mirror of
https://github.com/troglobit/finit.git
synced 2026-10-10 16:52:39 +07:00
Fix #357: allow sulogin with user different from 'root'
In issue #357 there's a proposal for optionally allowing /bin/login, but after intense discussions we've agreed that would be opening up for all sorts of potential (security) issues. it's better to keep things as-is but with the added twist of supporting a custom user at configure time, e.g., 'admin'. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit is contained in:
+9
-3
@@ -21,6 +21,8 @@
|
||||
* THE SOFTWARE.
|
||||
*/
|
||||
|
||||
#include "config.h"
|
||||
|
||||
#include <crypt.h>
|
||||
#include <err.h>
|
||||
#include <paths.h>
|
||||
@@ -32,6 +34,10 @@
|
||||
#include <unistd.h>
|
||||
#include <sys/ioctl.h>
|
||||
|
||||
#ifndef SULOGIN_USER
|
||||
#define SULOGIN_USER "root"
|
||||
#endif
|
||||
|
||||
/* getpwnam() cannot be used when statically linked */
|
||||
static int get_passwd(struct passwd *pw)
|
||||
{
|
||||
@@ -44,13 +50,13 @@ static int get_passwd(struct passwd *pw)
|
||||
return 1;
|
||||
|
||||
while ((tmp = fgets(buf, sizeof(buf), fp))) {
|
||||
if (!strstr(buf, ":0:0:"))
|
||||
continue; /* not uid 0 */
|
||||
|
||||
ptr = strsep(&tmp, ":");
|
||||
if (!ptr)
|
||||
break;
|
||||
|
||||
pw->pw_name = strdup(ptr);
|
||||
if (!pw->pw_name || strcmp(pw->pw_name, SULOGIN_USER))
|
||||
continue;
|
||||
|
||||
ptr = strsep(&tmp, ":");
|
||||
if (!ptr)
|
||||
|
||||
Reference in New Issue
Block a user