Though the petitboot UI is a user application, it is currently being run by root only because we use getty to display it on the console. Create an unprivileged user to run the UI instead. The unix socket the pb-discover daemon sets up is accessible to "petitgroup", so that should be the gid, with arbitrary uid "petituser" to match. This is currently the chain of processes leading to the UI: 1. /etc/init.d/pb-console start console 2. /usr/libexec/petitboot/pb-console --getty --detach -- -n -i 0 console linux 3. /sbin/getty -l/usr/libexec/petitboot/pb-console -n -i 0 console linux 4. /usr/libexec/petitboot/pb-console 5. /usr/sbin/petitboot-nc Instead of (3) running the pb-console helper directly with "getty -l", we can use "agetty -a" to autologin petituser, and run pb-console via petituser's login shell: 1. /etc/init.d/pb-console start console 2. /usr/libexec/petitboot/pb-console --getty=/sbin/agetty --detach -- -a petituser -n -i console linux 3. /sbin/agetty -a petituser -n -i console linux 4. /home/petituser/.profile 5. /usr/libexec/petitboot/pb-console 6. /usr/sbin/petiboot-nc Here, everything from (4) down is running as petituser. In (4), use $PPID to determine if we're logging in via getty, so that logging in by other means will give a normal shell. Otherwise we would recurse when trying to get a shell from the menu. Signed-off-by: Reza Arbab <arbab@linux.ibm.com> [Arnout: explicitly select util-linux, even though it comes indirectly through other dependencies] Signed-off-by: Arnout Vandecappelle <arnout@mind.be>
51 lines
2.0 KiB
Plaintext
51 lines
2.0 KiB
Plaintext
config BR2_PACKAGE_PETITBOOT
|
|
bool "petitboot"
|
|
depends on BR2_PACKAGE_KEXEC_ARCH_SUPPORTS || BR2_PACKAGE_KEXEC_LITE_ARCH_SUPPORTS
|
|
depends on BR2_USE_MMU # lvm2, agetty
|
|
depends on BR2_USE_WCHAR # elfutils, kexec-lite
|
|
depends on !BR2_STATIC_LIBS # elfutils, kexec-lite, lvm2
|
|
depends on BR2_TOOLCHAIN_HAS_THREADS # elfutils, kexec-lite, lvm2
|
|
depends on BR2_PACKAGE_HAS_UDEV
|
|
depends on BR2_TOOLCHAIN_HEADERS_AT_LEAST_3_17 || !BR2_PACKAGE_KEXEC_ARCH_SUPPORTS # kexec
|
|
select BR2_PACKAGE_ELFUTILS
|
|
select BR2_PACKAGE_LVM2 # devmapper
|
|
select BR2_PACKAGE_NCURSES
|
|
select BR2_PACKAGE_NCURSES_WCHAR
|
|
# run-time dependencies
|
|
select BR2_PACKAGE_KEXEC if !BR2_PACKAGE_KEXEC_LITE_ARCH_SUPPORTS
|
|
select BR2_PACKAGE_KEXEC_LITE if BR2_PACKAGE_KEXEC_LITE_ARCH_SUPPORTS && !BR2_PACKAGE_KEXEC
|
|
select BR2_PACKAGE_LIBXCRYPT if BR2_TOOLCHAIN_USES_GLIBC
|
|
select BR2_PACKAGE_NVME if ( BR2_powerpc || BR2_powerpc64 || BR2_powerpc64le )
|
|
select BR2_PACKAGE_POWERPC_UTILS if ( BR2_powerpc || BR2_powerpc64 || BR2_powerpc64le )
|
|
select BR2_PACKAGE_UTIL_LINUX
|
|
select BR2_PACKAGE_UTIL_LINUX_AGETTY
|
|
help
|
|
Petitboot is a small kexec-based bootloader
|
|
|
|
NOTE: petitboot looks best in a UTF-8 locale; be sure there
|
|
is one listed in BR2_GENERATE_LOCALE.
|
|
|
|
http://www.kernel.org/pub/linux/kernel/people/geoff/petitboot/petitboot.html
|
|
|
|
if BR2_PACKAGE_PETITBOOT
|
|
|
|
config BR2_PACKAGE_PETITBOOT_GETTY_PORT
|
|
string "TTY port(s)"
|
|
default "console"
|
|
help
|
|
Specify a space-separated list of ports to run the petitboot
|
|
UI on. Wildcards are allowed. Example: "hvc* ttys0 ttyS*"
|
|
|
|
endif # BR2_PACKAGE_PETITBOOT
|
|
|
|
comment "petitboot needs a toolchain w/ wchar, dynamic library, threads, udev /dev management"
|
|
depends on BR2_PACKAGE_KEXEC_ARCH_SUPPORTS
|
|
depends on BR2_USE_MMU
|
|
depends on !BR2_USE_WCHAR || BR2_STATIC_LIBS || \
|
|
!BR2_TOOLCHAIN_HAS_THREADS || \
|
|
!BR2_PACKAGE_HAS_UDEV
|
|
|
|
comment "petitboot w/ kexec needs a toolchain w/ headers >= 3.17"
|
|
depends on BR2_PACKAGE_KEXEC_ARCH_SUPPORTS && !BR2_PACKAGE_KEXEC_LITE_ARCH_SUPPORTS
|
|
depends on !BR2_TOOLCHAIN_HEADERS_AT_LEAST_3_17
|