Install & Compatibility
Where this runs
tested against v7.9.0 · pip install
no network on importno background threads
Install × environment matrix
Each cell = how many times install + import succeeded across repeated harness runs. Partial = flaky.
glibc = Debian/Ubuntu slim · musl = Alpine Linux
muslpy 3.10–3.910 runs
installs and imports cleanly · install 0.0s · import 0.000s · 19.9MB
glibcpy 3.10–3.910 runs
installs and imports cleanly · install 2.4s · import 0.000s · 21MB
21MB installed
● package 21MB
Code
Verified usage
Verified import paths — ran on the pinned version, not inferred.
RootwrapClient
✓ from oslo_rootwrap.client import RootwrapClient
✗ from oslo_rootwrap.client import RootwrapClient
This quickstart demonstrates how to initialize `oslo_config` and instantiate the `RootwrapClient`. While the client can be created, actual privilege escalation via `rootwrap_client.execute()` requires a fully configured `sudo` setup, `rootwrap.conf`, and filter files on the system, which are beyond a simple runnable code snippet.
import os
from oslo_config import cfg
from oslo_rootwrap import client
# Define oslo-rootwrap specific configuration options
rootwrap_group = cfg.OptGroup(
name='rootwrap',
title='Rootwrap Options for privilege escalation'
)
cfg.CONF.register_group(rootwrap_group)
cfg.CONF.register_opts([
cfg.StrOpt('rootwrap_config',
default='/etc/rootwrap.conf',
help='Path to the rootwrap configuration file.'),
cfg.StrOpt('filters_path',
default='/etc/rootwrap.d',
help='Path to the directory containing rootwrap filter files.'),
cfg.StrOpt('daemon_pid_dir',
default='/var/run/oslo-rootwrap',
help='Directory for rootwrap daemon PID files. Used only if in daemon mode.'),
cfg.StrOpt('daemon_wrapper',
default='/usr/bin/sudo',
help='Path to the sudo wrapper binary that executes the rootwrap daemon.'),
], group=rootwrap_group)
# Initialize oslo_config. In a real application, you'd usually load from files:
# cfg.CONF(project='my_app', default_config_files=['/etc/my_app/my_app.conf'])
# For this quickstart, we use registered defaults.
print("Initializing oslo_config and setting up rootwrap options...")
cfg.CONF() # This parses any command-line arguments and loads default config values
# Instantiate the RootwrapClient
try:
# The client uses the global cfg.CONF object
rootwrap_client = client.RootwrapClient(cfg.CONF)
print("RootwrapClient instantiated successfully using oslo_config.")
# Display some configured paths
print(f"Configured rootwrap config file: {cfg.CONF.rootwrap.rootwrap_config}")
print(f"Configured rootwrap filters path: {cfg.CONF.rootwrap.filters_path}")
print(f"Configured daemon wrapper (sudo path): {rootwrap_client.get_daemon_wrapper()}")
print("\n--- Important Note for Execution ---")
print("The oslo-rootwrap library requires extensive system-level setup to function:")
print("1. A 'rootwrap.conf' file (e.g., at /etc/rootwrap.conf) defining general rules.")
print("2. Filter files (e.g., in /etc/rootwrap.d/) specifying allowed commands and parameters.")
print("3. 'sudo' configured to execute the 'oslo-rootwrap' binary with SUID permissions.")
print("\nTo execute a command, you would typically use:")
print(" stdout, stderr, returncode = rootwrap_client.execute(['command', 'arg1', 'arg2'])")
print("Attempting to run `execute` without this setup will likely result in errors.")
except Exception as e:
print(f"Error during RootwrapClient instantiation: {e}")
print("Ensure oslo_config options are correctly registered and paths are valid for your setup.")
oslo-rootwrap --version
Upgrade
Version history
7.9.0latest on PyPI · released Feb 20, 2026
Audit
Dependencies
oslo.concurrencyrequiredRequired for inter-process communication and locking primitives.
oslo.configrequiredRequired for configuration management, including parsing rootwrap.conf and filter files.
oslo.i18nrequiredRequired for internationalization support.
oslo.utilsrequiredProvides common utility functions and helper classes.
pyinotifyoptionalOptional: Used for monitoring configuration file changes for live reloading.
PyYAMLoptionalOptional: Required if using YAML-formatted filter files.