217 Commits

Author SHA1 Message Date
vasilito 3b02e0b999 getty: harden the console<->PTY bridge against transient read/write/event errors (log-and-continue instead of panic; a panic here killed the live shell's I/O) 2026-07-19 18:02:17 +09:00
vasilito b0cfab717e login: remove diagnostics; keep the validated-cwd shell spawn fix 2026-07-18 23:07:58 +09:00
vasilito fbbb1d88cb login: hand the shell login's validated cwd, not raw home
The pre-exec child runs chdir(home) before execvp; chdir(/home/user) fails with
ENOENT on the live image (open succeeds, chdir does not) which aborted the whole
spawn before execve - the real reason the login shell never started. Use login's
already-validated cwd (home if reachable, else /). Diagnostics retained.
2026-07-18 21:26:27 +09:00
vasilito 02a86400cc login: pass shell console fds explicitly as Stdio (relibc inheritance drops login-shell stdio; getty does the same for login) 2026-07-18 18:13:44 +09:00
vasilito 1677bdd2c3 login: clear FD_CLOEXEC on stdio before spawning shell (+diag) so the login shell inherits console I/O 2026-07-18 17:56:46 +09:00
vasilito 09d078a555 login: fix termios flag cast type (tcflag_t) 2026-07-18 14:35:22 +09:00
vasilito 1cce5020ad login: reset the console terminal to canonical mode before the shell
The username is read with the liner line editor, which puts the console
pty into raw mode (ICANON/ECHO cleared) and does not restore it. In raw
mode the pty line discipline never flushes a completed line into the
slave read buffer the way a shell's canonical read_line expects, so the
interactive shell (brush) never receives a typed command even though
getty forwards it to the pty master. Reset stdin to sane cooked settings
(ICANON|ECHO|ISIG, ICRNL, OPOST|ONLCR, VMIN=1/VTIME=0) via tcsetattr
before spawning the shell.
2026-07-18 14:33:37 +09:00
vasilito e440bf86c1 login: restore blocking mode on console fds before spawning the shell
The login name is read via the liner line editor, which puts the console
fd into non-blocking (and raw) mode and does not restore it. The shell
inherits fd 0; an interactive shell doing blocking line reads on a
non-blocking pty slave never receives forwarded input (reads return
empty), so the shell can never run a command. Clear O_NONBLOCK on
stdin/stdout/stderr in spawn_shell before spawning. Restores the login
namespace restriction (skipping it did not affect the symptom).
2026-07-18 13:05:01 +09:00
vasilito c935e2689e login: DIAGNOSTIC — spawn login shell without namespace restriction
Getty forwards console input to the pty master correctly (verified), and
login reads the username fine, but after apply_login_schemes() restricts
the namespace the interactive shell's pty-slave read never returns the
forwarded input. Temporarily skip the restriction to confirm it is the
cause. Also removes the getty forward diagnostic.
2026-07-18 12:52:51 +09:00
vasilito 25826efb9e getty: temporary diag — log input forwarded from tty to pty 2026-07-18 12:42:04 +09:00
vasilito 106b7cb4e0 login: chdir to home (file scheme) before restricting the namespace
The login shell spawn was failing/hanging because login inherits its CWD
from init, which on the live image is on the 'initfs' scheme.
apply_login_schemes() switches to a namespace with only DEFAULT_SCHEMES
(no 'initfs'), leaving that inherited CWD fd unresolvable; relibc resolves
paths through the CWD fd (AT_REDOX_CWD_FD), so the shell child's chdir +
execve then fail with ENOENT (getty respawns login in a loop) or hang.
chdir into the user's home (on the always-present 'file' scheme, fallback
'/') while still in the full namespace, so the CWD fd stays valid after
the restriction and the shell spawns.
2026-07-18 11:01:23 +09:00
vasilito b6fb5ca2da login: drop spawn_shell CWD workaround and diagnostics
The real fix is in init (no longer leaves an initfs-scheme CWD that is
invalid in the restricted login namespace), so spawn_shell can stay
minimal again.
2026-07-18 10:43:07 +09:00
vasilito 36526f66a7 login: temporary spawn diagnostics to pinpoint shell-start hang 2026-07-18 10:26:46 +09:00
vasilito 0a1c31fd18 login: set a namespace-valid CWD before spawning the shell
After apply_login_schemes() swaps into the restricted login namespace
(only DEFAULT_SCHEMES), the CWD inherited from init on the live image is
/scheme/initfs, whose scheme is NOT in that namespace. File operations
that consult the CWD fd (notably the child's execve opening the shell
binary) then block, so the login shell never starts. chdir to the user's
home (fallback /), both on the always-present 'file' scheme, before
spawning. Also drops the temporary spawn_shell diagnostics.
2026-07-18 10:17:10 +09:00
vasilito 123649e200 login: add spawn_shell diagnostics to pinpoint shell-spawn ENOENT
Probe the shell binary and home directory in the (possibly restricted)
login namespace before spawning, and print the exact spawn error with
raw_os_error. This isolates whether a failed login shell spawn is due to
a missing binary, an unreachable cwd/home, or an exec-time error.
2026-07-18 08:08:20 +09:00
vasilito 0dc0cb73d1 Cargo.lock: regenerate after Cargo.toml version sync (branch 0.3.0 -> 0.3.1)
Cat 2 fork entries bumped: +rb0.3.0 -> +rb0.3.1
- libredox 0.1.18+rb0.3.0 -> 0.1.18+rb0.3.1
- redox-scheme 0.11.2+rb0.3.0 -> 0.11.2+rb0.3.1
- redox_syscall 0.9.0+rb0.3.0 -> 0.9.0+rb0.3.1
- userutils self 0.1.0+rb0.3.0 -> 0.1.0+rb0.3.1

Plus minor transitive patch bumps.

Part of Phase 0 fix for G1 (Cargo.lock drift).
2026-07-12 01:15:16 +03:00
vasilito 2bc1b8d5c7 userutils: apply Red Bear patches on latest upstream
- Path deps for redox_syscall, libredox, redox-scheme, relibc
- Login prompt fixes (standard C functions)
- Custom issue/motd branding
- Version suffix +rb0.3.1
- Author attribution
2026-07-11 11:35:08 +03:00
Jacob Lorentzon 2143eb7f33 Merge branch 'fix-sudo' into 'master'
fix: Set FD flag to send process fd during sudo

See merge request redox-os/userutils!64
2026-07-05 12:48:10 +02:00
Ibuki.O 8005fc0991 fix: Set FD flag to send process fd during sudo 2026-07-05 19:42:56 +09:00
Jeremy Soller 41ea648ef4 Merge branch 'libredox' into 'master'
misc: Update redox_syscall, libredox and redox-scheme

See merge request redox-os/userutils!63
2026-07-01 08:20:22 -06:00
Ibuki Omatsu c9af430c19 misc: Update redox_syscall, libredox and redox-scheme 2026-07-01 08:20:22 -06:00
Jeremy Soller dec67599f5 Merge branch 'ptyd-changes' into 'master'
getty: use standard C functions

See merge request redox-os/userutils!62
2026-06-03 19:25:21 -06:00
Connor-GH 2834434b9a getty: use standard C functions
grantpt() and unlockpt() need to be used according to the standard, even
though our grantpt is a no-op (since we auto-lock ptys as we give them
out).

This is part of my series for ptyd. This can be safely merged as long as
the relibc/ and base/ changes are merged at the same time.
2026-06-03 19:15:31 -05:00
Jeremy Soller 0c5274faa9 Merge branch 'sudo_switch_ns' into 'master'
sudo: Switch to the root namespace before execing the target process

See merge request redox-os/userutils!61
2026-03-01 07:05:31 -07:00
bjorn3 8bcdb70d76 sudo: Switch to the root namespace before execing the target process 2026-03-01 13:08:07 +01:00
Jeremy Soller 72424dd28b Merge branch 'namespace-improvement' into 'master'
Adapt sudo and getty to new namespace management, and enforce strict namespace at login.

See merge request redox-os/userutils!59
2026-01-20 20:58:27 -07:00
Ibuki Omatsu 3bdd1d9a6e Adapt sudo and getty to new namespace management, and enforce strict namespace at login. 2026-01-20 20:58:27 -07:00
Jeremy Soller 8ccf37d74a getty: determine correct tty size 2026-01-09 15:46:59 -07:00
Jeremy Soller 5375c180c4 Merge branch 'fix-compile' into 'master'
Fix compilation with newer syscall

See merge request redox-os/userutils!60
2025-12-28 06:20:48 -07:00
Wildan M 9dc487e1d8 Fix compilation with newer syscall 2025-12-28 17:40:14 +07:00
Jeremy Soller 1125042f6b Merge branch 'no_daemonize' into 'master'
Leave daemonization to init

See merge request redox-os/userutils!58
2025-11-30 07:25:24 -07:00
bjorn3 6d50c1220e Leave daemonization to init 2025-11-30 10:45:21 +01:00
Jeremy Soller 673c9bfd3e Update dependencies 2025-10-04 08:23:37 -06:00
Jeremy Soller 7316d58076 Merge branch 'minor-dependency-cleanup' into 'master'
Minor dependency cleanup

See merge request redox-os/userutils!56
2025-06-27 07:07:52 -06:00
James Matlik 6deaf4c51e Minor dependency cleanup
Fully use libredox instead of libc for all constants
2025-06-26 19:54:22 -04:00
Jeremy Soller 8ab3370d9a Merge branch 'passwd_no_setuid' into 'master'
passwd: Remove suid usage though the sudo daemon

See merge request redox-os/userutils!55
2025-04-20 19:58:06 +00:00
bjorn3 4ed8323351 passwd: Remove suid usage though the sudo daemon 2025-04-20 21:10:22 +02:00
bjorn3 cacb0dd67e passwd: Extract find_user 2025-04-20 20:54:52 +02:00
bjorn3 d514768aae passwd: Allow root to always change passwords
Previously root would need to know its own password. On Linux root can
change its own password without needing to enter its own password. It
can do so on Redox OS already anyway by directly editing /etc/shadow.
2025-04-20 20:52:24 +02:00
bjorn3 f557417ebf passwd: Extract ask_new_password 2025-04-20 20:40:37 +02:00
Jeremy Soller 479cce7b96 Merge branch 'simplify_passwd' into 'master'
passwd: Only allow locking accounts as root

See merge request redox-os/userutils!54
2025-04-20 18:36:57 +00:00
bjorn3 2e630a9f4d passwd: Only allow locking accounts as root
This is consistent with how Linux works and prevents accidentally
locking yourself out.
2025-04-20 20:23:17 +02:00
bjorn3 0a2dea6b04 passwd: Reduce code nesting and minor cleanups 2025-04-20 19:52:18 +02:00
Jeremy Soller 51d2db809f Merge branch 'su_no_setuid' into 'master'
Use the sudo daemon rather than setuid for su

See merge request redox-os/userutils!53
2025-04-20 15:22:33 +00:00
bjorn3 9c53a9a775 Use the sudo daemon rather than setuid for su 2025-04-20 16:46:50 +02:00
Jacob Lorentzon 9eadf3bb1d Merge branch 'fix_sudo' into 'master'
Fix sudo for procmgr

See merge request redox-os/userutils!52
2025-04-20 14:23:13 +00:00
bjorn3 bfd521ff49 Fix sudo for procmgr 2025-04-20 16:20:56 +02:00
Jeremy Soller 803fd8870f Merge branch 'no_setuid2' into 'master'
Introduce a sudo daemon as replacement for suid/escalated

See merge request redox-os/userutils!51
2025-04-16 15:49:21 +00:00
bjorn3 1fbb804f35 Introduce a sudo daemon as replacement for suid/escalated
This daemon will request the password of the user, check that the user
is in the sudo group and if everything checks out elevate the sudo
process to root after which the sudo process can exec the target process.
2025-04-14 20:16:33 +02:00
Jeremy Soller bd7592270d Merge branch 'cleanup' into 'master'
Various cleanups

See merge request redox-os/userutils!50
2025-04-13 20:15:18 +00:00
bjorn3 7fa1bf8df4 sudo: Simplify a bit 2025-04-13 18:03:49 +02:00
bjorn3 6a208c6b34 Rustfmt 2025-04-13 16:51:27 +02:00
bjorn3 6f2514ed95 Move to the 2024 edition 2025-04-13 16:50:06 +02:00
Jeremy Soller e3507e18bc Merge branch 'sudo_improvements' into 'master'
Cleanup the source of sudo a bit

See merge request redox-os/userutils!49
2025-03-11 21:28:12 +00:00
bjorn3 4ccec7baae sudo: Reduce indentation 2025-03-11 21:31:54 +01:00
bjorn3 88ccab8844 sudo: Rustfmt 2025-03-11 21:31:49 +01:00
Jeremy Soller dcec4b7f35 Merge branch 'deps' into 'master'
Bump dependencies

See merge request redox-os/userutils!48
2024-10-16 18:22:04 +00:00
Andrey Turkin 53992ad18c Bump dependencies 2024-10-16 21:17:20 +03:00
Jeremy Soller 7a96dab061 Merge branch 'no_legacy_scheme' into 'master'
Update redox_event and redox_users

See merge request redox-os/userutils!47
2024-08-19 16:47:45 +00:00
bjorn3 6907336a71 Update redox_event and redox_users
This remove all usages of the legacy scheme syntax
2024-08-19 18:43:15 +02:00
Jeremy Soller 97bbfc03cb Merge branch 'no_legacy_path' into 'master'
Use the new scheme format

See merge request redox-os/userutils!46
2024-07-11 23:31:57 +00:00
bjorn3 1e183ca4ba Use the new scheme format 2024-07-11 21:09:53 +02:00
Jeremy Soller 1530c8fceb Update dependencies 2024-03-31 06:58:16 -06:00
Jeremy Soller de5e7eb903 Use absolute path without scheme for default home and shell 2024-01-18 14:53:02 -07:00
Jeremy Soller b5a371be31 Do not set COLUMNS or LINES in getty 2024-01-18 14:52:13 -07:00
Jeremy Soller 5b9bb750f5 Merge branch 'use_fbcond' into 'master'
Fix for the introduction of fbcond

See merge request redox-os/userutils!45
2024-01-15 02:00:57 +00:00
bjorn3 41fde1045c Let fbcond rather than inputd handle input events 2024-01-14 18:30:51 +01:00
bjorn3 0148436174 Fix for the introduction of fbcond 2024-01-14 18:28:00 +01:00
Jeremy Soller 8071772c69 Merge branch 'contain_login' into 'master'
add option to getty to run contain_login

See merge request redox-os/userutils!44
2024-01-03 19:22:11 +00:00
Ron Williams 5cb44522f0 add option to getty to run contain_login 2023-12-19 21:00:27 -08:00
Jeremy Soller be77642b20 Merge branch 'libredox' into 'master'
Switch to libredox

See merge request redox-os/userutils!43
2023-11-05 12:57:33 +00:00
4lDO2 efd875b21e Use crates.io redox_event dependency. 2023-11-04 20:21:49 +01:00
4lDO2 8ab925eb65 Fully switch to libredox 2023-11-04 20:04:59 +01:00
4lDO2 ae3c0037d7 Update redox-daemon 2023-11-04 15:07:26 +01:00
4lDO2 8afb03544f Update redox_users. 2023-11-04 14:52:16 +01:00
4lDO2 01e612d79c Update dependencies. 2023-08-31 20:59:32 +02:00
Jeremy Soller f59cf56e6b Merge branch 'master' into 'master'
misc: getty open consumer channel to get events

See merge request redox-os/userutils!42
2023-08-02 15:11:28 +00:00
Anhad Singh 7c3c5f306e getty: make the consumer changes work with :debug
Signed-off-by: Anhad Singh <andypythonappdeveloper@gmail.com>
2023-07-22 18:15:43 +10:00
Anhad Singh 5e3956adf1 misc: getty open consumer channel to get events
Signed-off-by: Anhad Singh <andypythonappdeveloper@gmail.com>
2023-07-22 17:41:30 +10:00
Jeremy Soller 5a9cee6b22 Update libc crate 2023-02-11 14:41:07 -07:00
4lDO2 0621709286 Use redox-daemon in getty 2022-07-27 16:32:27 +02:00
Jeremy Soller f61edda364 Update Cargo.lock 2022-07-26 17:46:36 -06:00
4lDO2 cbed606ea7 Update syscall 2022-03-25 21:01:50 +01:00
4lDO2 09a04fc55b Update syscall. 2021-06-17 14:09:55 +02:00
Jeremy Soller bfa45b9da8 Update dependencies 2021-04-28 20:56:14 -06:00
Jeremy Soller 93b6791e29 Update redox_users 2021-01-26 12:52:03 -07:00
Jeremy Soller c33a464522 Update dependencies 2020-08-02 16:25:50 -06:00
Jeremy Soller 2fd54ec8d4 Update liner 2019-11-29 19:37:53 -07:00
Jeremy Soller 299d3ab37c Update dependencies 2019-10-02 20:54:46 -06:00
Jeremy Soller a208ce4aa8 Update redox_users 2019-08-07 20:00:09 -06:00
Jeremy Soller abf971b73e Update termion 2019-06-16 20:50:27 -06:00
Jeremy Soller 8d6649ec5a Merge changes from redox-unix 2019-06-15 09:34:55 -06:00
Jeremy Soller 32569c0620 Compile with LTO 2019-05-14 13:54:24 -06:00
Jeremy Soller dc387310f6 Update to new rust 2019-04-07 11:30:17 -06:00
Jeremy Soller 5b7594a64a Merge branch 'update-cargo-dot-lock' into 'master'
Update Cargo.lock

See merge request redox-os/userutils!41
2019-02-28 13:52:43 +00:00
Robin Randhawa bb0da5fa54 Update Cargo.lock
AArch64 builds broke because of a stale syscall crate ref.
2019-02-27 15:48:15 +00:00
Jeremy Soller c3e73ab0ce Update Cargo.lock 2018-10-14 19:56:48 -06:00
Jeremy Soller 957ef2ca5d Merge branch 'mggmuggins/usersv2' into 'master'
Update redox-users v0.2: Shadowfile support

See merge request redox-os/userutils!39
2018-08-17 12:24:27 +00:00
MggMuggins 48a8e2fa56 Update redox-users v0.2: Shadowfile support 2018-07-25 15:18:19 -05:00
Jeremy Soller 6635f8cb9e Update links to gitlab 2018-06-12 12:30:45 -06:00
Jeremy Soller 7d14b05a9d Merge pull request #38 from jD91mZM2/master
Support new edge-triggered model
2018-05-31 12:26:03 -06:00
jD91mZM2 3831828485 Return on EOF, don't break 2018-05-31 20:17:17 +02:00
jD91mZM2 e37ebb22f0 Support new edge-triggered model 2018-05-31 19:18:59 +02:00
Jeremy Soller 07e3c7e320 Remove debug print 2018-05-22 19:37:14 -06:00
Jeremy Soller a9ab9e18b3 Fix issues with new event method 2018-05-20 13:16:14 -06:00
Jeremy Soller f6b27be9d9 Update to new event 2018-05-20 11:08:13 -06:00
Jeremy Soller dd761d622f Merge pull request #37 from MggMuggins/master
Use Redox_users from crates.io
2018-03-28 13:19:22 -06:00
MggMuggins ba89992998 Update Cargo.lock 2018-03-28 13:37:34 -05:00
Jeremy Soller 4b32b682d4 Merge pull request #33 from MggMuggins/master
Implement Unimplemented; Bugs
2018-02-12 09:39:28 -07:00
MggMuggins 1d6b67cd42 Implement Unimplemented; Bugs
Fix a CLI bug with groupadd

Implement everything that involves removing user from groups, mostly
in userdel and usermod.
2018-02-12 09:07:17 -06:00
Jeremy Soller 235be05cf1 Merge pull request #32 from MggMuggins/master
Remove ArgParser dep, whoami
2018-02-10 11:23:46 -07:00
MggMuggins 69838054ab Remove ArgParser dep, whoami
Remove Arg parsing from sudo, (maybe in prep to deprecate in favor of
rudo)

Port login to clap-rs

Remove ArgParser dep

Remove whoami in favor of a link to id, and implemented linking in id.
2018-02-10 12:09:10 -06:00
Jeremy Soller a190dd55e3 Merge pull request #30 from MggMuggins/master
Port to clap-rs
2018-02-08 20:46:46 -07:00
MggMuggins fba0c70ae2 Port to clap-rs
I did a number of things here:

the *add, *mod, and *del utilities, as well as id recieved substantial
changes, probably what you'd call a rewrite. This was of course using
clap-rs. These should all be very stable at this point (except
unimplemented features in usermod, grr)

getty, passwd, and su are simply ported, using clap for arg parsing. I
didn't change any of the logic, just swapped ArgParser for clap.

Fixed a bug with passwd and unset passwords

I'll open issues about the ones I didn't mention.
2018-02-08 21:10:44 -06:00
Jeremy Soller e997bdd197 Merge pull request #28 from MggMuggins/master
Implement usermod, groupmod, userdel, groupdel; Fix passwd and useradd
2018-02-04 08:05:07 -07:00
MggMuggins d5e011a304 Implement usermod, groupmod, userdel, groupdel; Fix passwd and useradd
Here I've implemented the remainder of the core user utilities present
on most unix systems. They aren't particularly pretty, but they do work
for the most part.

Note that for some reason attempting to move the home directory of a
user via usermod -m does not work.

Also removing user's that have been deleted from groups is not yet
implemented, nor is updating /etc/passwd when a group id is changed.

Note that redox_users as used by Cargo.lock as of this commit is broken,
and may not work properly. If redox-os/users#11 is merged, cargo update
should fix.
2018-02-03 19:10:39 -06:00
Jeremy Soller 7bb8dea121 Merge pull request #27 from MggMuggins/master
Fix #26
2018-01-30 16:57:03 -07:00
MggMuggins cbb7f52381 Fix #26 2018-01-30 17:41:16 -06:00
Jeremy Soller b335c59e7e Merge pull request #25 from MggMuggins/master
Port to redox_users break-api
2018-01-29 19:47:32 -07:00
MggMuggins bc0dc6488b Update Cargo.lock; Fix su 2018-01-29 20:44:08 -06:00
MggMuggins 5e53b4b161 Port to redox_users break-api
All the utilities use the new API I defined in mu recent PR to
redox_users. `su`'s behavior was also fixed.

I also updated Cargo.toml (removing unused deps). This may require
another commit after my first PR is merged in order to appropriately
update Cargo.lock and make sure everything builds.
2018-01-29 16:39:52 -06:00
Jeremy Soller 02759b4a5a Fix bug causing ctrl-d to log in any user with su
Document su's logic
Return error code of shell from su
2018-01-22 08:01:02 -07:00
Jeremy Soller 5765da1ed9 Merge pull request #22 from goyox86/goyox86/unwrap_or_exit
Using new 'unwrap_or_exit' from libextra.
2017-12-15 12:40:50 -07:00
Jose Narvaez 0e327d8124 Using new 'unwrap_or_exit' from libextra. 2017-12-15 18:31:25 +00:00
Jeremy Soller 52cae8be05 Merge pull request #21 from MggMuggins/master
Add additional flags to user and groupadd; Update Cargo files
2017-12-10 07:26:59 -07:00
MggMuggins 0b8f40c234 Add additional flags to user and groupadd; Update Cargo files 2017-12-09 22:06:47 -06:00
Jeremy Soller 0db7c527a7 Merge pull request #20 from goyox86/goyox86/better-errors
Goyox86/better errors
2017-12-09 13:59:01 -07:00
Jose Narvaez cf8f7f3a25 Oops, commited local paths. Fixed. 2017-12-01 23:44:03 +00:00
Jose Narvaez fd81487760 Updated to new error types from redox_users and simplefied the inspection and downcasting of the error on login. 2017-12-01 23:16:14 +00:00
Jose Narvaez 13681c3442 Moved to new error hadling of . 2017-11-30 22:41:57 +00:00
Jeremy Soller 00eaa34aa6 Merge pull request #19 from fraang/master
Add missing included utility, add missing word
2017-11-29 06:30:14 -07:00
Florian R. A. Angermeier 0b1b978755 Add missing included utility, add missing word 2017-11-29 10:09:19 +01:00
Jeremy Soller dcf35e3548 Merge pull request #17 from MggMuggins/master
Implemented groupadd, fix for passwd compile
2017-11-28 21:12:39 -07:00
MggMuggins 65817077ee Cargo.lock update 2017-11-28 22:10:45 -06:00
MggMuggins d9d3635916 Implemented useradd; groupadd fix 2017-11-28 21:39:20 -06:00
MggMuggins 464b5c4aa5 Small fixes to better mesh with redox_users changes 2017-11-27 17:53:11 -06:00
MggMuggins 8fffeb1e57 Implemented groupadd, fix for passwd compile 2017-11-26 16:53:37 -06:00
Jeremy Soller 6b951a8bdc Merge pull request #15 from goyox86/goyox86-readme
README and docs tweaks.
2017-11-08 16:40:02 -07:00
Jose Narvaez 31d217b375 README and docs tweaks. 2017-11-08 23:23:00 +00:00
Jeremy Soller a857871fd8 Merge pull request #14 from goyox86/goyox86-redox-users
Migrated to `redox_users` and some refactoring and docs.
2017-11-08 16:09:24 -07:00
Jose Narvaez 0ed14bec6d Migrated to redox_users and some refactoring and docs.
Details

- Updated dependencies with `redox_users`.
- Migrated all user/group dependent functionality to calls to `redox_users`.
- Added top level documentation to the crate.
- Added a `spawn_shell` function to reuse a bit of code.
- `login`: Handled the case of an invalid login with "Login incorrect" (as in BSD).
- `passwd`: Refactored a bit and used `eprintln!` where possible.
- `su`: Refactored a bit and used `eprintln!` where possible.
- `sudo`: Refactored a bit to simplify logic also used `eprintln!` where possible.
- `whoami`: Refactored a bit and used `eprintln!/println!` where possible.
- Also added myself on the AUTHORS section :).
2017-11-08 22:49:00 +00:00
Jeremy Soller 28d097dbf3 Fix man pages 2017-10-14 08:49:19 -06:00
Jeremy Soller 1f9042f47c Update Cargo.lock 2017-10-11 20:54:45 -06:00
Jeremy Soller a1d096b0bf Update Cargo.lock 2017-10-04 20:29:41 -06:00
Jeremy Soller 712eb2967b Merge pull request #13 from andre-richter/master
Fix unused extern crates
2017-08-31 07:04:00 -06:00
Andre Richter 2a6615d343 Fix unused extern crates 2017-08-31 11:36:30 +02:00
Jeremy Soller bc31f4d490 Update Cargo.lock and Cargo.toml 2017-08-19 14:51:08 -06:00
Jeremy Soller aeda1ae4b4 Update Cargo.lock 2017-08-02 21:13:16 -06:00
Jeremy Soller d811d8758c Update password read to new method 2017-08-02 21:09:36 -06:00
Jeremy Soller f6fd552f45 Replace termion 2017-08-02 19:42:00 -06:00
Jeremy Soller d0e22dd165 Update Cargo.lock 2017-07-29 08:25:08 -06:00
Jeremy Soller c05f37f653 Merge pull request #10 from goyox86/goyox86/login-improvements
Revisited `login`.
2017-07-27 11:26:23 -06:00
Jeremy Soller 7cdd6c7e18 Merge pull request #11 from goyox86/goyox86/revisiting-su
Revisited `su`.
2017-07-26 17:02:04 -06:00
Jeremy Soller 8f0b9afac2 Merge pull request #12 from goyox86/goyox86/revisiting-passwd
Revisiting `passwd`.
2017-07-26 17:01:21 -06:00
Jose Narvaez 1aa558e205 Some improvements to login
- Added constants for standard file paths.
- Improved error reporting when opening the files.
- Used `Passwd::parse_file` instead of doing it manually.
- Removed all the calls to unwrap().
- Used `fail` to report errors and exit when possible.
2017-07-26 21:37:13 +01:00
Jose Narvaez 80e085e7f0 Revisiting passwd
- Replaced all `unwrap()` calls by `try()`.
- Replaced all `panic()` calls by `fail()`.
- Argument parsing is now all done by `ArgParser`.
- Used `Passwd::parse_file` where possible.
- This actually does not change the password, will be the next job.
2017-07-26 21:12:10 +01:00
Jose Narvaez b42b6dd835 Revisited su.
Details

- Moved cmd line args parsing to `ArgParser`.
- All the calls to `panic!` were replaced by calls to `fail`.
- Revisited synopsis in the docs.
- Using `try` where possible.
- Using `Passwd::parse_file` instead of doing it manually.
- Handled errors while parsing passwd file.
- Added some constants.
2017-07-26 20:41:05 +01:00
Jeremy Soller 1725b377cd Add Cargo.lock file 2017-07-26 08:04:04 -06:00
Jeremy Soller e35d0bc6cd Add Cargo.lock 2017-07-26 08:00:41 -06:00
Jeremy Soller 83d77f8124 Use PTY in getty to provide line control for raw consoles and vesad 2017-07-24 20:58:30 -06:00
Jeremy Soller 4e2561ed75 Correctly exit when parent, not child 2017-07-20 20:37:40 -06:00
Jeremy Soller ad00ba9eae Merge pull request #9 from goyox86/goyox86/getty-improved
Some improvements to `getty`
2017-07-20 17:54:08 -06:00
Jose Narvaez d4de8c0b79 Some improvements to getty
- Improved error handling over all.
- Switched to argument parsing by `ArgParser`.
- Replaced panics by calls to `fail.
- Removed unwraps ignoring results of syscalls when clearing the screen
and flushing stdout.
- Added docs for 'noclear' option.
- The current implementation was receiving n arguments and was
considering only the last one as the TTY this new one checks that we
have at least one and always use the first one.
- Added constants for columns and lines.
- Daemon receiver a reference to stderr to setup error reporting inside
there.
2017-07-20 23:49:37 +01:00
Jeremy Soller 73995693f6 Merge pull request #8 from goyox86/goyox86/some-tweaks
Some tweaks to the `id` docs and copy-pasta typos.
2017-07-20 11:47:53 -06:00
Jose Narvaez 4a4c45a7a7 Some tweaks to the id docs and copy-pasta typos.
Details

- Added docs for the `-r` flag of `id` also reindented to 80 cols.
- Fixed a typo on `getty`.
2017-07-20 17:34:06 +01:00
Jeremy Soller 6d5e183c81 Merge pull request #7 from goyox86/some-love
Some love to userutils \o/
2017-07-19 18:02:13 -06:00
Jose Narvaez ef5fdc82a0 Improved id and whoami.
Details

- New implementation of `id` inspired by BSD's one.
- Refactoring on `whoami`.
- Added few utility functions in `userutils` for getting processes user and group
real/effective ID and names.

