Reviewed-on: https://gitea.home.com:3000/TolaMironcenko/sudo/pulls/3
sudo - A Simple Sudo Implementation
A lightweight implementation of the sudo command for Unix-like systems, written in C.
Overview
This project provides a minimal yet functional sudo replacement that allows users to execute commands with root privileges. It's designed to be simple, secure, and easy to understand.
Features
- Execute commands as root user
- Minimal dependencies (standard C library only)
- Cross-platform support (Linux focused)
- Proper error handling and reporting
- Package creation for easy distribution
Building
Prerequisites
- GCC compiler
- Make utility
- Root access (for installation)
Compilation
make build
This will:
- Create the
bin/directory if it doesn't exist - Compile the source code with appropriate flags
- Set the binary owner to root (0:0)
- Set the setuid bit (4755 permissions)
Cleaning
make clean
Removes the compiled binary from the bin/ directory.
Installation
Manual Installation
After building, you can manually copy the binary to your system:
sudo cp bin/sudo /usr/bin/sudo
sudo chown root:root /usr/bin/sudo
sudo chmod 4755 /usr/bin/sudo
Package Installation
Create a package for distribution:
make package
This creates a sudo.pkg.gz archive containing:
- The binary
- Installation files
- Post-installation script for proper permissions
Usage
sudo COMMAND [ARG...]
Examples
# Edit a system file
sudo nano /etc/hosts
# Install a package
sudo apt update
# View system logs
sudo tail -f /var/log/syslog
# Run a command as root
sudo whoami
Security Considerations
⚠️ Important Security Notes:
-
Setuid Root: This binary runs with setuid root permissions, which is necessary for privilege escalation but comes with security risks.
-
No Authentication: This implementation does not include password authentication. In a production environment, you should implement proper authentication mechanisms.
-
No Access Control: There are no restrictions on which users can use this sudo implementation or which commands they can run.
-
Audit Logging: This version does not log command execution. Consider adding logging for security auditing.
Architecture
The implementation consists of:
- Command Line Parsing: Validates arguments and displays usage information
- Privilege Escalation: Uses
setuid(),setgid(), andsetgroups()to gain root privileges - Command Execution: Uses
execvp()to execute the target command - Error Handling: Comprehensive error reporting with proper exit codes
Code Structure
sudo/
├── src/
│ └── sudo.c # Main implementation
├── bin/ # Compiled binary (created during build)
├── Makefile # Build configuration
├── LICENSE # MIT License
└── README.md # This file
Development
Building for Development
# Build the project
make build
# Test the binary
./bin/sudo whoami
Debugging
For debugging, you can modify the CFLAGS in the Makefile to include debug symbols:
CFLAGS=-Wall -g -DDEBUG
Limitations
This is a simplified implementation and lacks many features of the full sudo:
- No configuration file (
/etc/sudoers) - No password authentication
- No user/group restrictions
- No command logging
- No timeout functionality
- No environment variable handling
Contributing
- Fork the repository
- Create a feature branch
- Make your changes
- Test thoroughly
- Submit a pull request
License
This project is licensed under the MIT License - see the LICENSE file for details.
Disclaimer
This software is provided for educational and development purposes. Use in production environments should be done with careful consideration of security implications. The authors are not responsible for any security vulnerabilities or system damage resulting from the use of this software.
Support
For questions, issues, or contributions, please refer to the project's issue tracker or contact the maintainers.