hush/loginutils/sulogin.c

113 lines
2.4 KiB
C
Raw Normal View History

/* vi: set sw=4 ts=4: */
/*
2006-09-08 17:22:05 +00:00
* Mini sulogin implementation for busybox
*
* Licensed under GPLv2 or later, see file LICENSE in this tarball for details.
*/
#include "libbb.h"
#include <syslog.h>
2008-07-05 09:18:54 +00:00
//static void catchalarm(int UNUSED_PARAM junk)
//{
// exit(EXIT_FAILURE);
//}
int sulogin_main(int argc, char **argv) MAIN_EXTERNALLY_VISIBLE;
2008-07-05 09:18:54 +00:00
int sulogin_main(int argc UNUSED_PARAM, char **argv)
{
char *cp;
int timeout = 0;
2006-09-08 17:22:05 +00:00
struct passwd *pwd;
const char *shell;
#if ENABLE_FEATURE_SHADOWPASSWDS
/* Using _r function to avoid pulling in static buffers */
char buffer[256];
struct spwd spw;
#endif
2006-01-25 00:08:53 +00:00
2006-09-09 14:00:58 +00:00
logmode = LOGMODE_BOTH;
2006-10-03 21:00:43 +00:00
openlog(applet_name, 0, LOG_AUTH);
2006-01-25 00:08:53 +00:00
opt_complementary = "t+"; /* -t N */
getopt32(argv, "t:", &timeout);
argv += optind;
2006-09-08 17:22:05 +00:00
if (argv[0]) {
2006-09-08 17:22:05 +00:00
close(0);
close(1);
dup(xopen(argv[0], O_RDWR));
close(2);
2006-09-08 17:22:05 +00:00
dup(0);
}
2006-09-08 17:22:05 +00:00
/* Malicious use like "sulogin /dev/sda"? */
2006-09-08 17:22:05 +00:00
if (!isatty(0) || !isatty(1) || !isatty(2)) {
2006-09-09 14:00:58 +00:00
logmode = LOGMODE_SYSLOG;
bb_error_msg_and_die("not a tty");
}
/* Clear dangerous stuff, set PATH */
sanitize_env_if_suid();
pwd = getpwuid(0);
if (!pwd) {
2006-09-09 14:00:58 +00:00
goto auth_error;
2006-09-17 16:28:10 +00:00
}
2006-09-08 17:22:05 +00:00
#if ENABLE_FEATURE_SHADOWPASSWDS
{
/* getspnam_r may return 0 yet set result to NULL.
* At least glibc 2.4 does this. Be extra paranoid here. */
struct spwd *result = NULL;
int r = getspnam_r(pwd->pw_name, &spw, buffer, sizeof(buffer), &result);
if (r || !result) {
goto auth_error;
}
pwd->pw_passwd = result->sp_pwdp;
}
#endif
2006-09-08 17:22:05 +00:00
while (1) {
char *encrypted;
int r;
2006-09-08 17:22:05 +00:00
/* cp points to a static buffer that is zeroed every time */
cp = bb_ask(STDIN_FILENO, timeout,
2006-09-09 14:00:58 +00:00
"Give root password for system maintenance\n"
"(or type Control-D for normal startup):");
if (!cp || !*cp) {
2006-09-08 17:22:05 +00:00
bb_info_msg("Normal startup");
2006-09-09 14:00:58 +00:00
return 0;
}
encrypted = pw_encrypt(cp, pwd->pw_passwd, 1);
r = strcmp(encrypted, pwd->pw_passwd);
free(encrypted);
if (r == 0) {
break;
}
bb_do_delay(FAIL_DELAY);
2006-09-09 14:00:58 +00:00
bb_error_msg("login incorrect");
}
2006-09-08 17:22:05 +00:00
memset(cp, 0, strlen(cp));
// signal(SIGALRM, SIG_DFL);
2006-09-08 17:22:05 +00:00
bb_info_msg("System Maintenance Mode");
IF_SELINUX(renew_current_security_context());
shell = getenv("SUSHELL");
if (!shell)
shell = getenv("sushell");
if (!shell)
shell = pwd->pw_shell;
/* Exec login shell with no additional parameters. Never returns. */
run_shell(shell, 1, NULL, NULL);
2006-09-09 14:00:58 +00:00
auth_error:
bb_error_msg_and_die("no password entry for root");
}