Added docs do `getty`, `login`, `passwd`, `su`, and `sudo`.

Details

- The docs are from BSD's ones.
- Also added `ArgParser` to all of them and added a -h/--help flag
to all of them.
- This is the start of a revision of all of those commands.
2017-07-19 18:06:48 +01:00
Jeremy Soller e70be16a48 Merge pull request #6 from goyox86/whoami-improved
whoami improved and a bit of love to the crate.
2017-07-16 18:59:20 -06:00
Jose Narvaez 0d0f726277 Updated deps. 2017-07-16 22:49:58 +01:00
Jose Narvaez 3a06dbbc8e Implemented whoami on top of system calls.
Details

- The current implementataion the `whoami` utility relies
on a env var to determine the user. With this change we get
the effective user id of the context and lookup that id on
/etc/passwd.
- Added the Redox `libextra` dependency as it has some goodies
for error handling. This will allow to make this crate upto date
with `coreutils` practices.
- Added a new small `arg_parser` crate that was extracted from
`coreutils` as is now commen between `coreutils` and here.
2017-07-16 17:47:18 +01:00
Jeremy Soller 3ca18917f8 Update to use sudo password 2017-04-06 21:05:46 -06:00
Jeremy Soller 1ee223f926 Better error messages for sudo 2017-02-27 15:34:35 -07:00
Jeremy Soller b1e0ae8722 Fix issue with variable not passed to daemon 2017-02-07 20:39:07 -07:00
Jeremy Soller 880c664a24 Better failure detection in getty 2017-02-07 20:38:21 -07:00
Jeremy Soller bb463a8f02 Merge pull request #2 from xTibor/implement_whoami
Implement whoami
2017-01-15 21:19:50 -07:00
xTibor 63985a11ff Implement whoami 2017-01-16 00:19:24 +01:00
Jeremy Soller 2011976381 Use source from crates.io 2017-01-13 15:06:38 -07:00
Jeremy Soller 2fdef17559 Use liner to get username 2017-01-12 19:12:59 -07:00
Jeremy Soller ccae9c0b0a Correctly set environment 2017-01-10 09:50:23 -07:00
Jeremy Soller 13ef8943df Fix UID, GROUPS setting 2017-01-10 09:46:02 -07:00
Jeremy Soller 6208a242f6 Merge branch 'master' of https://github.com/redox-os/userutils 2017-01-10 09:44:58 -07:00
Jeremy Soller 4a7d61eb1c Set other environmental variables 2017-01-10 09:44:43 -07:00
Jeremy Soller 8083f84cbc Add resource directory 2017-01-09 17:16:38 -07:00
Jeremy Soller 901caafce3 Use upstream argon2rs 2016-12-29 07:52:11 -07:00
Jeremy Soller 45cb3e8208 Add clear argument 2016-12-19 21:38:00 -07:00
Jeremy Soller 095a5baafa Do not checkout rand 2016-12-10 22:03:02 -07:00
Jeremy Soller 80379e0eae Remove replacement for libc 2016-12-06 15:14:53 -07:00
Jeremy Soller 56da6a40b0 Manually enter/exit raw mode 2016-11-20 11:59:08 -07:00
Jeremy Soller 5f9ff4d19e Remove cargo.lock 2016-11-16 21:32:05 -07:00
Jeremy Soller d44639145b Update syscall 2016-11-15 17:05:49 -07:00
Jeremy Soller 6305f222ad Update syscall 2016-11-15 16:01:51 -07:00
Jeremy Soller ba16f79ada Update syscall 2016-11-14 12:16:28 -07:00
Jeremy Soller b59deda452 Update syscall 2016-11-10 21:08:56 -07:00
Jeremy Soller 48938fa3fd Use clone instead of threading to daemonize 2016-11-10 20:09:15 -07:00
Jeremy Soller 61203b6a72 Update libc 2016-11-10 11:29:36 -07:00
Jeremy Soller 69a21ddd1f Use upstream rand! 2016-11-09 10:31:31 -07:00
Jeremy Soller 30187e1c64 WIP passwd implementation 2016-11-08 11:54:10 -07:00
Jeremy Soller 7511f6dd5a Update rand 2016-11-07 11:27:45 -07:00
Jeremy Soller 24859cb7a6 Update syscall 2016-11-04 13:47:32 -06:00
Jeremy Soller 8a7f4bba83 Update libc 2016-11-03 17:39:57 -06:00
Jeremy Soller 98d7b64a16 Update libc 2016-11-03 17:17:07 -06:00
Jeremy Soller d765b381f8 Update redox_syscall 2016-11-03 15:09:46 -06:00
Jeremy Soller 0073f5695e Use syscall git 2016-11-03 13:50:34 -06:00
Jeremy Soller f27ed41bcb Use fmap, fix syscall crate name 2016-11-02 19:47:24 -06:00
Jeremy Soller 359fe4b018 Use crate of redox_syscall 2016-11-02 19:37:44 -06:00
Jeremy Soller 5ae17129d3 Use syscall from git 2016-10-31 13:33:22 -06:00
Jeremy Soller ad314add6a Update termion 2016-10-26 13:55:29 -06:00
Jeremy Soller afac2a3ccc Reenable clear in getty 2016-10-24 14:21:21 -06:00
Jeremy Soller 46631df4f0 Use OsRng to get random data for seed 2016-10-24 14:07:55 -06:00
Jeremy Soller d32f2dc10e Correctly use salt 2016-10-24 13:12:58 -06:00
Jeremy Soller e0fe388ccf Switch to argon2: WIP 2016-10-24 12:22:13 -06:00
Jeremy Soller a05b8f4d25 Update libc 2016-10-15 21:12:03 -06:00
Jeremy Soller 3b7448c8fd Path does not have to be set by login 2016-10-14 21:10:41 -06:00
Jeremy Soller b556eefe60 Remove qeustion marks 2016-10-14 17:57:27 -06:00
Jeremy Soller 17896532dc Skip display number 2016-10-07 19:24:10 -06:00
Jeremy Soller eaf26765c1 Add su 2016-10-07 10:42:00 -06:00
Jeremy Soller 860c1f5f25 Initial commit 2016-10-07 10:19:08 -06:00
49 changed files with 2482 additions and 13769 deletions
-3
View File
@@ -1,4 +1 @@
pkg
sysroot
/target/
/test.bin
-34
View File
@@ -1,34 +0,0 @@
stages:
- lint
- test
workflow:
rules:
- if: '$CI_COMMIT_BRANCH == "master"'
- if: '$CI_MERGE_REQUEST_TARGET_BRANCH_NAME == "master"'
fmt:
image: "rust:latest"
stage: lint
script:
- rustup component add rustfmt
- cargo fmt -- --check
- cd gui && cargo fmt -- --check
cargo-test:
image: "rust:latest"
stage: test
script:
- apt update && apt install -y fuse3 libfuse3-dev
- cargo build --locked
- cargo test
- ./target/debug/redox_installer -c res/test.toml test.bin --no-mount
gui-build:
stage: test
script:
- apt update && apt install -y fuse3 libfuse3-dev
- cd gui
- redoxer build
- cargo build
+6
View File
@@ -0,0 +1,6 @@
language: rust
rust:
- nightly
sudo: false
notifications:
email: false
-3
View File
@@ -1,3 +0,0 @@
# format_bytes_inner was intentionally inlined as nested fn inner()
# inside format_bytes() in lib.rs — RB refactoring, not a bug.
src/installer.rs:format_bytes_inner
Generated
+180 -2208
View File
File diff suppressed because it is too large Load Diff
+67 -61
View File
@@ -1,76 +1,82 @@
[package]
name = "redox_installer"
version = "0.2.42+rb0.3.1"
description = "A Redox filesystem builder"
license = "MIT"
name = "userutils"
version = "0.1.0+rb0.3.1"
authors = ["Jeremy Soller <jackpot51@gmail.com>", "vasilito <adminpupkin@gmail.com>"]
repository = "https://gitlab.redox-os.org/redox-os/installer"
default-run = "redox_installer"
edition = "2021"
edition = "2024"
[[bin]]
name = "redox_installer"
path = "src/bin/installer.rs"
required-features = ["installer"]
name = "id"
path = "src/bin/id.rs"
[[bin]]
name = "redox_installer_tui"
path = "src/bin/installer_tui.rs"
required-features = ["installer"]
name = "getty"
path = "src/bin/getty.rs"
[lib]
name = "redox_installer"
path = "src/lib.rs"
[[bin]]
name = "groupadd"
path = "src/bin/groupadd.rs"
[[bin]]
name = "groupdel"
path = "src/bin/groupdel.rs"
[[bin]]
name = "groupmod"
path = "src/bin/groupmod.rs"
[[bin]]
name = "login"
path = "src/bin/login.rs"
[[bin]]
name = "passwd"
path = "src/bin/passwd.rs"
[[bin]]
name = "su"
path = "src/bin/su.rs"
[[bin]]
name = "sudo"
path = "src/bin/sudo.rs"
[[bin]]
name = "useradd"
path = "src/bin/useradd.rs"
[[bin]]
name = "userdel"
path = "src/bin/userdel.rs"
[[bin]]
name = "usermod"
path = "src/bin/usermod.rs"
[dependencies]
anyhow = "1"
arg_parser = "0.1.0"
fatfs = { version = "0.3.0", optional = true }
fscommon = { version = "0.1.1", optional = true }
gpt = { version = "3.0.0", optional = true }
libc = { version = "0.2.70", optional = true }
pkgar = { version = "0.2.2", optional = true }
pkgar-core = { version = "0.2.2", optional = true }
pkgar-keys = { version = "0.2.2", optional = true }
rand = { version = "0.9", optional = true }
redox-pkg = { version = "0.3.1", features = ["indicatif"], optional = true }
redox_syscall = { path = "../syscall", optional = true }
redoxfs = { path = "../redoxfs", optional = true, default-features = false, features = ["std", "log"] }
rust-argon2 = { version = "3", optional = true }
serde = "1"
serde_derive = "1.0"
termion = { version = "4", optional = true }
toml = "0.8"
uuid = { version = "1.4", features = ["v4"], optional = true }
clap = "2.33.0"
extra = { git = "https://gitlab.redox-os.org/redox-os/libextra.git" }
orbclient = "0.3.47"
plain = "0.2.3"
redox_liner = "0.5.2"
libredox = { path = "../libredox", features = ["mkns"] }
redox_termios = "0.1.3"
redox_event = "0.4.3"
redox-scheme = { path = "../redox-scheme" }
redox_syscall = { path = "../syscall" }
redox_users = "0.4.6"
termion = "4"
libc = "0.2"
serde = { version = "1.0.203", features = ["derive"] }
toml = "0.8.11"
ioslice = "0.6"
[target.'cfg(target_os = "redox")'.dependencies]
libredox = { path = "../libredox", optional = true }
ring = { version = "=0.17.8", optional = true }
[features]
default = ["installer", "fuse"]
installer = [
"fatfs",
"fscommon",
"gpt",
"libc",
"libredox",
"pkgar",
"pkgar-core",
"pkgar-keys",
"rand",
"redox-pkg",
"redox_syscall",
"redoxfs",
"ring",
"rust-argon2",
"termion",
"uuid",
]
fuse = ["redoxfs/fuse"]
redox-rt = { path = "../relibc/redox-rt", default-features = false }
[patch.crates-io]
# https://github.com/briansmith/ring/issues/1999
ring = { git = "https://gitlab.redox-os.org/redox-os/ring.git", branch = "redox-0.17.8" }
redox_syscall = { path = "../syscall" }
libredox = { path = "../libredox" }
redox-scheme = { path = "../redox-scheme" }
[profile.release]
lto = true
+2 -2
View File
@@ -1,6 +1,6 @@
MIT License
The MIT License (MIT)
Copyright (c) 2017 Redox OS
Copyright (c) 2016 The Redox developers
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
+19 -45
View File
@@ -1,50 +1,24 @@
# Redox OS installer
# Redox OS user and group utilities.
The Redox installer will allow you to produce a Redox OS image. You will
be able to specify:
- Output device (raw image, ISO, QEMU, VirtualBox, drive)
- Filesystem
- Included packages
- Method of installation (from source, from binary)
- User accounts
The `userutils` crate contains the utilities for dealing with users and groups in Redox OS.
They are heavily influenced by UNIX and are, when needed, tailored to specific Redox use cases.
You will be prompted to install dependencies, based on your OS and method of
installation. The easiest method is to install from binaries.
These implementations strive to be as simple as possible drawing particular
inspiration by BSD systems. They are indeed small, by choice.
## Usage
[![Travis Build Status](https://travis-ci.org/redox-os/userutils.svg?branch=master)](https://travis-ci.org/redox-os/userutils)
It is recommended to compile with `cargo`, in release mode:
```bash
cargo build --release
```
**Currently included:**
By default, you will be prompted to supply configuration options. You can
use the scripted mode by supplying a configuration file:
```bash
cargo run --release -- config/example.toml
```
An example configuration can be found in [config/example.toml](./config/example.toml).
Unsuplied configuration will use the default. You can use the `general.prompt`
setting to prompt when configuration is not set. Multiple configurations can
be specified, they will be built in order.
## Embedding
The installer can also be used inside of other crates, as a library:
```toml
# Cargo.toml
[dependencies]
redox_installer = "0.1"
```
```rust
// src/main.rs
extern crate redox_installer;
fn main() {
let mut config = redox_installer::Config::default();
...
redox_installer::install(config);
}
```
- `getty`: Used by `init(8)` to open and initialize the TTY line, read a login name and invoke `login(1)`.
- `id`: Displays user identity.
- `login`: Allows users to login into the system
- `passwd`: Allows users to modify their passwords.
- `su`: Allows users to substitute identity.
- `sudo`: Enables users to execute a command as another user.
- `useradd`: Add a user
- `usermod`: Modify user information
- `userdel`: Delete a user
- `groupadd`: Add a user group
- `groupmod`: Modify group information
- `groupdel`: Remove a user group
-174
View File
@@ -1,174 +0,0 @@
# This is the default configuration file
# General settings
[general]
# Do not prompt if settings are not defined
prompt = false
# Package settings
[packages]
#acid = {}
#autoconf = {}
#automake = {}
#bash = {}
#binutils = {}
#ca-certificates = {}
#cargo = {}
#contain = {}
coreutils = {}
#curl = {}
#dash = {}
#diffutils = {}
drivers = {}
extrautils = {}
findutils = {}
#games = {}
#gawk = {}
#gcc = {}
#git = {}
#gnu-binutils = {}
#gnu-make = {}
#installer = {}
ion = {}
#lua = {}
#nasm = {}
netstack = {}
netutils = {}
#newlib = {}
#openssl = {}
orbdata = {}
orbital = {}
orbterm = {}
orbutils = {}
pastel = {}
#patch = {}
#pixelcannon = {}
pkgutils = {}
ptyd = {}
#python = {}
randd = {}
#redoxfs = {}
#rust = {}
#rustual-boy = {}
#sed = {}
smith = {}
sodium = {}
userutils = {}
uutils = {}
#xz = {}
# User settings
[users.root]
password = "password"
uid = 0
gid = 0
name = "root"
home = "/root"
[users.user]
# Password is unset
password = ""
[groups.sudo]
gid = 1
members = ["user"]
[[files]]
path = "/etc/init.d/00_base"
data = """
pcid /etc/pcid/filesystem.toml
randd
ptyd
"""
[[files]]
path = "/etc/init.d/10_net"
data = """
ethernetd
ipd
icmpd
tcpd
udpd
dhcpd -b
"""
[[files]]
path = "/etc/init.d/20_orbital"
data = """
orbital orblogin launcher
"""
[[files]]
path = "/etc/init.d/30_console"
data = """
getty display/vesa:2
getty debug: -J
"""
[[files]]
path = "/etc/net/dns"
data = """
208.67.222.222
"""
[[files]]
path = "/etc/net/ip"
data = """
10.0.2.15
"""
[[files]]
path = "/etc/net/ip_router"
data = """
10.0.2.2
"""
[[files]]
path = "/etc/net/ip_subnet"
data = """
255.255.255.0
"""
[[files]]
path = "/etc/net/mac"
data = """
54-52-00-ab-cd-ef
"""
[[files]]
path = "/etc/pkg.d/50_redox"
data = "https://static.redox-os.org/pkg"
[[files]]
path = "/etc/hostname"
data = "redox"
[[files]]
path = "/etc/issue"
data = """
########## Redox OS ##########
# Login with the following: #
# `user` #
# `root`:`password` #
##############################
"""
[[files]]
path = "/etc/motd"
data = """
Welcome to Redox OS!
"""
[[files]]
path = "/usr"
data = "/"
symlink = true
[[files]]
path = "/tmp"
data = ""
directory = true
# 0o1777
mode = 1023
-24
View File
@@ -1,24 +0,0 @@
# This is the default configuration file
# General settings
[general]
# Do not prompt if settings are not defined
prompt = false
# Package settings
[packages]
binutils = {}
coreutils = {}
extrautils = {}
ion = {}
netutils = {}
pkgutils = {}
userutils = {}
# User settings
[users.root]
password = "password"
uid = 0
gid = 0
name = "root"
home = "/root"
-1
View File
@@ -1 +0,0 @@
/target/
-7016
View File
File diff suppressed because it is too large Load Diff
-31
View File
@@ -1,31 +0,0 @@
[package]
name = "redox_installer_gui"
version = "0.1.0"
edition = "2021"
[dependencies]
anyhow = "1"
pkgar = "0.2"
pkgar-core = "0.2"
pkgar-keys = "0.2"
redox_installer = { path = ".." }
redox_syscall = "0.9"
toml = "0.8"
# TODO: remove after pkgutils update
futures-channel = "0.3.32"
[target.'cfg(target_os = "redox")'.dependencies]
libredox = "0.1"
[target.'cfg(target_os = "linux")'.dependencies]
libc = "0.2"
[dependencies.libcosmic]
git = "https://github.com/pop-os/libcosmic.git"
# use the same rev with other cosmic app
rev = "bb10afd849f1ad172be6b78eeec347d548aa4fd7"
default-features = false
features = ["winit"]
[patch.crates-io]
ring = { git = "https://gitlab.redox-os.org/redox-os/ring.git", branch = "redox-0.17.8" }
-92
View File
@@ -1,92 +0,0 @@
# installer_gui
## Getting started
To make it easy for you to get started with GitLab, here's a list of recommended next steps.
Already a pro? Just edit this README.md and make it your own. Want to make it easy? [Use the template at the bottom](#editing-this-readme)!
## Add your files
- [ ] [Create](https://docs.gitlab.com/ee/user/project/repository/web_editor.html#create-a-file) or [upload](https://docs.gitlab.com/ee/user/project/repository/web_editor.html#upload-a-file) files
- [ ] [Add files using the command line](https://docs.gitlab.com/ee/gitlab-basics/add-file.html#add-a-file-using-the-command-line) or push an existing Git repository with the following command:
```
cd existing_repo
git remote add origin https://gitlab.redox-os.org/redox-os/installer_gui.git
git branch -M main
git push -uf origin main
```
## Integrate with your tools
- [ ] [Set up project integrations](https://gitlab.redox-os.org/redox-os/installer_gui/-/settings/integrations)
## Collaborate with your team
- [ ] [Invite team members and collaborators](https://docs.gitlab.com/ee/user/project/members/)
- [ ] [Create a new merge request](https://docs.gitlab.com/ee/user/project/merge_requests/creating_merge_requests.html)
- [ ] [Automatically close issues from merge requests](https://docs.gitlab.com/ee/user/project/issues/managing_issues.html#closing-issues-automatically)
- [ ] [Enable merge request approvals](https://docs.gitlab.com/ee/user/project/merge_requests/approvals/)
- [ ] [Automatically merge when pipeline succeeds](https://docs.gitlab.com/ee/user/project/merge_requests/merge_when_pipeline_succeeds.html)
## Test and Deploy
Use the built-in continuous integration in GitLab.
- [ ] [Get started with GitLab CI/CD](https://docs.gitlab.com/ee/ci/quick_start/index.html)
- [ ] [Analyze your code for known vulnerabilities with Static Application Security Testing(SAST)](https://docs.gitlab.com/ee/user/application_security/sast/)
- [ ] [Deploy to Kubernetes, Amazon EC2, or Amazon ECS using Auto Deploy](https://docs.gitlab.com/ee/topics/autodevops/requirements.html)
- [ ] [Use pull-based deployments for improved Kubernetes management](https://docs.gitlab.com/ee/user/clusters/agent/)
- [ ] [Set up protected environments](https://docs.gitlab.com/ee/ci/environments/protected_environments.html)
***
# Editing this README
When you're ready to make this README your own, just edit this file and use the handy template below (or feel free to structure it however you want - this is just a starting point!). Thank you to [makeareadme.com](https://www.makeareadme.com/) for this template.
## Suggestions for a good README
Every project is different, so consider which of these sections apply to yours. The sections used in the template are suggestions for most open source projects. Also keep in mind that while a README can be too long and detailed, too long is better than too short. If you think your README is too long, consider utilizing another form of documentation rather than cutting out information.
## Name
Choose a self-explaining name for your project.
## Description
Let people know what your project can do specifically. Provide context and add a link to any reference visitors might be unfamiliar with. A list of Features or a Background subsection can also be added here. If there are alternatives to your project, this is a good place to list differentiating factors.
## Badges
On some READMEs, you may see small images that convey metadata, such as whether or not all the tests are passing for the project. You can use Shields to add some to your README. Many services also have instructions for adding a badge.
## Visuals
Depending on what you are making, it can be a good idea to include screenshots or even a video (you'll frequently see GIFs rather than actual videos). Tools like ttygif can help, but check out Asciinema for a more sophisticated method.
## Installation
Within a particular ecosystem, there may be a common way of installing things, such as using Yarn, NuGet, or Homebrew. However, consider the possibility that whoever is reading your README is a novice and would like more guidance. Listing specific steps helps remove ambiguity and gets people to using your project as quickly as possible. If it only runs in a specific context like a particular programming language version or operating system or has dependencies that have to be installed manually, also add a Requirements subsection.
## Usage
Use examples liberally, and show the expected output if you can. It's helpful to have inline the smallest example of usage that you can demonstrate, while providing links to more sophisticated examples if they are too long to reasonably include in the README.
## Support
Tell people where they can go to for help. It can be any combination of an issue tracker, a chat room, an email address, etc.
## Roadmap
If you have ideas for releases in the future, it is a good idea to list them in the README.
## Contributing
State if you are open to contributions and what your requirements are for accepting them.
For people who want to make changes to your project, it's helpful to have some documentation on how to get started. Perhaps there is a script that they should run or some environment variables that they need to set. Make these steps explicit. These instructions could also be useful to your future self.
You can also document commands to lint the code or run tests. These steps help to ensure high code quality and reduce the likelihood that the changes inadvertently break something. Having instructions for running tests is especially helpful if it requires external setup, such as starting a Selenium server for testing in a browser.
## Authors and acknowledgment
Show your appreciation to those who have contributed to the project.
## License
For open source projects, say how it is licensed.
## Project status
If you have run out of energy or time for your project, put a note at the top of the README saying that development has slowed down or stopped completely. Someone may choose to fork your project or volunteer to step in as a maintainer or owner, allowing your project to keep going. You can also make an explicit request for maintainers.
-634
View File
@@ -1,634 +0,0 @@
use anyhow::format_err;
use cosmic::{
app::{self, Task},
iced::{
self, executor,
futures::sink::SinkExt,
widget::{row, text_input},
window, Alignment, Size, Subscription,
},
widget::{button, column, progress_bar, radio, space, text},
Application, ApplicationExt, Core, Element,
};
use futures_channel::mpsc;
use pkgar::{ext::EntryExt, PackageHead};
use pkgar_core::PackageSrc;
use pkgar_keys::PublicKeyFile;
use redox_installer::{try_fast_install, with_redoxfs_mount, with_whole_disk, Config, DiskOption};
use std::{
ffi::OsStr,
fs,
io::{self, Read, Write},
os::unix::fs::{symlink, MetadataExt, OpenOptionsExt},
path::Path,
sync::Arc,
};
mod sys;
pub use sys::*;
fn main() -> iced::Result {
let mut settings = app::Settings::default();
settings = settings.size(Size::new(608.0, 416.0));
settings = settings.exit_on_close(false);
app::run::<Window>(settings, ())
}
fn copy_file(src: &Path, dest: &Path, buf: &mut [u8]) -> anyhow::Result<()> {
if let Some(parent) = dest.parent() {
// Parent may be a symlink
if !parent.is_symlink() {
match fs::create_dir_all(&parent) {
Ok(()) => (),
Err(err) => {
return Err(format_err!(
"failed to create directory {}: {}",
parent.display(),
err
));
}
}
}
}
let metadata = match fs::symlink_metadata(&src) {
Ok(ok) => ok,
Err(err) => {
return Err(format_err!(
"failed to read metadata of {}: {}",
src.display(),
err
));
}
};
if metadata.file_type().is_symlink() {
let real_src = match fs::read_link(&src) {
Ok(ok) => ok,
Err(err) => {
return Err(format_err!(
"failed to read link {}: {}",
src.display(),
err
));
}
};
match symlink(&real_src, &dest) {
Ok(()) => (),
Err(err) => {
return Err(format_err!(
"failed to copy link {} ({}) to {}: {}",
src.display(),
real_src.display(),
dest.display(),
err
));
}
}
} else {
let mut src_file = match fs::File::open(&src) {
Ok(ok) => ok,
Err(err) => {
return Err(format_err!(
"failed to open file {}: {}",
src.display(),
err
));
}
};
let mut dest_file = match fs::OpenOptions::new()
.write(true)
.create_new(true)
.mode(metadata.mode())
.open(&dest)
{
Ok(ok) => ok,
Err(err) => {
return Err(format_err!(
"failed to create file {}: {}",
dest.display(),
err
));
}
};
loop {
let count = match src_file.read(buf) {
Ok(ok) => ok,
Err(err) => {
return Err(format_err!(
"failed to read file {}: {}",
src.display(),
err
));
}
};
if count == 0 {
break;
}
match dest_file.write_all(&buf[..count]) {
Ok(()) => (),
Err(err) => {
return Err(format_err!(
"failed to write file {}: {}",
dest.display(),
err
));
}
}
}
}
Ok(())
}
fn package_files(
root_path: &Path,
config: &mut Config,
files: &mut Vec<String>,
) -> Result<(), anyhow::Error> {
//TODO: Remove packages from config where all files are located (and have valid shasum?)
config.packages.clear();
let pkey_path = "pkg/id_ed25519.pub.toml";
let pkey = PublicKeyFile::open(&root_path.join(pkey_path))?.pkey;
files.push(pkey_path.to_string());
for item_res in fs::read_dir(&root_path.join("pkg"))? {
let item = item_res?;
let pkg_path = item.path();
if pkg_path.extension() == Some(OsStr::new("pkgar_head")) {
let mut pkg = PackageHead::new(&pkg_path, &root_path, &pkey)?;
for entry in pkg.read_entries()? {
files.push(entry.check_path()?.to_str().unwrap().to_string());
}
files.push(
pkg_path
.strip_prefix(root_path)
.unwrap()
.to_str()
.unwrap()
.to_string(),
);
}
}
Ok(())
}
fn install<F: FnMut(Message)>(disk_path: String, password_opt: Option<String>, mut f: F) {
let start = std::time::Instant::now();
let mut progress = 0;
macro_rules! message {
($($arg:tt)*) => {{
eprintln!($($arg)*);
f(Message::Install(
progress,
format!($($arg)*)
));
}}
}
let root_path = Path::new("/scheme/file/");
message!("Loading bootloader");
let bootloader_bios = {
let path = root_path.join("boot").join("bootloader.bios");
if path.exists() {
match fs::read(&path) {
Ok(ok) => ok,
Err(err) => {
f(Message::Error(format!(
"{}: failed to read: {}",
path.display(),
err
)));
return;
}
}
