Documentation
¶
Overview ¶
Package sudo provides support for various methods of running commands with elevated privileges.
Index ¶
- Variables
- func Doas(cmd string) string
- func Noop(cmd string) string
- func RegisterDefaults(provider *Registry)
- func RegisterDoas(repository *Registry)
- func RegisterSudo(repository *Registry)
- func RegisterUID0Noop(repository *Registry)
- func RegisterWindowsNoop(repository *Registry)
- func Sudo(cmd string) string
- type Factory
- type Provider
- type Registry
- type RunnerProvider
Constants ¶
This section is empty.
Variables ¶
var ( // ErrNoSudo is returned when no supported sudo method is found. ErrNoSudo = errors.New("no supported sudo method found") // DefaultRegistry is the default sudo repository. DefaultRegistry = sync.OnceValue(func() *Registry { provider := NewRegistry() RegisterDefaults(provider) return provider }) )
Functions ¶
func Doas ¶
Doas is a DecorateFunc that will wrap the given command in a doas call.
The command runs through an explicit POSIX shell for the same reasons as in Sudo.
func RegisterDefaults ¶ added in v2.2.0
func RegisterDefaults(provider *Registry)
RegisterDefaults registers the sudo methods rig ships with, which is what DefaultRegistry holds. Use it to build a registry of your own without having to list them, and without missing methods added in later versions.
The order matters here and is part of what this registers: a root host with sudo installed matches both RegisterUID0Noop and RegisterSudo, and it is registered first so such a host runs its commands unmodified.
The factories are appended, so one of your own that has to take precedence over them must be registered before this call, or with Registry.RegisterFirst.
func RegisterDoas ¶
func RegisterDoas(repository *Registry)
RegisterDoas registers a doas DecorateFunc with the given repository.
func RegisterSudo ¶
func RegisterSudo(repository *Registry)
RegisterSudo registers a sudo DecorateFunc with the given repository.
func RegisterUID0Noop ¶
func RegisterUID0Noop(repository *Registry)
RegisterUID0Noop registers a noop DecorateFunc with the given repository which can be used when the user is root.
func RegisterWindowsNoop ¶
func RegisterWindowsNoop(repository *Registry)
RegisterWindowsNoop registers a noop DecorateFunc with the given repository if the current session has effective administrator privileges. IsInRole uses CheckTokenMembership, which returns true only when the Administrators SID is present and not marked deny-only — the correct signal for an effectively elevated token. SSH sessions on Windows always provide a full elevated token for Administrators group members regardless of UAC; WinRM does too for domain accounts or when LocalAccountTokenFilterPolicy=1 is set.
func Sudo ¶
Sudo is a DecorateFunc that will wrap the given command in a sudo call.
The command runs through an explicit POSIX shell: sudo execs its argument directly, so compound expressions (pipes, redirections, boolean lists) need a shell to interpret them, and rig's commands are POSIX, which the target user's login shell is not guaranteed to be.
Types ¶
type Provider ¶
type Provider struct {
// contains filtered or unexported fields
}
Provider provides a unified interface to interact with different sudo methods. It ensures that a suitable sudo runner is lazily initialized and made available for privileged command execution.
func NewSudoProvider ¶
func NewSudoProvider(get RunnerProvider, runner cmd.Runner) *Provider
NewSudoProvider creates a new instance of Provider with the provided RunnerProvider function and runner.