From 887e331abb6ac0a850e5d53de55f43c9ebdee5a2 Mon Sep 17 00:00:00 2001 From: David Kalnischkies Date: Thu, 25 Jan 2018 17:14:49 +0100 Subject: =?UTF-8?q?add=20apt-helper=20drop-privs=20command=E2=80=A6?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- cmdline/apt-helper.cc | 17 +++++++++++++++++ doc/examples/configure-index | 25 +++++++++++++++++++------ test/integration/test-apt-helper | 7 +++++++ 3 files changed, 43 insertions(+), 6 deletions(-) diff --git a/cmdline/apt-helper.cc b/cmdline/apt-helper.cc index d1a3b4e6e..beac0efba 100644 --- a/cmdline/apt-helper.cc +++ b/cmdline/apt-helper.cc @@ -219,6 +219,22 @@ static bool DoWaitOnline(CommandLine &) return _error->PendingError() == false; } /*}}}*/ +static bool DropPrivsAndRun(CommandLine &CmdL) /*{{{*/ +{ + if (CmdL.FileSize() < 2) + return _error->Error("No command given to run without privileges"); + if (DropPrivileges() == false) + return _error->Error("Dropping Privileges failed, not executing '%s'", CmdL.FileList[1]); + + std::vector Args; + Args.reserve(CmdL.FileSize() + 1); + for (auto a = CmdL.FileList + 1; *a != nullptr; ++a) + Args.push_back(*a); + Args.push_back(nullptr); + auto const pid = ExecuteProcess(Args.data()); + return ExecWait(pid, CmdL.FileList[1]); +} + /*}}}*/ static bool ShowHelp(CommandLine &) /*{{{*/ { std::cout << @@ -239,6 +255,7 @@ static std::vector GetCommands() /*{{{*/ {"cat-file", &DoCatFile, _("concatenate files, with automatic decompression")}, {"auto-detect-proxy", &DoAutoDetectProxy, _("detect proxy using apt.conf")}, {"wait-online", &DoWaitOnline, _("wait for system to be online")}, + {"drop-privs", &DropPrivsAndRun, _("drop privileges before running given command")}, {nullptr, nullptr, nullptr}}; } /*}}}*/ diff --git a/doc/examples/configure-index b/doc/examples/configure-index index 9088bd844..b5a0b5657 100644 --- a/doc/examples/configure-index +++ b/doc/examples/configure-index @@ -533,7 +533,6 @@ Debug pkgAcqArchive::NoQueue ""; Hashes ""; APT::FtpArchive::Clean ""; - NoDropPrivs ""; EDSP::WriteSolution ""; InstallProgress::Fancy ""; APT::Progress::PackageManagerFd ""; @@ -596,6 +595,25 @@ APT::FTPArchive::release Version ""; }; +Debug::NoDropPrivs ""; +APT::Sandbox +{ + User ""; + ResetEnvironment ""; + Verify "" + { + Groups ""; + IDs ""; + Regain ""; + }; + seccomp "" + { + print ""; // print what syscall was trapped + allow ""; + trap ""; + }; +}; + // having both seems wrong dpkgpm::progress ""; dpkg::progress ""; @@ -638,11 +656,6 @@ apt::solver ""; apt::planner ""; apt::system ""; apt::acquire::translation ""; // deprecated in favor of Acquire::Languages -apt::sandbox::user ""; -apt::sandbox::seccomp ""; -apt::sandbox::seccomp::print ""; // print what syscall was trapped -apt::sandbox::seccomp::allow ""; -apt::sandbox::seccomp::trap ""; apt::color::highlight ""; apt::color::neutral ""; diff --git a/test/integration/test-apt-helper b/test/integration/test-apt-helper index fda28968f..ae1ca7456 100755 --- a/test/integration/test-apt-helper +++ b/test/integration/test-apt-helper @@ -123,3 +123,10 @@ testfailureequal 'E: Must specify at least one SRV record' apthelper srv-lookup testfailureequal 'E: GetSrvRec failed for localhost' apthelper -q=1 srv-lookup 'localhost' testfailureequal "E: GetSrvRec failed for localhost:${APTHTTPPORT}" apthelper -q=1 srv-lookup "localhost:${APTHTTPPORT}" testfailureequal "E: GetSrvRec failed for localhost:${APTHTTPSPORT}" apthelper -q=1 srv-lookup "localhost:${APTHTTPSPORT}" + +msgmsg 'apt-helper' 'drop-privs' +testfailureequal "E: No command given to run without privileges" apthelper drop-privs +testsuccess apthelper -- drop-privs true +testsuccess apthelper drop-privs -- true +DATE="$(date -u +'%Y-%m-%d')" +testsuccessequal "$DATE" apthelper drop-privs -- date -u -d "$DATE" +'%Y-%m-%d' -- cgit v1.2.3