chiark / gitweb /
main: refuse system to be started in a chroot
[elogind.git] / src / ask-password.c
1 /*-*- Mode: C; c-basic-offset: 8; indent-tabs-mode: nil -*-*/
2
3 /***
4   This file is part of systemd.
5
6   Copyright 2010 Lennart Poettering
7
8   systemd is free software; you can redistribute it and/or modify it
9   under the terms of the GNU General Public License as published by
10   the Free Software Foundation; either version 2 of the License, or
11   (at your option) any later version.
12
13   systemd is distributed in the hope that it will be useful, but
14   WITHOUT ANY WARRANTY; without even the implied warranty of
15   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
16   General Public License for more details.
17
18   You should have received a copy of the GNU General Public License
19   along with systemd; If not, see <http://www.gnu.org/licenses/>.
20 ***/
21
22 #include <sys/socket.h>
23 #include <sys/poll.h>
24 #include <sys/types.h>
25 #include <assert.h>
26 #include <string.h>
27 #include <errno.h>
28 #include <unistd.h>
29 #include <fcntl.h>
30 #include <sys/un.h>
31 #include <sys/stat.h>
32 #include <sys/signalfd.h>
33 #include <getopt.h>
34 #include <termios.h>
35 #include <limits.h>
36 #include <stddef.h>
37
38 #include "log.h"
39 #include "macro.h"
40 #include "util.h"
41 #include "strv.h"
42 #include "ask-password-api.h"
43
44 static const char *arg_icon = NULL;
45 static const char *arg_message = NULL;
46 static bool arg_use_tty = true;
47 static usec_t arg_timeout = 60 * USEC_PER_SEC;
48 static bool arg_accept_cached = false;
49 static bool arg_multiple = false;
50
51 static int help(void) {
52
53         printf("%s [OPTIONS...] MESSAGE\n\n"
54                "Query the user for a system passphrase, via the TTY or an UI agent.\n\n"
55                "  -h --help          Show this help\n"
56                "     --icon=NAME     Icon name\n"
57                "     --timeout=SEC   Timeout in sec\n"
58                "     --no-tty        Ask question via agent even on TTY\n"
59                "     --accept-cached Accept cached passwords\n"
60                "     --multiple      List multiple passwords if available\n",
61                program_invocation_short_name);
62
63         return 0;
64 }
65
66 static int parse_argv(int argc, char *argv[]) {
67
68         enum {
69                 ARG_ICON = 0x100,
70                 ARG_TIMEOUT,
71                 ARG_NO_TTY,
72                 ARG_ACCEPT_CACHED,
73                 ARG_MULTIPLE
74         };
75
76         static const struct option options[] = {
77                 { "help",          no_argument,       NULL, 'h'               },
78                 { "icon",          required_argument, NULL, ARG_ICON          },
79                 { "timeout",       required_argument, NULL, ARG_TIMEOUT       },
80                 { "no-tty",        no_argument,       NULL, ARG_NO_TTY        },
81                 { "accept-cached", no_argument,       NULL, ARG_ACCEPT_CACHED },
82                 { "multiple",      no_argument,       NULL, ARG_MULTIPLE      },
83                 { NULL,            0,                 NULL, 0                 }
84         };
85
86         int c;
87
88         assert(argc >= 0);
89         assert(argv);
90
91         while ((c = getopt_long(argc, argv, "h", options, NULL)) >= 0) {
92
93                 switch (c) {
94
95                 case 'h':
96                         help();
97                         return 0;
98
99                 case ARG_ICON:
100                         arg_icon = optarg;
101                         break;
102
103                 case ARG_TIMEOUT:
104                         if (parse_usec(optarg, &arg_timeout) < 0 || arg_timeout <= 0) {
105                                 log_error("Failed to parse --timeout parameter %s", optarg);
106                                 return -EINVAL;
107                         }
108                         break;
109
110                 case ARG_NO_TTY:
111                         arg_use_tty = false;
112                         break;
113
114                 case ARG_ACCEPT_CACHED:
115                         arg_accept_cached = true;
116                         break;
117
118                 case ARG_MULTIPLE:
119                         arg_multiple = true;
120                         break;
121
122                 case '?':
123                         return -EINVAL;
124
125                 default:
126                         log_error("Unknown option code %c", c);
127                         return -EINVAL;
128                 }
129         }
130
131         if (optind != argc-1) {
132                 help();
133                 return -EINVAL;
134         }
135
136         arg_message = argv[optind];
137         return 1;
138 }
139
140 int main(int argc, char *argv[]) {
141         int r;
142
143         log_parse_environment();
144         log_open();
145
146         if ((r = parse_argv(argc, argv)) <= 0)
147                 goto finish;
148
149         if (arg_use_tty && isatty(STDIN_FILENO)) {
150                 char *password = NULL;
151
152                 if ((r = ask_password_tty(arg_message, now(CLOCK_MONOTONIC) + arg_timeout, NULL, &password)) >= 0) {
153                         puts(password);
154                         free(password);
155                 }
156
157         } else {
158                 char **l;
159
160                 if ((r = ask_password_agent(arg_message, arg_icon, now(CLOCK_MONOTONIC) + arg_timeout, arg_accept_cached, &l)) >= 0) {
161                         char **p;
162
163                         STRV_FOREACH(p, l) {
164                                 puts(*p);
165
166                                 if (!arg_multiple)
167                                         break;
168                         }
169
170                         strv_free(l);
171                 }
172         }
173
174 finish:
175
176         return r < 0 ? EXIT_FAILURE : EXIT_SUCCESS;
177 }