} else {
Vec::new()
}
};
message!("Loading bootloader.efi");
let bootloader_efi = {
let path = root_path.join("boot").join("bootloader.efi");
if path.exists() {
match fs::read(&path) {
Ok(ok) => ok,
Err(err) => {
f(Message::Error(format!(
"{}: failed to read: {}",
path.display(),
err
)));
return;
}
}
} else {
Vec::new()
}
};
message!("Formatting disk");
let disk_option = DiskOption {
bootloader_bios: &bootloader_bios,
bootloader_efi: &bootloader_efi,
password_opt: password_opt.as_ref().map(|x| x.as_bytes()),
efi_partition_size: None,
skip_partitions: false,
};
let res = with_whole_disk(&disk_path, &disk_option, |mut fs| -> anyhow::Result<()> {
// Fast install method via filesystem clone
let mut last_progress = 0;
if try_fast_install(&mut fs, |used, used_old| {
progress = ((used * 100) / used_old) as usize;
if progress != last_progress {
message!(
"{}%: {} MB/{} MB",
progress,
used / 1000 / 1000,
used_old / 1000 / 1000
);
last_progress = progress;
}
})? {
progress = 100;
message!("Finished installing using fast mode");
return Ok(());
}
with_redoxfs_mount(fs, None, |mount_path: &Path| -> anyhow::Result<()> {
message!("Loading filesystem.toml");
let mut config: Config = {
let path = root_path.join("filesystem.toml");
match fs::read_to_string(&path) {
Ok(config_data) => match toml::from_str(&config_data) {
Ok(config) => config,
Err(err) => {
return Err(format_err!(
"{}: failed to decode: {}",
path.display(),
err
));
}
},
Err(err) => {
return Err(format_err!("{}: failed to read: {}", path.display(), err));
}
}
};
// Copy filesystem.toml, which is not packaged
let mut files = vec!["filesystem.toml".to_string()];
// Copy files from locally installed packages
message!("Loading package files");
if let Err(err) = package_files(&root_path, &mut config, &mut files) {
return Err(format_err!("failed to read package files: {}", err));
}
// Sort and remove duplicates
files.sort();
files.dedup();
// Perform config install (after packages have been converted to files)
message!("Configuring system");
let cookbook: Option<&'static str> = None;
redox_installer::install_dir(config, mount_path, cookbook)
.map_err(|err| io::Error::new(io::ErrorKind::Other, err))?;
// Install files
let mut buf = vec![0; 4096 * 1024];
for (i, name) in files.iter().enumerate() {
progress = (i * 100) / files.len();
message!("Copy {} [{}/{}]", name, i, files.len());
let src = root_path.join(name);
let dest = mount_path.join(name);
copy_file(&src, &dest, &mut buf)?;
}
progress = 100;
message!("Finished installing, unmounting filesystem");
Ok(())
})
});
match res {
Ok(()) => {
f(Message::Success(format!(
"Finished installing in {:?}, ready to reboot",
start.elapsed()
)));
}
Err(err) => {
f(Message::Error(format!("Failed to install: {}", err)));
}
}
}
#[derive(Debug)]
enum Page {
Sudo(String),
Disk(Option<usize>),
Install(usize, String),
Success(String),
Error(String),
}
#[derive(Clone, Debug)]
struct Worker {
command_sender: std::sync::mpsc::Sender<(String, Option<String>)>,
join_handle: Arc<std::thread::JoinHandle<()>>,
}
#[derive(Clone, Debug)]
enum Message {
None,
Worker(Worker),
SudoInput(String),
SudoSubmit,
DiskChoose(usize),
DiskConfirm(usize),
Install(usize, String),
Success(String),
Exit,
Error(String),
}
struct Window {
core: Core,
page: Page,
disk_paths: Vec<(String, bool, u64)>,
worker_opt: Option<Worker>,
}
enum State {
Ready,
Waiting(mpsc::UnboundedReceiver<Message>),
Finished,
}
impl Window {
fn worker_stream() -> impl iced::futures::Stream<Item = Message> {
iced::stream::channel(100, |mut output: mpsc::Sender<Message>| async move {
let mut state = State::Ready;
loop {
let (message, new_state) = match state {
State::Ready => {
let (command_sender, command_receiver) = std::sync::mpsc::channel();
let (message_sender, message_receiver) = mpsc::unbounded();
//TODO: kill worker thread?
let join_handle = std::thread::spawn(move || {
while let Ok((disk_path, password_opt)) = command_receiver.recv() {
println!("Installing to {:?}", disk_path);
install(disk_path, password_opt, |message| {
message_sender.unbounded_send(message).unwrap();
});
}
});
let worker = Worker {
command_sender,
join_handle: std::sync::Arc::new(join_handle),
};
(Message::Worker(worker), State::Waiting(message_receiver))
}
State::Waiting(mut message_receiver) => {
use iced::futures::StreamExt;
match message_receiver.next().await {
Some(message) => (message, State::Waiting(message_receiver)),
None => (Message::None, State::Finished),
}
}
State::Finished => iced::futures::future::pending().await,
};
output.send(message).await.unwrap();
state = new_state;
}
})
}
}
impl Application for Window {
type Executor = executor::Default;
type Flags = ();
type Message = Message;
const APP_ID: &'static str = "org.redox-os.InstallerGui";
fn init(core: Core, _flags: ()) -> (Self, Task<Message>) {
//TODO: load in background
let (page, disk_paths) = match disk_paths() {
Ok(disk_paths) => (Page::Disk(None), disk_paths),
Err(err) => (Page::Error(err), Vec::new()),
};
let mut app = Self {
core,
page,
disk_paths,
worker_opt: None,
};
let task = app.set_window_title("Redox OS Installer".to_string());
(app, task)
}
fn core(&self) -> &Core {
&self.core
}
fn core_mut(&mut self) -> &mut Core {
&mut self.core
}
fn update(&mut self, message: Message) -> Task<Message> {
match message {
Message::None => {}
Message::Worker(worker) => {
self.worker_opt = Some(worker);
}
Message::SudoInput(password) => {
self.page = Page::Sudo(password);
}
Message::SudoSubmit => {
#[cfg(target_os = "redox")]
if let Page::Sudo(password) = &self.page {
match ask_root(&password) {
Ok(()) => {
self.page = Page::Disk(None);
}
Err(err) => {
eprintln!("{err}");
}
}
}
#[cfg(target_os = "linux")]
match ask_root() {
Ok(()) => {
if let Some(window_id) = self.core.main_window_id() {
return window::close(window_id);
}
}
Err(err) => {
eprintln!("{err}");
}
}
}
Message::DiskChoose(disk_i) => {
self.page = Page::Disk(Some(disk_i));
}
Message::DiskConfirm(disk_i) => match self.disk_paths.get(disk_i) {
Some((disk_path, _is_partition, _disk_size)) => match &self.worker_opt {
Some(worker) => match worker.command_sender.send((disk_path.clone(), None)) {
Ok(()) => self.page = Page::Install(0, format!("Starting install...")),
Err(err) => {
self.page = Page::Error(format!("failed to send command: {}", err));
}
},
None => {
self.page = Page::Error(format!("command sender not found"));
}
},
None => {
self.page = Page::Error(format!("invalid disk number {} chosen", disk_i));
}
},
Message::Install(progress, description) => {
self.page = Page::Install(progress, description);
}
Message::Success(description) => {
self.page = Page::Success(description);
}
Message::Error(err) => {
self.page = Page::Error(err);
}
Message::Exit => {
if let Some(worker) = self.worker_opt.take() {
drop(worker.command_sender);
let join_handle = Arc::try_unwrap(worker.join_handle).unwrap();
join_handle.join().unwrap();
}
if let Some(window_id) = self.core.main_window_id() {
return window::close(window_id);
}
}
}
Task::none()
}
fn view(&self) -> Element<'_, Message> {
let mut widgets = Vec::new();
match &self.page {
Page::Sudo(password) => {
widgets.push(text("Enter your password:").into());
widgets.push(
text_input("", password)
.on_input(Message::SudoInput)
.secure(true)
.on_submit(Message::SudoSubmit)
.into(),
);
}
Page::Disk(disk_i_opt) => {
if !self.disk_paths.is_empty() {
if is_root() {
widgets.push(text("Choose a drive:").size(24).into());
for (disk_i, (disk_path, is_partition, disk_size)) in
self.disk_paths.iter().enumerate()
{
if !is_partition {
widgets.push(
row![
radio(
text(disk_path),
disk_i,
*disk_i_opt,
Message::DiskChoose
),
space::horizontal(),
text(redox_installer::format_bytes(*disk_size)),
]
.into(),
);
}
}
if let Some(disk_i) = *disk_i_opt {
widgets.push(space::vertical().into());
widgets.push(
row![
space::horizontal(),
button::destructive("Confirm")
.on_press(Message::DiskConfirm(disk_i)),
]
.into(),
);
}
} else {
#[cfg(target_os = "linux")]
let page = Message::SudoSubmit;
#[cfg(target_os = "redox")]
let page = Message::SudoInput(String::new());
widgets.push(space::vertical().into());
widgets.push(
row![
text("Ask superuser permission to install into drives"),
space::horizontal(),
button::suggested("Ask root access").on_press(page),
]
.into(),
);
}
} else {
widgets.push(text("No drives found").into());
// TODO: expose disk.pci-*-*nvme/* */ scheme to user
widgets.push(text("(try to rerun with sudo)").into());
}
}
Page::Install(progress, description) => {
widgets.push(text("Installation progress:").size(24).into());
widgets.push(progress_bar::determinate_linear(*progress as f32 / 100.).into());
widgets.push(text(description).into());
}
Page::Success(description) => {
widgets.push(text("Installation complete!").size(24).into());
widgets.push(text(description).into());
widgets.push(space::vertical().into());
widgets.push(
row![
space::horizontal(),
button::standard("Exit").on_press(Message::Exit),
]
.into(),
);
}
Page::Error(err) => {
widgets.push(text(format!("{}", err)).into());
}
};
column::with_children(widgets)
.spacing(8)
.padding(24)
.align_x(Alignment::Start)
.into()
}
fn subscription(&self) -> Subscription<Message> {
Subscription::run(Self::worker_stream)
}
}
-12
View File
@@ -1,12 +0,0 @@
#[cfg(target_os = "linux")]
mod linux;
#[cfg(target_os = "redox")]
mod redox;
#[cfg(target_os = "linux")]
pub use linux::*;
#[cfg(target_os = "redox")]
pub use redox::*;
#[cfg(not(any(target_os = "linux", target_os = "redox")))]
compile_error!("Platform is not ported");
-76
View File
@@ -1,76 +0,0 @@
use std::{fs, os::unix::process::CommandExt, process::Command};
pub fn ask_root() -> Result<(), String> {
let Ok(exe_path) = std::env::current_exe() else {
return Err(format!("Could not determine current_exe"));
};
let mut cmd = Command::new("pkexec");
cmd.arg("env");
for (key, value) in std::env::vars() {
if [
"DISPLAY",
"WAYLAND_DISPLAY",
"XAUTHORITY",
"XDG_RUNTIME_DIR",
"DBUS_SESSION_BUS_ADDRESS",
]
.contains(&key.as_str())
{
cmd.arg(format!("{}={}", key, value));
}
}
cmd.arg(exe_path);
// will never return unless fail
let e = cmd.exec();
return Err(format!("Failed to escalate: {e}"));
}
pub fn is_root() -> bool {
let euid = unsafe { libc::geteuid() };
euid == 0
}
pub fn disk_paths() -> Result<Vec<(String, bool, u64)>, String> {
let mut paths = Vec::new();
let entries = match fs::read_dir("/sys/class/block") {
Ok(entries) => entries,
Err(err) => return Err(format!("failed to read /sys/class/block: {}", err)),
};
for entry_res in entries {
if let Ok(entry) = entry_res {
let file_name = entry.file_name();
let name = file_name.to_string_lossy();
if name.starts_with("loop")
|| name.starts_with("ram")
|| name.starts_with("sr")
|| name.starts_with("zram")
{
continue;
}
let path = entry.path();
let is_partition = path.join("partition").exists();
let size_path = path.join("size");
let Ok(size_str) = fs::read_to_string(&size_path) else {
continue;
};
let Ok(sectors) = size_str.trim().parse::<u64>() else {
continue;
};
// /sys/class/block/*/size is 512 (cmiiw)
let size_bytes = sectors * 512;
if size_bytes == 0 {
continue;
}
paths.push((format!("/dev/{}", name), is_partition, size_bytes));
continue;
}
}
paths.sort_by(|a, b| a.0.cmp(&b.0));
Ok(paths)
}
-95
View File
@@ -1,95 +0,0 @@
use std::fs;
pub fn ask_root(password: &str) -> Result<(), String> {
let file = libredox::Fd::open("/scheme/sudo", libredox::flag::O_CLOEXEC, 0)
.map_err(|err| err.to_string())?;
file.write(password.as_bytes())
.map_err(|err| err.to_string())?;
// FIXME move to libredox
unsafe extern "C" {
safe fn redox_cur_procfd_v0() -> usize;
}
// Elevate privileges of our own process with help from the sudo daemon
file.call_wo(
&libredox::call::dup(redox_cur_procfd_v0(), &[])
.map_err(|err| err.to_string())?
.to_ne_bytes(),
syscall::CallFlags::FD,
&[],
)
.map_err(|err| err.to_string())?;
Ok(())
}
pub fn is_root() -> bool {
let euid = libredox::call::geteuid().unwrap();
euid == 0
}
pub fn disk_paths() -> Result<Vec<(String, bool, u64)>, String> {
let mut schemes = Vec::new();
match fs::read_dir("/scheme/") {
Ok(entries) => {
for entry_res in entries {
if let Ok(entry) = entry_res {
let path = entry.path();
if let Ok(path_str) = path.into_os_string().into_string() {
let scheme = path_str.trim_start_matches("/scheme/").trim_matches('/');
if scheme.starts_with("disk") {
if scheme == "disk/live" {
// Skip live disks
continue;
}
schemes.push(format!("/scheme/{}", scheme));
}
}
}
}
}
Err(err) => {
return Err(format!("failed to list schemes: {}", err));
}
}
let mut paths = Vec::new();
for scheme in schemes {
let is_dir = fs::metadata(&scheme).map(|x| x.is_dir()).unwrap_or(false);
if !is_dir {
continue;
}
match fs::read_dir(&scheme) {
Ok(entries) => {
for entry_res in entries {
let Ok(entry) = entry_res else {
continue;
};
let Ok(file_name) = entry.file_name().into_string() else {
continue;
};
let Ok(path) = entry.path().into_os_string().into_string() else {
continue;
};
let Ok(metadata) = entry.metadata() else {
continue;
};
let is_partition = file_name.contains('p');
let size = metadata.len();
if size == 0 {
continue;
}
paths.push((path, is_partition, size));
}
}
Err(err) => {
return Err(format!("failed to list {:?}: {}", scheme, err));
}
}
}
Ok(paths)
}
+6
View File
@@ -0,0 +1,6 @@
########## Red Bear OS #########
# Login with the following: #
# `user` #
# `root`:`password` #
################################
+6
View File
@@ -0,0 +1,6 @@
########## Redox OS ##########
# Login with the following: #
# `user` #
# `root`:`password` #
##############################
+2
View File
@@ -0,0 +1,2 @@
Welcome to Red Bear OS!
-372
View File
@@ -1,372 +0,0 @@
# Automatically generated by update.sh
include = []
[general]
prompt = false
filesystem_size = 196
[packages.base]
[packages.bootloader]
[packages.ca-certificates]
[packages.coreutils]
[packages.extrautils]
[packages.ion]
[packages.kernel]
[packages.kibi]
[packages.libgcc]
[packages.libstdcxx]
[packages.netdb]
[packages.netutils]
[packages.pkgutils]
[packages.relibc]
[packages.userutils]
[packages.uutils]
[packages.uutils-procps]
[[files]]
path = "/etc/login_schemes.toml"
data = """
[user_schemes.root]
schemes = ["*"]
[user_schemes.user]
schemes = [
# Kernel schemes
"debug",
"event",
"memory",
"pipe",
"serio",
"irq",
"time",
"sys",
# Base schemes
"rand",
"null",
"zero",
"log",
# Network schemes
"ip",
"icmp",
"tcp",
"udp",
# IPC schemes
"shm",
"chan",
"uds_stream",
"uds_dgram",
# File schemes
"file",
# Display schemes
"display.vesa",
"display*",
# Other schemes
"proc",
"pty",
"sudo",
"audio",
"orbital",
]
"""
symlink = false
directory = false
recursive_chown = false
postinstall = false
[[files]]
path = "/etc/hostname"
data = "redox"
symlink = false
directory = false
recursive_chown = false
postinstall = false
[[files]]
path = "/etc/net/dns"
data = """
9.9.9.9
"""
symlink = false
directory = false
recursive_chown = false
postinstall = false
[[files]]
path = "/etc/net/ip"
data = """
10.0.2.15
"""
symlink = false
directory = false
recursive_chown = false
postinstall = false
[[files]]
path = "/etc/net/ip_router"
data = """
10.0.2.2
"""
symlink = false
directory = false
recursive_chown = false
postinstall = false
[[files]]
path = "/etc/net/ip_subnet"
data = """
255.255.255.0
"""
symlink = false
directory = false
recursive_chown = false
postinstall = false
[[files]]
path = "/usr/lib/os-release"
data = """
PRETTY_NAME="Redox OS 0.9.0"
NAME="Redox OS"
VERSION_ID="0.9.0"
VERSION="0.9.0"
ID="redox-os"
HOME_URL="https://redox-os.org/"
DOCUMENTATION_URL="https://redox-os.org/docs/"
SUPPORT_URL="https://redox-os.org/community/"
"""
symlink = false
directory = false
recursive_chown = false
postinstall = false
[[files]]
path = "/etc/os-release"
data = "../usr/lib/os-release"
symlink = true
directory = false
recursive_chown = false
postinstall = false
[[files]]
path = "/etc/pkg.d/50_redox"
data = "https://static.redox-os.org/pkg"
symlink = false
directory = false
recursive_chown = false
postinstall = false
[[files]]
path = "/usr"
data = ""
symlink = false
directory = true
mode = 493
recursive_chown = false
postinstall = false
[[files]]
path = "/usr/bin"
data = ""
symlink = false
directory = true
mode = 493
recursive_chown = false
postinstall = false
[[files]]
path = "/bin"
data = "usr/bin"
symlink = true
directory = false
recursive_chown = false
postinstall = false
[[files]]
path = "/usr/include"
data = ""
symlink = false
directory = true
mode = 493
recursive_chown = false
postinstall = false
[[files]]
path = "/include"
data = "usr/include"
symlink = true
directory = false
recursive_chown = false
postinstall = false
[[files]]
path = "/usr/lib"
data = ""
symlink = false
directory = true
mode = 493
recursive_chown = false
postinstall = false
[[files]]
path = "/lib"
data = "usr/lib"
symlink = true
directory = false
recursive_chown = false
postinstall = false
[[files]]
path = "/usr/libexec"
data = ""
symlink = false
directory = true
mode = 493
recursive_chown = false
postinstall = false
[[files]]
path = "/usr/share"
data = ""
symlink = false
directory = true
mode = 493
recursive_chown = false
postinstall = false
[[files]]
path = "/share"
data = "usr/share"
symlink = true
directory = false
recursive_chown = false
postinstall = false
[[files]]
path = "/ui"
data = "usr/share/ui"
symlink = true
directory = false
recursive_chown = false
postinstall = false
[[files]]
path = "/usr/share/ui/fonts"
data = "/usr/share/fonts"
symlink = true
directory = false
recursive_chown = false
postinstall = false
[[files]]
path = "/usr/share/ui/icons"
data = "/usr/share/icons"
symlink = true
directory = false
recursive_chown = false
postinstall = false
[[files]]
path = "/var"
data = ""
symlink = false
directory = true
mode = 493
recursive_chown = false
postinstall = false
[[files]]
path = "/var/cache"
data = ""
symlink = false
directory = true
mode = 493
recursive_chown = false
postinstall = false
[[files]]
path = "/var/lib"
data = ""
symlink = false
directory = true
mode = 493
recursive_chown = false
postinstall = false
[[files]]
path = "/var/lock"
data = ""
symlink = false
directory = true
mode = 1023
recursive_chown = false
postinstall = false
[[files]]
path = "/var/log"
data = ""
symlink = false
directory = true
mode = 493
recursive_chown = false
postinstall = false
[[files]]
path = "/var/run"
data = ""
symlink = false
directory = true
mode = 493
recursive_chown = false
postinstall = false
[[files]]
path = "/var/tmp"
data = ""
symlink = false
directory = true
mode = 1023
recursive_chown = false
postinstall = false
[[files]]
path = "/usr/lib/init.d/30_console"
data = """
requires_weak 10_net.target
inputd -A 2
nowait getty 2
nowait getty /scheme/debug/no-preserve -J
"""
symlink = false
directory = false
recursive_chown = false
postinstall = false
[users.root]
password = "password"
uid = 0
gid = 0
shell = "/usr/bin/ion"
[users.user]
password = ""
shell = "/usr/bin/ion"
[groups.sudo]
gid = 1
members = ["user"]
-21
View File
@@ -1,21 +0,0 @@
#!/usr/bin/env bash
set -e
RES_PATH="$(dirname "$0")"
if [ -d "$1" ]
then
REDOX_PATH="$1"
else
echo "$0 [path to redox repository]" >&2
exit 1
fi
set -x
# Update res/test.toml from the redoxer.toml template
"${REDOX_PATH}/build/fstools/bin/redox_installer" \
--config="${REDOX_PATH}/config/minimal.toml" \
--output-config="${RES_PATH}/test.toml"
sed -i '1s/^/# Automatically generated by update.sh\n\n/' "${RES_PATH}/test.toml"
+318
View File
@@ -0,0 +1,318 @@
#[macro_use]
extern crate clap;
use core::ptr::slice_from_raw_parts;
use std::error::Error;
use std::fs::File;
use std::io::{self, ErrorKind, Read, Stderr, Write};
use std::os::unix::io::{AsRawFd, FromRawFd, RawFd};
use std::process::{Child, Command, Stdio};
use std::str;
use std::time::{Duration, Instant};
use event::{EventFlags, RawEventQueue};
use extra::io::fail;
use libc::{grantpt, ptsname, strlen, unlockpt};
use libredox::call as redox;
use libredox::errno::EAGAIN;
use libredox::flag;
const _MAN_PAGE: &'static str = /* @MANSTART{getty} */
r#"
NAME
getty - set terminal mode
SYNOPSIS
getty [-J | --noclear | -C | --contain ] tty
getty [ -h | --help ]
DESCRIPTION
The getty utility is called by init(8) to open and initialize the tty line,
read a login name, and invoke login(1).
OPTIONS
-h, --help
Display this help and exit.
-J, --noclear
Do not clear the screen before forking login(1).
-C, --contain
Run contain_login instead of login
AUTHOR
Written by Jeremy Soller.
"#; /* @MANEND */
const DEFAULT_COLS: u16 = 80;
const DEFAULT_LINES: u16 = 30;
pub fn handle(
event_queue: &mut RawEventQueue,
tty_fd: RawFd,
master_fd: RawFd,
process: &mut Child,
) {
// tty_fd => Display
// master_fd => PTY
let handle_event = |event_id: usize| {
// The console<->PTY bridge must never panic on a transient read/write
// error: getty runs this while the login shell is alive, so a panic here
// kills the shell's I/O forwarding (input stops, output stops). Log and
// stop the current forwarding cycle instead; the event loop keeps going.
if event_id as RawFd == tty_fd {
let mut packet = [0; 4096];
loop {
let count = match redox::read(tty_fd as usize, &mut packet) {
Ok(0) => return,
Ok(count) => count,
Err(ref err) if err.errno() == EAGAIN => break,
Err(err) => {
eprintln!("getty: failed to read from TTY: {err}");
return;
}
};
if let Err(err) = redox::write(master_fd as usize, &packet[..count]) {
eprintln!("getty: failed to write master PTY: {err}");
break;
}
}
} else if event_id as RawFd == master_fd {
let mut packet = [0; 4096];
loop {
let count = match redox::read(master_fd as usize, &mut packet) {
Ok(0) => return,
Ok(count) => count,
Err(ref err) if err.errno() == EAGAIN => break,
Err(err) => {
eprintln!("getty: failed to read from master PTY: {err}");
return;
}
};
if let Err(err) = redox::write(tty_fd as usize, &packet[1..count]) {
eprintln!("getty: failed to write to TTY: {err}");
break;
}
if packet[0] & 1 == 1 {
let _ = redox::fsync(tty_fd as usize);
}
}
}
};
handle_event(tty_fd as usize);
handle_event(master_fd as usize);
'events: loop {
let sys_event = match event_queue.next() {
Some(Ok(event)) => event,
Some(Err(err)) => {
eprintln!("getty: failed to read event file: {err}; exiting bridge");
break 'events;
}
None => {
eprintln!("getty: event queue stopped; exiting bridge");
break 'events;
}
};
handle_event(sys_event.fd);
match process.try_wait() {
Ok(Some(_code)) => break 'events,
Ok(None) => (),
Err(err) => match err.kind() {
ErrorKind::WouldBlock => (),
_ => {
eprintln!("getty: failed to wait on child: {err:?}; exiting bridge");
break 'events;
}
},
}
}
let _ = process.kill();
if let Err(err) = process.wait() {
eprintln!("getty: failed to wait on login: {err}");
}
}
pub fn getpty(columns: u16, lines: u16) -> (RawFd, String) {
let master = redox::open(
"/scheme/pty/ptmx",
flag::O_CLOEXEC | flag::O_RDWR | flag::O_CREAT | flag::O_NONBLOCK,
0,
)
.expect("getty: failed to create PTY");
if let Ok(winsize_fd) = redox::dup(master, b"winsize") {
let _ = redox::write(
winsize_fd,
&redox_termios::Winsize {
ws_row: lines,
ws_col: columns,
},
);
let _ = redox::close(winsize_fd);
}
let _ = unsafe { grantpt(master as RawFd) };
let _ = unsafe { unlockpt(master as RawFd) };
let name = unsafe { ptsname(master as RawFd) };
let count = unsafe { strlen(name) };
let buf = unsafe { &*slice_from_raw_parts(name.cast(), count) };
(master as RawFd, unsafe {
String::from_utf8_unchecked(Vec::from(&buf[..count]))
})
}
// termion cursor_pos prone to error and does not work on nonblocking files
fn tty_cursor_pos(tty: &mut File) -> Result<(u16, u16), Box<dyn Error>> {
write!(tty, "\x1B[6n")?;
tty.flush()?;
let timeout = Duration::from_millis(500);
let instant = Instant::now();
let mut data = String::new();
while instant.elapsed() < timeout {
let mut bytes = [0];
match tty.read(&mut bytes) {
Ok(count) => {
if count == 1 {
let c = bytes[0] as char;
if c == 'R' {
break;
}
data.push(c);
}
}
Err(err) => {
if err.kind() != ErrorKind::WouldBlock {
return Err(err.into());
}
}
}
}
if data.is_empty() {
return Err("cursor position timed out".into());
}
let beg = data.rfind('[').ok_or("failed to find [")?;
let coords: String = data.chars().skip(beg + 1).collect();
let mut nums = coords.split(';');
let row = nums.next().ok_or("failed to find row")?.parse::<u16>()?;
let col = nums.next().ok_or("failed to find col")?.parse::<u16>()?;
Ok((col, row))
}
fn tty_columns_lines(tty: &mut File) -> Result<(u16, u16), Box<dyn Error>> {
write!(tty, "{}", termion::cursor::Save)?;
tty.flush()?;
write!(tty, "{}", termion::cursor::Goto(999, 999))?;
tty.flush()?;
let res = tty_cursor_pos(tty);
write!(tty, "{}", termion::cursor::Restore)?;
tty.flush()?;
res
}
fn daemon(tty: &mut File, clear: bool, contain: bool, stderr: &mut Stderr) {
let (columns, lines) = tty_columns_lines(tty).unwrap_or((DEFAULT_COLS, DEFAULT_LINES));
let tty_fd = tty.as_raw_fd();
let (master_fd, pty) = getpty(columns, lines);
let mut event_queue = event::RawEventQueue::new().expect("getty: failed to open event queue");
event_queue
.subscribe(tty_fd as usize, 0, EventFlags::READ)
.expect("getty: failed to fevent TTY");
event_queue
.subscribe(master_fd as usize, 0, EventFlags::READ)
.expect("getty: failed to fevent master PTY");
loop {
if clear {
let _ = redox::write(tty_fd as usize, b"\x1Bc");
}
let _ = redox::fsync(tty_fd as usize);
let slave_stdin = redox::open(&pty, flag::O_CLOEXEC | flag::O_RDONLY, 0)
.expect("getty: failed to open slave stdin");
