Sudo and signal propagation
dxuuu.xyz
dxuuu.xyz
[1]: https://github.com/nmap/nmap/commit/f2e162d2245679f420b40feb...
* https://jdebp.uk/FGA/dont-abuse-su-for-dropping-privileges.h...
One wonders if perhaps these systems weren't on to something.
Their then asserted correct solution to TIOCSTI was that su, sudo, doas, and the like should open a pseudo-terminal and get involved in pumping pseudo-terminal I/O. They were to do this as well as, presumably, managing all of setsid(), child process stopping/suspending with a signal, and setlogname() for the new session; to keep what the old books all say about keeping the same logname even though one has switched user, and being able to use the suspend command in the second shell.
* https://www.openwall.com/lists/oss-security/2017/06/03/9
* https://www.openwall.com/lists/kernel-hardening/2017/05/10/3...
Six months ago, TIOCSTI became optional in Linux.
Oof, weird inference. File inheritance is pretty well known. TIOCSTI is really esoteric.
If you have BusyBox installed, you have runit's chpst and setuidgid built in to it. And most Linux distributions not only package that but also package one or more of these toolsets; most often daemontools and runit, but nosh has an Arch package for example.
I've needed to use it in some scripts for checking/managing content on FUSE mounts which are mounted without “-o allow_root”, here calling the script through sudo doesn't do the full job as root can't access the content through the fuse-based mount so we sudo again to impersonate the user owning the mount.
----
[1] if the script may be a while doing other things before the first sudo call, you might want to run “sudo -v”² early on meaning the user can give auth at the start if needed so they don't run your script, it ask for auth a minute later, and them not notice as they are looking at something else at the time.
[2] from the manpage: -v, --validate, Update the user's cached credentials, authenticating the user if necessary.
also, sudo can be used to explicitly whitelist certain commands, so "killall processname" can work, but "rm - rf" wont. If you run the whole script as root, everyone who can edit can introduce a footgun.