aboutsummaryrefslogtreecommitdiff
path: root/src/util.lisp
diff options
context:
space:
mode:
authorSean Whitton <spwhitton@spwhitton.name>2021-07-01 23:08:58 -0700
committerSean Whitton <spwhitton@spwhitton.name>2021-07-06 21:19:39 -0700
commit60d2ca122ee7dc29fc66b4364bcf79f5a7041b64 (patch)
tree60c6a0b68d5d08cec4dd12c3b9064a657a97823b /src/util.lisp
parentb98a381028b03e1b71b9ade24a9999d858134b2f (diff)
downloadconsfigurator-60d2ca122ee7dc29fc66b4364bcf79f5a7041b64.tar.gz
add POSIX-LOGIN-ENVIRONMENT and use in :SETUID connection
Signed-off-by: Sean Whitton <spwhitton@spwhitton.name>
Diffstat (limited to 'src/util.lisp')
-rw-r--r--src/util.lisp23
1 files changed, 23 insertions, 0 deletions
diff --git a/src/util.lisp b/src/util.lisp
index 73810ae..2b20d13 100644
--- a/src/util.lisp
+++ b/src/util.lisp
@@ -440,6 +440,29 @@ Should be called soon after fork(2) in child processes."
(uiop:quit 2))))
,@forms))
+(defun posix-login-environment (logname home)
+ "Reset the environment after switching UID, or similar, in a :LISP connection.
+Does not currently establish a PAM session."
+ (let ((euid (foreign-funcall "geteuid" :int))
+ (maybe-preserve '("TERM")))
+ (when (zerop euid)
+ (push "SSH_AUTH_SOCK" maybe-preserve))
+ (let ((preserved (loop for var in maybe-preserve
+ for val = (getenv var)
+ when val collect var and collect val)))
+ (unless (zerop (foreign-funcall "clearenv" :int))
+ (failed-change "clearenv(3) failed!"))
+ (loop for (var val) on preserved by #'cddr do (setf (getenv var) val)))
+ (setf (getenv "HOME") (drop-trailing-slash (unix-namestring home))
+ (getenv "USER") logname
+ (getenv "LOGNAME") logname
+ (getenv "SHELL") "/bin/sh"
+ (getenv "PATH")
+ (if (zerop euid)
+ "/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin"
+ "/usr/local/bin:/bin:/usr/bin"))
+ (uiop:chdir home)))
+
;;;; Lisp data files