let slave_stdout = redox::open(&pty, flag::O_CLOEXEC | flag::O_WRONLY, 0)
.expect("getty: failed to open slave stdout");
let slave_stderr = redox::open(&pty, flag::O_CLOEXEC | flag::O_WRONLY, 0)
.expect("getty: failed to open slave stderr");
let mut command = if contain {
Command::new("contain_login")
} else {
Command::new("login")
};
unsafe {
command
.stdin(Stdio::from_raw_fd(slave_stdin as RawFd))
.stdout(Stdio::from_raw_fd(slave_stdout as RawFd))
.stderr(Stdio::from_raw_fd(slave_stderr as RawFd))
.env("TERM", "xterm-256color")
.env("TTY", &pty);
}
match command.spawn() {
Ok(mut process) => {
handle(&mut event_queue, tty_fd, master_fd, &mut process);
}
Err(err) => fail(&format!("getty: failed to execute login: {}", err), stderr),
}
}
}
pub fn main() {
let mut stderr = io::stderr();
let args = clap_app!(getty =>
(author: "Jeremy Soller")
(about: "Set terminal mode")
(@arg TTY: +required "")
(@arg NO_CLEAR: -J --("no-clear") "Do not clear the screen before forking")
(@arg CONTAIN: -C --("contain") "Run contain_login instead of login")
)
.get_matches();
let clear = !args.is_present("NO_CLEAR");
let contain = args.is_present("CONTAIN");
let vt = args.value_of("TTY").unwrap();
let buf: String;
let vt_path = if vt.parse::<usize>().is_ok() {
buf = format!("/scheme/fbcon/{vt}");
&*buf
} else {
vt
};
let mut tty = match redox::open(
&vt_path,
flag::O_CLOEXEC | flag::O_RDWR | flag::O_NONBLOCK,
0,
) {
Ok(fd) => unsafe { File::from_raw_fd(fd as RawFd) },
Err(err) => fail(
&format!("getty: failed to open TTY {}: {}", vt_path, err),
&mut stderr,
),
};
daemon(&mut tty, clear, contain, &mut stderr);
}
+82
View File
@@ -0,0 +1,82 @@
#[macro_use]
extern crate clap;
use extra::option::OptionalExt;
use std::process::exit;
use redox_users::{All, AllGroups, Config, Error, GroupBuilder};
const _MAN_PAGE: &'static str = /* @MANSTART{groupadd} */
r#"
NAME
groupadd - add a user group
SYNOPSIS
groupadd [ -f | --force ] GROUP
groupadd [ -h | --help ]
DESCRIPTION
The groupadd utility adds a new user group using values
passed on the command line and system defaults.
OPTIONS
-f, --force
Simply forces the exit status of the program to 0
even if the group already exists. A message is still
printed to stdout.
-g, --gid GID
The group id to use. This value must not be used and must
be non-negative. The default is to pick the smallest available
group id (between values defined in redox_users).
-h, --help
Display this help and exit.
AUTHOR
Written by Wesley Hershberger.
"#; /* @MANEND */
fn main() {
let args = clap_app!(groupadd =>
(author: "Wesley Hershberger")
(about: "Add groups based on the system's redox_users backend")
(@arg GROUP: +required "Add group GROUP")
(@arg FORCE: -f --force "Force the status of the program to be 0 even if the group exists")
(@arg GID: -g --gid +takes_value "Group id. Positive integer and must not be in use")
)
.get_matches();
let mut sys_groups = AllGroups::new(Config::default().writeable(true)).unwrap_or_exit(1);
let groupname = args.value_of("GROUP").unwrap();
let gid = match args.value_of("GID") {
Some(gid) => {
let id = gid.parse::<usize>().unwrap_or_exit(1);
if let Some(_group) = sys_groups.get_by_id(id) {
eprintln!("groupadd: group already exists");
exit(1);
}
id
}
None => sys_groups.get_unique_id().unwrap_or_else(|| {
eprintln!("groupadd: no available gid");
exit(1);
}),
};
let group = GroupBuilder::new(groupname).gid(gid);
match sys_groups.add_group(group) {
Ok(_) => (),
Err(Error::GroupAlreadyExists) if args.is_present("FORCE") => {
exit(0);
}
Err(err) => {
eprintln!("groupadd: {}", err);
exit(1);
}
}
sys_groups.save().unwrap_or_exit(1);
}
+47
View File
@@ -0,0 +1,47 @@
#[macro_use]
extern crate clap;
use extra::option::OptionalExt;
use redox_users::{All, AllGroups, Config};
const _MAN_PAGE: &'static str = /* @MANSTART{groupdel} */
r#"
NAME
groupdel - modify system files to delete groups
SYNOPSYS
groupdel [ options ] GROUP
groupdel [ -h | --help ]
DESCRIPTION
groupdel removes groups from whatever backend is employed by
the system's redox_users.
Note that you should not remove a primary user group before
removing the user. It is also generally wise not to remove
groups that still own files on the system.
OPTIONS
-h, --help
Print this help page and exit.
AUTHORS
Wesley Hershberger.
"#; /* @MANEND */
fn main() {
let matches = clap_app!(groupdel =>
(author: "Wesley Hershberger")
(about: "Removes a group from the system using redox_users")
(@arg GROUP: +required "Removes group GROUP")
)
.get_matches();
let group = matches.value_of("GROUP").unwrap();
let mut sys_groups = AllGroups::new(Config::default().writeable(true)).unwrap_or_exit(1);
sys_groups.remove_by_name(group.to_string());
sys_groups.save().unwrap_or_exit(1);
}
+81
View File
@@ -0,0 +1,81 @@
#[macro_use]
extern crate clap;
use std::process::exit;
use extra::option::OptionalExt;
use redox_users::{All, AllGroups, AllUsers, Config};
const _MAN_PAGE: &'static str = /* @MANSTART{groupmod} */
r#"
NAME
groupmod - modify group information
SYNOPSYS
groupmod [ options ] GROUP
groupmod [ -h | --help ]
DESCRIPTION
groupmod modifies a user group GROUP in the system's
redox_users backend.
OPTIONS
-h, --help
Print this help page and exit.
-g, --gid GID
Change GROUP's group id. GID must be a non-negative
decimal integer.
Files with GROUP's old gid will not be updated.
User's who use the old gid as their primary gid will
be updated.
-n, --name NAME
The name of the group will be set to NAME
AUTHORS
Wesley Hershberger.
"#; /* @MANEND */
fn main() {
let args = clap_app!(groupmod =>
(author: "Wesley Hershberger")
(about: "Modify users according to the system's redox_users backend")
(@arg GROUP: +required "Modify GROUP")
(@arg GID: -g --gid +takes_value "Change GROUP's group id. See man page for details")
(@arg NAME: -n --name +takes_value "Change GROUP's name")
)
.get_matches();
let groupname = args.value_of("GROUP").unwrap();
let mut sys_groups = AllGroups::new(Config::default().writeable(true)).unwrap_or_exit(1);
{
let group = sys_groups.get_mut_by_name(groupname).unwrap_or_else(|| {
eprintln!("groupmod: group not found: {}", groupname);
exit(1);
});
if let Some(gid) = args.value_of("GID") {
let gid = gid.parse::<usize>().unwrap_or_exit(1);
// Update users
let mut sys_users =
AllUsers::authenticator(Config::default().writeable(true)).unwrap_or_exit(1);
for user in sys_users.iter_mut() {
if user.gid == group.gid {
user.gid = gid;
}
}
sys_users.save().unwrap_or_exit(1);
group.gid = gid;
}
if let Some(name) = args.value_of("NAME") {
group.group = name.to_string();
}
}
sys_groups.save().unwrap_or_exit(1);
}
+163
View File
@@ -0,0 +1,163 @@
#[macro_use]
extern crate clap;
use std::env::args;
use std::process::exit;
use extra::option::OptionalExt;
use redox_users::{All, AllGroups, AllUsers, Config, get_egid, get_euid, get_gid, get_uid};
const _MAN_PAGE: &'static str = /* @MANSTART{id} */
r#"
NAME
id - display user identity
SYNOPSIS
id
id -g [-nr]
id -u [-nr]
id [ -h | --help ]
DESCRIPTION
The id utility displays the user and group names and numeric IDs, of
the calling process, to the standard output.
OPTIONS
-G, --groups
Display the different group IDs (effective and real) as white-space
separated numbers, in no particular order.
-g, --group
Display the effective group ID as a number.
-n, --name
Display the name of the user or group ID for the -g and -u options
instead of the number.
-u, --user
Display the effective user ID as a number.
-a
Ignored for compatibility with other id implementations.
-r, --real
Display the real ID for the -g and -u options instead of the effective ID.
-h, --help
Display help and exit.
AUTHOR
Written by Jose Narvaez.
"#; /* @MANEND */
pub fn main() {
let app = clap_app!(id =>
(author: "Jose Narvaez")
(about: "Get user and group information about the current user")
(@arg IGNORE: -a "Ignored for compatibility with other impls of id")
(@arg GROUPS: -G --groups conflicts_with[selector modifier] "Display current user's real and effective group id's")
(@group selector =>
(@arg GROUP: -g --group "Display current user's effective group id")
(@arg USER: -u --user "Display the effective userid")
)
(@group modifier =>
(@arg NAME: -n --name requires[selector] "Display names of groups/users instead of ids (use with -g or -u)")
(@arg REAL: -r --real requires[selector] "Display real id's instead of effective ids (use with -g and -u)")
)
);
let args = match &*args().nth(0).unwrap_or(String::new()) {
"whoami" => app.get_matches_from(["id", "-un"].iter()),
_ => app.get_matches(),
};
// Display the different group IDs (effective and real)
// as white-space separated numbers, in no particular order.
if args.is_present("GROUPS") {
let egid = get_egid().unwrap_or_exit(1);
let gid = get_gid().unwrap_or_exit(1);
println!("{} {}", egid, gid);
exit(0);
}
// Display effective/real process user ID UNIX user name
if args.is_present("USER") && args.is_present("NAME") {
// Did they pass -r? If so, we show the real
let uid = if args.is_present("REAL") {
get_uid()
} else {
get_euid()
}
.unwrap_or_exit(1);
let users = AllUsers::basic(Config::default()).unwrap_or_exit(1);
let user = users.get_by_id(uid).unwrap_or_exit(1);
println!("{}", user.user);
exit(0);
}
// Display real user ID
if args.is_present("USER") && args.is_present("REAL") {
let uid = get_uid().unwrap_or_exit(1);
println!("{}", uid);
exit(0);
}
// Display effective user ID
if args.is_present("USER") {
let euid = get_euid().unwrap_or_exit(1);
println!("{}", euid);
exit(0);
}
// Display effective/real process group ID UNIX group name
if args.is_present("GROUP") && args.is_present("NAME") {
// Did they pass -r? If so we show the real one
let gid = if args.is_present("REAL") {
get_gid()
} else {
get_egid()
}
.unwrap_or_exit(1);
let groups = AllGroups::new(Config::default()).unwrap_or_exit(1);
let group = groups.get_by_id(gid).unwrap_or_exit(1);
println!("{}", group.group);
exit(0);
}
// Display the real group ID
if args.is_present("GROUP") && args.is_present("REAL") {
let gid = get_gid().unwrap_or_exit(1);
println!("{}", gid);
exit(0);
}
// Display effective group ID
if args.is_present("GROUP") {
let egid = get_egid().unwrap_or_exit(1);
println!("{}", egid);
exit(0);
}
// We get everything we can and show
let euid = get_euid().unwrap_or_exit(1);
let egid = get_egid().unwrap_or_exit(1);
let users = AllUsers::basic(Config::default()).unwrap_or_exit(1);
let groups = AllGroups::new(Config::default()).unwrap_or_exit(1);
let user = users.get_by_id(euid).unwrap_or_exit(1);
let group = groups.get_by_id(egid).unwrap_or_exit(1);
println!("uid={}({}) gid={}({})", euid, user.user, egid, group.group);
exit(0);
}
-220
View File
@@ -1,220 +0,0 @@
extern crate arg_parser;
extern crate redox_installer;
extern crate serde;
extern crate toml;
use std::cell::RefCell;
use std::path::Path;
use std::rc::Rc;
use std::{env, fs, process};
use arg_parser::ArgParser;
use pkg::net_backend::DownloadBackend;
use redox_installer::{Config, PackageConfig};
const HELP_STR: &str = r#"
redox_installer - Redox Installer.
Refer to link below for filesystem config reference:
https://doc.redox-os.org/book/configuration-settings.html
Using redox_installer as an installer:
redox_installer <diskpath.img> [--config=file.toml] [--write-bootloader=file.img] [--live] [--no-mount] [--skip-partition]
<diskpath.img> Disk file to write
--config Path to filesystem config TOML
--write-bootloader Path to write UEFI bootloader to in addition to the embedded ESP
--skip-partition Skip writing GPT partition tables
Use this only if you plan to use other partition tool
--live Use bootloader configured for live disk
--no-mount Use RedoxFS AR instead of FUSE to write files
--cookbook Use local Redox OS build system rather than downloading packages
--config-name Name of the filesystem configuration used for os-release VARIANT
Using redox_installer as a configuration parser:
redox_installer --config=file.toml [--list-packages|--filesystem-size|--output-config path]
--list-packages List packages will be installed
--filesystem-size Output filesystem size in MB
--output-config Path to write the parsed config as another TOML
"#;
fn os_release_quote(value: &str) -> String {
let escaped = value.replace('\\', "\\\\").replace('"', "\\\"");
format!("\"{}\"", escaped)
}
fn build_id_from_repo_toml(repo_toml: &str) -> Option<String> {
toml::from_str::<toml::Value>(repo_toml)
.ok()?
.get("build_id")?
.as_str()
.and_then(|value| {
if value.is_empty() {
None
} else {
Some(value.to_string())
}
})
}
fn local_repo_build_id(cookbook: &str) -> Option<String> {
let repo_toml = Path::new(cookbook)
.join("repo")
.join(redox_installer::get_target())
.join("repo.toml");
let repo_toml = fs::read_to_string(repo_toml).ok()?;
build_id_from_repo_toml(&repo_toml)
}
fn remote_repo_build_id() -> Option<String> {
let callback = Rc::new(RefCell::new(pkg::callback::SilentCallback::new()));
let download_backend = pkg::net_backend::DefaultNetBackend::new().ok()?;
let mut repo = pkg::RepoManager::new(callback, Box::new(download_backend));
repo.add_remote(
"https://static.redox-os.org/pkg",
&redox_installer::get_target(),
)
.ok()?;
let package = pkg::PackageName::new("repo").ok()?;
let (repo_toml, _) = repo.get_package_toml(&package).ok()?;
build_id_from_repo_toml(&repo_toml)
}
fn append_os_release_metadata(
config: &mut Config,
config_name: Option<&str>,
build_id: Option<String>,
) {
let mut data = String::new();
if let Some(config_name) = config_name.filter(|value| !value.is_empty()) {
data.push_str("VARIANT=");
data.push_str(&os_release_quote(config_name));
data.push('\n');
}
if let Some(build_id) = build_id.filter(|value| !value.is_empty()) {
data.push_str("BUILD_ID=");
data.push_str(&os_release_quote(&build_id));
data.push('\n');
}
if !data.is_empty() {
config.files.push(redox_installer::FileConfig {
path: "/usr/lib/os-release".to_string(),
data,
append: true,
..Default::default()
});
}
}
fn main() {
let mut parser = ArgParser::new(4)
.add_opt("b", "cookbook")
.add_opt("", "config-name")
.add_opt("c", "config")
.add_opt("o", "output-config")
.add_opt("", "write-bootloader")
.add_flag(&["skip-partition"])
.add_flag(&["filesystem-size"])
.add_flag(&["r", "repo-binary"]) // TODO: Remove
.add_flag(&["l", "list-packages"])
.add_flag(&["live"])
.add_flag(&["no-mount"]);
parser.parse(env::args());
let skip_partition = parser.found("skip-partition");
let mut config = if let Some(path) = parser.get_opt("config") {
match Config::from_file(Path::new(&path)) {
Ok(config) => config,
Err(err) => {
eprintln!("installer: {err}");
process::exit(1);
}
}
} else {
redox_installer::Config::default()
};
// Get toml of merged config
let merged_toml = toml::to_string_pretty(&config).unwrap();
// Just output merged config and exit
if let Some(path) = parser.get_opt("output-config") {
fs::write(path, merged_toml).unwrap();
return;
}
// Add filesystem.toml to config
config.files.push(redox_installer::FileConfig {
path: "filesystem.toml".to_string(),
data: merged_toml,
..Default::default()
});
if skip_partition {
config.general.skip_partitions = Some(true);
}
if parser.found("filesystem-size") {
println!("{}", config.general.filesystem_size.unwrap_or(0));
} else if parser.found("list-packages") {
// List the packages that should be fetched or built by the cookbook
for (packagename, package) in &config.packages {
match package {
PackageConfig::Build(rule) if rule == "ignore" => {
// skip this package
}
_ => {
println!("{}", packagename);
}
}
}
} else {
let cookbook = if let Some(path) = parser.get_opt("cookbook") {
if !Path::new(&path).is_dir() {
eprintln!("installer: {}: cookbook not found", path);
process::exit(1);
}
Some(path)
} else {
None
};
let build_id = if let Some(cookbook) = cookbook.as_deref() {
local_repo_build_id(cookbook)
} else {
remote_repo_build_id()
};
append_os_release_metadata(
&mut config,
parser.get_opt("config-name").as_deref(),
build_id,
);
if cookbook.is_some() {
config.general.cookbook = cookbook;
}
if parser.found("live") {
config.general.live_disk = Some(true);
}
if parser.found("no-mount") {
config.general.no_mount = Some(true);
}
let write_bootloader = parser.get_opt("write-bootloader");
if write_bootloader.is_some() {
config.general.write_bootloader = write_bootloader;
}
if let Some(path) = parser.args.first() {
if let Err(err) = redox_installer::install(config, path) {
eprintln!("installer: failed to install: {:?}", err);
process::exit(1);
}
} else {
eprint!("{}", HELP_STR);
process::exit(1);
}
}
}
-373
View File
@@ -1,373 +0,0 @@
use anyhow::{anyhow, bail, Result};
use pkgar::{ext::EntryExt, PackageHead};
use pkgar_core::PackageSrc;
use pkgar_keys::PublicKeyFile;
use redox_installer::{try_fast_install, with_redoxfs_mount, with_whole_disk, Config, DiskOption};
use std::{
ffi::OsStr,
fs,
io::{self, Read, Write},
os::unix::fs::{symlink, MetadataExt, OpenOptionsExt},
path::{Path, PathBuf},
process,
};
// TODO: This is not the TUI a regular user would expect it does
// 1. Linux: Implement disk listing, use "dd" to write into whole disk
// 2. Allow partitioning to allow dual boot, possibly an integration with systemd-boot/grub
// 3. Prompt everything (disk password, users, preconfigured packages, import from existing img)
#[cfg(not(target_os = "redox"))]
fn disk_paths(_paths: &mut Vec<(PathBuf, u64)>) {}
#[cfg(target_os = "redox")]
fn disk_paths(paths: &mut Vec<(PathBuf, u64)>) {
let mut schemes = Vec::new();
match fs::read_dir("/scheme") {
Ok(entries) => {
for entry_res in entries {
if let Ok(entry) = entry_res {
if let Ok(file_name) = entry.file_name().into_string() {
if file_name.starts_with("disk") {
schemes.push(entry.path());
}
}
}
}
}
Err(err) => {
eprintln!("redox_installer_tui: failed to list schemes: {}", err);
}
}
for scheme in schemes {
if scheme.is_dir() {
match fs::read_dir(&scheme) {
Ok(entries) => {
for entry_res in entries {
if let Ok(entry) = entry_res {
if let Ok(file_name) = entry.file_name().into_string() {
if file_name.contains('p') {
// Skip partitions
continue;
}
if let Ok(metadata) = entry.metadata() {
let size = metadata.len();
if size > 0 {
paths.push((entry.path(), size));
}
}
}
}
}
}
Err(err) => {
eprintln!(
"redox_installer_tui: failed to list '{}': {}",
scheme.display(),
err
);
}
}
}
}
}
fn copy_file(src: &Path, dest: &Path, buf: &mut [u8]) -> Result<()> {
if let Some(parent) = dest.parent() {
// Parent may be a symlink
if !parent.is_symlink() {
match fs::create_dir_all(&parent) {
Ok(()) => (),
Err(err) => {
bail!("failed to create directory {}: {}", parent.display(), err);
}
}
}
}
let metadata = match fs::symlink_metadata(&src) {
Ok(ok) => ok,
Err(err) => {
bail!("failed to read metadata of {}: {}", src.display(), err);
}
};
if metadata.file_type().is_symlink() {
let real_src = match fs::read_link(&src) {
Ok(ok) => ok,
Err(err) => {
bail!("failed to read link {}: {}", src.display(), err);
}
};
match symlink(&real_src, &dest) {
Ok(()) => (),
Err(err) => {
bail!(
"failed to copy link {} ({}) to {}: {}",
src.display(),
real_src.display(),
dest.display(),
err
);
}
}
} else {
let mut src_file = match fs::File::open(&src) {
Ok(ok) => ok,
Err(err) => {
bail!("failed to open file {}: {}", src.display(), err);
}
};
let mut dest_file = match fs::OpenOptions::new()
.write(true)
.create_new(true)
.mode(metadata.mode())
.open(&dest)
{
Ok(ok) => ok,
Err(err) => {
bail!("failed to create file {}: {}", dest.display(), err);
}
};
loop {
let count = match src_file.read(buf) {
Ok(ok) => ok,
Err(err) => {
bail!("failed to read file {}: {}", src.display(), err);
}
};
if count == 0 {
break;
}
match dest_file.write_all(&buf[..count]) {
Ok(()) => (),
Err(err) => {
bail!("failed to write file {}: {}", dest.display(), err);
}
}
}
}
Ok(())
}
fn package_files(
root_path: &Path,
config: &mut Config,
files: &mut Vec<String>,
) -> Result<(), anyhow::Error> {
//TODO: Remove packages from config where all files are located (and have valid shasum?)
config.packages.clear();
let pkey_path = "pkg/id_ed25519.pub.toml";
let pkey = PublicKeyFile::open(&root_path.join(pkey_path))?.pkey;
files.push(pkey_path.to_string());
for item_res in fs::read_dir(&root_path.join("pkg"))? {
let item = item_res?;
let pkg_path = item.path();
if pkg_path.extension() == Some(OsStr::new("pkgar_head")) {
let mut pkg = PackageHead::new(&pkg_path, &root_path, &pkey)?;
for entry in pkg.read_entries()? {
files.push(entry.check_path()?.to_str().unwrap().to_string());
}
files.push(
pkg_path
.strip_prefix(root_path)
.unwrap()
.to_str()
.unwrap()
.to_string(),
);
}
}
Ok(())
}
fn choose_disk() -> PathBuf {
let mut paths = Vec::new();
disk_paths(&mut paths);
loop {
for (i, (path, size)) in paths.iter().enumerate() {
eprintln!(
"\x1B[1m{}\x1B[0m: {}: {}",
i + 1,
path.display(),
redox_installer::format_bytes(*size)
);
}
if paths.is_empty() {
eprintln!("redox_installer_tui: no RedoxFS partition found");
eprintln!("redox_installer_tui: this tool is used to overwrite unmounted RedoxFS disk in Redox OS");
process::exit(1);
} else {
eprint!("Select a drive from 1 to {}: ", paths.len());
let mut line = String::new();
match io::stdin().read_line(&mut line) {
Ok(0) => {
eprintln!("redox_installer_tui: failed to read line: end of input");
process::exit(1);
}
Ok(_) => (),
Err(err) => {
eprintln!("redox_installer_tui: failed to read line: {}", err);
process::exit(1);
}
}
match line.trim().parse::<usize>() {
Ok(i) => {
if i >= 1 && i <= paths.len() {
break paths[i - 1].0.clone();
} else {
eprintln!("{} not from 1 to {}", i, paths.len());
}
}
Err(err) => {
eprintln!("invalid input: {}", err);
}
}
}
}
}
fn main() {
let root_path = Path::new("/");
let disk_path = choose_disk();
let Ok(password_opt) = redox_installer::prompt_password(
"redox_installer_tui: redoxfs password (empty for none)",
"redox_installer_tui: confirm password",
) else {
process::exit(1);
};
let instant = std::time::Instant::now();
let bootloader_bios = {
let path = root_path.join("usr/lib/boot/bootloader.bios");
if path.exists() {
match fs::read(&path) {
Ok(ok) => ok,
Err(err) => {
eprintln!(
"redox_installer_tui: {}: failed to read: {}",
path.display(),
err
);
process::exit(1);
}
}
} else {
Vec::new()
}
};
let bootloader_efi = {
let path = root_path.join("usr/lib/boot/bootloader.efi");
if path.exists() {
match fs::read(&path) {
Ok(ok) => ok,
Err(err) => {
eprintln!(
"redox_installer_tui: {}: failed to read: {}",
path.display(),
err
);
process::exit(1);
}
}
} else {
Vec::new()
}
};
let disk_option = DiskOption {
bootloader_bios: &bootloader_bios,
bootloader_efi: &bootloader_efi,
password_opt: password_opt.as_ref().map(|x| x.as_bytes()),
efi_partition_size: None,
skip_partitions: false, // TODO?
};
let res = with_whole_disk(&disk_path, &disk_option, |mut fs| {
// Fast install method via filesystem clone
let mut last_percent = 0;
if try_fast_install(&mut fs, move |used, used_old| {
let percent = (used * 100) / used_old;
if percent != last_percent {
eprint!(
"\r{}%: {} MB/{} MB",
percent,
used / 1000 / 1000,
used_old / 1000 / 1000
);
last_percent = percent;
}
})? {
eprintln!("\rfinished installing using fast mode");
return Ok(());
}
// Slow install method via file copy
with_redoxfs_mount(fs, None, |mount_path| {
let mut config: Config = Config::from_file(&root_path.join("filesystem.toml"))?;
// Copy filesystem.toml, which is not packaged
let mut files = vec!["filesystem.toml".to_string()];
// Copy files from locally installed packages
package_files(&root_path, &mut config, &mut files)
// TODO: implement Error trait
.map_err(|err| anyhow!("failed to read package files: {err}"))?;
// Perform config install (after packages have been converted to files)
eprintln!("configuring system");
let cookbook: Option<&'static str> = None;
redox_installer::install_dir(config, mount_path, cookbook)
.map_err(|err| io::Error::other(err))?;
// Sort and remove duplicates
files.sort();
files.dedup();
// Install files
let mut buf = vec![0; 4096 * 1024];
for (i, name) in files.iter().enumerate() {
eprintln!("copy {} [{}/{}]", name, i, files.len());
let src = root_path.join(name);
let dest = mount_path.join(name);
copy_file(&src, &dest, &mut buf)?;
}
eprintln!("finished installing, unmounting filesystem");
Ok(())
})
});
match res {
Ok(()) => {
eprintln!(
"redox_installer_tui: installed successfully in {:?}",
instant.elapsed()
);
process::exit(0);
}
Err(err) => {
eprintln!("redox_installer_tui: failed to install: {:?}", err);
process::exit(1);
}
}
}
+220
View File
@@ -0,0 +1,220 @@
#[macro_use]
extern crate clap;
use libredox::error::Result;
use std::fs::File;
use std::io::{self, Write};
use std::str;
use extra::option::OptionalExt;
use redox_users::{All, AllUsers, Config, User};
use termion::input::TermRead;
use userutils::spawn_shell;
const _MAN_PAGE: &'static str = /* @MANSTART{login} */
r#"
NAME
login - log into the computer
SYNOPSIS
login
DESCRIPTION
The login utility logs users (and pseudo-users) into the computer system.
OPTIONS
-h --help
Display help info and exit.
AUTHOR
Written by Jeremy Soller, Jose Narvaez.
"#; /* @MANEND */
const ISSUE_FILE: &'static str = "/etc/issue";
const MOTD_FILE: &'static str = "/etc/motd";
// TODO: Move to redox_users once the definition solidifies.
const DEFAULT_SCHEMES: [&'static str; 26] = [
// Kernel schemes
"debug",
"event",
"memory",
"pipe",
"serio",
"irq",
"time",
"sys",
// Base schemes
"rand",
"null",
"zero",
"log",
// Network schemes
"ip",
"icmp",
"tcp",
"udp",
// IPC schemes
"shm",
"chan",
"uds_stream",
