@maroallegro commented on Mon Jan 29 2018
I am trying to check if .NetCore code is running as sudo/admin on Linux. It works on Windows but throws exception on Linux.
How do I check if app is run by admin/sudo on Ubuntu Linux by using .NET Core2.0 build-in class?
Here is the code I have tried (however i thought that it will not manage admin rights on Linux):
using System;
using System.Security.Principal;
namespace smallTestsCore
{
class Program
{
static void Main(string[] args)
{
Console.WriteLine(Program.IsAdministrator);
Console.ReadLine();
}
public static bool IsAdministrator =>
new WindowsPrincipal(WindowsIdentity.GetCurrent())
.IsInRole(WindowsBuiltInRole.Administrator);
}
}
The code works on Windows, but does not work on Linux:
Exception has occurred: CLR/System.PlatformNotSupportedException
An unhandled exception of type 'System.PlatformNotSupportedException' occurred in
System.Security.Principal.Windows.dll: 'Windows Principal functionality is not supported on this platform.'
at System.Security.Principal.WindowsIdentity.GetCurrent()
at adminTst.Program.get_IsAdministrator() in /home/user/adminTst/Program.cs:line 15
at adminTst.Program.Main(String[] args) in /home/user/adminTst/Program.cs:line 11
@maroallegro I do not think there is an API. This is how we do it for tests:
https://github.com/dotnet/corefx/blob/master/src/CoreFx.Private.TestUtilities/src/System/AdminHelpers.Unix.cs
You could propose an API, perhaps? This is the process: https://github.com/dotnet/corefx/blob/master/Documentation/project-docs/api-review-process.md
You will want to decide whether there should be a generic API, or Unix specific, ie., are sudo and the Windows concept of elevated sufficiently common concepts.
one way would be to check effective rights. (SystemNative_GetEUid) However things may be more complicate with POSIX capabilities. With work for dotnet/corefx#26431 we may have enough plumbing to process groups as well.
@eerhardt @wfurt are the concepts of Unix sudo and Windows elevation sufficiently analogous that we could have some single boolean property for both? My guess is not because after this boolean concepts quickly diverge.
Also is there a reasonable type where such API could go? RuntimeInformation is more about static information about the platform. Environment is a grab bag.
To check if you are running as root on Unix:
IsAdminstrator to the following:C#
public static bool IsAdministrator =>
RuntimeInformation.IsOSPlatform(OSPlatform.Windows) ?
new WindowsPrincipal(WindowsIdentity.GetCurrent())
.IsInRole(WindowsBuiltInRole.Administrator) :
Mono.Unix.Native.Syscall.geteuid() == 0;
I believe @eerhardt's suggestion addressed the original request.
If you'd like to file an API suggestion, please follow the process using appropriate template.
Most helpful comment
To check if you are running as
rooton Unix:IsAdminstratorto the following:C# public static bool IsAdministrator => RuntimeInformation.IsOSPlatform(OSPlatform.Windows) ? new WindowsPrincipal(WindowsIdentity.GetCurrent()) .IsInRole(WindowsBuiltInRole.Administrator) : Mono.Unix.Native.Syscall.geteuid() == 0;