2002-06-23 09:54:25 +05:30
|
|
|
/* vi: set sw=4 ts=4: */
|
2006-07-12 13:26:04 +05:30
|
|
|
/*
|
2006-09-08 22:52:05 +05:30
|
|
|
* Mini sulogin implementation for busybox
|
|
|
|
*
|
2006-07-12 13:26:04 +05:30
|
|
|
* Licensed under GPLv2 or later, see file LICENSE in this tarball for details.
|
|
|
|
*/
|
|
|
|
|
2007-05-27 00:30:18 +05:30
|
|
|
#include "libbb.h"
|
2008-01-27 18:20:12 +05:30
|
|
|
#include <syslog.h>
|
2002-06-23 09:54:25 +05:30
|
|
|
|
2008-07-05 14:48:54 +05:30
|
|
|
//static void catchalarm(int UNUSED_PARAM junk)
|
2007-10-21 00:50:22 +05:30
|
|
|
//{
|
|
|
|
// exit(EXIT_FAILURE);
|
|
|
|
//}
|
2002-06-23 09:54:25 +05:30
|
|
|
|
|
|
|
|
2007-10-11 15:35:36 +05:30
|
|
|
int sulogin_main(int argc, char **argv) MAIN_EXTERNALLY_VISIBLE;
|
2008-07-05 14:48:54 +05:30
|
|
|
int sulogin_main(int argc UNUSED_PARAM, char **argv)
|
2002-06-23 09:54:25 +05:30
|
|
|
{
|
|
|
|
char *cp;
|
|
|
|
int timeout = 0;
|
2006-09-08 22:52:05 +05:30
|
|
|
struct passwd *pwd;
|
2006-10-14 17:17:02 +05:30
|
|
|
const char *shell;
|
2007-03-13 18:31:14 +05:30
|
|
|
#if ENABLE_FEATURE_SHADOWPASSWDS
|
|
|
|
/* Using _r function to avoid pulling in static buffers */
|
|
|
|
char buffer[256];
|
|
|
|
struct spwd spw;
|
|
|
|
#endif
|
2006-01-25 05:38:53 +05:30
|
|
|
|
2006-09-09 19:30:58 +05:30
|
|
|
logmode = LOGMODE_BOTH;
|
2006-10-04 02:30:43 +05:30
|
|
|
openlog(applet_name, 0, LOG_AUTH);
|
2006-01-25 05:38:53 +05:30
|
|
|
|
2008-03-17 14:39:09 +05:30
|
|
|
opt_complementary = "t+"; /* -t N */
|
|
|
|
getopt32(argv, "t:", &timeout);
|
2006-09-08 22:52:05 +05:30
|
|
|
|
|
|
|
if (argv[optind]) {
|
|
|
|
close(0);
|
|
|
|
close(1);
|
|
|
|
dup(xopen(argv[optind], O_RDWR));
|
2006-09-11 06:04:01 +05:30
|
|
|
close(2);
|
2006-09-08 22:52:05 +05:30
|
|
|
dup(0);
|
2002-06-23 09:54:25 +05:30
|
|
|
}
|
2006-09-08 22:52:05 +05:30
|
|
|
|
2008-03-17 14:39:09 +05:30
|
|
|
/* Malicious use like "sulogin /dev/sda"? */
|
2006-09-08 22:52:05 +05:30
|
|
|
if (!isatty(0) || !isatty(1) || !isatty(2)) {
|
2006-09-09 19:30:58 +05:30
|
|
|
logmode = LOGMODE_SYSLOG;
|
|
|
|
bb_error_msg_and_die("not a tty");
|
2006-09-07 21:50:03 +05:30
|
|
|
}
|
2002-06-23 09:54:25 +05:30
|
|
|
|
2007-11-06 10:56:51 +05:30
|
|
|
/* Clear dangerous stuff, set PATH */
|
2008-02-18 16:38:33 +05:30
|
|
|
sanitize_env_if_suid();
|
2002-06-23 09:54:25 +05:30
|
|
|
|
2007-10-21 00:50:22 +05:30
|
|
|
// bb_askpass() already handles this
|
|
|
|
// signal(SIGALRM, catchalarm);
|
2006-09-08 22:52:05 +05:30
|
|
|
|
2006-10-14 17:17:02 +05:30
|
|
|
pwd = getpwuid(0);
|
|
|
|
if (!pwd) {
|
2006-09-09 19:30:58 +05:30
|
|
|
goto auth_error;
|
2006-09-17 21:58:10 +05:30
|
|
|
}
|
2006-09-08 22:52:05 +05:30
|
|
|
|
2006-12-30 20:16:51 +05:30
|
|
|
#if ENABLE_FEATURE_SHADOWPASSWDS
|
2007-10-30 00:55:45 +05:30
|
|
|
{
|
|
|
|
/* getspnam_r may return 0 yet set result to NULL.
