92 lines
2.7 KiB
Bash
92 lines
2.7 KiB
Bash
#!/bin/bash
|
|
|
|
# omarchy:hidden=true
|
|
# omarchy:summary=Provide internal helpers for command-scoped sudo authentication
|
|
|
|
if [[ ${BASH_SOURCE[0]} == "$0" ]]; then
|
|
echo "omarchy-security-functions is an internal function library." >&2
|
|
exit 64
|
|
fi
|
|
|
|
omarchy_security_require_privileged_bash_startup() {
|
|
[[ $- == *p* ]] || return 1
|
|
/usr/bin/env -i /usr/bin/bash -p -c '
|
|
mapfile -d "" -t argv <"/proc/$1/cmdline" || exit 1
|
|
executable=$(/usr/bin/readlink -e -- "/proc/$1/exe") || exit 1
|
|
[[ $executable == "/usr/bin/bash" &&
|
|
( ${argv[0]:-} == "/bin/bash" || ${argv[0]:-} == "/usr/bin/bash" ) &&
|
|
${argv[1]:-} == "-p" ]]
|
|
' omarchy-bash-startup "$$"
|
|
}
|
|
|
|
omarchy_security_sanitize_bash_environment() {
|
|
local script=$1
|
|
shift
|
|
local entry name environment_fd environment_pid
|
|
local -a unsets=()
|
|
|
|
# Read the raw environment: privileged Bash ignores exported functions, but
|
|
# leaves their records for ordinary child interpreters to import later.
|
|
exec {environment_fd}< <(/usr/bin/env -0)
|
|
environment_pid=$!
|
|
while IFS= read -r -d '' entry <&"$environment_fd"; do
|
|
name=${entry%%=*}
|
|
case "$name" in
|
|
BASH_ENV|ENV|SHELLOPTS|BASHOPTS|PS4|CDPATH|GLOBIGNORE|BASH_FUNC_*%%)
|
|
unsets+=(-u "$name")
|
|
;;
|
|
esac
|
|
done
|
|
exec {environment_fd}<&-
|
|
wait "$environment_pid" || return 1
|
|
if (( ${#unsets[@]} > 0 )); then
|
|
exec /usr/bin/env "${unsets[@]}" /usr/bin/bash -p -- "$script" "$@"
|
|
fi
|
|
}
|
|
|
|
omarchy_security_sudo_supports_no_update() {
|
|
local help
|
|
help=$(LC_ALL=C /usr/bin/sudo -h 2>&1) || return 1
|
|
/usr/bin/grep -Eq '^usage: sudo .*\[[^]]*N[^]]*\]' <<< "$help"
|
|
}
|
|
|
|
omarchy_security_revoke_sudo_timestamp() {
|
|
/usr/bin/sudo -k
|
|
}
|
|
|
|
omarchy_security_exit_with_revoked_sudo() {
|
|
local status=$1
|
|
trap - EXIT HUP INT TERM
|
|
if ! omarchy_security_revoke_sudo_timestamp; then
|
|
echo "Could not invalidate cached sudo authorization." >&2
|
|
(( status != 0 )) || status=1
|
|
fi
|
|
exit "$status"
|
|
}
|
|
|
|
omarchy_security_install_signal_exit_traps() {
|
|
trap 'exit 129' HUP
|
|
trap 'exit 130' INT
|
|
trap 'exit 143' TERM
|
|
}
|
|
|
|
omarchy_security_install_sudo_cleanup_traps() {
|
|
trap 'omarchy_security_exit_with_revoked_sudo "$?"' EXIT
|
|
omarchy_security_install_signal_exit_traps
|
|
}
|
|
|
|
omarchy_security_enable_no_update_sudo() {
|
|
local wrapper_dir="$OMARCHY_PATH/default/omarchy/sudo-no-update"
|
|
if ! omarchy_security_sudo_supports_no_update; then
|
|
echo "This sudo does not support --no-update; refusing mixed-trust work." >&2
|
|
return 1
|
|
fi
|
|
if [[ ! -f $wrapper_dir/sudo || ! -x $wrapper_dir/sudo ]]; then
|
|
echo "The command-scoped sudo wrapper is missing." >&2
|
|
return 1
|
|
fi
|
|
PATH="$wrapper_dir:$OMARCHY_PATH/bin:/usr/bin:/usr/sbin:/bin:/sbin"
|
|
OMARCHY_SUDO_NO_UPDATE=1
|
|
export PATH OMARCHY_SUDO_NO_UPDATE
|
|
}
|