Support for disabling invocation of rescue mode from kernel cmdline

The rescue mode that can be invoked from the kernel command line is
potentially unsafe.  Many systems lock the root user account, or use
another account for managing, e.g. 'admin'.  The sulogin program(s)
would on such systems give the user a root prompt.

In #357 we added support for setting a custom sulogin user, but for some
systems that is not enough.  On many embedded systems the /etc/passwd
and shadow files are populated at bootstrap and at the time rescue mode
runs, these files will be unpopulated.

The only, truly safe, approach on such systems is to disable rescue mode
completely.  Otherwise intricate Finit plugins have to be used that run
before rescue mode is started -- increasing the complexity of the system
as a whole.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit is contained in:
Joachim Wiberg
2023-09-13 12:45:03 +02:00
parent 5a946a4ea7
commit 263aec292a
5 changed files with 19 additions and 1 deletions
+9 -1
View File
@@ -71,7 +71,7 @@ AC_ARG_ENABLE(redirect,
enable_redirect=yes])
AC_ARG_ENABLE(logrotate,
AS_HELP_STRING([--disable-logrotate], [Disable built-in rotation of /var/log/wtmp, default enabled]),,[
AS_HELP_STRING([--disable-logrotate], [Disable built-in rotation of /var/log/wtmp]),,[
enable_logrotate=yes])
AC_ARG_ENABLE(doc,
@@ -82,6 +82,10 @@ AC_ARG_ENABLE(contrib,
AS_HELP_STRING([--disable-contrib], [Disable build and install of contrib section]),,[
enable_contrib=yes])
AC_ARG_ENABLE([rescue],
AS_HELP_STRING([--disable-rescue], [Disable potentially unsafe rescue mode]),,
[enable_rescue=yes])
# Check for extra plugins to enable
AC_ARG_ENABLE(all_plugins,
AS_HELP_STRING([--enable-all-plugins], [Enable all plugins, default: auto]),
@@ -185,6 +189,9 @@ AS_IF([test "x$enable_redirect" = "xyes"], [
AS_IF([test "x$enable_logrotate" != "xno"], [
AC_DEFINE(LOGROTATE_ENABLED, 1, [Enable built-in rotation of /var/log/wtmp et al.])])
AS_IF([test "x$enable_rescue" != "xno"], [
AC_DEFINE([RESCUE_MODE], 1, [Define to enable support for rescue mode.])])
AM_CONDITIONAL(LOGROTATE, [test "x$enable_logrotate" = "xyes"])
### With features ##############################################################################
@@ -355,6 +362,7 @@ Optional features:
Skip fsck check.......: $enable_fastboot
Run fsck fix mode.....: $enable_fsckfix
Redirect output.......: $enable_redirect
Rescue mode...........: $enable_rescue
Default hostname......: $hostname
Default group.........: $group
Default runlevel......: $runlevel
+2
View File
@@ -86,6 +86,8 @@ The `bool` setting is one of `on, off, true false, 1, 0`.
the system booted in a limited fallback mode. See [config.md][]
for more information.
This option can be disabled with `configure --without-rescue`
**Note:** in this mode `initctl` will not work. Correct the problem
and use `reboot -f` to force reboot.
+4
View File
@@ -1141,6 +1141,10 @@ Finit supports a rescue mode which is activated by the `rescue` option
on the kernel command line. See [cmdline docs](cmdline.md) for how to
activate it.
This rescue mode can be disabled at configure time using:
configure --without-rescue
The rescue mode comes in two flavors; *traditional* and *fallback*.
> **Note:** in this mode `initctl` will not work. Use the `-f` flag to
+2
View File
@@ -246,10 +246,12 @@ static void parse_arg(char *arg)
return;
}
#ifdef RESCUE_MODE
if (string_compare(arg, "rescue") || string_compare(arg, "recover")) {
rescue = 1;
return;
}
#endif
if (string_compare(arg, "single") || string_compare(arg, "S")) {
single = 1;
+2
View File
@@ -649,8 +649,10 @@ int main(int argc, char *argv[])
/*
* In case of emergency.
*/
#ifdef RESCUE_MODE
if (rescue)
rescue = sulogin(0);
#endif
/*
* Load plugins early, the first hook is in banner(), so we