"uds_dgram",
// File schemes
"file",
// Display schemes
"display.vesa",
"display*",
// Other schemes
"pty",
"sudo",
"audio",
];
pub fn apply_login_schemes(
user: &User<redox_users::auth::Full>,
default_schemes: &[&str],
) -> Result<libredox::Fd> {
let schemes = match load_config_schemes(user) {
Some(s) => s,
_ => default_schemes.iter().map(|s| s.to_string()).collect(),
};
let mut names: Vec<ioslice::IoSlice> = Vec::with_capacity(schemes.len());
for scheme in schemes.iter() {
names.push(ioslice::IoSlice::new(scheme.as_bytes()));
}
let ns_fd = libredox::call::mkns(&names)?;
let before_ns_fd = libredox::Fd::new(libredox::call::setns(ns_fd)?);
Ok(before_ns_fd)
}
fn load_config_schemes(user: &User<redox_users::auth::Full>) -> Option<Vec<String>> {
use serde::{Deserialize, Serialize};
use std::collections::BTreeMap;
use std::fs;
const LOGIN_SCHEMES_FILE: &'static str = "/etc/login_schemes.toml";
#[derive(Debug, Clone, Serialize, Deserialize)]
struct UserSchemeConfig {
pub schemes: Vec<String>,
}
#[derive(Debug, Clone, Serialize, Deserialize)]
struct LoginConfig {
#[serde(rename = "user_schemes")]
pub user_schemes: BTreeMap<String, UserSchemeConfig>,
}
let config_str = fs::read_to_string(LOGIN_SCHEMES_FILE).ok()?;
let config: LoginConfig = toml::from_str(&config_str).ok()?;
config
.user_schemes
.get(&user.user)
.map(|cfg| cfg.schemes.clone())
}
pub fn main() {
let mut stdout = io::stdout();
let mut stderr = io::stderr();
let _args = clap_app!(login =>
(author: "Jeremy Soller, Jose Narvaez")
(about: "Login as a user")
)
.get_matches();
if let Ok(mut issue) = File::open(ISSUE_FILE) {
io::copy(&mut issue, &mut stdout).r#try(&mut stderr);
stdout.flush().r#try(&mut stderr);
}
loop {
let user = liner::Context::new()
.read_line(
liner::Prompt::from("\x1B[1mRed Bear login:\x1B[0m "),
None,
&mut liner::BasicCompleter::new(Vec::<String>::new()),
)
.r#try(&mut stderr);
if !user.is_empty() {
let stdin = io::stdin();
let mut stdin = stdin.lock();
let sys_users = AllUsers::authenticator(Config::default()).unwrap_or_exit(1);
match sys_users.get_by_name(user) {
None => {
stdout.write(b"\nLogin incorrect\n").r#try(&mut stderr);
stdout.write(b"\n").r#try(&mut stderr);
stdout.flush().r#try(&mut stderr);
continue;
}
Some(user) => {
// Establish a working directory on the `file` scheme (the
// user's home) BEFORE any namespace restriction. login runs
// with the CWD inherited from init, which on the live image
// lives on the `initfs` scheme. apply_login_schemes() below
// switches to a namespace containing only DEFAULT_SCHEMES
// (which excludes `initfs`), after which that inherited CWD
// fd is unresolvable — and because relibc resolves paths via
// the CWD fd (AT_REDOX_CWD_FD), the login shell's spawn
// (Command child chdir + execve) then fails or hangs. Doing
// this chdir here, while still in the full namespace, points
// the CWD at `file:` (home, fallback `/`), which remains
// valid inside the restricted login namespace.
if std::env::set_current_dir(&user.home).is_err() {
let _ = std::env::set_current_dir("/");
}
if user.is_passwd_blank() {
if let Ok(mut motd) = File::open(MOTD_FILE) {
io::copy(&mut motd, &mut stdout).r#try(&mut stderr);
stdout.flush().r#try(&mut stderr);
}
let before_ns_fd =
apply_login_schemes(user, &DEFAULT_SCHEMES).unwrap_or_exit(1);
let _ = syscall::fcntl(
before_ns_fd.raw(),
syscall::F_SETFD,
syscall::O_CLOEXEC,
);
spawn_shell(user).unwrap_or_exit(1);
let _ = syscall::fcntl(before_ns_fd.raw(), syscall::F_SETFD, 0);
let _ = libredox::call::close(
libredox::call::setns(before_ns_fd.into_raw()).unwrap_or_exit(1),
);
break;
}
stdout
.write_all(b"\x1B[1mpassword:\x1B[0m ")
.r#try(&mut stderr);
stdout.flush().r#try(&mut stderr);
if let Some(password) = stdin.read_passwd(&mut stdout).r#try(&mut stderr) {
stdout.write(b"\n").r#try(&mut stderr);
stdout.flush().r#try(&mut stderr);
if user.verify_passwd(&password) {
if let Ok(mut motd) = File::open(MOTD_FILE) {
io::copy(&mut motd, &mut stdout).r#try(&mut stderr);
stdout.flush().r#try(&mut stderr);
}
spawn_shell(user).unwrap_or_exit(1);
break;
}
}
}
}
} else {
stdout.write(b"\n").r#try(&mut stderr);
stdout.flush().r#try(&mut stderr);
}
}
}
+197
View File
@@ -0,0 +1,197 @@
#[macro_use]
extern crate clap;
use std::io;
use std::io::Write;
use std::process::exit;
use extra::option::OptionalExt;
use libredox::flag::O_CLOEXEC;
use libredox::errno::EPERM;
use redox_users::{All, AllUsers, Config, get_uid};
use termion::input::TermRead;
const _MAN_PAGE: &'static str = /* @MANSTART{passwd} */
r#"
NAME
passwd - modify a user's password
SYNOPSIS
passwd [ LOGIN ]
passwd [ -h | --help ]
DESCRIPTION
The passwd utility changes the user's local password. If the user is not
the super-user, passwd first prompts for the current password and will
not continue unless the correct password is entered.
OPTIONS
-h, --help
Display this help and exit.
-l, --lock
Lock the password of the named account. This changes the stored password
hash so that it matches no encrypted value ("!")
Users with locked passwords are not allowed to change their password.
AUTHOR
Written by Jeremy Soller, Jose Narvaez.
"#; /* @MANEND */
fn main() {
let mut stdin = io::stdin().lock();
let mut stdout = io::stdout().lock();
let mut stderr = io::stderr();
let args = clap_app!(passwd =>
(author: "Jeremy Soller, Jose Narvaez")
(about: "Set user passwords")
(@arg LOGIN: "Apply to login. Sets password for current user if not supplied")
(@arg LOCK: -l --lock "Lock the password for an account (no login)")
)
.get_matches();
if args.is_present("LOCK") {
if get_uid().unwrap_or_exit(1) != 0 {
eprintln!("passwd: only root is allowed to lock accounts");
exit(1);
}
let mut users =
AllUsers::authenticator(Config::default().writeable(true)).unwrap_or_exit(1);
let Some(login) = args.value_of("LOGIN") else {
eprintln!("passwd: no account specified to lock");
exit(1);
};
let user = users.get_mut_by_name(login).unwrap_or_else(|| {
eprintln!("passwd: user does not exist: {}", login);
exit(1);
});
user.unset_passwd();
users.save().unwrap_or_exit(1);
return;
}
let uid = get_uid().unwrap_or_exit(1);
if uid == 0 {
let mut users =
AllUsers::authenticator(Config::default().writeable(true)).unwrap_or_exit(1);
let user = find_user(&args, &mut users);
let msg = format!("changing password for '{}' \n", user.user);
stdout.write_all(&msg.as_bytes()).r#try(&mut stderr);
stdout.flush().r#try(&mut stderr);
let new_password = ask_new_password(stdin, stdout, stderr);
user.set_passwd(&new_password).unwrap_or_exit(1);
users.save().unwrap_or_exit(1);
return;
}
let mut users = AllUsers::basic(Config::default()).unwrap_or_exit(1);
let user = find_user(&args, &mut users);
if user.uid != uid {
eprintln!(
"passwd: you do not have permission to set the password of '{}'",
user.user
);
exit(1);
}
let msg = format!("changing password for '{}' \n", user.user);
stdout.write_all(&msg.as_bytes()).r#try(&mut stderr);
stdout.flush().r#try(&mut stderr);
drop(users); // Unlock /etc/passwd
stdout.write_all(b"current password: ").r#try(&mut stderr);
stdout.flush().r#try(&mut stderr);
let file = libredox::call::open("/scheme/sudo/passwd", O_CLOEXEC, 0).unwrap();
if let Some(password) = stdin.read_passwd(&mut stdout).r#try(&mut stderr) {
stdout.write(b"\n").r#try(&mut stderr);
stdout.flush().r#try(&mut stderr);
match libredox::call::write(file, password.as_bytes()) {
Ok(_) => {}
Err(err) if err.errno() == EPERM => {
eprintln!("passwd: incorrect current password");
exit(1);
}
Err(err) => panic!("{err}"),
}
} else {
eprintln!("passwd: incorrect current password");
exit(1);
}
let new_password = ask_new_password(stdin, stdout, stderr);
match libredox::call::write(file, new_password.as_bytes()) {
Ok(_) => {}
Err(err) if err.errno() == EPERM => {
eprintln!("passwd: invalid new password");
exit(1);
}
Err(err) => panic!("{err}"),
}
}
fn find_user<'a, T: Default>(
args: &clap::ArgMatches<'_>,
users: &'a mut AllUsers<T>,
) -> &'a mut redox_users::User<T> {
let uid = get_uid().unwrap_or_exit(1);
match args.value_of("LOGIN") {
Some(login) => users.get_mut_by_name(login).unwrap_or_else(|| {
eprintln!("passwd: user does not exist: {}", login);
exit(1);
}),
None => users.get_mut_by_id(uid).unwrap_or_else(|| {
eprintln!("passwd: you do not exist");
exit(1);
}),
}
}
fn ask_new_password(
mut stdin: io::StdinLock<'_>,
mut stdout: io::StdoutLock<'_>,
mut stderr: io::Stderr,
) -> String {
stdout.write_all(b"new password: ").r#try(&mut stderr);
stdout.flush().r#try(&mut stderr);
let Some(new_password) = stdin.read_passwd(&mut stdout).r#try(&mut stderr) else {
eprintln!("passwd: no new password provided");
exit(1);
};
stdout.write(b"\nconfirm password: ").r#try(&mut stderr);
stdout.flush().r#try(&mut stderr);
let Some(confirm_password) = stdin.read_passwd(&mut stdout).r#try(&mut stderr) else {
eprintln!("\npasswd: no confirm password provided");
exit(1);
};
stdout.write(b"\n").r#try(&mut stderr);
stdout.flush().r#try(&mut stderr);
if new_password != confirm_password {
eprintln!("passwd: new password does not match confirm password");
exit(1);
}
new_password
}
+84
View File
@@ -0,0 +1,84 @@
#[macro_use]
extern crate clap;
use std::io::{self, Write};
use std::process::exit;
use std::str;
use extra::option::OptionalExt;
use libredox::flag::O_CLOEXEC;
use redox_users::{All, AllUsers, Config, get_uid};
use syscall::EPERM;
use termion::input::TermRead;
use userutils::spawn_shell;
const _MAN_PAGE: &'static str = /* @MANSTART{su} */
r#"
NAME
su - substitute user identity
SYNOPSIS
su [ user ]
su [ -h | --help ]
DESCRIPTION
The su utility requests appropriate user credentials via PAM and switches to
that user ID (the default user is the superuser). A shell is then executed.
OPTIONS
-h, --help
Display this help and exit.
AUTHOR
Written by Jeremy Soller, Jose Narvaez.
"#; /* @MANEND */
pub fn main() {
let stdin = io::stdin();
let mut stdin = stdin.lock();
let stdout = io::stdout();
let mut stdout = stdout.lock();
let mut stderr = io::stderr();
let args = clap_app!(su =>
(author: "Jeremy Soller, Jose Narvaez")
(about: "substitue user identity")
(@arg LOGIN: "Login as LOGIN. Default is \'root\'")
)
.get_matches();
let target_user = args.value_of("LOGIN").unwrap_or("root");
let uid = get_uid().unwrap_or_exit(1);
let users = AllUsers::basic(Config::default()).unwrap_or_exit(1);
let user = users.get_by_name(&target_user).unwrap_or_exit(1);
// If the user executing su is root, then they can do anything without a password.
// Same if the user we're being asked to login as doesn't have a password.
if uid == 0 {
writeln!(stdout).unwrap_or_exit(1);
exit(spawn_shell(user).unwrap_or_exit(1));
} else {
let file = libredox::call::open("/scheme/sudo/su", O_CLOEXEC, 0).unwrap();
write!(stdout, "password: ").unwrap_or_exit(1);
stdout.flush().unwrap_or_exit(1);
// Read the password, reading an empty string if CTRL-d is specified
let password = stdin
.read_passwd(&mut stdout)
.r#try(&mut stderr)
.unwrap_or(String::new());
match libredox::call::write(file, password.as_bytes()) {
Ok(_) => exit(spawn_shell(user).unwrap_or_exit(1)),
Err(err) if err.errno() == EPERM => {
writeln!(stderr, "su: authentication failed").unwrap_or_exit(1);
exit(1);
}
Err(err) => panic!("{err}"),
}
}
}
+402
View File
@@ -0,0 +1,402 @@
use std::collections::HashMap;
use std::env;
use std::io::{self, Write};
use std::os::fd::{AsRawFd, FromRawFd, OwnedFd, RawFd};
use std::os::unix::process::CommandExt;
use std::process::{Command, exit};
use extra::option::OptionalExt;
use libredox::flag::O_CLOEXEC;
use libredox::protocol::ProcCall;
use redox_rt::sys::proc_call;
use redox_scheme::scheme::{SchemeSync, register_sync_scheme};
use redox_scheme::{
CallerCtx, OpenResult, RequestKind, Response, SendFdRequest, SignalBehavior, Socket,
};
use redox_users::{All, AllGroups, AllUsers, Config, get_uid};
use syscall::error::*;
use syscall::flag::*;
use syscall::schemev2::NewFdFlags;
use termion::input::TermRead;
const MAX_ATTEMPTS: u16 = 3;
const _MAN_PAGE: &'static str = /* @MANSTART{sudo} */
r#"
NAME
sudo - execute a command as another user
SYNOPSIS
sudo command
sudo [ -h | --help ]
DESCRIPTION
The sudo utility allows a permitted user to execute a command as the
superuser or another user, as specified by the security policy.
EXIT STATUS
Upon successful execution of a command, the exit status from sudo will
be the exit status of the program that was executed. In case of error
the exit status will be >0.
AUTHOR
Written by Jeremy Soller, Jose Narvaez, bjorn3.
"#; /* @MANEND */
fn main() {
if env::args().nth(1).as_deref() == Some("--daemon") {
daemon_main();
}
let mut args = env::args().skip(1);
let cmd = args.next().unwrap_or_else(|| {
eprintln!("sudo: no command provided");
exit(1);
});
let users = AllUsers::basic(Config::default()).unwrap_or_exit(1);
let uid = get_uid().unwrap_or_exit(1);
let user = users.get_by_id(uid).unwrap_or_exit(1);
if uid == 0 {
// We are root already. No need to elevate privileges
run_command_as_root(&cmd, &args.collect());
}
let file = libredox::call::open("/scheme/sudo", O_CLOEXEC, 0).unwrap();
let mut attempts = 0;
loop {
print!("[sudo] password for {}: ", user.user);
let _ = io::stdout().flush();
match io::stdin().read_passwd(&mut io::stdout()).unwrap() {
Some(password) => {
println!();
match libredox::call::write(file, password.as_bytes()) {
Ok(_) => break,
Err(err) if err.errno() == EPERM => {
attempts += 1;
eprintln!(
"sudo: incorrect password or not in sudo group ({}/{})",
attempts, MAX_ATTEMPTS,
);
if attempts >= MAX_ATTEMPTS {
exit(1);
}
}
Err(err) => panic!("{err}"),
}
}
None => {
println!();
exit(1);
}
}
}
// FIXME move to libredox
unsafe extern "C" {
safe fn redox_cur_procfd_v0() -> usize;
}
// Elevate privileges of our own process with help from the sudo daemon
syscall::sendfd(
file,
syscall::dup(redox_cur_procfd_v0(), &[]).unwrap(),
0,
0,
)
.unwrap();
// FIXME perhaps keep the original namespace available in a subdirectory of the namespace we switch to?
let ns = syscall::openat(file, "ns", 0, syscall::O_CLOEXEC).unwrap();
libredox::call::setns(ns).unwrap();
run_command_as_root(&cmd, &args.collect());
}
enum Policy {
Deny,
Authenticate,
}
fn policy_for_user(uid: u32) -> Policy {
let users = AllUsers::authenticator(Config::default()).unwrap_or_exit(1);
let groups = AllGroups::new(Config::default()).unwrap_or_exit(1);
let user = users.get_by_id(uid as usize).unwrap_or_exit(1);
let sudo_group = groups.get_by_name("sudo").unwrap_or_exit(1);
if !sudo_group.users.iter().any(|name| name == &user.user) {
return Policy::Deny;
}
Policy::Authenticate
}
fn run_command_as_root(cmd: &str, args: &Vec<String>) -> ! {
let mut command = Command::new(&cmd);
for arg in args {
command.arg(&arg);
}
command.uid(0);
command.gid(0);
command.env("USER", "root");
command.env("UID", "0");
command.env("GROUPS", "0");
let err = command.exec();
eprintln!("sudo: failed to execute {}: {}", cmd, err);
exit(1);
}
struct Scheme {
next_fd: usize,
handles: HashMap<usize, Handle>,
}
enum Handle {
AwaitingPassword { uid: u32 },
AwaitingRootPassword,
AwaitingContextFd,
AwaitingNamespaceFetch { ns: libredox::Fd },
AwaitingPasswordForPasswd { uid: u32 },
AwaitingNewPassword { uid: u32 },
Placeholder,
SchemeRoot,
}
impl SchemeSync for Scheme {
fn scheme_root(&mut self) -> Result<usize> {
let fd = self.next_fd;
self.next_fd = self.next_fd.checked_add(1).ok_or(Error::new(EMFILE))?;
self.handles.insert(fd, Handle::SchemeRoot);
Ok(fd)
}
fn openat(
&mut self,
dirfd: usize,
path: &str,
_flags: usize,
_fcntl_flags: u32,
ctx: &CallerCtx,
) -> Result<OpenResult> {
let handle = match self.handles.get_mut(&dirfd).ok_or(Error::new(EBADF))? {
Handle::SchemeRoot => match path {
"" => Handle::AwaitingPassword { uid: ctx.uid },
"su" => Handle::AwaitingRootPassword,
"passwd" => Handle::AwaitingPasswordForPasswd { uid: ctx.uid },
_ => return Err(Error::new(ENOENT)),
},
Handle::AwaitingNamespaceFetch { .. } => {
if path != "ns" {
return Err(Error::new(ENOENT));
}
let ns = match self.handles.insert(dirfd, Handle::Placeholder).unwrap() {
Handle::AwaitingNamespaceFetch { ns } => ns,
_ => unreachable!(),
};
return Ok(OpenResult::OtherScheme { fd: ns.into_raw() });
}
_ => return Err(Error::new(EINVAL)),
};
let fd = self.next_fd;
self.next_fd = self.next_fd.checked_add(1).ok_or(Error::new(EMFILE))?;
self.handles.insert(fd, handle);
Ok(OpenResult::ThisScheme {
number: fd,
flags: NewFdFlags::empty(),
})
}
fn write(
&mut self,
id: usize,
buf: &[u8],
_off: u64,
_flags: u32,
_ctx: &CallerCtx,
) -> Result<usize> {
let handle = self.handles.get_mut(&id).ok_or(Error::new(EBADF))?;
let validate_utf8 = |buf| std::str::from_utf8(buf).map_err(|_| Error::new(EINVAL));
match std::mem::replace(handle, Handle::Placeholder) {
Handle::AwaitingPassword { uid } => {
let users = AllUsers::authenticator(Config::default()).unwrap_or_exit(1);
let user = users.get_by_id(uid as usize).unwrap_or_exit(1);
match policy_for_user(uid) {
Policy::Deny => {
*handle = Handle::AwaitingPassword { uid };
return Err(Error::new(EPERM));
}
Policy::Authenticate => {
let password = validate_utf8(buf)?;
if user.verify_passwd(&password) {
*handle = Handle::AwaitingContextFd
} else {
*handle = Handle::AwaitingPassword { uid };
return Err(Error::new(EPERM));
}
}
}
}
Handle::AwaitingRootPassword => {
let users = AllUsers::authenticator(Config::default()).unwrap_or_exit(1);
let user = users.get_by_id(0).unwrap_or_exit(1);
let password = validate_utf8(buf)?;
if user.verify_passwd(&password) {
*handle = Handle::AwaitingContextFd
} else {
*handle = Handle::AwaitingRootPassword;
return Err(Error::new(EPERM));
}
}
Handle::AwaitingContextFd => {
*handle = Handle::AwaitingContextFd;
return Err(Error::new(EINVAL));
}
Handle::AwaitingPasswordForPasswd { uid } => {
let users =
AllUsers::authenticator(Config::default()).map_err(|_| Error::new(ENOLCK))?;
let user = users.get_by_id(uid as usize).ok_or(Error::new(EEXIST))?;
let password = validate_utf8(buf)?;
if user.verify_passwd(&password) {
*handle = Handle::AwaitingNewPassword { uid }
} else {
*handle = Handle::AwaitingPasswordForPasswd { uid };
return Err(Error::new(EPERM));
}
}
Handle::AwaitingNewPassword { uid } => {
let mut users = AllUsers::authenticator(Config::default().writeable(true))
.map_err(|_| Error::new(ENOLCK))?;
let user = users
.get_mut_by_id(uid as usize)
.ok_or(Error::new(EEXIST))?;
let new_password = validate_utf8(buf)?;
if user.set_passwd(&new_password).is_ok() {
users.save().map_err(|_| Error::new(ENOLCK))?;
*handle = Handle::Placeholder
} else {
*handle = Handle::AwaitingNewPassword { uid };
return Err(Error::new(EPERM));
}
}
Handle::AwaitingNamespaceFetch { .. } => {
eprintln!("sudo: found namespace fetch handle with ID {id}");
return Err(Error::new(EBADFD));
}
Handle::Placeholder => {
eprintln!("sudo: found placeholder handle with ID {id}");
return Err(Error::new(EBADFD));
}
Handle::SchemeRoot => {
eprintln!("sudo: found Scheme root handle with ID {id}");
return Err(Error::new(EBADFD));
}
}
Ok(buf.len())
}
}
impl Scheme {
fn on_close(&mut self, id: usize) {
self.handles.remove(&id);
}
fn on_sendfd(&mut self, socket: &Socket, req: &SendFdRequest) -> Result<usize> {
let handle = self.handles.get_mut(&req.id()).ok_or(Error::new(EBADF))?;
match std::mem::replace(handle, Handle::Placeholder) {
Handle::AwaitingContextFd => {
let mut proc_fd = usize::MAX;
req.obtain_fd(
socket,
FobtainFdFlags::empty(),
std::slice::from_mut(&mut proc_fd),
)?;
let proc_fd = unsafe { OwnedFd::from_raw_fd(proc_fd as RawFd) };
let [ruid, euid, suid] = [0, 0, 0];
let [rgid, egid, sgid] = [0, 0, 0];
let mut payload = [0; size_of::<u32>() * 6];
plain::slice_from_mut_bytes(&mut payload)
.unwrap()
.copy_from_slice(&[ruid, euid, suid, rgid, egid, sgid]);
if let Err(err) = proc_call(
proc_fd.as_raw_fd() as usize,
&mut payload,
CallFlags::empty(),
&[ProcCall::SetResugid as u64],
) {
eprintln!("failed to setresugid: {err}");
}
*handle = Handle::AwaitingNamespaceFetch {
ns: libredox::Fd::new(
syscall::dup(libredox::call::getns().unwrap(), b"").unwrap(),
),
};
}
old => {
*handle = old;
return Err(Error::new(EBADF));
}
}
Ok(0)
}
}
fn daemon_main() -> ! {
// TODO: Linux kernel audit-like logging?
let socket = Socket::create().expect("failed to open scheme socket");
let mut scheme = Scheme {
next_fd: 1,
handles: HashMap::new(),
};
let mut scheme_state = redox_scheme::scheme::SchemeState::new();
register_sync_scheme(&socket, "sudo", &mut scheme)
.expect("failed to register sudo scheme to namespace");
loop {
let Some(req) = socket
.next_request(SignalBehavior::Restart)
.expect("failed to get request")
else {
break;
};
let response = match req.kind() {
RequestKind::Call(call) => call.handle_sync(&mut scheme, &mut scheme_state),
RequestKind::SendFd(req) => Response::new(scheme.on_sendfd(&socket, &req), req),
RequestKind::OnClose { id } => {
scheme.on_close(id);
continue;
}
_ => continue,
};
socket
.write_response(response, SignalBehavior::Restart)
.expect("sudo: scheme write failed");
}
std::process::exit(0)
}
+205
View File
@@ -0,0 +1,205 @@
#[macro_use]
extern crate clap;
use std::process::exit;
use extra::option::OptionalExt;
use redox_users::{All, AllGroups, AllUsers, Config, GroupBuilder, UserBuilder};
use userutils::create_user_dir;
const _MAN_PAGE: &'static str = /* @MANSTART{useradd} */
r#"
NAME
useradd - add a new user
SYNOPSYS
useradd [ options ] LOGIN
useradd [ -h | --help ]
DESCRIPTION
The useradd utility creates a new user based on
system defaults and values passed on the command line.
Useradd creates a new group for the user by default and
can also be instructed to create the user's home directory.
Note that useradd creates a new user with the password
unset (no login). This is better documented with the
redox_users crate.
OPTIONS
-h, --help
Display this help and exit.
-c, --comment
Any text string, usually used as the user's full name.
Historically known as the GECOS field
-d, --home-dir HOME_DIR
The new user will be created with HOME_DIR as their home
directory. The default value is LOGIN prepended with "/home/".
This flag DOES NOT create the home directory. See --create-home
-g, --gid GID
The group id to use when creating the default login group. This value
must not be in use and must be non-negative. The default is to pick the
smallest available group id between values defined in redox_users.
-m, --create-home
Creates the user's home directory if it does not already exist.
This option is not enabled by default. This option must be specified
for a home directory to be created. If not set, the user's home dir is
set to "/"
-N, --no-user-group
Do not attempt to create the user's user group. Instead, the groupid
is set to 99 ("nobody"). -N and -g are mutually exclusive.
-s, --shell SHELL
The path to the user's default login shell. If not specified, the
default shell is set as "/bin/ion"
-u, --uid UID
The user id to use. This value must not be in use and must be
non-negative. The default is to pick the smallest available
user id between the defaults defined in redox_users
AUTHORS
Written by Wesley Hershberger.
"#; /* @MANEND */
const DEFAULT_SHELL: &'static str = "/bin/ion";
const DEFAULT_HOME: &'static str = "/home";
const DEFAULT_NO_GROUP: &'static str = "nobody";
fn main() {
let args = clap_app!(useradd =>
(author: "Wesley Hershberger")
(about: "Add users based on the system's redox_users backend")
(@arg LOGIN:
+required
"Add user LOGIN")
(@arg COMMENT:
-c --comment
+takes_value
"Set user description (GECOS field)")
(@arg HOME_DIR:
-d --("home-dir")
+takes_value
"Set LOGIN's home dir to HOME_DIR (does not create directory)")
(@arg CREATE_HOME:
-m --("create-home")
"Create the user's home directory")
(@arg SHELL:
-s --shell
+takes_value
"Set user's default login shell")
(@arg GID:
-g --gid
+takes_value
"Set LOGIN's primary group id. Positive integer and must not be in use.")
(@arg NO_USER_GROUP:
-N --("no-user-group")
conflicts_with[GID]
"Do not create primary user group (set gid to 99, \"nobody\")")
(@arg UID:
-u --uid
+takes_value
"Set LOGIN's user id. Positive ineger and must not be in use.")
)
.get_matches();
// unwrap is safe because of "+required". clap-rs is cool...
let login = args.value_of("LOGIN").unwrap();
let mut sys_users =
AllUsers::authenticator(Config::default().writeable(true)).unwrap_or_exit(1);
let mut sys_groups = AllGroups::new(Config::default().writeable(true)).unwrap_or_exit(1);
let uid = match args.value_of("UID") {
Some(uid) => {
let id = uid.parse::<usize>().unwrap_or_exit(1);
if let Some(_user) = sys_users.get_by_id(id) {
eprintln!("useradd: userid already in use: {}", id);
exit(1);
}
id
}
None => sys_users.get_unique_id().unwrap_or_else(|| {
eprintln!("useradd: no available uid");
exit(1);
}),
};
let gid = if args.is_present("NO_USER_GROUP") {
let nobody = sys_groups
.get_mut_by_name(DEFAULT_NO_GROUP)
.unwrap_or_else(|| {
eprintln!("useradd: group not found: {}", DEFAULT_NO_GROUP);
exit(1)
});
nobody.users.push(login.to_string());
99
} else {
let id = match args.value_of("GID") {
Some(id) => {
let id = id.parse::<usize>().unwrap_or_exit(1);
if let Some(_group) = sys_groups.get_by_id(id) {
eprintln!("useradd: group already exists with gid: {}", id);
exit(1);
}
id
}
None => sys_groups.get_unique_id().unwrap_or_else(|| {
eprintln!("useradd: no available gid");
exit(1);
}),
};
sys_groups
.add_group(GroupBuilder::new(login).gid(id).user(login))
.unwrap_or_else(|err| {
eprintln!("useradd: {}: {}", err, login);
