Support for disabling invocation of rescue mode from kernel cmdline

The rescue mode that can be invoked from the kernel command line is
potentially unsafe.  Many systems lock the root user account, or use
another account for managing, e.g. 'admin'.  The sulogin program(s)
would on such systems give the user a root prompt.

In #357 we added support for setting a custom sulogin user, but for some
systems that is not enough.  On many embedded systems the /etc/passwd
and shadow files are populated at bootstrap and at the time rescue mode
runs, these files will be unpopulated.

The only, truly safe, approach on such systems is to disable rescue mode
completely.  Otherwise intricate Finit plugins have to be used that run
before rescue mode is started -- increasing the complexity of the system
as a whole.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit is contained in:
Joachim Wiberg
2023-09-13 12:45:03 +02:00
parent 5a946a4ea7
commit 263aec292a
5 changed files with 19 additions and 1 deletions
+2
View File
@@ -246,10 +246,12 @@ static void parse_arg(char *arg)
return;
}
#ifdef RESCUE_MODE
if (string_compare(arg, "rescue") || string_compare(arg, "recover")) {
rescue = 1;
return;
}
#endif
if (string_compare(arg, "single") || string_compare(arg, "S")) {
single = 1;
+2
View File
@@ -649,8 +649,10 @@ int main(int argc, char *argv[])
/*
* In case of emergency.
*/
#ifdef RESCUE_MODE
if (rescue)
rescue = sulogin(0);
#endif
/*
* Load plugins early, the first hook is in banner(), so we