<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>7137</bug_id>
          
          <creation_ts>2015-01-13 19:29:04 +0000</creation_ts>
          <short_desc>busybox shell + shadow breaks &apos;su&apos;</short_desc>
          <delta_ts>2015-09-09 13:44:17 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>OE-Core</product>
          <component>core</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>VERIFIED</bug_status>
          <resolution>FIXED</resolution>
          
          <see_also>http://bugzilla.yoctoproject.org/show_bug.cgi?id=5359</see_also>
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>1.9</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Gary Thomas">gary</reporter>
          <assigned_to name="Saul Wold">sgw</assigned_to>
          <cc>bogdanx.a.voiculescu</cc>
    
    <cc>meta.mr.watcher</cc>
    
    <cc>meta.watcher</cc>
    
    <cc>Qi.Chen</cc>
    
    <cc>richard.purdie</cc>
          
          <qa_contact name="Bogdan Alexandru Voiculescu">bogdanx.a.voiculescu</qa_contact>
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>Don&apos;t know</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>47895</commentid>
    <comment_count>0</comment_count>
    <who name="Gary Thomas">gary</who>
    <bug_when>2015-01-13 19:29:04 +0000</bug_when>
    <thetext>A system with busybox only as the shell and shadow creates a non-working &apos;su&apos;

  root@my-target:~# su -l sys
  su: must be suid to work properly
       ... or sometimes ...
  root@my-target:~# su -l sys
  su: applet not found

This is because of this setup:
  root@tmy-target:~# ls -l /bin/su*
  lrwxrwxrwx 1 root root    14 Jan  9 21:37 /bin/su -&gt; /bin/su.shadow
  -rwsr-xr-x 1 root root 41308 Dec  8 16:38 /bin/su.shadow

When you execute &apos;su -l&apos; the actual program su.shadow tries to start a new
shell with the desired [new user] login environment via
  /bin/sh -su
but /bin/sh is marked as nosuid
  root@my-target:~# ls -l /bin/sh
  lrwxrwxrwx 1 root root 19 Jan  9 21:37 /bin/sh -&gt; /bin/busybox.nosuid

Note that the problem only happens when using &apos;su -l&apos; because of the way
/bin/su.shadow works (the execution paths are quite different depending
on whether or not -l is used).

I&apos;m not sure the best way to fix this.  A work around (which turns out to
be a common setup anyway) is to use bash for /bin/sh</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>48074</commentid>
    <comment_count>1</comment_count>
    <who name="Saul Wold">sgw</who>
    <bug_when>2015-01-20 14:19:00 +0000</bug_when>
    <thetext>This seems to be a behaviour difference between busybox&apos;s implementation and 
bash, I did some similar research into this with bug 5359 which this bug might 
be a duplicate.  We can look into busybox and try to get the upstream to 
address this.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>53712</commentid>
    <comment_count>2</comment_count>
    <who name="Saul Wold">sgw</who>
    <bug_when>2015-09-03 17:54:50 +0000</bug_when>
    <thetext>From Bug #5359

Module: openembedded-core.git
Branch: master
Commit: 6820f05dad0b4f9b9bbcf7c2a0af8c34f66199ae
URL:    
http://git.openembedded.org/?p=openembedded-core.git&amp;a=commit;h=6820f05dad0b4f9b9bbcf7c2a0af8c34f66199ae

Author: Chen Qi &lt;Qi.Chen@windriver.com&gt;
Date:   Tue Apr 21 17:30:46 2015 +0800

shadow: fix `su&apos; behaviour

0001-su.c-fix-to-exec-command-correctly.patch is removed. Below is the reason.
This patch is introduced to solve the &apos;su: applet not found&apos; problem when
executing `su -l xxx -c env&apos;. The patch references codes of previous release
of shadow. However, this patch introduces bug#5359. So it&apos;s not correct.

Let&apos;s first look at the root cause of &apos;su: applet not found&apos; problem.
This problem appears when /bin/sh is provided by busybox.
When executing `su -l xxx -c env&apos; command, the following function is invoked.
    execve(&quot;/bin/sh&quot;, [&quot;-su&quot;, &quot;-c&quot;, &quot;env&quot;], [/* 6 vars */])
Note that the argv[0] provided to new executable file (/bin/sh) is &quot;-su&quot;.
As /bin/sh is a symlink to /bin/busybox. It&apos;s /bin/busybox that is executed.
In busybox&apos;s appletlib.c, it would examine argv[0], try to find an applet
that has the same name, and then try to execute the main function of the
applet. This logic results in `su&apos; applet from busybox to be executed.
However, we default to set &apos;BUSYBOX_SPLIT_SUID&apos; to &quot;1&quot;, so &apos;su&apos; is not found.
Further more, even if we set &apos;BUSYBOX_SPLIT_SUID&apos; to &quot;0&quot;, so that &apos;su&apos; applet
is found. The whole behaviour is still not correct. Because &apos;su&apos; from shadow
takes higher priority than that from busybox, so &apos;su&apos; from busybox should never
be executed on such system unless it&apos;s specified clearly by the end user.
The logic of busybox&apos;s appletlib.c is totally correct from the point of busybox
itself. It&apos;s an integration problem.

To solve the above problem, this patch comment out SU_NAME in /etc/login.defs
so that the final function executed in shadow&apos;s su is as below.
    execve(&quot;/bin/sh&quot;, [&quot;-sh&quot;, &quot;-c&quot;, &quot;env&quot;], [/* 6 vars */])

[YOCTO #5359]
[YOCTO #7137]

Signed-off-by: Chen Qi &lt;Qi.Chen@windriver.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>53886</commentid>
    <comment_count>3</comment_count>
    <who name="Bogdan Alexandru Voiculescu">bogdanx.a.voiculescu</who>
    <bug_when>2015-09-09 13:44:17 +0000</bug_when>
    <thetext>verified on master c1df471feacaf2590216aa476ce242908dac38cf;
After building a core-image-minimal + shadow package; problem does not reproduce</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>