--- embedaddon/rsync/support/lsh 2012/02/17 15:09:30 1.1.1.1 +++ embedaddon/rsync/support/lsh 2013/10/14 07:51:15 1.1.1.2 @@ -1,33 +1,81 @@ -#!/bin/sh +#!/usr/bin/perl # This script can be used as a "remote shell" command that is only # capable of pretending to connect to "localhost". This is useful # for testing or for running a local copy where the sender and the # receiver needs to use different options (e.g. --fake-super). If -# we get a -l USER option, we try to use "sudo -u USER" to run the -# command. +# we get -l USER, we try to become the USER, either directly (must +# be root) or by using "sudo -H -u USER" (requires --sudo option). -user='' -do_cd=y # Default path is user's home dir, just like ssh. +use strict; +use warnings; +use Getopt::Long; +use English '-no_match_vars'; -while : ; do - case "$1" in - -l) user="$2"; shift; shift ;; - -l*) user=`echo "$1" | sed 's/^-l//'`; shift ;; - --no-cd) do_cd=n; shift ;; - -*) shift ;; - localhost) shift; break ;; - *) echo "lsh: unable to connect to host $1" 1>&2; exit 1 ;; - esac -done +&Getopt::Long::Configure('bundling'); +&Getopt::Long::Configure('require_order'); +GetOptions( + 'l=s' => \( my $login_name ), + '1|2|4|6|A|a|C|f|g|k|M|N|n|q|s|T|t|V|v|X|x|Y' => sub { }, # Ignore + 'b|c|D|e|F|i|L|m|O|o|p|R|S|w=s' => sub { }, # Ignore + 'no-cd' => \( my $no_chdir ), + 'sudo' => \( my $use_sudo ), +) or &usage; +&usage unless @ARGV > 1; -if [ "$user" ]; then - prefix='' - if [ $do_cd = y ]; then - home=`perl -e "print((getpwnam('$user'))[7])"` - prefix="cd '$home' ;" - fi - sudo -H -u "$user" sh -c "$prefix $*" -else - [ $do_cd = y ] && cd - eval "${@}" -fi +my $host = shift; +if ($host =~ s/^([^@]+)\@//) { + $login_name = $1; +} +if ($host ne 'localhost') { + die "lsh: unable to connect to host $host\n"; +} + +my ($home_dir, @cmd); +if ($login_name) { + my ($uid, $gid); + if ($login_name =~ /\D/) { + $uid = getpwnam($login_name); + die "Unknown user: $login_name\n" unless defined $uid; + } else { + $uid = $login_name; + } + ($login_name, $gid, $home_dir) = (getpwuid($uid))[0,3,7]; + if ($use_sudo) { + unshift @ARGV, "cd '$home_dir' &&" unless $no_chdir; + unshift @cmd, qw( sudo -H -u ), $login_name; + $no_chdir = 1; + } else { + my $groups = "$gid $gid"; + while (my ($grgid, $grmembers) = (getgrent)[2,3]) { + if ($grgid != $gid && $grmembers =~ /(^|\s)\Q$login_name\E(\s|$)/o) { + $groups .= " $grgid"; + } + } + + my ($ruid, $euid) = ($UID, $EUID); + $GID = $EGID = $groups; + $UID = $EUID = $uid; + die "Cannot set ruid: $! (use --sudo?)\n" if $UID == $ruid && $ruid != $uid; + die "Cannot set euid: $! (use --sudo?)\n" if $EUID == $euid && $euid != $uid; + + $ENV{USER} = $ENV{USERNAME} = $login_name; + $ENV{HOME} = $home_dir; + } +} else { + $home_dir = (getpwuid($UID))[7]; +} + +unless ($no_chdir) { + chdir $home_dir or die "Unable to chdir to $home_dir: $!\n"; +} + +push @cmd, '/bin/sh', '-c', "@ARGV"; +exec @cmd; +die "Failed to exec: $!\n"; + +sub usage +{ + die <