Skip to main content

Module privilege

Module privilege 

Source
Expand description

Privilege-escalation helpers for operations that need root.

Toride runs either as root (sudo toride) or as a normal user. When a write operation targets root-owned files (/etc/ssh/sshd_config, other users’ authorized_keys), it goes through run_privileged, which runs the command directly when already root, or wraps it in sudo -n (non- interactive) otherwise.

sudo -n is used deliberately: interactive sudo would fight the TUI for the TTY password prompt. With -n, sudo fails fast when no credentials are cached, producing a clear error the UI can surface. The user runs sudo -v in another terminal first, or runs the whole app under sudo.

The privilege boundary is explicit and narrow — a caller cannot execute an arbitrary command; it must describe one of the enumerated PrivilegedOps.

Enums§

PrivilegedOp
An operation that requires elevated privileges to perform.
ValidateOutcome
The result of validating a staged sshd_config.

Functions§

is_root
Return true when the process is running as root (effective UID 0).
run_privileged
Execute a privileged operation asynchronously.