From 263aec292ac00f9f889ffd3cccc913f3b3eaec6f Mon Sep 17 00:00:00 2001 From: Joachim Wiberg Date: Wed, 13 Sep 2023 12:45:03 +0200 Subject: [PATCH] Support for disabling invocation of rescue mode from kernel cmdline The rescue mode that can be invoked from the kernel command line is potentially unsafe. Many systems lock the root user account, or use another account for managing, e.g. 'admin'. The sulogin program(s) would on such systems give the user a root prompt. In #357 we added support for setting a custom sulogin user, but for some systems that is not enough. On many embedded systems the /etc/passwd and shadow files are populated at bootstrap and at the time rescue mode runs, these files will be unpopulated. The only, truly safe, approach on such systems is to disable rescue mode completely. Otherwise intricate Finit plugins have to be used that run before rescue mode is started -- increasing the complexity of the system as a whole. Signed-off-by: Joachim Wiberg --- configure.ac | 10 +++++++++- doc/cmdline.md | 2 ++ doc/config.md | 4 ++++ src/conf.c | 2 ++ src/finit.c | 2 ++ 5 files changed, 19 insertions(+), 1 deletion(-) diff --git a/configure.ac b/configure.ac index 303ea224..36986e37 100644 --- a/configure.ac +++ b/configure.ac @@ -71,7 +71,7 @@ AC_ARG_ENABLE(redirect, enable_redirect=yes]) AC_ARG_ENABLE(logrotate, - AS_HELP_STRING([--disable-logrotate], [Disable built-in rotation of /var/log/wtmp, default enabled]),,[ + AS_HELP_STRING([--disable-logrotate], [Disable built-in rotation of /var/log/wtmp]),,[ enable_logrotate=yes]) AC_ARG_ENABLE(doc, @@ -82,6 +82,10 @@ AC_ARG_ENABLE(contrib, AS_HELP_STRING([--disable-contrib], [Disable build and install of contrib section]),,[ enable_contrib=yes]) +AC_ARG_ENABLE([rescue], + AS_HELP_STRING([--disable-rescue], [Disable potentially unsafe rescue mode]),, + [enable_rescue=yes]) + # Check for extra plugins to enable AC_ARG_ENABLE(all_plugins, AS_HELP_STRING([--enable-all-plugins], [Enable all plugins, default: auto]), @@ -185,6 +189,9 @@ AS_IF([test "x$enable_redirect" = "xyes"], [ AS_IF([test "x$enable_logrotate" != "xno"], [ AC_DEFINE(LOGROTATE_ENABLED, 1, [Enable built-in rotation of /var/log/wtmp et al.])]) +AS_IF([test "x$enable_rescue" != "xno"], [ + AC_DEFINE([RESCUE_MODE], 1, [Define to enable support for rescue mode.])]) + AM_CONDITIONAL(LOGROTATE, [test "x$enable_logrotate" = "xyes"]) ### With features ############################################################################## @@ -355,6 +362,7 @@ Optional features: Skip fsck check.......: $enable_fastboot Run fsck fix mode.....: $enable_fsckfix Redirect output.......: $enable_redirect + Rescue mode...........: $enable_rescue Default hostname......: $hostname Default group.........: $group Default runlevel......: $runlevel diff --git a/doc/cmdline.md b/doc/cmdline.md index 7e2ae218..eb36d322 100644 --- a/doc/cmdline.md +++ b/doc/cmdline.md @@ -86,6 +86,8 @@ The `bool` setting is one of `on, off, true false, 1, 0`. the system booted in a limited fallback mode. See [config.md][] for more information. + This option can be disabled with `configure --without-rescue` + **Note:** in this mode `initctl` will not work. Correct the problem and use `reboot -f` to force reboot. diff --git a/doc/config.md b/doc/config.md index 2ee5fde9..539cfdd7 100644 --- a/doc/config.md +++ b/doc/config.md @@ -1141,6 +1141,10 @@ Finit supports a rescue mode which is activated by the `rescue` option on the kernel command line. See [cmdline docs](cmdline.md) for how to activate it. +This rescue mode can be disabled at configure time using: + + configure --without-rescue + The rescue mode comes in two flavors; *traditional* and *fallback*. > **Note:** in this mode `initctl` will not work. Use the `-f` flag to diff --git a/src/conf.c b/src/conf.c index 01ce9718..6c0fcfb4 100644 --- a/src/conf.c +++ b/src/conf.c @@ -246,10 +246,12 @@ static void parse_arg(char *arg) return; } +#ifdef RESCUE_MODE if (string_compare(arg, "rescue") || string_compare(arg, "recover")) { rescue = 1; return; } +#endif if (string_compare(arg, "single") || string_compare(arg, "S")) { single = 1; diff --git a/src/finit.c b/src/finit.c index bb3c46d1..ea37dd3f 100644 --- a/src/finit.c +++ b/src/finit.c @@ -649,8 +649,10 @@ int main(int argc, char *argv[]) /* * In case of emergency. */ +#ifdef RESCUE_MODE if (rescue) rescue = sulogin(0); +#endif /* * Load plugins early, the first hook is in banner(), so we