From bf72e6b9c87cefd1b06086644dfd4651792011fc Mon Sep 17 00:00:00 2001 From: Joachim Wiberg Date: Tue, 3 May 2022 05:58:57 +0200 Subject: [PATCH] Make bundled sulogin optional, use ./configure --with-sulogin The bundled sulogin could be considered insecure, so leave it up to the administrator, or system integrator, to decide which sulogin(8) is best suited. Signed-off-by: Joachim Wiberg --- configure.ac | 7 +++++++ doc/build.md | 4 ++++ src/Makefile.am | 5 ++++- 3 files changed, 15 insertions(+), 1 deletion(-) diff --git a/configure.ac b/configure.ac index 66a3a2b7..a609630d 100644 --- a/configure.ac +++ b/configure.ac @@ -139,6 +139,9 @@ AC_ARG_WITH(random-seed, AC_ARG_WITH(keventd, AS_HELP_STRING([--with-keventd], [Enable built-in keventd, default: no]),, [with_keventd=no]) +AC_ARG_WITH(sulogin, + AS_HELP_STRING([--with-sulogin], [Enable built-in sulogin, default: no.]),, [with_sulogin=no]) + AC_ARG_WITH(watchdog, AS_HELP_STRING([--with-watchdog=[DEV]], [Enable built-in watchdog, default: /dev/watchdog]), [watchdog=$withval], [with_watchdog=no watchdog=]) @@ -228,6 +231,8 @@ AS_IF([test "x$with_random_seed" != "xno"], [ AS_IF([test "x$with_keventd" != "xno"], [with_keventd=yes]) +AS_IF([test "x$with_sulogin" != "xno"], [with_sulogin=yes]) + AS_IF([test "x$with_watchdog" != "xno"], [ AS_IF([test "x$watchdog" = "xyes"], [ watchdog=/dev/watchdog]) @@ -238,6 +243,7 @@ AS_IF([test "x$with_watchdog" != "xno"], [ # Control build with automake flags AM_CONDITIONAL(STATIC, [test "x$enable_static" = "xyes"]) AM_CONDITIONAL(KEVENTD, [test "x$with_keventd" != "xno"]) +AM_CONDITIONAL(SULOGIN, [test "x$with_sulogin" != "xno"]) AM_CONDITIONAL(WATCHDOGD, [test "x$with_watchdog" != "xno"]) AM_CONDITIONAL(DOC, [test "x$enable_doc" = "xyes"]) AM_CONDITIONAL(CONTRIB, [test "x$enable_contrib" = "xyes"]) @@ -289,6 +295,7 @@ Optional features: Install doc/..........: $enable_doc Install contrib/......: $enable_contrib Built-in keventd......: $with_keventd + Built-in sulogin......: $with_sulogin Built-in watchdogd....: $with_watchdog $watchdog Built-in logrotate....: $enable_logrotate Skip fsck check.......: $enable_fastboot diff --git a/doc/build.md b/doc/build.md index 21aa9878..b2fb6353 100644 --- a/doc/build.md +++ b/doc/build.md @@ -65,6 +65,10 @@ Below are a few of the main switches to configure: * `--enable-x11-common-plugin`: Enable the optional X Window `x11-common.so` plugin. +* `--with-sulgin`: Enable bundled `sulogin` program. Default is to use the + system `sulogin(8)`. The sulogin shipped with Finit *allows password-less* + login if the `root` user is disabled or has no password at all. + For more configure flags, see ./configure --help > **Note:** the configure script is not available in the GIT sources. It is diff --git a/src/Makefile.am b/src/Makefile.am index 27200f87..9b8d25a7 100644 --- a/src/Makefile.am +++ b/src/Makefile.am @@ -8,7 +8,10 @@ AM_LDFLAGS = -export-dynamic endif sbin_PROGRAMS = finit initctl -pkglibexec_PROGRAMS = getty logit sulogin +pkglibexec_PROGRAMS = getty logit +if SULOGIN +pkglibexec_PROGRAMS += sulogin +endif if KEVENTD pkglibexec_PROGRAMS += keventd endif