Re: Root running Informix utilities via su -c
Posted in 2003
Topics: Installation, Setup & Upgrades, Server Administration, Platform-Specific Issues, Versions, Editions & End-of-Life
Red Valsen wrote:
> This dead horse has had the flesh flayed from its bones years ago, but
> I discovered a new twist -- which purportedly didn't work.
>
> I attempted to run an alter statement during a postinstall script in a
> Solaris pkgadd package thus:
>
> su informix -c "alter table bla add (col1 char)"|dbaccess
> databasename
Hmmmm...taken literally, that sets the real and effective UID to
informix and runs a shell that runs a command called alter with
arguments 'table', 'bla', 'add', and probably syntax errors on the
open parentheses - or does something with a subshell and a program
called col1 given an argument char. The non-erroneous output from
that is sent to dbaccess databasename (presumably, email/news put a
linebreak in the wrong place).
Note that DB-Access is signally not run SUID anything. If you want
DB-Access run like that too, the whole process needs to be done rather
differently:
echo 'alter table bla add (col1 char(1) not null)' |
su informix -c "dbaccess databasename -"
This runs the echo command as root (it'll probably work), and the
dbaccess command as informix, rather than vice versa. [You also
forgot the NOT NULL constraint, and the size of a CHAR field is
CHAR(1); I prefer to be explicit :-) Of course, NOT NULL doesn't work
if the table already has data in it, unless you also specify a default
clause - but that is then concentrating too much on the SQL and not
enough on the Unix!]
I don't like that much either; I'd write:
su informix -c "sqlcmd -d databasename -e 'alter table bla add(col1
char(1) not null)'"
(Actually - the echo | su formulation is version 2; it isn't as bad as
version 1 which had both the echo and the dbaccess running as
informix. That was messier - and more worthy of "I don't like that
much".)
> On one database -- which some dork had granted privileges to root --
> the statement ran just fine; the other, configured correctly for
> production, received "No connect permission" error. Fine and well --
Yes - the error was probably correct.
> CDI posts from 4/2001 indicate this should happen.
Found them. TinyURL saves 325 characters:
http://tinyurl.com/rp7d
> However, I
> implemented the workaround from those posts which should have failed,
> but didn't: I modified the postinstall script to cat out the alter
> statement to a file; chowned the file to 'informix' and chmoded it
> SETUID, too; then had root execute the file as informix:
>
> su informix -c commandfile
>
> WTF? It worked this time.
Of course - as I explained earlier, it is the DB-Access command that
must be run as user informix. By putting everything - echo/cat and
dbaccess into the commandfile, everything in there is run by informix,
so it works as you wanted.
Please remove the SETUID permissions from the script - SETUID scripts
are even more fraught with danger than SUID programs. Not to mention
that it had no effect on the process anyway.
> So: Executing from the command line won't
> work, but from a SETUID script file it does. Can somebody (Jonathen?)
Err, is that me, Rad? :-)
> explain this weird phenomenon? -- in one case dbaccess is getting the
> real userid of 'root', in the other case 'informix', all by chmod'ing
> 4xxx?
In the first case, you didn't run DB-Access with the su command.
In the second case, you did.
In the first case, the real UID of DB-Access was root because you had
not changed it with su informix.
In the second case, the real UID of DB-Access was informix because the
whole command was run by 'su informix'.
> Running IDS 7.31.UC-4 on Solaris 2.7/Intel (don't ask).
Thanks for the platform information - not incredibly important this
time, but always a good idea to include it.
--
Jonathan Leffler #include <disclaimer.h>
Email: jleffler@earthlink.net, jleffler@us.ibm.com
Guardian of DBD::Informix v2003.04 -- http://dbi.perl.org/
Mercy bocoo to the two luminaries of CDI for their replies -- I learned something.
This definitely works without resorting to cat'ing out the script:
echo 'alter table bla add (col1 char(1) not null)' |
su informix -c "dbaccess databasename -"
Always a better way -- and someone who can explain . . .
Jonathan Leffler <jleffler@earthlink.net> wrote in message news:<3F94C5E3.9020308@earthlink.net>...
>
> In the first case, you didn't run DB-Access with the su command.
> In the second case, you did.
> In the first case, the real UID of DB-Access was root because you had
> not changed it with su informix.
> In the second case, the real UID of DB-Access was informix because the
> whole command was run by 'su informix'.