Luk*_*as1 6 macos shell cocoa objective-c
我正在尝试以launchctlroot身份从OSX应用程序启动samba服务,但我收到错误状态-60031.我可以在终端中运行没有问题的命令:
sudo launchctl load -F /System/Library/LaunchDaemons/com.apple.smbd.plist
Run Code Online (Sandbox Code Playgroud)
在objective-c代码中,我正在使用(我知道它已被弃用,但这不应该是这里的问题)AuthorizationExecuteWithPrivileges方法.
这是代码:
NSString *command = @"launchctl";
// Conversion of NSArray args to char** args here (not relevant part of the code)
OSStatus authStatus = AuthorizationCreate(NULL, kAuthorizationEmptyEnvironment, kAuthorizationFlagDefaults, &_authRef);
if (authStatus != errAuthorizationSuccess) {
NSLog(@"Failed to create application authorization: %d", (int)authStatus);
return;
}
FILE* pipe = NULL;
AuthorizationFlags flags = kAuthorizationFlagDefaults;
AuthorizationItem right = {kAuthorizationRightExecute, 0, NULL, 0};
AuthorizationRights rights = {1, &right};
// Call AuthorizationCopyRights to determine or extend the allowable rights.
OSStatus stat = AuthorizationCopyRights(_authRef, &rights, NULL, flags, NULL);
if (stat != errAuthorizationSuccess) {
NSLog(@"Copy Rights Unsuccessful: %d", (int)stat);
return;
}
OSStatus status = AuthorizationExecuteWithPrivileges(_authRef,
command.UTF8String,
flags,
args,
&pipe);
if (status != errAuthorizationSuccess) {
NSLog(@"Error executing command %@ with status %d", command, status);
} else {
// some other stuff
}
Run Code Online (Sandbox Code Playgroud)
我也尝试使用不同的标志然后kAuthorizationFlagDefaults,但这导致相同的问题或错误代码-60011- >无效标志.
我在这做错了什么,拜托?
我建议使用 STPrivilegedTask - https://github.com/sveinbjornt/STPrivilegedTask
我有类似的问题,我发现上面写得很好的包装。它非常直接且非常简单。如果需要的话,你可以根据你的需要修改它,否则就用它吧!
它对我有用,我希望它也对你有帮助。
谢谢。
更新(2014 年 8 月 28 日):使用root 权限执行命令和以root 身份执行命令 是有区别的!
在您的特定情况下,您尝试加载/卸载守护进程(必须属于根目录)。在这种情况下,您必须以 root 身份执行命令。如果您尝试仅使用 root 权限加载/卸载,那么您将在您的用户下运行守护进程!- 不好!
现在,您的代码示例和我对 STPrivilegedTask 的引用都使用相同的代码,并允许用户以 root 权限但不能以 root 身份执行任务!为了以 root 身份执行,您有多种选择。首先,您可能想查看 Apple Docs 以获取推荐的方法。就我而言,我无法采用推荐的方式,因为我的应用程序未签名并且不会签名+它需要在旧的 OSX 上工作。
所以我的解决方案很简单。创建一个命令实用程序辅助工具,让它假设为 root 并执行您通过参数传递给它的任何内容。现在请记下(这不是非常安全的做事方式)。另请注意,您将使用 root 权限调用辅助工具,并且它将采用 root 身份。
代码:
int main(int argc, const char * argv[])
{
@autoreleasepool {
if (argc >= 2)
{
setuid(0); // Here is a key - set user id to 0 - meaning become a root and everything below executes as root.
NSMutableArray *arguments = [[NSMutableArray alloc] init];
NSString *command = [[NSString alloc] initWithFormat:@"%s", argv[1]];
for (int idx = 2; idx < argc; idx++) {
NSString *tmp = [[NSString alloc] initWithFormat:@"%s", argv[idx]];
[arguments addObject:tmp];
}
NSTask *task = [[NSTask alloc] init];
[task setLaunchPath:command];
[task setArguments:arguments];
NSPipe * out = [NSPipe pipe];
[task setStandardOutput:out];
[task launch];
[task waitUntilExit];
NSFileHandle * read = [out fileHandleForReading];
NSData * dataRead = [read readDataToEndOfFile];
NSString * stringRead = [[NSString alloc] initWithData:dataRead encoding:NSUTF8StringEncoding];
printf("%s", [stringRead UTF8String]);
}
return 0;
}
}
Run Code Online (Sandbox Code Playgroud)
| 归档时间: |
|
| 查看次数: |
1381 次 |
| 最近记录: |