Method 2 could use inotify to wake up when the file changes. It wouldn't have to poll. Method 3 could launch from inetd so it wouldn't have to always be running if these events are infrequent.
Linux
From Wikipedia, the free encyclopedia
Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).
Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.
Rules
- Posts must be relevant to operating systems running the Linux kernel. GNU/Linux or otherwise.
- No misinformation
- No NSFW content
- No hate speech, bigotry, etc
Related Communities
Community icon by AlpΓ‘r-Etele MΓ©der, licensed under CC BY 3.0
Have you looked into the suid bit? You can set it on the file, then change the script owner to root and it runs in elevated mode: https://linuxhandbook.com/suid-sgid-sticky-bit/
If your command doesn't change (doesn't require dynamic input), sudoers file can make specific command+argument run without password required.
https://www.cyberciti.biz/faq/linux-unix-running-sudo-command-without-a-password/ (ctrl+f search "A better solution")
(You can also use wildcards in sudoers file but with nftables I imagine it's a big security risk)
- Is the usual solution, but instead of file use unix socket and user/group permissions as auth - the running user has to be part of some group so that the control client (A) can access the control socket of (B) daemon.
Alternatively you could use capabilities:
Thank you very much @taaz
So you say 2 but with unix socket
so it the same as my proposal number 3 ? no ?
I'll check capabilities
Yeah kinda, unix socket does count as ipc
You could try pkexec
insted of sudo
. Pkexec pops up the password prompt in a window insted of prompting in the terminal.
It's a good way of solving it. It's not scriptable though as it requires user-input.
indeed I need it to be scriptable.
Then implement polkit perhaps? https://polkit.pages.freedesktop.org/polkit/polkit-apps.html
Basically the root using bit is handled via polkit. Three unprivileged bit calls the privileged bit via polkit.