Hi, I'm looking into use of rbash/set -r for sourcing and extracting values from a script (*). For my usecase, a Bash loadable plugin works for allowing `source` in such an environment for a limited subset of paths.
I'd like to detect any operation which was denied by `set -r`, but I don't want to impose `set -e` semantics as it'd be excessive and break some of the scripts I need to source (which I can't modify for this). Could any denied operation by way of set -r set some read-only variable that I can fetch after sourcing? So something like: ``` set -r source foo.sh [[ -v BASH_RESTRICTED_DENIED ]] && exit 1 ``` Or have it affect the exit status of `source` but that feels less desirable. (*) I'm aware of the many caveats and limitations of the restricted shell and that it's not a particularly robust security boundary. thanks, sam
signature.asc
Description: PGP signature
