Hi,

I'm looking into use of rbash/set -r for sourcing and extracting values
from a script (*). For my usecase, a Bash loadable plugin works for
allowing `source` in such an environment for a limited subset of paths.

I'd like to detect any operation which was denied by `set -r`, but I
don't want to impose `set -e` semantics as it'd be excessive and break
some of the scripts I need to source (which I can't modify for this).

Could any denied operation by way of set -r set some read-only variable
that I can fetch after sourcing?

So something like:
```
set -r
source foo.sh
[[ -v BASH_RESTRICTED_DENIED ]] && exit 1
```

Or have it affect the exit status of `source` but that feels less
desirable.

(*) I'm aware of the many caveats and limitations of the restricted
shell and that it's not a particularly robust security boundary.

thanks,
sam

Attachment: signature.asc
Description: PGP signature

Reply via email to