Skip to content

Feature request: Ability to change user and group #44

Description

@jprider63

I'd like to change the user and group of the forked process (I'm using Linux, but I think this would still make sense for Windows). I looked into implementing this myself, but it seems like there's extensive FFI use (ie runInteractiveProcess), and it could require some potentially breaking API changes.

Do you think this is feasible?

Activity

  1. snoyberg commented on Oct 9, 2015

    @snoyberg
    Collaborator

    When I've needed this I've always used sudo. I suppose adding some logic to the C part of the code to optionally call setuid and setgid should work. I can't think of a way to make this meaningful on Windows, however.

  2. jprider63 commented on Oct 9, 2015

    @jprider63
    Author

    I'm currently using a script to change the group and user, which then calls the target executable. I avoided using sudo because I need to explicitly control argv inputs and was concerned about the shell having to parse the arguments.

    For the API, maybe we could add two fields to CreateProcess called child_user :: Maybe String and child_group :: Maybe String. I could take a shot at implementing this if it seems reasonable to you.

  3. snoyberg commented on Oct 11, 2015

    @snoyberg
    Collaborator

    Seems fine. My only question would be whether it should use a String or
    expect Int (user ID). I'm fine either way.

    Please note in the haddocks which OSs it's expected to work on.

    On Fri, Oct 9, 2015, 9:50 PM JP [email protected] wrote:

    I'm currently using a script to change the group and user, which then
    calls the target executable. I avoided using sudo because I need to
    explicitly control argv inputs and was concerned about the shell having to
    parse the arguments.

    For the API, maybe we could add two fields to CreateProcess called child_user
    :: Maybe String and child_group :: Maybe String. I could take a shot at
    implementing this if it seems reasonable to you.

    —
    Reply to this email directly or view it on GitHub
    #44 (comment).

  4. jprider63 commented on Oct 14, 2015

    @jprider63
    Author

    I just made a pull request with this implemented. I ended up going with CGid and CUid instead of String. I've only tested on unix with ghc, but I think other targets should be unaffected.

  5. snoyberg commented on Oct 15, 2015

    @snoyberg
    Collaborator

    Implemented by PR #45, thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions