the underlying problem fails - there is a last-ditch solution you could employ. You still should try your utmost to avoid needing that. See also here, which is basically the same principle at work.

I hope this helps.

These 2 Users Gave Thanks to bakunin For This Post:
rbatte1 (08-25-2017), solaris_1977 (08-24-2017)
# 10  
Old 08-24-2017
Thanks much.
But as you and other suggested, I will try to fix ownership issue with app team, then we may not need to tweek sudoers
Login to Reply

Thread Tools Search this Thread
Search this Thread:
Advanced Search

Similar Threads More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Non root user access to /dev/mem Soumyadip Dutta UNIX for Advanced & Expert Users 13 08-09-2018 08:01 AM
How to provide root access via sudo with restrictions? anuragr UNIX for Advanced & Expert Users 5 03-11-2018 08:43 AM
One user to su to another without allowing root access and password pokhraj_d UNIX for Advanced & Expert Users 6 04-18-2017 04:08 PM
Sudo to user other than root but do not allow sudo to root westmoreland Red Hat 1 02-03-2015 01:40 PM
Create user with sudo ability to root. Rockyc3400 UNIX for Dummies Questions & Answers 3 09-23-2013 12:30 PM
How to give root access to non root user? adisky123 Shell Programming and Scripting 4 04-30-2013 05:09 PM
how to remove sudo access from a user ? wingcross AIX 2 10-07-2012 05:22 AM
Sudo to delegate permission from non-root user to another non-root user canar UNIX for Dummies Questions & Answers 1 04-06-2012 06:59 PM
sudo/root access daWonderer UNIX for Dummies Questions & Answers 0 02-10-2012 06:47 AM
Cron job initiating ssh AND sudo (from user, not root) eh3civic Shell Programming and Scripting 5 04-08-2011 08:18 AM
sudo user access daveisme AIX 2 07-15-2010 04:39 PM
How to allow access to some commands having root privleges to be run bu non root user suryashikha UNIX for Dummies Questions & Answers 5 10-30-2009 06:46 AM
access user history as root sardare Shell Programming and Scripting 4 07-01-2009 01:09 PM
I can not access root user through LAN rizwan225 Solaris 6 03-18-2009 07:03 PM
user commands without root access emealogistics HP-UX 1 05-27-2007 12:04 AM
All times are GMT -4. The time now is 08:50 PM.

Unix & Linux Forums Content Copyright 1993-2018. All Rights Reserved.
Show Password

Not a Forum Member?
Forgot Password?