exit(1);
});
id
};
let gecos = args.value_of("COMMENT").unwrap_or(login);
//Ugly way to satisfy the borrow checker...
let mut sys_homes = String::from(DEFAULT_HOME);
let userhome = args.value_of("HOME_DIR").unwrap_or_else(|| {
if args.is_present("CREATE_HOME") {
sys_homes.push_str("/");
sys_homes.push_str(&login);
sys_homes.as_str()
} else {
"/"
}
});
let shell = args.value_of("SHELL").unwrap_or(DEFAULT_SHELL);
let user = UserBuilder::new(login)
.uid(uid)
.gid(gid)
.name(gecos)
.home(userhome)
.shell(shell);
sys_users.add_user(user).unwrap_or_else(|err| {
eprintln!("useradd: {}: {}", err, login);
exit(1);
});
// Make sure to try and create the user/groups before we create
// their home, that way we get a permissions error that makes
// more sense
sys_groups.save().unwrap_or_exit(1);
sys_users.save().unwrap_or_exit(1);
if args.is_present("CREATE_HOME") {
//Shouldn't ever error...
let user = sys_users.get_by_id(uid).unwrap_or_exit(1);
create_user_dir(user, userhome).unwrap_or_exit(1);
}
}
+69
View File
@@ -0,0 +1,69 @@
#[macro_use]
extern crate clap;
use std::fs::remove_dir;
use std::process::exit;
use extra::option::OptionalExt;
use redox_users::{All, AllGroups, AllUsers, Config};
use userutils::AllGroupsExt;
const _MAN_PAGE: &'static str = /* @MANSTART{userdel} */
r#"
NAME
userdel - modify system files to delete users
SYNOPSYS
userdel [ options ] LOGIN
userdel [ -h | --help ]
DESCRIPTION
userdel removes users from whatever backend is employed by
the system's redox_users. The utility removes the user from
all groups of which they are a member.
It can also be used to manage removal of home directories.
OPTIONS
-h, --help
Print this help page and exit.
-r, --remove
The user's home directory and all files inside will be
removed.
AUTHORS
Wesley Hershberger.
"#; /* @MANEND */
fn main() {
let args = clap_app!(userdel =>
(author: "Wesley Hershberger")
(about: "Removes system users using redox_users")
(@arg LOGIN: +required "Remove user LOGIN")
(@arg REMOVE: -r --remove "Remove the user's home and all files and directories inside")
)
.get_matches();
let login = args.value_of("LOGIN").unwrap();
let mut sys_users =
AllUsers::authenticator(Config::default().writeable(true)).unwrap_or_exit(1);
let mut sys_groups = AllGroups::new(Config::default().writeable(true)).unwrap_or_exit(1);
{
sys_groups.remove_user_from_all_groups(login);
if args.is_present("REMOVE") {
let user = sys_users.get_by_name(login).unwrap_or_else(|| {
eprintln!("userdel: user does not exist: {}", login);
exit(1);
});
remove_dir(&user.home).unwrap_or_exit(1);
}
}
sys_users.remove_by_name(login.to_string());
sys_groups.save().unwrap_or_exit(1);
sys_users.save().unwrap_or_exit(1);
}
+196
View File
@@ -0,0 +1,196 @@
#[macro_use]
extern crate clap;
use std::fs::{remove_dir, rename};
use std::process::exit;
use extra::option::OptionalExt;
use redox_users::{All, AllGroups, AllUsers, Config};
use userutils::{AllGroupsExt, create_user_dir};
const _MAN_PAGE: &'static str = /* @MANSTART{usermod} */
r#"
NAME
usermod - modify user information
SYNOPSYS
usermod [ options ] LOGIN
usermod [ -h | --help ]
DESCRIPTION
The usermod utility can be used to modify user information.
This utility uses the redox_users API, so the backend is whatever
backend in use on the system for that API at the time.
See passwd for setting user passwords.
OPTIONS
-h, --help
Display this help and exit.
-c, --comment COMMENT
The comment field (or GECOS, historically) for the user. This
is typically the full name of the user, although sometimes it
includes an e-mail.
-d, --home-dir HOME_DIR
Sets the home directory to HOME_DIR and creates the directory.
See -m for move
-m, --move-home
Moves the the user's old home directory into the home directory
specified by --home-dir. Has no effect if passed without --home-dir
-G, --append-groups GROUP[,GROUP, ...]
Add this user to GROUP groups. This does not remove the user from
any group of which they are already a member.
-S, --set-groups GROUP[,GROUP, ...]
Remove the user from all groups of which they are a part and add
them to GROUP groups.
-g, --gid GID
Set the user's primary group id. If the group does not exist,
a warning is issued and no changes are applied.
-l, --login NEW_LOGIN
Set the new login name for the user. Must not be in use.
-s, --shell SHELL
Set the user's login shell as SHELL. This must be a full path.
-u, --uid UID
Set the user's user id. If another user's userid is the same as
UID, a warning is issued and no changes are applied. Note that
changing the value of the user's userid may have unexpected consequences.
AUTHORS
Written by Wesley Hershberger.
"#; /* @MANEND */
fn main() {
let args = clap_app!(usermod =>
(author: "Wesley Hershberger")
(about: "Modify users according to the system's redox_users backend")
(@arg LOGIN:
+required
"Apply modifications to LOGIN")
(@arg COMMENT:
-c --comment
+takes_value
"Set LOGIN's description (GECOS field)")
(@arg HOME_DIR:
-d --("home-dir")
+takes_value
"Create and set LOGIN's home directory")
(@arg MOVE_HOME:
-m --("move-home")
requires[HOME_DIR]
"Move LOGIN's old home to HOME_DIR (see --home-dir) instead of creating it. Requires -d")
(@arg APPEND_GROUPS:
-G --("append-groups")
+takes_value conflicts_with[SET_GROUPS]
"Add user to groups specified (comma separated list, see man page)")
(@arg SET_GROUPS:
-S --("set-groups")
+takes_value conflicts_with[APPEND_GROUPS]
"Set LOGIN's groups as specified (truncates existing, see man page)")
(@arg GID:
-g --gid
+takes_value
"Set LOGIN's primary group id. Group must exist")
(@arg NEW_LOGIN:
-l --login
+takes_value
"Set LOGIN's name to NEW_LOGIN")
(@arg SHELL:
-s --shell
+takes_value
"Set LOGIN's default login shell")
(@arg UID:
-u --uid
+takes_value
"Set LOGIN's user id. See man page for details")
).get_matches();
let login = args.value_of("LOGIN").unwrap();
//TODO: Does not always need shadowfile access
let mut sys_users =
AllUsers::authenticator(Config::default().writeable(true)).unwrap_or_exit(1);
let mut sys_groups;
if let Some(new_groups) = args.value_of("SET_GROUPS") {
sys_groups = AllGroups::new(Config::default().writeable(true)).unwrap_or_exit(1);
sys_groups.remove_user_from_all_groups(login);
sys_groups
.add_user_to_groups(login, new_groups.split(',').collect())
.unwrap_or_exit(1);
sys_groups.save().unwrap_or_exit(1);
}
if let Some(new_groups) = args.value_of("APPEND_GROUPS") {
sys_groups = AllGroups::new(Config::default().writeable(true)).unwrap_or_exit(1);
sys_groups
.add_user_to_groups(login, new_groups.split(',').collect())
.unwrap_or_exit(1);
sys_groups.save().unwrap_or_exit(1);
}
let uid = args.value_of("UID").map(|uid| {
let uid = uid.parse::<usize>().unwrap_or_exit(1);
if let Some(_user) = sys_users.get_by_id(uid) {
eprintln!("usermod: userid already in use: {}", uid);
exit(1);
}
uid
});
{
let user = sys_users.get_mut_by_name(&login).unwrap_or_else(|| {
eprintln!("usermod: user \"{}\" not found", login);
exit(1);
});
if let Some(gecos) = args.value_of("COMMENT") {
user.name = gecos.to_string();
}
if let Some(new_login) = args.value_of("NEW_LOGIN") {
user.user = new_login.to_string();
}
if let Some(shell) = args.value_of("SHELL") {
user.shell = shell.to_string();
}
if let Some(home) = args.value_of("HOME_DIR") {
if args.is_present("MOVE_HOME") {
rename(&user.home, &home).unwrap_or_exit(1);
} else {
create_user_dir(user, &home).unwrap_or_exit(1);
remove_dir(&user.home).unwrap_or_exit(1);
}
user.home = home.to_string();
}
if let Some(uid) = uid {
user.uid = uid;
}
if let Some(gid) = args.value_of("GID") {
sys_groups = AllGroups::new(Config::default()).unwrap_or_exit(1);
let gid = gid.parse::<usize>().unwrap_or_exit(1);
if let Some(_group) = sys_groups.get_by_id(gid) {
user.gid = gid;
} else {
eprintln!("usermod: no group found for id: {}", gid);
exit(1);
}
}
}
sys_users.save().unwrap_or_exit(1);
}
-418
View File
@@ -1,418 +0,0 @@
//! Runtime file-collision detection for `install_dir()`.
//!
//! The installer writes files in four layers (see AGENTS.md § "Installer File
//! Layering"):
//!
//! ```text
//! Layer 1: Config pre-install [[files]] (postinstall = false)
//! Layer 2: Package staging (install_packages())
//! Layer 3: Config post-install [[files]] (postinstall = true)
//! Layer 4: User/group creation (passwd, shadow, group)
//! ```
//!
//! Last writer wins. Layer 2 silently overwriting Layer 1 is the D-Bus
//! regression class: a config `[[files]]` entry writes to a path, a package
//! stages the same path during `install_packages()`, the package wins, the
//! operator's customization is gone — and the build succeeds. This module
//! makes that class of bug visible at install time.
//!
//! ## Behavior
//!
//! - Every file write (regular file or symlink) is recorded with its layer
//! and source.
//! - When a later layer overwrites a path written by an earlier layer, a
//! `[COLLISION-WARN]` line is emitted to stderr. The build-time
//! `scripts/validate-collision-log.sh` greps logs for that marker.
//! - Layer 3 (`ConfigPostInstall`) is the *intentional override* layer — its
//! whole purpose is to overwrite package defaults. Collisions from Layer 3
//! are suppressed by design and never warn.
//! - Known-safe override path pairs (e.g. `/etc/init.d/` over
//! `/usr/lib/init.d/`, mirroring the init system's `config_for_dirs()`
//! priority) are also suppressed.
//! - Strict mode (`REDBEAR_INSTALLER_STRICT_COLLISIONS=1`) promotes
//! collisions to hard errors via `anyhow::bail!`. Default is warn-only.
//!
//! ## What is NOT tracked
//!
//! Directory creation. `fs::create_dir_all` is idempotent; two layers
//! creating the same directory is a no-op, not a collision. Only regular
//! files and symlinks are recorded.
use std::collections::HashMap;
use std::path::{Path, PathBuf};
use anyhow::{bail, Result};
/// Installer file-write layers, in write order. The numeric value matches
/// the layer numbering in AGENTS.md § "Installer File Layering" and is used
/// in user-facing warning text.
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
#[repr(u8)]
pub enum Layer {
/// `[[files]]` entries with `postinstall = false`. Written first.
ConfigPreInstall = 1,
/// Package staging via `install_packages()`. Layer 2 overwriting
/// Layer 1 is the D-Bus regression class (silent loss of config).
PackageStaging = 2,
/// `[[files]]` entries with `postinstall = true`. Intentional override
/// layer — collisions from this layer never warn by design.
ConfigPostInstall = 3,
/// Files the installer itself writes at the end of `install_dir()`
/// (`/etc/passwd`, `/etc/shadow`, `/etc/group`).
InstallerBuiltin = 4,
}
impl Layer {
/// Numeric layer identifier as documented in AGENTS.md. Stable across
/// releases — used in `[COLLISION-WARN]` output.
pub fn as_u8(self) -> u8 {
self as u8
}
}
/// Where a tracked file came from.
#[derive(Debug, Clone)]
pub enum ProvenanceSource {
/// `[[files]]` entry. The string is the config-visible path
/// (leading-slash form, e.g. `"/etc/passwd"`).
ConfigFile(String),
/// Package staging. The string is a package identifier, or `"staged"`
/// when the writing package cannot be identified (the common case —
/// `install_packages()` does not report per-file provenance).
Package(String),
/// Installer-builtin file (`/etc/passwd`, `/etc/shadow`, `/etc/group`).
InstallerBuiltin,
}
/// Provenance record for one file path.
#[derive(Debug, Clone)]
pub struct FileProvenance {
/// What wrote the file.
pub source: ProvenanceSource,
/// Which install layer wrote it.
pub layer: Layer,
}
/// One collision event recorded by the tracker.
#[derive(Debug, Clone)]
pub struct Collision {
/// Absolute filesystem path that was overwritten.
pub path: PathBuf,
/// Provenance of the earlier (overwritten) write.
pub previous: FileProvenance,
/// Provenance of the later (overwriting) write.
pub current: FileProvenance,
}
/// Marker emitted on stderr for every collision warning. The build-time
/// `scripts/validate-collision-log.sh` script greps logs for this token.
pub const WARN_MARKER: &str = "[COLLISION-WARN]";
/// Marker emitted on stderr when strict mode promotes a collision to an
/// error. Paired with `WARN_MARKER` in the same message so log-grepping
/// for either token catches every collision.
pub const ERROR_MARKER: &str = "[COLLISION-ERROR]";
/// Environment variable name that opts into strict mode (promotes
/// collisions to hard errors). Default is warn-only.
pub const STRICT_ENV_VAR: &str = "REDBEAR_INSTALLER_STRICT_COLLISIONS";
/// Pairs of `(override_dir, package_default_dir)`. When the current write
/// is under `override_dir` and the previous write was under
/// `package_default_dir`, the collision is considered intentional and is
/// suppressed. These mirror the init system's `config_for_dirs()` priority
/// directories documented in AGENTS.md § "Init Service File Ownership".
const KNOWN_SAFE_OVERRIDE_PAIRS: &[(&str, &str)] = &[
// Config overrides at /etc/init.d/ intentionally replace package
// defaults at /usr/lib/init.d/ for the same filename. The init
// system's config_for_dirs() BTreeMap gives /etc/init.d/ priority.
("/etc/init.d", "/usr/lib/init.d"),
// Likewise for environment.d — config overrides at /etc/ replace
// package defaults at /usr/lib/.
("/etc/environment.d", "/usr/lib/environment.d"),
];
/// Returns true if `(previous_config_path, current_config_path)` matches a
/// known-safe override pair: previous under a package default dir, current
/// under the matching config override dir. Both arguments are absolute
/// config-visible paths (leading `/`).
fn is_known_safe_override(previous_config_path: &str, current_config_path: &str) -> bool {
for &(override_dir, default_dir) in KNOWN_SAFE_OVERRIDE_PAIRS {
let curr_is_override =
current_config_path == override_dir || is_dir_member(current_config_path, override_dir);
let prev_is_default =
previous_config_path == default_dir || is_dir_member(previous_config_path, default_dir);
if curr_is_override && prev_is_default {
return true;
}
}
false
}
/// True if `child` is a file path strictly inside `parent` (not `parent`
/// itself). Both arguments are absolute config-visible paths with no
/// trailing slash. Uses byte comparison to stay I/O-free.
fn is_dir_member(child: &str, parent: &str) -> bool {
// We expect paths like "/etc/init.d/foo" inside "/etc/init.d".
let parent_with_slash = format!("{parent}/");
child.starts_with(&parent_with_slash)
}
/// File-write provenance tracker for `install_dir()`.
///
/// Construct with [`CollisionTracker::new`] to pick up strict mode from the
/// environment, or with [`CollisionTracker::new_with_strict`] for tests and
/// explicit control. Call [`CollisionTracker::record`] before each file
/// write, and [`CollisionTracker::scan_package_staging`] once after
/// `install_packages()` returns.
pub struct CollisionTracker {
/// Map from absolute filesystem path to the most recent provenance.
files: HashMap<PathBuf, FileProvenance>,
/// Map from absolute filesystem path back to the leading-`/` config
/// path, when known. Lets the known-safe override check compare
/// previous vs. current config-visible paths even when both resolves
/// land at the same physical file (e.g. via a symlinked /etc/init.d).
config_paths: HashMap<PathBuf, String>,
strict: bool,
collisions: Vec<Collision>,
}
impl CollisionTracker {
/// Construct a tracker, reading strict mode from the
/// `REDBEAR_INSTALLER_STRICT_COLLISIONS` environment variable.
pub fn new() -> Self {
let strict = std::env::var(STRICT_ENV_VAR)
.map(|v| v == "1" || v.eq_ignore_ascii_case("true"))
.unwrap_or(false);
Self::new_with_strict(strict)
}
/// Construct a tracker with explicit strict-mode control.
///
/// Tests should prefer this over [`Self::new`] to avoid env-var races
/// under parallel test execution.
pub fn new_with_strict(strict: bool) -> Self {
Self {
files: HashMap::new(),
config_paths: HashMap::new(),
strict,
collisions: Vec::new(),
}
}
/// Number of distinct file paths currently tracked.
#[allow(dead_code)]
pub fn len(&self) -> usize {
self.files.len()
}
/// Whether the tracker has observed any file writes.
#[allow(dead_code)]
pub fn is_empty(&self) -> bool {
self.files.is_empty()
}
/// Number of collisions recorded (warnings emitted, or errors raised in
/// strict mode).
pub fn collision_count(&self) -> usize {
self.collisions.len()
}
/// Snapshot of recorded collisions (for test inspection and reporting).
pub fn collisions(&self) -> &[Collision] {
&self.collisions
}
/// Whether strict mode is enabled on this tracker.
#[allow(dead_code)]
pub fn is_strict(&self) -> bool {
self.strict
}
/// Record a file write at `abs_path` (absolute filesystem path) with
/// the given provenance.
///
/// `config_path` is the leading-`/` config-visible path when known
/// (used for the known-safe override check), or `None` for paths whose
/// config-visible form is not meaningful.
///
/// # Collisions
///
/// A collision is when the same `abs_path` was previously written by a
/// *different* layer. Collisions emit `[COLLISION-WARN]` on stderr and
/// are recorded. In strict mode they additionally return `Err`.
///
/// # Suppression
///
/// Warnings are suppressed when either:
/// - the current write is from `Layer::ConfigPostInstall` (the
/// intentional override layer), or
/// - the previous config path and the current config path form a
/// known-safe override pair (e.g. `/etc/init.d/X` over
/// `/usr/lib/init.d/X`).
///
/// Suppressed collisions are still recorded in the `files` map (the
/// latest provenance wins) but do not emit a warning and do not
/// increment `collision_count()`.
pub fn record(
&mut self,
abs_path: PathBuf,
provenance: FileProvenance,
config_path: Option<&str>,
) -> Result<()> {
// Capture previous state BEFORE any mutation. The known-safe
// override check compares the previous config_path against the
// current one; if we let the insert below clobber the map first,
// we'd compare the new path against itself.
let previous_provenance = self.files.get(&abs_path).cloned();
let previous_config_path = self.config_paths.get(&abs_path).cloned();
if let Some(cp) = config_path {
self.config_paths.insert(abs_path.clone(), cp.to_string());
}
let Some(previous) = previous_provenance else {
self.files.insert(abs_path, provenance);
return Ok(());
};
// Same-layer re-write is not a collision. Config merges already
// deduplicate same-path entries; package staging may legitimately
// touch a file twice (e.g. an inner archive extraction).
if previous.layer == provenance.layer {
self.files.insert(abs_path, provenance);
return Ok(());
}
// Layer 3 is the intentional override layer by design. Its whole
// purpose is to overwrite package defaults — collisions from it
// must not warn or the override mechanism would be unusable.
let is_layer3_override = provenance.layer == Layer::ConfigPostInstall;
// Known-safe override path pairs (e.g. /etc/init.d over
// /usr/lib/init.d). Only meaningful when both layers recorded a
// config-visible path for the same abs_path.
let is_known_safe = match (previous_config_path.as_deref(), config_path) {
(Some(prev_cp), Some(curr_cp)) => is_known_safe_override(prev_cp, curr_cp),
_ => false,
};
if is_layer3_override || is_known_safe {
self.files.insert(abs_path, provenance);
return Ok(());
}
// Real collision — warn (and bail in strict mode).
let collision = Collision {
path: abs_path.clone(),
previous: previous.clone(),
current: provenance.clone(),
};
self.collisions.push(collision.clone());
emit_warning(&collision);
self.files.insert(abs_path, provenance);
if self.strict {
bail!(
"{ERROR_MARKER} strict mode ({STRICT_ENV_VAR}=1): collision at {} \
— {} layer {} overwritten by {} layer {}. Aborting install. \
Fix the conflicting paths, or unset {STRICT_ENV_VAR} to demote \
this to a warning.",
collision.path.display(),
source_label(&collision.previous.source),
collision.previous.layer.as_u8(),
source_label(&collision.current.source),
collision.current.layer.as_u8(),
);
}
Ok(())
}
/// Walk `dest` after `install_packages()` returns, recording every file
/// the package staging wrote.
///
/// Files already tracked from Layer 1 trigger the Layer 2 overwrites
/// Layer 1 collision (the D-Bus regression class). Files not previously
/// tracked are recorded with `Layer::PackageStaging` provenance.
///
/// Directories are not tracked — `fs::create_dir_all` is idempotent and
/// directory paths are shared infrastructure. Only regular files and
/// symlinks are recorded.
///
/// I/O errors during the walk are tolerated (treated as "no file here")
/// so a partially-populated tree does not abort the install. The
/// collision decision is made from what we *can* read.
pub fn scan_package_staging(&mut self, dest: &Path) -> Result<()> {
if !dest.exists() {
return Ok(());
}
walk_for_files(dest, dest, self)
}
}
impl Default for CollisionTracker {
fn default() -> Self {
Self::new()
}
}
/// Recursive walker that records every file (regular or symlink) under
/// `root` as a Layer 2 (PackageStaging) write.
fn walk_for_files(root: &Path, current: &Path, tracker: &mut CollisionTracker) -> Result<()> {
let read_dir = match std::fs::read_dir(current) {
Ok(rd) => rd,
// Tolerate unreadable subdirs — they contribute no files.
Err(_) => return Ok(()),
};
for entry in read_dir {
let Ok(entry) = entry else {
continue;
};
let Ok(file_type) = entry.file_type() else {
continue;
};
let abs_path = entry.path();
if file_type.is_symlink() || file_type.is_file() {
let provenance = FileProvenance {
source: ProvenanceSource::Package("staged".to_string()),
layer: Layer::PackageStaging,
};
// For package-staged files the config-visible path is the path
// under `root` (with a leading `/`). This matches how a config
// `[[files]]` entry would address the same file.
let config_visible = match abs_path.strip_prefix(root) {
Ok(rel) => format!("/{}", rel.display()),
Err(_) => abs_path.to_string_lossy().into_owned(),
};
tracker.record(abs_path, provenance, Some(&config_visible))?;
} else if file_type.is_dir() {
walk_for_files(root, &abs_path, tracker)?;
}
}
Ok(())
}
/// Emit a single `[COLLISION-WARN]` line on stderr. The build's
/// `validate-collision-log.sh` greps for this token after the install
/// finishes.
fn emit_warning(c: &Collision) {
eprintln!(
"{WARN_MARKER} {} layer {} overwritten by layer {} ({} -> {}). \
Set {STRICT_ENV_VAR}=1 to promote this to an error.",
c.path.display(),
c.previous.layer.as_u8(),
c.current.layer.as_u8(),
source_label(&c.previous.source),
source_label(&c.current.source),
);
}
/// Short human-readable label for a provenance source, used in warning and
/// error text.
fn source_label(s: &ProvenanceSource) -> &'static str {
match s {
ProvenanceSource::ConfigFile(_) => "config",
ProvenanceSource::Package(_) => "package",
ProvenanceSource::InstallerBuiltin => "installer",
}
}
-88
View File
@@ -1,88 +0,0 @@
use std::fmt::Display;
fn is_false(value: &bool) -> bool {
!*value
}
#[derive(Clone, Debug, Default, Deserialize, Serialize)]
pub struct FileConfig {
pub path: String,
pub data: String,
#[serde(default)]
pub symlink: bool,
#[serde(default)]
pub directory: bool,
pub mode: Option<u32>,
pub uid: Option<u32>,
pub gid: Option<u32>,
#[serde(default)]
pub recursive_chown: bool,
#[serde(default)]
pub postinstall: bool,
#[serde(default, skip_serializing_if = "is_false")]
pub append: bool,
}
impl FileConfig {
pub fn new_file(path: String, data: String) -> FileConfig {
FileConfig {
path,
data,
..Default::default()
}
}
pub fn new_directory(path: String) -> FileConfig {
FileConfig {
path,
data: String::new(),
directory: true,
..Default::default()
}
}
pub fn with_mod(&mut self, mode: u32, uid: u32, gid: u32) -> &mut FileConfig {
self.mode = Some(mode);
self.uid = Some(uid);
self.gid = Some(gid);
self
}
pub fn with_recursive_mod(&mut self, mode: u32, uid: u32, gid: u32) -> &mut FileConfig {
self.with_mod(mode, uid, gid);
self.recursive_chown = true;
self
}
}
impl Display for FileConfig {
fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
write!(f, "{}", self.path)?;
if self.symlink {
write!(f, " -> {}", self.data)?;
} else if self.directory {
write!(f, " type=dir")?;
if self.recursive_chown {
write!(f, " chown=yes")?;
}
} else {
write!(f, " size={}", crate::format_bytes(self.data.len() as u64))?;
if self.postinstall {
write!(f, "!")?;
}
if self.append {
write!(f, " append=yes")?;
}
}
if let Some(uid) = self.uid {
write!(f, " uid={}", uid)?;
}
if let Some(uid) = self.uid {
write!(f, " gid={}", uid)?;
}
if let Some(mode) = self.mode {
write!(f, " mode={:3o}", mode)?;
}
Ok(())
}
}
-98
View File
@@ -1,98 +0,0 @@
use anyhow::{Context, Result};
use libc::{gid_t, uid_t};
use std::ffi::{CString, OsStr};
use std::fs::{self, File};
use std::io::{Error, Write};
use std::os::unix::ffi::OsStrExt;
use std::os::unix::fs::{symlink, PermissionsExt};
use std::path::Path;
fn chown<P: AsRef<Path>>(path: P, uid: uid_t, gid: gid_t, recursive: bool) -> Result<()> {
let path = path.as_ref();
let c_path = CString::new(path.as_os_str().as_bytes()).unwrap();
if unsafe { libc::chown(c_path.as_ptr(), uid, gid) } != 0 {
return Err(Error::last_os_error().into());
}
if recursive && path.is_dir() {
for entry_res in fs::read_dir(path)? {
let entry = entry_res?;
chown(entry.path(), uid, gid, recursive)?;
}
}
Ok(())
}
// TODO: Rewrite impls
impl crate::FileConfig {
pub(crate) fn create<P: AsRef<Path>>(&self, prefix: P) -> Result<()> {
