# Remote execution of a script trigged by Particle cloud event

**URL:** <https://community.particle.io/t/remote-execution-of-a-script-trigged-by-particle-cloud-event/42463>\
**Category:** Raspberry Pi\
**Created:** [June 17, 2018, 9:58am UTC](https://community.particle.io/t/remote-execution-of-a-script-trigged-by-particle-cloud-event/42463 "2018-06-17T09:58:01Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mgalos](https://avatars.discourse-cdn.com/v4/letter/m/9fc29f/32.png) [@mgalos](https://community.particle.io/u/mgalos)\
**Post date:** [June 17, 2018, 9:58am UTC](https://community.particle.io/t/remote-execution-of-a-script-trigged-by-particle-cloud-event/42463/1 "2018-06-17T09:58:02Z")

</div>

I am using two Raspberry Pis : one gets triggered from the particle cloud, connects to the second over ssh and executes a bash script on it. I got it running using the following code:

First Pi, firmware:

```
#include <fcntl.h>
#include <unistd.h>
#include <stdio.h>

#include "Particle.h"

void doCall(String arguments){
    Particle.publish(arguments);
  Process proc = Process::run(arguments);
    proc.wait();
    while (!proc.exited()) {
        delay(1000);   
    }

    Particle.publish(String("exit_code ")+String(proc.exitCode()));
    delay(1000);   
}

void stdoutEventHandler(const char *event, const char *data){
    //Particle.publish("pi received a tv event");
    String arguments {data}; 
    
    String command {"/home/userone/scripts/remote_tv_command.sh "};
    String command_and_arguments{command +arguments};
    //Particle.publish(command_and_arguments);
    doCall(command_and_arguments);
}

void setup() {
    Particle.subscribe("homeTvEvent", stdoutEventHandler);
    Particle.publish("Alive!");
}

void loop() {
}

```

First Pi, trigger script /home/userone/scripts/remote\_tv\_command.sh:

```
#!/bin/bash

command="sshpass -p 'UserTwoPassword' ssh -oStrictHostKeyChecking=no usertwo@192.168.0.101 'cd ~/scripts/flirc && ./tv_command.sh $1'"
eval $command

```

Second pi, tv\_command.sh:

```
#!/bin/bash

echo $1 # to be used later
sudo ./flirc_util send_ir_raw 0,9170,4365,617,472,618,472,617,1600,617,473,617,472,617,473,617,472,617,473,617,1600,613,1604,613,477,613,1604,613,1601,617,1600,618,1600,617,1606,637,447,617,472,617,473,643,1574,617,472,617,473,617,489,601,472,617,1600,629,1588,618,1600,617,472,617,1601,617,1600,617,1600,587,1630,613

```

I would like to have a solution where I don’t type the password for usertwo in cleartext. I have therefore generated a ssh fingerprint as described [here](https://stackoverflow.com/a/9607373/2394327). SSH-ing manually from the first to the second pi requires no password, but when I call it from the firmware, it doesn’t get through. Can anyone please help with the matter?

Many thanks in advance.

---

<div class="post-metadata">

**Author:** ![nrobinson2000](https://sea2.discourse-cdn.com/flex026/user_avatar/community.particle.io/nrobinson2000/32/15624_2.png) [@nrobinson2000](https://community.particle.io/u/nrobinson2000)\
**Post date:** [June 18, 2018, 12:43am UTC](https://community.particle.io/t/remote-execution-of-a-script-trigged-by-particle-cloud-event/42463/2 "2018-06-18T00:43:02Z")

</div>

I think when the Pi calls the script through the firmware it does it as root. You should check if the ssh fingerprint works with root/sudo.

---

<div class="post-metadata">

**Author:** ![mgalos](https://avatars.discourse-cdn.com/v4/letter/m/9fc29f/32.png) [@mgalos](https://community.particle.io/u/mgalos)\
**Post date:** [June 19, 2018, 3:25pm UTC](https://community.particle.io/t/remote-execution-of-a-script-trigged-by-particle-cloud-event/42463/3 "2018-06-19T15:25:05Z")

</div>

can a maintainer please try to reproduce? I see no reason why a normal ssh fingerprint should not work. If what @nrobinson2000 says is true, and the firmware runs a Process::run as root, it should at least have an overload specifying the user one would like to run as.

---

<div class="post-metadata">

**Author:** ![nrobinson2000](https://sea2.discourse-cdn.com/flex026/user_avatar/community.particle.io/nrobinson2000/32/15624_2.png) [@nrobinson2000](https://community.particle.io/u/nrobinson2000)\
**Post date:** [June 19, 2018, 3:30pm UTC](https://community.particle.io/t/remote-execution-of-a-script-trigged-by-particle-cloud-event/42463/4 "2018-06-19T15:30:41Z")

</div>

This thread might help you:

> [@Remote script execution on Pi](https://community.particle.io/t/remote-script-execution-on-pi/27692/9):
>
> As @nrobinson2000 mentioned, the GPIO access is done by direct memory writes to the GPIO registers which can only be done by root. The Process::run can run commands as other users by doing Process::run("sudo -u pi my\_command"); This would prevent accidentally running commands that affect the system. This can be added to the docs, or this behavior could be the default, unless someone does Process::run\_sudo() maybe. What do you think?

---

<div class="post-metadata">

**Author:** ![mgalos](https://avatars.discourse-cdn.com/v4/letter/m/9fc29f/32.png) [@mgalos](https://community.particle.io/u/mgalos)\
**Post date:** [June 19, 2018, 7:28pm UTC](https://community.particle.io/t/remote-execution-of-a-script-trigged-by-particle-cloud-event/42463/5 "2018-06-19T19:28:48Z")

</div>

Ashamed I didn’t think about it earlier. Thank you loads, @nrobinson2000! It works now.

---

<div class="post-metadata">

**Author:** ![Joe](https://sea2.discourse-cdn.com/flex026/user_avatar/community.particle.io/joe/32/16963_2.png) [@Joe](https://community.particle.io/u/Joe)\
**Post date:** [December 11, 2019, 9:11pm UTC](https://community.particle.io/t/remote-execution-of-a-script-trigged-by-particle-cloud-event/42463/6 "2019-12-11T21:11:08Z")

</div>


