SYSTEM command shell
Posted in 2000
Topics: Stored Procedures & SPL
I'm running Informix on a Sun/Solaris UNIX machine. The documentation says the SPL "SYSTEM" command runs with the same permissions as the user who invokes the command. But I'm finding that I can do things from the command line that the SYSTEM command won't do. In particular, I seem to lose membership in all the unix groups except my initial login group, so the stored procedure SYSTEM command can't write to certain directories that I can write to from the command line. And I haven't been able to get it to change groups (using newgrp, for example). Does anyone know what shell the SYSTEM command invokes? I'd also appreciate any information about restrictions the SYSTEM command imposes, if there are any. Thanks for the advice, -- Bob Koerner -- Bradford & Galt Consulting Services -- St. Louis, Missouri -- -- BobKoerner@aol.com
BobKoerner wrote: > I'm running Informix on a Sun/Solaris UNIX machine. The documentation says the > SPL "SYSTEM" command runs with the same permissions as the user who invokes the > command. But I'm finding that I can do things from the command line that the > SYSTEM command won't do. In particular, I seem to lose membership in all the > unix groups except my initial login group, so the stored procedure SYSTEM > command can't write to certain directories that I can write to from the command > line. And I haven't been able to get it to change groups (using newgrp, for > example). > > Does anyone know what shell the SYSTEM command invokes? I'd also appreciate > any information about restrictions the SYSTEM command imposes, if there are > any. Hmm; interesting questions. Don't forget that the SYSTEM command is run inside the server. That is a wholly separate process from your program that kicks it off. The key information (at least username, probably primary group) are relayed from your application to the server during the connection process. I assume that the auxilliary group information is not relayed, not least because I don't think there's an API which allows even root to set supplementary groups...but there has to be, the system does it at login...but it won't be standardized, probably. I don't recall seeing an API to set supplementary groups, but there must be one, and it's an odds on bet that Informix does not employ it. So, your shell (which ever it is, and it might come from your SHELL environment variable, or it might come from the environment when the server was started, or it might just be /bin/sh) will only have the most basic permissions set. Using newgrp is a no-no, because the shell execs newgrp and it loses its context when you run it. It really only works in an interactive environment. I have a variant called newgid which is a cross between newgrp and su; it changes group like newgrp does, but it has extra options to run commands like su, and it is not exec'd by the shell. However, I don't actually use it very often because the supplementary groups normally do the trick for me. -- Jonathan Leffler (jleffler@informix.com, jleffler@earthlink.net) Guardian of DBD::Informix v0.95 -- see http://www.perl.com/CPAN #include <disclaimer.h>