let path = self.path.trim_start_matches('/');
let target_file = prefix.as_ref().join(path);
if self.directory {
println!("Create directory {}", target_file.display());
fs::create_dir_all(&target_file)
.with_context(|| format!("failed to create directory {}", target_file.display()))?;
self.apply_perms(&target_file)?;
return Ok(());
} else if let Some(parent) = target_file.parent() {
println!("Create file parent {}", parent.display());
fs::create_dir_all(parent)
.with_context(|| format!("failed to create file parent {}", parent.display()))?;
}
if self.symlink {
println!("Create symlink {} to {}", target_file.display(), self.data);
if target_file.is_symlink() {
fs::remove_file(&target_file).with_context(|| {
format!("failed to remove old symlink {}", target_file.display())
})?;
}
symlink(&OsStr::new(&self.data), &target_file).with_context(|| {
format!(
"failed to create symlink {} to {}",
target_file.display(),
self.data
)
})?;
Ok(())
} else {
let action = if self.append { "Append" } else { "Create" };
println!("{action} file {}", target_file.display());
let mut file = if self.append {
fs::OpenOptions::new()
.create(true)
.append(true)
.open(&target_file)
.with_context(|| format!("failed to append file {}", target_file.display()))?
} else {
File::create(&target_file)
.with_context(|| format!("failed to create file {}", target_file.display()))?
};
file.write_all(self.data.as_bytes())?;
self.apply_perms(target_file)
}
}
fn apply_perms<P: AsRef<Path>>(&self, target: P) -> Result<()> {
let path = target.as_ref();
let mode = self
.mode
.unwrap_or_else(|| if self.directory { 0o0755 } else { 0o0644 });
let uid = self.uid.unwrap_or(!0);
let gid = self.gid.unwrap_or(!0);
// chmod
fs::set_permissions(path, fs::Permissions::from_mode(mode))
.with_context(|| format!("failed to set permissions on {}", path.display()))?;
// chown
chown(path, uid, gid, self.recursive_chown)
.with_context(|| format!("failed to chown {}", path.display()))
}
}
-42
View File
@@ -1,42 +0,0 @@
#[derive(Clone, Debug, Default, Deserialize, Serialize)]
pub struct GeneralConfig {
/// Specify a path where cookbook exists, all packages will be installed locally
pub cookbook: Option<String>,
/// Allow prompts for missing information such as user password
pub prompt: Option<bool>,
/// Total filesystem size in MB
pub filesystem_size: Option<u32>,
/// EFI partition size in MB, default to 2MB
pub efi_partition_size: Option<u32>,
/// Skip disk partitioning, assume whole disk is a partition
pub skip_partitions: Option<bool>,
/// Set a plain text password to encrypt the disk
pub encrypt_disk: Option<String>,
/// Use live disk for bootloader config, default is false
pub live_disk: Option<bool>,
/// If set, write bootloader disk into this path
pub write_bootloader: Option<String>,
/// Use AR to write files instead of FUSE-based mount
/// (bypasses FUSE, but slower and requires namespaced context such as "podman unshare")
pub no_mount: Option<bool>,
}
impl GeneralConfig {
/// Merge two config, "other" is more dominant
pub(super) fn merge(&mut self, other: GeneralConfig) {
if let Some(cookbook) = other.cookbook {
self.cookbook = Some(cookbook);
}
self.filesystem_size = other.filesystem_size.or(self.filesystem_size);
self.efi_partition_size = other.efi_partition_size.or(self.efi_partition_size);
self.skip_partitions = other.skip_partitions.or(self.skip_partitions);
if let Some(encrypt_disk) = other.encrypt_disk {
self.encrypt_disk = Some(encrypt_disk);
}
self.live_disk = other.live_disk.or(self.live_disk);
if let Some(write_bootloader) = other.write_bootloader {
self.write_bootloader = Some(write_bootloader);
}
self.no_mount = other.no_mount.or(self.no_mount);
}
}
-154
View File
@@ -1,154 +0,0 @@
use std::collections::BTreeMap;
use std::fmt::Display;
use std::fs;
use std::mem;
use std::path::{Path, PathBuf};
use anyhow::bail;
use anyhow::Context;
use anyhow::Result;
use crate::PackageConfig;
pub mod file;
#[cfg(feature = "installer")]
pub mod file_impl;
pub mod general;
pub mod package;
pub mod user;
#[derive(Clone, Debug, Default, Deserialize, Serialize)]
pub struct Config {
#[serde(default)]
pub include: Vec<PathBuf>,
#[serde(default)]
pub general: general::GeneralConfig,
#[serde(default)]
pub packages: BTreeMap<String, package::PackageConfig>,
#[serde(default)]
pub files: Vec<file::FileConfig>,
#[serde(default)]
pub users: BTreeMap<String, user::UserConfig>,
#[serde(default)]
pub groups: BTreeMap<String, user::GroupConfig>,
}
impl Config {
/// Load installer config from a TOML path
pub fn from_file(path: &Path) -> Result<Self> {
let mut config: Config = match fs::read_to_string(&path) {
Ok(config_data) => match toml::from_str(&config_data) {
Ok(config) => config,
Err(err) => {
bail!("failed to decode '{}': {}", path.display(), err);
}
},
Err(err) => {
bail!("failed to read '{}': {}", path.display(), err);
}
};
let config_dir = path.parent().unwrap();
let mut configs = mem::take(&mut config.include)
.into_iter()
.map(|path| {
Config::from_file(&config_dir.join(&path))
.with_context(|| format!("Importing from {}", path.display()))
})
.collect::<Result<Vec<Config>>>()?;
configs.push(config); // Put ourself last to ensure that it overwrites anything else.
config = configs.remove(0);
for other_config in configs {
config.merge(other_config);
}
Ok(config)
}
/// Load hardcoded install config to fetch bootloaders
pub fn bootloader_config() -> Self {
let mut bootloader_config = Config::default();
// TODO: This is unused
bootloader_config.files.push(file::FileConfig {
path: "/etc/pkg.d/50_redox".to_string(),
data: "https://static.redox-os.org/pkg".to_string(),
..Default::default()
});
bootloader_config
.packages
.insert("bootloader".to_string(), PackageConfig::default());
bootloader_config
}
pub fn merge(&mut self, other: Config) {
assert!(self.include.is_empty());
assert!(other.include.is_empty());
let Config {
include: _,
general: other_general,
packages: other_packages,
files: other_files,
users: other_users,
groups: other_groups,
} = other;
self.general.merge(other_general);
for (package, package_config) in other_packages {
self.packages.insert(package, package_config);
}
// File entries from later-included configs override earlier ones for
// the same path. Previously this was `self.files.extend(other_files)`,
// which silently accumulated duplicate paths and left the winner to
// whichever entry the installer wrote last — an invisible, order-
// dependent override that is a frequent source of "my config edit did
// nothing" confusion (e.g. an init service redefined by a legacy
// overlay config). Make the override explicit and visible: warn on the
// console and replace in place so the last definition deterministically
// wins with no duplicate left in the list.
for file in other_files {
if let Some(existing) = self.files.iter_mut().find(|f| f.path == file.path) {
eprintln!(
"config: WARNING: file '{}' redefined by a later-included config \
(override — last definition wins)",
file.path
);
*existing = file;
} else {
self.files.push(file);
}
}
for (user, user_config) in other_users {
self.users.insert(user, user_config);
}
for (group, group_config) in other_groups {
self.groups.insert(group, group_config);
}
}
}
impl Display for Config {
fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
writeln!(f, "files:")?;
for file in &self.files {
writeln!(f, "- {}", file)?;
}
writeln!(f, "users:")?;
for (name, user) in &self.users {
writeln!(f, "- {}:{}", name, user)?;
}
write!(f, "packages: ")?;
for name in self.packages.keys() {
write!(f, " {}", name)?;
}
writeln!(f, "")?;
Ok(())
}
}
-19
View File
@@ -1,19 +0,0 @@
#[derive(Clone, Debug, Deserialize, Serialize)]
#[serde(untagged)]
pub enum PackageConfig {
Empty,
Build(String),
// TODO: Sum type
Spec {
version: Option<String>,
git: Option<String>,
path: Option<String>,
},
}
impl Default for PackageConfig {
fn default() -> Self {
Self::Empty
}
}
-43
View File
@@ -1,43 +0,0 @@
use std::fmt::Display;
#[derive(Clone, Debug, Default, Deserialize, Serialize)]
pub struct UserConfig {
pub password: Option<String>,
pub uid: Option<u32>,
pub gid: Option<u32>,
pub name: Option<String>,
pub home: Option<String>,
pub shell: Option<String>,
}
#[derive(Clone, Debug, Default, Deserialize, Serialize)]
pub struct GroupConfig {
pub gid: Option<u32>,
// FIXME move this to the UserConfig struct as extra_groups
pub members: Vec<String>,
}
impl Display for UserConfig {
fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
if let Some(uid) = &self.uid {
write!(f, " uid={}", uid)?;
}
if let Some(gid) = &self.gid {
write!(f, " gid={}", gid)?;
}
if let Some(name) = &self.name {
write!(f, " name={}", name)?;
}
if let Some(home) = &self.home {
write!(f, " home={}", home)?;
}
if let Some(shell) = &self.shell {
write!(f, " shell={}", shell)?;
}
if self.password.as_ref().is_some_and(|s| !s.is_empty()) {
write!(f, " password=yes")?;
}
Ok(())
}
}
-127
View File
@@ -1,127 +0,0 @@
use std::{
cmp,
convert::TryInto,
fs::{File, OpenOptions},
io::{Read, Result, Seek, SeekFrom, Write},
path::Path,
};
#[derive(Debug)]
pub struct DiskWrapper {
disk: File,
size: u64,
block: Box<[u8]>,
seek: u64,
}
enum Buffer<'a> {
Read(&'a mut [u8]),
Write(&'a [u8]),
}
impl DiskWrapper {
pub fn open<P: AsRef<Path>>(path: P) -> Result<Self> {
let disk = OpenOptions::new().read(true).write(true).open(path)?;
let metadata = disk.metadata()?;
let size = metadata.len();
// TODO: get real block size: disk_metadata.blksize() works on disks but not image files
let block_size = 512;
let block = vec![0u8; block_size].into_boxed_slice();
Ok(Self {
disk,
size,
block,
seek: 0,
})
}
pub fn block_size(&self) -> usize {
self.block.len()
}
pub fn size(&self) -> u64 {
self.size
}
fn io<'a>(&mut self, buf: &mut Buffer<'a>) -> Result<usize> {
let buf_len = match buf {
Buffer::Read(read) => read.len(),
Buffer::Write(write) => write.len(),
};
let block_len: u64 = self.block.len().try_into().unwrap();
// Do aligned I/O quickly
if self.seek % block_len == 0 && buf_len as u64 % block_len == 0 {
self.disk.seek(SeekFrom::Start(self.seek))?;
match buf {
Buffer::Read(read) => self.disk.read_exact(read)?,
Buffer::Write(write) => self.disk.write_all(write)?,
}
self.seek = self.seek.checked_add(buf_len.try_into().unwrap()).unwrap();
return Ok(buf_len);
}
let mut i = 0;
while i < buf_len {
let block = self.seek / block_len;
let offset: usize = (self.seek % block_len).try_into().unwrap();
let remaining = buf_len.checked_sub(i).unwrap();
let len = cmp::min(remaining, self.block.len().checked_sub(offset).unwrap());
self.disk
.seek(SeekFrom::Start(block.checked_mul(block_len).unwrap()))?;
self.disk.read_exact(&mut self.block)?;
match buf {
Buffer::Read(read) => {
read[i..i.checked_add(len).unwrap()]
.copy_from_slice(&self.block[offset..offset.checked_add(len).unwrap()]);
}
Buffer::Write(write) => {
self.block[offset..offset.checked_add(len).unwrap()]
.copy_from_slice(&write[i..i.checked_add(len).unwrap()]);
self.disk
.seek(SeekFrom::Start(block.checked_mul(block_len).unwrap()))?;
self.disk.write_all(&mut self.block)?;
}
}
i = i.checked_add(len).unwrap();
self.seek = self.seek.checked_add(len.try_into().unwrap()).unwrap();
}
Ok(i)
}
}
impl Read for DiskWrapper {
fn read(&mut self, buf: &mut [u8]) -> Result<usize> {
self.io(&mut Buffer::Read(buf))
}
}
impl Seek for DiskWrapper {
fn seek(&mut self, pos: SeekFrom) -> Result<u64> {
let current: i64 = self.seek.try_into().unwrap();
let end: i64 = self.size.try_into().unwrap();
self.seek = match pos {
SeekFrom::Start(offset) => cmp::min(self.size, offset),
SeekFrom::End(offset) => cmp::max(0, cmp::min(end, end.wrapping_add(offset))) as u64,
SeekFrom::Current(offset) => {
cmp::max(0, cmp::min(end, current.wrapping_add(offset))) as u64
}
};
Ok(self.seek)
}
}
impl Write for DiskWrapper {
fn write(&mut self, buf: &[u8]) -> Result<usize> {
self.io(&mut Buffer::Write(buf))
}
fn flush(&mut self) -> Result<()> {
self.disk.flush()
}
}
-918
View File
@@ -1,918 +0,0 @@
use anyhow::Context;
use anyhow::{bail, Result};
use pkg::Library;
use rand::{rngs::OsRng, TryRngCore};
use redoxfs::{unmount_path, Disk, DiskIo, FileSystem, BLOCK_SIZE};
use termion::input::TermRead;
use crate::collision::{CollisionTracker, FileProvenance, Layer, ProvenanceSource};
use crate::config::file::FileConfig;
use crate::config::package::PackageConfig;
use crate::config::Config;
use crate::disk_wrapper::DiskWrapper;
use std::{
cell::RefCell,
collections::BTreeMap,
env,
fmt::Write as WriteFmt,
fs,
io::{self, Seek, SeekFrom, Write},
path::{Path, PathBuf},
process,
rc::Rc,
sync::mpsc::channel,
thread,
time::{SystemTime, UNIX_EPOCH},
};
pub struct DiskOption<'a> {
pub bootloader_bios: &'a [u8],
pub bootloader_efi: &'a [u8],
pub password_opt: Option<&'a [u8]>,
pub efi_partition_size: Option<u32>, //MiB
pub skip_partitions: bool,
}
pub fn get_target() -> String {
// TODO: Configurable from filesystem config?
env::var("TARGET").unwrap_or(
option_env!("TARGET").map_or("x86_64-unknown-redox".to_string(), |x| x.to_string()),
)
}
/// Converts a password to a serialized argon2rs hash, understandable
/// by redox_users. If the password is blank, the hash is blank.
fn hash_password(password: &str) -> Result<String> {
if !password.is_empty() {
let salt = format!("{:X}", OsRng.try_next_u64()?);
let config = argon2::Config::default();
let hash = argon2::hash_encoded(password.as_bytes(), salt.as_bytes(), &config)?;
Ok(hash)
} else {
Ok("".into())
}
}
fn syscall_error(err: syscall::Error) -> io::Error {
io::Error::from_raw_os_error(err.errno)
}
/// Returns a password collected from the user (plaintext)
pub fn prompt_password(prompt: &str, confirm_prompt: &str) -> Result<Option<String>> {
let stdin = io::stdin();
let mut stdin = stdin.lock();
let stdout = io::stdout();
let mut stdout = stdout.lock();
for i in 0..3 {
print!("{}", prompt);
let mut password = stdin.read_passwd(&mut stdout)?;
if let Some(password) = password.as_mut() {
*password = password.trim().to_string();
}
password.take_if(|s| s.is_empty());
if password.is_none() {
return Ok(None);
}
print!("\n{}", confirm_prompt);
let confirm_password = stdin.read_passwd(&mut stdout)?;
// Note: Actually comparing two Option<String> values
if confirm_password == password {
return Ok(password);
} else if i < 2 {
eprintln!("passwords do not match, please try again");
}
}
bail!("passwords do not match, giving up");
}
fn install_packages(config: &Config, dest: &Path, cookbook: Option<&str>) -> anyhow::Result<()> {
let target = &get_target();
let packages: Vec<&String> = config
.packages
.iter()
.filter_map(|(packagename, package)| match package {
PackageConfig::Build(rule) if rule == "ignore" => None,
_ => Some(packagename),
})
.collect();
let mut library = if let Some(cookbook) = cookbook {
let callback = pkg::callback::PlainCallback::new();
let repo = Path::new(cookbook).join("repo");
let pubkey = Path::new(cookbook).join("build");
Library::new_local(
repo,
pubkey,
dest.to_path_buf(),
target,
Rc::new(RefCell::new(callback)),
)
} else {
let callback = pkg::callback::IndicatifCallback::new();
Library::new_remote(
&vec!["https://static.redox-os.org/pkg"],
dest,
target,
Rc::new(RefCell::new(callback)),
)
}?;
let packages = pkg::PackageName::from_list(packages)?;
library.install(packages)?;
library.apply()?;
Ok(())
}
pub fn install_dir(
config: Config,
output_dir: impl AsRef<Path>,
cookbook: Option<&str>,
) -> Result<()> {
let output_dir = output_dir.as_ref();
let output_dir = output_dir.to_owned();
let mut tracker = CollisionTracker::new();
// Layer 1: config pre-install [[files]] (postinstall = false).
for file in &config.files {
if !file.postinstall {
record_config_file(&mut tracker, &output_dir, file, Layer::ConfigPreInstall)?;
file.create(&output_dir)?;
}
}
// Layer 2: package staging. install_packages() is opaque to per-file
// provenance, so we walk output_dir afterwards to register what it wrote
// and detect the Layer 2 overwrites Layer 1 collision (D-Bus regression
// class — config edits silently lost).
install_packages(&config, &output_dir, cookbook)?;
tracker.scan_package_staging(&output_dir)?;
// Layer 3: config post-install [[files]] (postinstall = true). This is
// the intentional override layer — CollisionTracker suppresses its
// collisions by design.
for file in &config.files {
if file.postinstall {
record_config_file(&mut tracker, &output_dir, file, Layer::ConfigPostInstall)?;
file.create(&output_dir)?;
}
}
let mut passwd = String::new();
let mut shadow = String::new();
let mut next_uid = 1000;
let mut next_gid = 1000;
let mut groups = vec![];
for (username, user) in config.users {
// plaintext
let password = if let Some(password) = user.password {
password
} else if config.general.prompt.unwrap_or(true) {
prompt_password(
&format!("{}: enter password: ", username),
&format!("{}: confirm password: ", username),
)?
.unwrap_or_default()
} else {
String::new()
};
let uid = user.uid.unwrap_or(next_uid);
if uid >= next_uid {
next_uid = uid + 1;
}
let gid = user.gid.unwrap_or(next_gid);
if gid >= next_gid {
next_gid = gid + 1;
}
let name = user.name.unwrap_or(username.clone());
let home = user.home.unwrap_or(format!("/home/{}", username));
let shell = user.shell.unwrap_or("/bin/ion".into());
println!("Adding user {username}:");
if password.is_empty() {
println!("\tPassword: unset");
} else {
println!("\tPassword: set");
}
println!("\tUID: {uid}");
println!("\tGID: {gid}");
println!("\tName: {name}");
println!("\tHome: {home}");
println!("\tShell: {shell}");
FileConfig::new_directory(home.clone())
.with_recursive_mod(0o700, uid, gid)
.create(&output_dir)?;
if uid >= 1000 {
prepare_user_home(&output_dir, uid, gid, &home)?;
}
let password = hash_password(&password)?;
passwd.push_str(&format!("{username};{uid};{gid};{name};{home};{shell}\n",));
shadow.push_str(&format!("{username};{password}\n"));
groups.push((username.clone(), gid, vec![username]));
}
for (group, group_config) in config.groups {
// FIXME this assumes there is no overlap between auto-created groups for users
// and explicitly specified groups.
let gid = group_config.gid.unwrap_or(next_gid);
if gid >= next_gid {
next_gid = gid + 1;
}
groups.push((group, gid, group_config.members));
}
// Layer 4: installer-builtin files (/etc/passwd, /etc/shadow, /etc/group).
// A collision here means a package or config also wrote one of these
// core files — almost always a real misconfiguration worth surfacing.
if !passwd.is_empty() {
record_installer_builtin(&mut tracker, &output_dir, "/etc/passwd")?;
FileConfig::new_file("/etc/passwd".to_string(), passwd).create(&output_dir)?;
}
if !shadow.is_empty() {
record_installer_builtin(&mut tracker, &output_dir, "/etc/shadow")?;
FileConfig::new_file("/etc/shadow".to_string(), shadow)
.with_mod(0o0600, 0, 0)
.create(&output_dir)?;
}
if !groups.is_empty() {
let mut groups_data = String::new();
for (name, gid, members) in groups {
use std::fmt::Write;
writeln!(groups_data, "{name};x;{gid};{}", members.join(","))?;
println!("Adding group {name}:");
println!("\tGID: {gid}");
println!("\tMembers: {}", members.join(", "));
}
record_installer_builtin(&mut tracker, &output_dir, "/etc/group")?;
FileConfig::new_file("/etc/group".to_string(), groups_data)
.with_mod(0o0600, 0, 0)
.create(&output_dir)?;
}
Ok(())
}
// CollisionTracker wiring helpers. Each records the provenance of one file
// write that is about to happen; the actual write (`FileConfig::create`)
// is performed by the caller. Directory creations are not recorded (see
// collision.rs module docs).
fn record_config_file(
tracker: &mut CollisionTracker,
output_dir: &Path,
file: &FileConfig,
layer: Layer,
) -> Result<()> {
if file.directory {
return Ok(());
}
let abs_path = output_dir.join(file.path.trim_start_matches('/'));
tracker.record(
abs_path,
FileProvenance {
source: ProvenanceSource::ConfigFile(file.path.clone()),
layer,
},
Some(&file.path),
)
}
fn record_installer_builtin(
tracker: &mut CollisionTracker,
output_dir: &Path,
config_path: &str,
) -> Result<()> {
tracker.record(
output_dir.join(config_path.trim_start_matches('/')),
FileProvenance {
source: ProvenanceSource::InstallerBuiltin,
layer: Layer::InstallerBuiltin,
},
Some(config_path),
)
}
fn prepare_user_home(
output_dir: &PathBuf,
uid: u32,
gid: u32,
home: &String,
) -> Result<(), anyhow::Error> {
for xdg_folder in &[
"Desktop",
"Documents",
"Downloads",
"Music",
"Pictures",
"Public",
"Templates",
"Videos",
".config",
".local",
".local/share",
".local/share/Trash",
".local/share/Trash/info",
] {
FileConfig::new_directory(format!("{}/{}", home, xdg_folder))
.with_mod(0o0700, uid, gid)
.create(output_dir)?;
}
FileConfig::new_file(
format!("{}/.config/user-dirs.dirs", home),
r#"# Produced by redox installer
XDG_DESKTOP_DIR="$HOME/Desktop"
XDG_DOCUMENTS_DIR="$HOME/Documents"
XDG_DOWNLOAD_DIR="$HOME/Downloads"
XDG_MUSIC_DIR="$HOME/Music"
XDG_PICTURES_DIR="$HOME/Pictures"
XDG_PUBLICSHARE_DIR="$HOME/Public"
XDG_TEMPLATES_DIR="$HOME/Templates"
XDG_VIDEOS_DIR="$HOME/Videos"
"#
.to_string(),
)
.with_mod(0o0600, uid, gid)
.create(output_dir)?;
let skel_dir = output_dir.join("etc/skel");
if skel_dir.is_dir() {
copy_dir_all(&skel_dir, home.clone(), output_dir, uid, gid)?;
}
Ok(())
}
fn copy_dir_all(
src: impl AsRef<Path>,
dst: String,
output_dir: &Path,
uid: u32,
gid: u32,
) -> anyhow::Result<()> {
if !Path::new(dst.as_str()).is_dir() {
FileConfig::new_directory(dst.clone())
.with_mod(0o0700, uid, gid)
.create(&output_dir)?;
}
for entry in fs::read_dir(src)? {
let entry = entry?;
let file_type = entry.file_type()?;
let dst_path = format!("{}/{}", dst, entry.file_name().display());
if file_type.is_dir() {
copy_dir_all(entry.path(), dst_path, output_dir, uid, gid)?;
} else if file_type.is_file() {
FileConfig::new_file(
dst_path,
fs::read_to_string(entry.path())
.with_context(|| format!("Reading {}", entry.path().display()))?,
)
.with_mod(0o0600, uid, gid)
.create(&output_dir)?;
} else if file_type.is_symlink() {
// TODO
}
}
Ok(())
}
pub fn with_redoxfs<D, T, F>(disk: D, password_opt: Option<&[u8]>, callback: F) -> Result<T>
where
D: Disk + Send + 'static,
F: FnOnce(FileSystem<D>) -> Result<T>,
{
let ctime = SystemTime::now().duration_since(UNIX_EPOCH)?;
let fs = FileSystem::create(disk, password_opt, ctime.as_secs(), ctime.subsec_nanos())
.map_err(syscall_error)?;
callback(fs)
}
fn decide_mount_path(mount_path: Option<&Path>) -> PathBuf {
let mount_path = mount_path.map(|p| p.to_path_buf()).unwrap_or_else(|| {
PathBuf::from(if cfg!(target_os = "redox") {
format!("file.redox_installer_{}", process::id())
} else {
format!("/tmp/redox_installer_{}", process::id())
})
});
mount_path
}
pub fn with_redoxfs_mount<D, T, F>(
fs: FileSystem<D>,
mount_path: Option<&Path>,
callback: F,
) -> Result<T>
where
D: Disk + Send + 'static,
F: FnOnce(&Path) -> Result<T>,
{
let mount_path = decide_mount_path(mount_path);
if cfg!(not(target_os = "redox")) && !mount_path.exists() {
fs::create_dir(&mount_path)?;
}
let (tx, rx) = channel();
let join_handle = {
let mount_path = mount_path.clone();
thread::spawn(move || {
let res = redoxfs::mount(fs, &mount_path, |real_path| {
tx.send(Ok(real_path.to_owned())).unwrap();
});
match res {
Ok(()) => (),
Err(err) => {
tx.send(Err(err)).unwrap();
}
};
})
};
let res = match rx.recv() {
Ok(ok) => match ok {
Ok(real_path) => callback(&real_path),
Err(err) => return Err(err.into()),
},
Err(_) => {
return Err(io::Error::new(
io::ErrorKind::NotConnected,
"redoxfs thread did not send a result",
)
.into())
}
};
unmount_path(&mount_path.as_os_str().to_str().unwrap())?;
join_handle.join().unwrap();
if cfg!(not(target_os = "redox")) {
fs::remove_dir_all(&mount_path)?;
}
res
}
pub fn with_redoxfs_ar<D, T, F>(
mut fs: FileSystem<D>,
mount_path: Option<&Path>,
callback: F,
) -> Result<T>
where
D: Disk + Send + 'static,
F: FnOnce(&Path) -> Result<T>,
{
let mount_path = decide_mount_path(mount_path);
let res = callback(Path::new(&mount_path));
if res.is_ok() {
let _end_block = fs
.tx(|tx| {
// Archive_at root node
redoxfs::archive_at(tx, Path::new(&mount_path), redoxfs::TreePtr::root())
.map_err(|err| syscall::Error::new(err.raw_os_error().unwrap()))?;
// Squash alloc log
tx.sync(true)?;
let end_block = tx.header.size() / BLOCK_SIZE;
/* TODO: Cut off any free blocks at the end of the filesystem
let mut end_changed = true;
while end_changed {
end_changed = false;
let allocator = fs.allocator();
let levels = allocator.levels();
for level in 0..levels.len() {
let level_size = 1 << level;
for &block in levels[level].iter() {
if block < end_block && block + level_size >= end_block {
end_block = block;
end_changed = true;
}
}
}
}
*/
// Update header
tx.header.size = (end_block * BLOCK_SIZE).into();
tx.header_changed = true;
tx.sync(false)?;
Ok(end_block)
})
.map_err(syscall_error)?;
// let size = (fs.block + end_block) * BLOCK_SIZE;
// fs.disk.file.set_len(size)?;
}
fs::remove_dir_all(&mount_path)?;
res
}
pub fn fetch_bootloaders(
config: &Config,
cookbook: Option<&str>,
live: bool,
) -> Result<(Vec<u8>, Vec<u8>)> {
let bootloader_dir =
PathBuf::from(format!("/tmp/redox_installer_bootloader_{}", process::id()));
if bootloader_dir.exists() {
fs::remove_dir_all(&bootloader_dir)?;
}
fs::create_dir(&bootloader_dir)?;
let mut bootloader_config = Config::bootloader_config();
bootloader_config.general = config.general.clone();
install_packages(&bootloader_config, &bootloader_dir, cookbook)?;
