X-Git-Url: http://git.iain.cx/?a=blobdiff_plain;f=opt%2Fbin%2Fbecome;h=0825bd68c65e1b02f5137a01dff8938300d465aa;hb=47ff5806af2ee0d85d1026cc6a1bd6219bdb9e26;hp=cfc498e6a8f90851c8869efc503ca910483daeb6;hpb=b4a621b41b7b6f31eb8777514e8bcb504f6006f1;p=profile.git diff --git a/opt/bin/become b/opt/bin/become index cfc498e..0825bd6 100755 --- a/opt/bin/become +++ b/opt/bin/become @@ -1,9 +1,11 @@ #!/bin/bash +chdir=0 kerberos=0 x11=0 while getopts ":kx" opt; do case $opt in + c) chdir=1;; k) kerberos=1;; x) x11=1;; esac @@ -12,8 +14,9 @@ shift $((OPTIND-1)) user="$1"; shift if [ -z "$user" ]; then - echo >&2 "Usage: become [-k] [-x] " - echo >&2 "Options: -k Delegate Kerberos credentials even if target user is not root." + echo >&2 "Usage: become [-c] [-k] [-x] " + echo >&2 "Options: -c Stay in current directory even if target user is not root." + echo >&2 " -k Delegate Kerberos credentials even if target user is not root." echo >&2 " -x Delegate X11 cookie even if target user is not root." exit 1 fi @@ -25,6 +28,7 @@ if [ -z "$uid" ]; then fi if [ $uid = 0 ]; then + chdir=1 kerberos=1 x11=1 fi @@ -37,19 +41,19 @@ BECOME="$HOME/.become" profile="$BECOME/$user" [ -f "$profile" ] || profile="$BECOME/all" -file="$(mktemp)" -if [ -n "$file" ]; then - exec 3>"$file" - exec <"$file" - rm "$file" - +file="${TMPDIR:-/tmp}/$USER.become.$user.$RANDOM.$$" +umask=$(builtin umask -p) +builtin umask 077 +if exec 3>"$file" && exec <"$file" && rm "$file"; then + builtin $umask echo >&3 "cd" echo >&3 "PROFILE_HOME='$HOME'" if [ -n "$PRINCIPAL" ]; then echo >&3 "PRINCIPAL='$PRINCIPAL'" if [ $kerberos = 1 ]; then - ccname=$(klist 2>/dev/null | sed -n 's/^Ticket cache: FILE://p') + ccname=$(klist 2>/dev/null | sed -n 's/^Ticket cache: [DF]I[LR][E:]://p') if [ -f "$ccname" ]; then + echo >&3 "export KRB5CCNAME='$KRB5CCNAME'" openssl=$(find_working openssl) if [ -n "$openssl" ]; then echo >&3 "KRB5OPENSSL='$openssl'" @@ -63,12 +67,16 @@ if [ -n "$file" ]; then else echo >&3 "unset DISPLAY" fi - - echo >&3 2>/dev/null ". $HOME/.bash_profile" - [ -f "$BECOME/all" ] && cat >&3 2>/dev/null "$BECOME/all" - [ -f "$BECOME/$user" ] && cat >&3 2>/dev/null "$BECOME/$user" +else + exit 111 fi +echo >&3 ". $HOME/.bash_profile" +[ -f "$BECOME/all" ] && cat >&3 2>/dev/null "$BECOME/all" +[ -f "$BECOME/$user" ] && cat >&3 2>/dev/null "$BECOME/$user" +[ $chdir = 1 ] && echo >&3 2>/dev/null "cd - &>/dev/null" + +exec 3>&- dir=$(dirname "$0") [ "$dir" = "." ] && dir="$PWD" exec sudo -H -u "$user" "$dir/became"