From 6e7a2fb6d52fc93f2d964baf6da20bb733917f3a Mon Sep 17 00:00:00 2001 From: Joachim Wiberg Date: Wed, 13 Sep 2023 11:37:15 +0200 Subject: [PATCH] Fix #357: allow sulogin with user different from 'root' In issue #357 there's a proposal for optionally allowing /bin/login, but after intense discussions we've agreed that would be opening up for all sorts of potential (security) issues. it's better to keep things as-is but with the added twist of supporting a custom user at configure time, e.g., 'admin'. Signed-off-by: Joachim Wiberg --- configure.ac | 13 +++++++++---- src/sulogin.c | 12 +++++++++--- 2 files changed, 18 insertions(+), 7 deletions(-) diff --git a/configure.ac b/configure.ac index 99e21fe8..303ea224 100644 --- a/configure.ac +++ b/configure.ac @@ -145,10 +145,10 @@ AC_ARG_WITH(keventd, AS_HELP_STRING([--with-keventd], [Enable built-in keventd, default: no]),, [with_keventd=no]) AC_ARG_WITH(sulogin, - AS_HELP_STRING([--with-sulogin], [Enable built-in sulogin, default: no.]),, [with_sulogin=no]) + AS_HELP_STRING([--with-sulogin@<:@=USER@:>@], [Enable built-in sulogin, optional USER to request password for (default root), default: no.]),[sulogin=$withval],[with_sulogin=no]) AC_ARG_WITH(watchdog, - AS_HELP_STRING([--with-watchdog=[DEV]], [Enable built-in watchdog, default: /dev/watchdog]), + AS_HELP_STRING([--with-watchdog@<:@=DEV@:>@], [Enable built-in watchdog, default: /dev/watchdog]), [watchdog=$withval], [with_watchdog=no watchdog=]) AC_ARG_WITH(hook-scripts-path, @@ -252,7 +252,12 @@ AS_IF([test "x$rtc_date" != "xno"], [ AS_IF([test "x$with_keventd" != "xno"], [with_keventd=yes]) -AS_IF([test "x$with_sulogin" != "xno"], [with_sulogin=yes]) +AS_IF([test "x$with_sulogin" != "xno"], [ + AS_IF([test "x$sulogin" = "xyes"], [ + sulogin=root]) + with_sulogin=yes + AC_DEFINE_UNQUOTED(SULOGIN_USER, "$sulogin", [Built-in sulogin user, default: root])], [ + sulogin=]) AS_IF([test "x$with_watchdog" != "xno"], [ AS_IF([test "x$watchdog" = "xyes"], [ @@ -344,7 +349,7 @@ Optional features: Install doc/..........: $enable_doc Install contrib/......: $enable_contrib Built-in keventd......: $with_keventd - Built-in sulogin......: $with_sulogin + Built-in sulogin......: $with_sulogin $sulogin Built-in watchdogd....: $with_watchdog $watchdog Built-in logrotate....: $enable_logrotate Skip fsck check.......: $enable_fastboot diff --git a/src/sulogin.c b/src/sulogin.c index 29ca4553..83197417 100644 --- a/src/sulogin.c +++ b/src/sulogin.c @@ -21,6 +21,8 @@ * THE SOFTWARE. */ +#include "config.h" + #include #include #include @@ -32,6 +34,10 @@ #include #include +#ifndef SULOGIN_USER +#define SULOGIN_USER "root" +#endif + /* getpwnam() cannot be used when statically linked */ static int get_passwd(struct passwd *pw) { @@ -44,13 +50,13 @@ static int get_passwd(struct passwd *pw) return 1; while ((tmp = fgets(buf, sizeof(buf), fp))) { - if (!strstr(buf, ":0:0:")) - continue; /* not uid 0 */ - ptr = strsep(&tmp, ":"); if (!ptr) break; + pw->pw_name = strdup(ptr); + if (!pw->pw_name || strcmp(pw->pw_name, SULOGIN_USER)) + continue; ptr = strsep(&tmp, ":"); if (!ptr)