2002-06-23 09:54:25 +05:30
|
|
|
/* vi: set sw=4 ts=4: */
|
2006-07-12 13:26:04 +05:30
|
|
|
/*
|
2006-09-08 22:52:05 +05:30
|
|
|
* Mini sulogin implementation for busybox
|
|
|
|
*
|
2010-08-16 23:44:46 +05:30
|
|
|
* Licensed under GPLv2 or later, see file LICENSE in this source tree.
|
2006-07-12 13:26:04 +05:30
|
|
|
*/
|
2015-10-19 04:50:36 +05:30
|
|
|
//config:config SULOGIN
|
2017-07-19 01:31:24 +05:30
|
|
|
//config: bool "sulogin (17 kb)"
|
2015-10-19 04:50:36 +05:30
|
|
|
//config: default y
|
|
|
|
//config: select FEATURE_SYSLOG
|
|
|
|
//config: help
|
2017-07-21 13:20:55 +05:30
|
|
|
//config: sulogin is invoked when the system goes into single user
|
|
|
|
//config: mode (this is done through an entry in inittab).
|
2015-10-19 04:50:36 +05:30
|
|
|
|
2017-08-04 23:25:01 +05:30
|
|
|
//applet:IF_SULOGIN(APPLET_NOEXEC(sulogin, sulogin, BB_DIR_SBIN, BB_SUID_DROP, sulogin))
|
2015-10-19 04:50:36 +05:30
|
|
|
|
|
|
|
//kbuild:lib-$(CONFIG_SULOGIN) += sulogin.o
|
2006-07-12 13:26:04 +05:30
|
|
|
|
2011-04-02 02:26:30 +05:30
|
|
|
//usage:#define sulogin_trivial_usage
|
|
|
|
//usage: "[-t N] [TTY]"
|
|
|
|
//usage:#define sulogin_full_usage "\n\n"
|
|
|
|
//usage: "Single user login\n"
|
|
|
|
//usage: "\n -t N Timeout"
|
|
|
|
|
2007-05-27 00:30:18 +05:30
|
|
|
#include "libbb.h"
|
2008-01-27 18:20:12 +05:30
|
|
|
#include <syslog.h>
|
2002-06-23 09:54:25 +05:30
|
|
|
|
2007-10-11 15:35:36 +05:30
|
|
|
int sulogin_main(int argc, char **argv) MAIN_EXTERNALLY_VISIBLE;
|
2008-07-05 14:48:54 +05:30
|
|
|
int sulogin_main(int argc UNUSED_PARAM, char **argv)
|
2002-06-23 09:54:25 +05:30
|
|
|
{
|
|
|
|
int timeout = 0;
|
2006-09-08 22:52:05 +05:30
|
|
|
struct passwd *pwd;
|
2006-10-14 17:17:02 +05:30
|
|
|
const char *shell;
|
2006-01-25 05:38:53 +05:30
|
|
|
|
2016-03-30 20:57:32 +05:30
|
|
|
/* Note: sulogin is not a suid app. It is meant to be run by init
|
|
|
|
* for single user / emergency mode. init starts it as root.
|
2017-08-04 23:25:01 +05:30
|
|
|
* Normal users (potentially malicious ones) can only run it under
|
2016-03-30 20:57:32 +05:30
|
|
|
* their UID, therefore no paranoia here is warranted:
|
|
|
|
* $LD_LIBRARY_PATH in env, TTY = /dev/sda
|
|
|
|
* are no more dangerous here than in e.g. cp applet.
|
|
|
|
*/
|
|
|
|
|
2006-09-09 19:30:58 +05:30
|
|
|
logmode = LOGMODE_BOTH;
|
2006-10-04 02:30:43 +05:30
|
|
|
openlog(applet_name, 0, LOG_AUTH);
|
2006-01-25 05:38:53 +05:30
|
|
|
|
2016-07-07 01:28:02 +05:30
|
|
|
getopt32(argv, "t:+", &timeout);
|
2008-11-09 05:45:11 +05:30
|
|
|
argv += optind;
|
2006-09-08 22:52:05 +05:30
|
|
|
|
2008-11-09 05:45:11 +05:30
|
|
|
if (argv[0]) {
|
2006-09-08 22:52:05 +05:30
|
|
|
close(0);
|
|
|
|
close(1);
|
2008-11-09 05:45:11 +05:30
|
|
|
dup(xopen(argv[0], O_RDWR));
|
2006-09-11 06:04:01 +05:30
|
|
|
close(2);
|
2006-09-08 22:52:05 +05:30
|
|
|
dup(0);
|
2002-06-23 09:54:25 +05:30
|
|
|
}
|
2006-09-08 22:52:05 +05:30
|
|
|
|
2006-10-14 17:17:02 +05:30
|
|
|
pwd = getpwuid(0);
|
|
|
|
if (!pwd) {
|
2016-03-30 20:57:32 +05:30
|
|
|
bb_error_msg_and_die("no password entry for root");
|
2006-09-17 21:58:10 +05:30
|
|
|
}
|
2006-09-08 22:52:05 +05:30
|
|
|
|
2002-06-23 09:54:25 +05:30
|
|
|
while (1) {
|
2008-06-12 22:26:52 +05:30
|
|
|
int r;
|
|
|
|
|
2013-11-19 17:39:06 +05:30
|
|
|
r = ask_and_check_password_extended(pwd, timeout,
|
|
|
|
"Give root password for system maintenance\n"
|
|
|
|
"(or type Control-D for normal startup):"
|
|
|
|
);
|
|
|
|
if (r < 0) {
|
2013-05-21 20:31:55 +05:30
|
|
|
/* ^D, ^C, timeout, or read error */
|
2016-03-30 21:06:20 +05:30
|
|
|
bb_error_msg("normal startup");
|
2006-09-09 19:30:58 +05:30
|
|
|
return 0;
|
2002-06-23 09:54:25 +05:30
|
|
|
}
|
2013-11-19 17:39:06 +05:30
|
|
|
if (r > 0) {
|
2002-06-23 09:54:25 +05:30
|
|
|
break;
|
|
|
|
}
|
2011-03-09 01:37:05 +05:30
|
|
|
bb_do_delay(LOGIN_FAIL_DELAY);
|
2016-03-30 21:06:20 +05:30
|
|
|
bb_error_msg("Login incorrect");
|
2002-06-23 09:54:25 +05:30
|
|
|
}
|
2005-05-03 11:55:50 +05:30
|
|
|
|
2016-03-30 21:06:20 +05:30
|
|
|
bb_error_msg("starting shell for system maintenance");
|
2005-05-03 11:55:50 +05:30
|
|
|
|
2009-04-21 16:39:40 +05:30
|
|
|
IF_SELINUX(renew_current_security_context());
|
2005-05-03 11:55:50 +05:30
|
|
|
|
2006-10-14 17:17:02 +05:30
|
|
|
shell = getenv("SUSHELL");
|
2007-09-10 18:45:28 +05:30
|
|
|
if (!shell)
|
|
|
|
shell = getenv("sushell");
|
2010-06-27 06:53:31 +05:30
|
|
|
if (!shell)
|
|
|
|
shell = pwd->pw_shell;
|
|
|
|
|
2007-09-10 18:45:28 +05:30
|
|
|
/* Exec login shell with no additional parameters. Never returns. */
|
2016-11-04 02:43:08 +05:30
|
|
|
run_shell(shell, 1, NULL);
|
2002-06-23 09:54:25 +05:30
|
|
|
}
|