Fix #357: allow sulogin with user different from 'root'

In issue #357 there's a proposal for optionally allowing /bin/login, but
after intense discussions we've agreed that would be opening up for all
sorts of potential (security) issues.

it's better to keep things as-is but with the added twist of supporting
a custom user at configure time, e.g., 'admin'.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit is contained in:
Joachim Wiberg
2023-09-13 11:37:15 +02:00
parent ddedcf77e8
commit 6e7a2fb6d5
2 changed files with 18 additions and 7 deletions
+9 -4
View File
@@ -145,10 +145,10 @@ AC_ARG_WITH(keventd,
AS_HELP_STRING([--with-keventd], [Enable built-in keventd, default: no]),, [with_keventd=no])
AC_ARG_WITH(sulogin,
AS_HELP_STRING([--with-sulogin], [Enable built-in sulogin, default: no.]),, [with_sulogin=no])
AS_HELP_STRING([--with-sulogin@<:@=USER@:>@], [Enable built-in sulogin, optional USER to request password for (default root), default: no.]),[sulogin=$withval],[with_sulogin=no])
AC_ARG_WITH(watchdog,
AS_HELP_STRING([--with-watchdog=[DEV]], [Enable built-in watchdog, default: /dev/watchdog]),
AS_HELP_STRING([--with-watchdog@<:@=DEV@:>@], [Enable built-in watchdog, default: /dev/watchdog]),
[watchdog=$withval], [with_watchdog=no watchdog=])
AC_ARG_WITH(hook-scripts-path,
@@ -252,7 +252,12 @@ AS_IF([test "x$rtc_date" != "xno"], [
AS_IF([test "x$with_keventd" != "xno"], [with_keventd=yes])
AS_IF([test "x$with_sulogin" != "xno"], [with_sulogin=yes])
AS_IF([test "x$with_sulogin" != "xno"], [
AS_IF([test "x$sulogin" = "xyes"], [
sulogin=root])
with_sulogin=yes
AC_DEFINE_UNQUOTED(SULOGIN_USER, "$sulogin", [Built-in sulogin user, default: root])], [
sulogin=])
AS_IF([test "x$with_watchdog" != "xno"], [
AS_IF([test "x$watchdog" = "xyes"], [
@@ -344,7 +349,7 @@ Optional features:
Install doc/..........: $enable_doc
Install contrib/......: $enable_contrib
Built-in keventd......: $with_keventd
Built-in sulogin......: $with_sulogin
Built-in sulogin......: $with_sulogin $sulogin
Built-in watchdogd....: $with_watchdog $watchdog
Built-in logrotate....: $enable_logrotate
Skip fsck check.......: $enable_fastboot
+9 -3
View File
@@ -21,6 +21,8 @@
* THE SOFTWARE.
*/
#include "config.h"
#include <crypt.h>
#include <err.h>
#include <paths.h>
@@ -32,6 +34,10 @@
#include <unistd.h>
#include <sys/ioctl.h>
#ifndef SULOGIN_USER
#define SULOGIN_USER "root"
#endif
/* getpwnam() cannot be used when statically linked */
static int get_passwd(struct passwd *pw)
{
@@ -44,13 +50,13 @@ static int get_passwd(struct passwd *pw)
return 1;
while ((tmp = fgets(buf, sizeof(buf), fp))) {
if (!strstr(buf, ":0:0:"))
continue; /* not uid 0 */
ptr = strsep(&tmp, ":");
if (!ptr)
break;
pw->pw_name = strdup(ptr);
if (!pw->pw_name || strcmp(pw->pw_name, SULOGIN_USER))
continue;
ptr = strsep(&tmp, ":");
if (!ptr)