|
|
|
|
* At least glibc 2.4 does this. Be extra paranoid here. */
|
|
|
|
struct spwd *result = NULL;
|
|
|
|
int r = getspnam_r(pwd->pw_name, &spw, buffer, sizeof(buffer), &result);
|
|
|
|
if (r || !result) {
|
|
|
|
goto auth_error;
|
|
|
|
}
|
|
|
|
pwd->pw_passwd = result->sp_pwdp;
|
2002-06-23 09:54:25 +05:30
|
|
|
}
|
2006-12-30 20:16:51 +05:30
|
|
|
#endif
|
2006-09-08 22:52:05 +05:30
|
|
|
|
2002-06-23 09:54:25 +05:30
|
|
|
while (1) {
|
2008-06-12 22:26:52 +05:30
|
|
|
char *encrypted;
|
|
|
|
int r;
|
|
|
|
|
2006-09-08 22:52:05 +05:30
|
|
|
/* cp points to a static buffer that is zeroed every time */
|
2006-09-09 19:30:58 +05:30
|
|
|
cp = bb_askpass(timeout,
|
|
|
|
"Give root password for system maintenance\n"
|
|
|
|
"(or type Control-D for normal startup):");
|
|
|
|
|
2002-06-23 09:54:25 +05:30
|
|
|
if (!cp || !*cp) {
|
2006-09-08 22:52:05 +05:30
|
|
|
bb_info_msg("Normal startup");
|
2006-09-09 19:30:58 +05:30
|
|
|
return 0;
|
2002-06-23 09:54:25 +05:30
|
|
|
}
|
2008-06-12 22:26:52 +05:30
|
|
|
encrypted = pw_encrypt(cp, pwd->pw_passwd, 1);
|
|
|
|
r = strcmp(encrypted, pwd->pw_passwd);
|
|
|
|
free(encrypted);
|
|
|
|
if (r == 0) {
|
2002-06-23 09:54:25 +05:30
|
|
|
break;
|
|
|
|
}
|
2006-01-07 02:29:09 +05:30
|
|
|
bb_do_delay(FAIL_DELAY);
|
2006-09-09 19:30:58 +05:30
|
|
|
bb_error_msg("login incorrect");
|
2002-06-23 09:54:25 +05:30
|
|
|
}
|
2006-09-08 22:52:05 +05:30
|
|
|
memset(cp, 0, strlen(cp));
|
2007-10-21 00:50:22 +05:30
|
|
|
// signal(SIGALRM, SIG_DFL);
|
2005-05-03 11:55:50 +05:30
|
|
|
|
2006-09-08 22:52:05 +05:30
|
|
|
bb_info_msg("System Maintenance Mode");
|
2005-05-03 11:55:50 +05:30
|
|
|
|
2006-09-08 22:52:05 +05:30
|
|
|
USE_SELINUX(renew_current_security_context());
|
2005-05-03 11:55:50 +05:30
|
|
|
|
2006-10-14 17:17:02 +05:30
|
|
|
shell = getenv("SUSHELL");
|
2007-09-10 18:45:28 +05:30
|
|
|
if (!shell)
|
|
|
|
shell = getenv("sushell");
|
2006-10-14 17:17:02 +05:30
|
|
|
if (!shell) {
|
|
|
|
shell = "/bin/sh";
|
|
|
|
if (pwd->pw_shell[0])
|
|
|
|
shell = pwd->pw_shell;
|
|
|
|
}
|
2007-09-10 18:45:28 +05:30
|
|
|
/* Exec login shell with no additional parameters. Never returns. */
|
|
|
|
run_shell(shell, 1, NULL, NULL);
|
2006-09-09 19:30:58 +05:30
|
|
|
|
2007-10-21 00:50:22 +05:30
|
|
|
auth_error:
|
|
|
|
bb_error_msg_and_die("no password entry for root");
|
2002-06-23 09:54:25 +05:30
|
|
|
}
|