getty: if we cannot execute /bin/login, try sulogin before /bin/sh

Basic security measure, don't bail to shell if we cannot find/exec
login, instead try sulogin before falling back to plain shell.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit is contained in:
Joachim Wiberg
2021-05-30 12:42:48 +02:00
parent 654f8aeb19
commit 9cc9e3ddbb
3 changed files with 12 additions and 6 deletions
+1 -1
View File
@@ -19,7 +19,7 @@ endif
finit_pkglibdir = $(pkglibdir)
finit_pkglib_SCRIPTS = rescue.conf sample.conf
getty_SOURCES = getty.c helpers.h logrotate.c stty.c utmp-api.c utmp-api.h
getty_SOURCES = finit.h getty.c helpers.h logrotate.c stty.c utmp-api.c utmp-api.h
getty_CFLAGS = -W -Wall -Wextra -std=gnu99
getty_CFLAGS += $(lite_CFLAGS)
getty_LDADD = $(lite_LIBS)
+1
View File
@@ -50,6 +50,7 @@
#define FINIT_CGPATH "/sys/fs/cgroup"
#endif
/* To use these, include config.h, or define FINIT_LIBPATH_ */
#define _PATH_LOGIT FINIT_LIBPATH_ "/logit"
#define _PATH_SULOGIN FINIT_LIBPATH_ "/sulogin"
#define _PATH_GETTY FINIT_LIBPATH_ "/getty"
+10 -5
View File
@@ -21,6 +21,8 @@
* THE SOFTWARE.
*/
#include "config.h"
#include <err.h>
#include <errno.h>
#include <paths.h>
@@ -32,6 +34,7 @@
#include <sys/ttydefaults.h> /* Not included by default in musl libc */
#include <termios.h>
#include "finit.h"
#include "helpers.h"
#include "utmp-api.h"
@@ -179,12 +182,14 @@ static int do_login(char *name)
/*
* Failed to exec login, should not happen on normal systems.
* Try a starting a rescue shell instead.
*
* Note: Add /etc/securetty handling.
*/
warnx("Failed exec %s, attempting fallback to %s ...", _PATH_LOGIN, _PATH_BSHELL);
if (fstat(0, &st) == 0 && S_ISCHR(st.st_mode))
execl(_PATH_BSHELL, _PATH_BSHELL, NULL); /* XXX: run sulogin instead! */
if (fstat(0, &st) == 0 && S_ISCHR(st.st_mode)) {
warnx("Failed exec %s, attempting fallback to %s ...", _PATH_LOGIN, _PATH_SULOGIN);
execl(_PATH_SULOGIN, _PATH_SULOGIN, NULL);
warnx("Failed exec %s, attempting fallback to %s ...", _PATH_SULOGIN, _PATH_BSHELL);
execl(_PATH_BSHELL, _PATH_BSHELL, NULL);
}
return 1; /* We shouldn't get here ... */
}