let boot_dir = bootloader_dir.join("usr/lib/boot");
let bios_path = boot_dir.join(if live {
"bootloader-live.bios"
} else {
"bootloader.bios"
});
let efi_path = boot_dir.join(if live {
"bootloader-live.efi"
} else {
"bootloader.efi"
});
let bios_data = if bios_path.exists() {
fs::read(bios_path)?
} else {
Vec::new()
};
let efi_data = if efi_path.exists() {
fs::read(efi_path)?
} else {
Vec::new()
};
fs::remove_dir_all(&bootloader_dir)?;
Ok((bios_data, efi_data))
}
//TODO: make bootloaders use Option, dynamically create BIOS and EFI partitions
pub fn with_whole_disk<P, F, T>(disk_path: P, disk_option: &DiskOption, callback: F) -> Result<T>
where
P: AsRef<Path>,
F: FnOnce(FileSystem<DiskIo<fscommon::StreamSlice<DiskWrapper>>>) -> Result<T>,
{
let target = get_target();
let bootloader_efi_name = match target.as_str() {
"aarch64-unknown-redox" => "BOOTAA64.EFI",
"i586-unknown-redox" | "i686-unknown-redox" => "BOOTIA32.EFI",
"x86_64-unknown-redox" => "BOOTX64.EFI",
"riscv64gc-unknown-redox" => "BOOTRISCV64.EFI",
_ => {
bail!("target '{target}' not supported");
}
};
// Open disk and read metadata
eprintln!("Opening disk {}", disk_path.as_ref().display());
let mut disk_file = DiskWrapper::open(disk_path.as_ref())?;
let disk_size = disk_file.size();
let block_size = disk_file.block_size() as u64;
if disk_option.skip_partitions {
return with_redoxfs(
DiskIo(fscommon::StreamSlice::new(
disk_file,
0,
disk_size.next_multiple_of(block_size),
)?),
disk_option.password_opt,
callback,
);
}
let gpt_block_size = match block_size {
512 => gpt::disk::LogicalBlockSize::Lb512,
_ => {
// TODO: support (and test) other block sizes
bail!("block size {block_size} not supported");
}
};
// Calculate partition offsets
let gpt_reserved = 34 * 512; // GPT always reserves 34 512-byte sectors
let mibi = 1024 * 1024;
// First megabyte of the disk is reserved for BIOS partition, wich includes GPT tables
let bios_start = gpt_reserved / block_size;
let bios_end = (mibi / block_size) - 1;
// Second megabyte of the disk is reserved for EFI partition
let efi_start = bios_end + 1;
let efi_size = if let Some(size) = disk_option.efi_partition_size {
size as u64
} else {
1
};
let efi_end = efi_start + (efi_size * mibi / block_size) - 1;
// The rest of the disk is RedoxFS, reserving the GPT table mirror at the end of disk
let redoxfs_start = efi_end + 1;
let redoxfs_end = ((((disk_size - gpt_reserved) / mibi) * mibi) / block_size) - 1;
// Format and install BIOS partition
{
// Write BIOS bootloader to disk
eprintln!(
"Write bootloader with size {:#x}",
disk_option.bootloader_bios.len()
);
disk_file.seek(SeekFrom::Start(0))?;
disk_file.write_all(&disk_option.bootloader_bios)?;
// Replace MBR tables with protective MBR
// TODO: div_ceil
let mbr_blocks = ((disk_size + block_size - 1) / block_size) - 1;
eprintln!("Writing protective MBR with disk blocks {mbr_blocks:#x}");
gpt::mbr::ProtectiveMBR::with_lb_size(mbr_blocks as u32)
.update_conservative(&mut disk_file)?;
// Open disk, mark it as not initialized
let mut gpt_disk = gpt::GptConfig::new()
.initialized(false)
.writable(true)
.logical_block_size(gpt_block_size)
.create_from_device(Box::new(&mut disk_file), None)?;
// Add BIOS boot partition
let mut partitions = BTreeMap::new();
let mut partition_id = 1;
partitions.insert(
partition_id,
gpt::partition::Partition {
part_type_guid: gpt::partition_types::BIOS,
part_guid: uuid::Uuid::new_v4(),
first_lba: bios_start,
last_lba: bios_end,
flags: 0, // TODO
name: "BIOS".to_string(),
},
);
partition_id += 1;
// Add EFI boot partition
partitions.insert(
partition_id,
gpt::partition::Partition {
part_type_guid: gpt::partition_types::EFI,
part_guid: uuid::Uuid::new_v4(),
first_lba: efi_start,
last_lba: efi_end,
flags: 0, // TODO
name: "EFI".to_string(),
},
);
partition_id += 1;
// Add RedoxFS partition
partitions.insert(
partition_id,
gpt::partition::Partition {
//TODO: Use REDOX_REDOXFS type (needs GPT crate changes)
part_type_guid: gpt::partition_types::LINUX_FS,
part_guid: uuid::Uuid::new_v4(),
first_lba: redoxfs_start,
last_lba: redoxfs_end,
flags: 0,
name: "REDOX".to_string(),
},
);
eprintln!("Writing GPT tables: {partitions:#?}");
// Initialize GPT table
gpt_disk.update_partitions(partitions)?;
// Write partition layout, returning disk file
gpt_disk.write()?;
}
// Format and install EFI partition
{
let disk_efi_start = efi_start * block_size;
let disk_efi_end = (efi_end + 1) * block_size;
let mut disk_efi =
fscommon::StreamSlice::new(&mut disk_file, disk_efi_start, disk_efi_end)?;
eprintln!(
"Formatting EFI partition with size {:#x}",
disk_efi_end - disk_efi_start
);
fatfs::format_volume(&mut disk_efi, fatfs::FormatVolumeOptions::new())?;
eprintln!("Opening EFI partition");
let fs = fatfs::FileSystem::new(&mut disk_efi, fatfs::FsOptions::new())?;
eprintln!("Creating EFI directory");
let root_dir = fs.root_dir();
root_dir.create_dir("EFI")?;
eprintln!("Creating EFI/BOOT directory");
let efi_dir = root_dir.open_dir("EFI")?;
efi_dir.create_dir("BOOT")?;
eprintln!(
"Writing EFI/BOOT/{} file with size {:#x}",
bootloader_efi_name,
disk_option.bootloader_efi.len()
);
let boot_dir = efi_dir.open_dir("BOOT")?;
let mut file = boot_dir.create_file(bootloader_efi_name)?;
file.truncate()?;
file.write_all(&disk_option.bootloader_efi)?;
}
// Format and install RedoxFS partition
eprintln!(
"Installing to RedoxFS partition with size {:#x}",
(redoxfs_end - redoxfs_start) * block_size
);
let disk_redoxfs = DiskIo(fscommon::StreamSlice::new(
disk_file,
redoxfs_start * block_size,
(redoxfs_end + 1) * block_size,
)?);
with_redoxfs(disk_redoxfs, disk_option.password_opt, callback)
}
#[cfg(not(target_os = "redox"))]
pub fn try_fast_install<D: redoxfs::Disk, F: FnMut(u64, u64)>(
_fs: &mut redoxfs::FileSystem<D>,
_progress: F,
) -> Result<bool> {
Ok(false)
}
/// Try fast install using live disk memory
#[cfg(target_os = "redox")]
pub fn try_fast_install<D: redoxfs::Disk, F: FnMut(u64, u64)>(
fs: &mut redoxfs::FileSystem<D>,
mut progress: F,
) -> Result<bool> {
use libredox::{call::MmapArgs, flag};
use std::os::fd::AsRawFd;
use syscall::PAGE_SIZE;
let phys = env::var("DISK_LIVE_ADDR")
.ok()
.and_then(|x| usize::from_str_radix(&x, 16).ok())
.unwrap_or(0);
let size = env::var("DISK_LIVE_SIZE")
.ok()
.and_then(|x| usize::from_str_radix(&x, 16).ok())
.unwrap_or(0);
if phys == 0 || size == 0 {
return Ok(false);
}
let start = (phys / PAGE_SIZE) * PAGE_SIZE;
let end = phys
.checked_add(size)
.context("phys + size overflow")?
.next_multiple_of(PAGE_SIZE);
let size = end - start;
let original = unsafe {
//TODO: unmap this memory
let file = fs::File::open("/scheme/memory/physical")?;
let base = libredox::call::mmap(MmapArgs {
fd: file.as_raw_fd() as usize,
addr: core::ptr::null_mut(),
offset: start as u64,
length: size,
prot: flag::PROT_READ,
flags: flag::MAP_SHARED,
})
.map_err(|err| anyhow::anyhow!("failed to mmap livedisk: {}", err))?;
std::slice::from_raw_parts(base as *const u8, size)
};
struct DiskLive {
original: &'static [u8],
}
impl redoxfs::Disk for DiskLive {
unsafe fn read_at(&mut self, block: u64, buffer: &mut [u8]) -> syscall::Result<usize> {
let offset = (block * redoxfs::BLOCK_SIZE) as usize;
if offset + buffer.len() > self.original.len() {
return Err(syscall::Error::new(syscall::EINVAL));
}
buffer.copy_from_slice(&self.original[offset..offset + buffer.len()]);
Ok(buffer.len())
}
unsafe fn write_at(&mut self, _block: u64, _buffer: &[u8]) -> syscall::Result<usize> {
Err(syscall::Error::new(syscall::EINVAL))
}
fn size(&mut self) -> syscall::Result<u64> {
Ok(self.original.len() as u64)
}
}
let mut fs_old = redoxfs::FileSystem::open(DiskLive { original }, None, None, false)?;
let size_old = fs_old.header.size();
let free_old = fs_old.allocator().free() * redoxfs::BLOCK_SIZE;
let used_old = size_old - free_old;
redoxfs::clone(&mut fs_old, fs, move |used| {
progress(used, used_old);
})?;
Ok(true)
}
fn install_inner(config: Config, output: &Path) -> Result<()> {
println!("Installing to {}:\n{}", output.display(), config);
let cookbook = config.general.cookbook.clone();
let cookbook = cookbook.as_ref().map(|p| p.as_str());
if output.is_dir() {
install_dir(config, output, cookbook)
} else {
if !output.is_file() {
let fs_size = config.general.filesystem_size.unwrap_or(0) as u64;
// arbitrary size approximately fit just for initfs
if fs_size < 32 {
bail!("Refusing to create image disk less than 32 MB");
}
eprintln!(
"Creating a new file to {} with size {} MB",
output.display(),
fs_size
);
let file = fs::File::create(output)?;
file.set_len(fs_size * 1024 * 1024)?;
}
let live = config.general.live_disk.unwrap_or(false);
let password_opt = config.general.encrypt_disk.clone();
let password_opt = password_opt.as_ref().map(|p| p.as_bytes());
let (bootloader_bios, bootloader_efi) = fetch_bootloaders(&config, cookbook, live)?;
if let Some(write_bootloader) = &config.general.write_bootloader {
std::fs::write(write_bootloader, &bootloader_efi)?;
}
let disk_option = DiskOption {
bootloader_bios: &bootloader_bios,
bootloader_efi: &bootloader_efi,
password_opt: password_opt,
efi_partition_size: config.general.efi_partition_size,
skip_partitions: config.general.skip_partitions.unwrap_or(false),
};
with_whole_disk(output, &disk_option, move |fs| {
if config.general.no_mount.unwrap_or(false) {
with_redoxfs_ar(fs, None, move |mount_path| {
install_dir(config, mount_path, cookbook)
})
} else {
with_redoxfs_mount(fs, None, move |mount_path| {
install_dir(config, mount_path, cookbook)
})
}
})
}
}
/// Install RedoxFS into a new disk file, or a sysroot directory.
/// This function assumes all interactive prompts resolved by the caller.
pub fn install(config: Config, output: impl AsRef<Path>) -> Result<()> {
install_inner(config, output.as_ref())
}
pub use crate::format_bytes;
+131 -42
View File
@@ -1,51 +1,140 @@
#[macro_use]
extern crate serde_derive;
//! Redox OS user and group utilities.
//!
//! The `userutils` crate contains the utilities for dealing with users and groups in Redox OS.
//! They are heavily influenced by UNIX and are, when needed, tailored to specific Redox use cases.
//!
//! These implementations strive to be as simple as possible drawing particular
//! inspiration by BSD systems. They are indeed small, by choice.
//!
//! The included utilities are:
//!
//! - `getty`: Used by `init(8)` to open and initialize the TTY line, read a login name and invoke `login(1)`.
//! - `id`: Displays user identity.
//! - `login`: Allows users to into the system.
//! - `passwd`: Allows users to modify their passwords.
//! - `su`: Allows users to substitute identity.
//! - `sudo`: Enables users to execute a command as another user.
//! - `whoami`: Display effective user ID.
// Not feature-gated: only depends on std + anyhow, so the cookbook can pull
// it in via default-features = false without the installer feature deps.
pub mod collision;
use std::io::Result as IoResult;
mod config;
#[cfg(feature = "installer")]
mod disk_wrapper;
#[cfg(feature = "installer")]
mod installer;
#[cfg(feature = "installer")]
pub use crate::installer::*;
use libredox::call::{fchown, fcntl, open};
use libredox::error::Result as SysResult;
use libredox::flag::{O_CLOEXEC, O_CREAT, O_DIRECTORY, O_NONBLOCK};
use redox_users::{All, AllGroups, Error, Result, User, auth};
pub use crate::collision::{
Collision, CollisionTracker, FileProvenance, Layer, ProvenanceSource, ERROR_MARKER,
STRICT_ENV_VAR, WARN_MARKER,
const DEFAULT_MODE: u16 = 0o700;
// Not the prettiest thing in the world, but some functionality here makes
// some of the utils much less gross
pub trait AllGroupsExt {
fn add_user_to_groups(&mut self, login: &str, groups: Vec<&str>) -> Result<()>;
fn remove_user_from_all_groups(&mut self, login: &str);
}
impl AllGroupsExt for AllGroups {
// new_groups is a comma separated list of groupnames
fn add_user_to_groups(&mut self, login: &str, new_groups: Vec<&str>) -> Result<()> {
for groupname in new_groups {
let group = match self.get_mut_by_name(groupname) {
Some(group) => group,
None => return Err(Error::UserNotFound),
};
pub use crate::config::file::FileConfig;
pub use crate::config::package::PackageConfig;
pub use crate::config::Config;
use core::fmt::Write as _;
pub fn format_bytes(len: u64) -> String {
const GB: u64 = 1024 * 1024 * 1024;
const MB: u64 = 1024 * 1024;
const KB: u64 = 1024;
fn inner(len: u64, divisor: u64, suffix: &str) -> String {
let mut s = format!("{}", len / divisor);
if s.len() == 1 {
let _ = write!(s, ".{:02}", (len % divisor) / (divisor / 100));
} else if s.len() == 2 {
let _ = write!(s, ".{:01}", (len % divisor) / (divisor / 10));
group.users.push(login.to_string());
}
let _ = write!(s, " {suffix}");
s
Ok(())
}
if len > GB {
inner(len, GB, "GB")
} else if len > MB {
inner(len, MB, "MB")
} else if len > KB {
inner(len, KB, "KB")
} else {
format!("{len} B")
/// Remove a user from all groups of which they are a member
fn remove_user_from_all_groups(&mut self, login: &str) {
for group in self.iter_mut() {
let op_pos = group.users.iter().position(|username| username == login);
if let Some(indx) = op_pos {
group.users.remove(indx);
}
}
}
}
/// Spawns a shell for the given `User`.
///
/// This function wraps the shell_cmd function of the User struct
/// from redox_users and manages the child process. It is a blocking
/// operation.
///
/// # Examples
///
/// ```
/// use redox_users::AllUsers;
///
/// let sys_users = AllUsers::new().unwrap();
/// let user = sys_users.get_by_name("goyox86");
/// spawn_shell(user).unwrap();
/// ```
pub fn spawn_shell<T: Default>(user: &User<T>) -> IoResult<i32> {
// The login name is read by a line editor (liner) that puts the console
// fd into non-blocking (and raw) mode and does not always restore it. The
// shell inherits fd 0, and an interactive shell that does blocking line
// reads on a non-blocking pty slave never receives forwarded input (the
// read returns empty). Restore blocking mode on stdin/stdout/stderr before
// spawning the shell.
const F_GETFL: usize = 3;
const F_SETFL: usize = 4;
for fd in 0..=2 {
if let Ok(flags) = fcntl(fd, F_GETFL, 0) {
let _ = fcntl(fd, F_SETFL, flags & !(O_NONBLOCK as usize));
}
}
// The login name is read with the `liner` line editor, which switches the
// console pty into raw mode (ICANON/ECHO cleared) and does not restore it.
// In raw mode the pty's line discipline never flushes a completed line to
// the slave's read buffer the way a shell's canonical `read_line` expects,
// so the interactive shell can never receive a typed command. Reset the
// terminal to sane canonical/cooked settings before exec'ing the shell.
#[cfg(target_os = "redox")]
unsafe {
let mut t: libc::termios = core::mem::zeroed();
if libc::tcgetattr(0, &mut t) == 0 {
t.c_iflag |= (libc::ICRNL | libc::IXON) as libc::tcflag_t;
t.c_oflag |= (libc::OPOST | libc::ONLCR) as libc::tcflag_t;
t.c_lflag |= (libc::ICANON
| libc::ECHO
| libc::ECHOE
| libc::ECHOK
| libc::ISIG
| libc::IEXTEN) as libc::tcflag_t;
t.c_cc[libc::VMIN] = 1;
t.c_cc[libc::VTIME] = 0;
let _ = libc::tcsetattr(0, libc::TCSANOW, &t);
}
}
let mut command = user.shell_cmd();
// redox_users' shell_cmd() forces current_dir(home). Rust's pre-exec child
// runs chdir(home) before execvp; if that chdir fails (observed on the live
// image: chdir("/home/user") errors even though the directory opens fine),
// the whole spawn aborts with the chdir errno BEFORE ever reaching execve —
// which is why the login shell never started. login has already established
// a valid working directory (the user's home if reachable, otherwise "/"),
// so hand the shell THAT validated cwd instead of the raw home path.
if let Ok(cwd) = std::env::current_dir() {
command.current_dir(cwd);
}
let mut child = command.spawn()?;
match child.wait()?.code() {
Some(code) => Ok(code),
None => Ok(1),
}
}
/// Creates a directory with 700 user:user permissions
pub fn create_user_dir<T>(user: &User<auth::Full>, dir: T) -> SysResult<()>
where
T: AsRef<str> + std::convert::AsRef<[u8]>,
{
let fd = open(dir, O_CREAT | O_DIRECTORY | O_CLOEXEC, DEFAULT_MODE)?;
fchown(fd, user.uid as u32, user.gid as u32)?;
Ok(())
}
-29
View File
@@ -1,29 +0,0 @@
#!/usr/bin/env bash
IMAGE=test.bin
QEMU_ARGS=(
-cpu max
-machine q35
-m 2048
-smp 4
-serial mon:stdio
-netdev user,id=net0
-device e1000,netdev=net0
)
if [ -e /dev/kvm ]
then
QEMU_ARGS+=(-accel kvm)
fi
set -ex
cargo build --release
rm -f "${IMAGE}"
fallocate -l 1GiB "${IMAGE}"
target/release/redox_installer -c res/test.toml "${IMAGE}"
qemu-system-x86_64 "${QEMU_ARGS[@]}" -drive "file=${IMAGE},format=raw"
-295
View File
@@ -1,295 +0,0 @@
//! Integration tests for the runtime file-collision tracker.
//!
//! These exercise the public API only (`CollisionTracker` and friends,
//! re-exported at the crate root). They live in `tests/` rather than inline
//! in `src/collision.rs` to keep the production module under the 250 pure
//! LOC ceiling and to enforce the public-API-only test contract — the
//! tracker's private helpers are not touched here, so a future internal
//! rewrite stays test-compatible as long as the public surface is stable.
use redox_installer::{
CollisionTracker, FileProvenance, Layer, ProvenanceSource, ERROR_MARKER, STRICT_ENV_VAR,
};
use std::path::PathBuf;
#[test]
fn test_no_collision_when_paths_distinct() {
// Given: an empty tracker and two distinct paths.
let mut tracker = CollisionTracker::new_with_strict(false);
let path_a = PathBuf::from("/output/etc/foo.conf");
let path_b = PathBuf::from("/output/etc/bar.conf");
// When: both paths are recorded from different layers.
tracker
.record(
path_a.clone(),
FileProvenance {
source: ProvenanceSource::ConfigFile("/etc/foo.conf".to_string()),
layer: Layer::ConfigPreInstall,
},
Some("/etc/foo.conf"),
)
.unwrap();
tracker
.record(
path_b.clone(),
FileProvenance {
source: ProvenanceSource::ConfigFile("/etc/bar.conf".to_string()),
layer: Layer::ConfigPostInstall,
},
Some("/etc/bar.conf"),
)
.unwrap();
// Then: no collisions, both paths tracked.
assert_eq!(tracker.collision_count(), 0, "distinct paths never collide");
assert_eq!(tracker.len(), 2);
assert!(tracker.collisions().is_empty());
}
#[test]
fn test_collision_warning_when_layer2_overwrites_layer1() {
// Given: a tracker with a Layer 1 (ConfigPreInstall) write to a path.
let mut tracker = CollisionTracker::new_with_strict(false);
let abs_path = PathBuf::from("/output/usr/lib/init.d/dbus");
tracker
.record(
abs_path.clone(),
FileProvenance {
source: ProvenanceSource::ConfigFile("/usr/lib/init.d/dbus".to_string()),
layer: Layer::ConfigPreInstall,
},
Some("/usr/lib/init.d/dbus"),
)
.unwrap();
assert_eq!(tracker.collision_count(), 0);
// When: Layer 2 (PackageStaging) writes the same path.
let result = tracker.record(
abs_path.clone(),
FileProvenance {
source: ProvenanceSource::Package("base".to_string()),
layer: Layer::PackageStaging,
},
Some("/usr/lib/init.d/dbus"),
);
// Then: a collision is recorded, the call succeeds (warn-only mode),
// and the collision metadata points at the right layers.
assert!(result.is_ok(), "warn-only mode must not error");
assert_eq!(
tracker.collision_count(),
1,
"Layer 2 overwriting Layer 1 is a collision"
);
let collision = &tracker.collisions()[0];
assert_eq!(collision.path, abs_path);
assert_eq!(collision.previous.layer, Layer::ConfigPreInstall);
assert_eq!(collision.current.layer, Layer::PackageStaging);
}
#[test]
fn test_no_warning_for_postinstall_override() {
// Given: a tracker where Layer 2 (PackageStaging) has written a path.
let mut tracker = CollisionTracker::new_with_strict(false);
let abs_path = PathBuf::from("/output/etc/system.conf");
tracker
.record(
abs_path.clone(),
FileProvenance {
source: ProvenanceSource::Package("base".to_string()),
layer: Layer::PackageStaging,
},
Some("/etc/system.conf"),
)
.unwrap();
assert_eq!(tracker.collision_count(), 0);
// When: Layer 3 (ConfigPostInstall) writes the same path — the
// documented intentional-override pattern.
let result = tracker.record(
abs_path.clone(),
FileProvenance {
source: ProvenanceSource::ConfigFile("/etc/system.conf".to_string()),
layer: Layer::ConfigPostInstall,
},
Some("/etc/system.conf"),
);
// Then: no collision is recorded. Layer 3 is the override layer.
assert!(result.is_ok());
assert_eq!(
tracker.collision_count(),
0,
"Layer 3 postinstall overrides are intentional and must not warn"
);
assert!(tracker.collisions().is_empty());
}
#[test]
fn test_known_safe_override_paths_dont_warn() {
// Given: a tracker where Layer 2 (PackageStaging) has written the
// package-default init service at /usr/lib/init.d/dbus.
//
// In a real install the config override at /etc/init.d/dbus would
// resolve to a different abs_path and no collision would fire. The
// known-safe rule only matters when both writes land at the same
// abs_path — e.g. when /etc/init.d is a symlink to /usr/lib/init.d,
// or in unit tests that exercise the rule directly.
let mut tracker = CollisionTracker::new_with_strict(false);
let abs_path = PathBuf::from("/output/etc/init.d/dbus");
tracker
.record(
abs_path.clone(),
FileProvenance {
source: ProvenanceSource::Package("base".to_string()),
layer: Layer::PackageStaging,
},
Some("/usr/lib/init.d/dbus"),
)
.unwrap();
assert_eq!(tracker.collision_count(), 0);
// When: a config write (Layer 1 — not Layer 3, so the layer-3
// suppression rule does not apply) targets /etc/init.d/dbus, which
// resolves to the same abs_path but matches the known-safe override
// pair (/etc/init.d over /usr/lib/init.d).
let result = tracker.record(
abs_path.clone(),
FileProvenance {
source: ProvenanceSource::ConfigFile("/etc/init.d/dbus".to_string()),
layer: Layer::ConfigPreInstall,
},
Some("/etc/init.d/dbus"),
);
// Then: no collision — the known-safe override pair suppresses the
// warning, even though the layers differ and neither is Layer 3.
assert!(result.is_ok());
assert_eq!(
tracker.collision_count(),
0,
"known-safe override pair (/etc/init.d over /usr/lib/init.d) must not warn"
);
// Sanity: the opposite direction (default after override) is NOT
// suppressed — that would be a package clobbering a config override,
// which is the D-Bus regression class.
let result2 = tracker.record(
abs_path,
FileProvenance {
source: ProvenanceSource::Package("base".to_string()),
layer: Layer::PackageStaging,
},
Some("/usr/lib/init.d/dbus-other-direction"),
);
assert!(result2.is_ok());
assert_eq!(
tracker.collision_count(),
1,
"default-after-override direction is NOT a known-safe override"
);
}
#[test]
fn test_strict_mode_promotes_collision_to_error() {
// Given: a strict-mode tracker with a Layer 1 write.
let mut tracker = CollisionTracker::new_with_strict(true);
let abs_path = PathBuf::from("/output/etc/dbus.conf");
tracker
.record(
abs_path.clone(),
FileProvenance {
source: ProvenanceSource::ConfigFile("/etc/dbus.conf".to_string()),
layer: Layer::ConfigPreInstall,
},
Some("/etc/dbus.conf"),
)
.unwrap();
// When: Layer 2 writes the same path.
let result = tracker.record(
abs_path.clone(),
FileProvenance {
source: ProvenanceSource::Package("base".to_string()),
layer: Layer::PackageStaging,
},
Some("/etc/dbus.conf"),
);
// Then: the call returns Err and the error message references the
// strict env var so the operator knows how to demote if needed.
assert!(
result.is_err(),
"strict mode must promote collisions to errors"
);
let err = result.unwrap_err().to_string();
assert!(
err.contains(ERROR_MARKER),
"strict-mode error must carry the {ERROR_MARKER} marker for log grepping"
);
assert!(
err.contains(STRICT_ENV_VAR),
"strict-mode error must name the env var so the operator can demote"
);
assert!(
err.contains("layer 1"),
"strict-mode error must name the overwritten layer"
);
assert!(
err.contains("layer 2"),
"strict-mode error must name the overwriting layer"
);
// And: the collision is still counted in the tracker's history.
assert_eq!(tracker.collision_count(), 1);
}
#[test]
fn test_scan_package_staging_detects_layer2_over_layer1_on_real_disk() {
// End-to-end: write a Layer 1 file to a tempdir, then ask
// scan_package_staging to walk it. The walk must detect the file as a
// Layer 2 write that collides with the already-recorded Layer 1 entry.
//
// This is the closest unit-level proof of the D-Bus regression class:
// a config wrote to a path, then a package stages the same path, and
// the walk catches it.
let dir = std::env::temp_dir().join(format!(
"redbear_collision_test_{}_{}",
std::process::id(),
std::time::SystemTime::now()
.duration_since(std::time::UNIX_EPOCH)
.map(|d| d.as_nanos())
.unwrap_or(0),
));
std::fs::create_dir_all(&dir).unwrap();
// Layer 1: a config writes /usr/lib/init.d/dbus.
let rel = "usr/lib/init.d/dbus";
let abs_path = dir.join(rel);
std::fs::create_dir_all(abs_path.parent().unwrap()).unwrap();
std::fs::write(&abs_path, b"# config layer 1").unwrap();
let mut tracker = CollisionTracker::new_with_strict(false);
tracker
.record(
abs_path.clone(),
FileProvenance {
source: ProvenanceSource::ConfigFile("/usr/lib/init.d/dbus".to_string()),
layer: Layer::ConfigPreInstall,
},
Some("/usr/lib/init.d/dbus"),
)
.unwrap();
assert_eq!(tracker.collision_count(), 0);
// Layer 2: the walk sees the same file on disk and flags the collision.
tracker.scan_package_staging(&dir).unwrap();
assert_eq!(
tracker.collision_count(),
1,
"scan_package_staging must catch a Layer 2 write to a Layer 1 path"
);
let _ = std::fs::remove_dir_all(&dir);
}